From null at suse.de Wed Jul 1 08:30:09 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 08:30:09 -0000 Subject: SUSE-SU-2026:2716-1: important: Security update for pacemaker Message-ID: <178289460918.11796.12426192816536279340@b8d31ed95d57> # Security update for pacemaker Announcement ID: SUSE-SU-2026:2716-1 Release Date: 2026-06-30T15:34:32Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issue * CVE-2026-10649: denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-2716=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2716=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * pacemaker-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-debugsource-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cli-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-devel-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cli-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-libs-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-libs-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-remote-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-remote-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (noarch) * pacemaker-schemas-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cts-2.1.7+20231219.0f7f88312-150600.6.15.1 * python3-pacemaker-2.1.7+20231219.0f7f88312-150600.6.15.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * pacemaker-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-debugsource-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-devel-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cli-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cli-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-libs-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-libs-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-remote-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-remote-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * openSUSE Leap 15.6 (noarch) * pacemaker-schemas-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cts-2.1.7+20231219.0f7f88312-150600.6.15.1 * python3-pacemaker-2.1.7+20231219.0f7f88312-150600.6.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 12:30:30 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 12:30:30 -0000 Subject: SUSE-SU-2026:2717-1: important: Security update for apache2 Message-ID: <178290903038.74.8983854198219572488@f3f8e2fb38c1> # Security update for apache2 Announcement ID: SUSE-SU-2026:2717-1 Release Date: 2026-07-01T08:05:44Z Rating: important References: * bsc#1267503 * bsc#1267955 * bsc#1267956 * bsc#1267962 * bsc#1267963 * bsc#1267965 * bsc#1267969 * bsc#1267970 * bsc#1267971 * bsc#1267972 * bsc#1267976 * bsc#1267977 * bsc#1267978 Cross-References: * CVE-2026-29167 * CVE-2026-29170 * CVE-2026-34355 * CVE-2026-34356 * CVE-2026-42535 * CVE-2026-42536 * CVE-2026-43951 * CVE-2026-44119 * CVE-2026-44185 * CVE-2026-44186 * CVE-2026-44631 * CVE-2026-48913 * CVE-2026-49975 CVSS scores: * CVE-2026-29167 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29167 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29170 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-29170 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34355 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34356 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42535 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42535 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-42535 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42536 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43951 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43951 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-43951 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44119 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44119 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44186 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44186 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44186 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44631 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44631 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48913 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48913 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48913 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-49975 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-49975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978). * CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955). * CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956). * CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962). * CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963). * CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965). * CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969). * CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of service (bsc#1267970). * CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971). * CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free (bsc#1267972). * CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2717=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2717=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * apache2-tls13-devel-2.4.66-35.81.1 * apache2-worker-2.4.66-35.81.1 * apache2-devel-2.4.66-35.81.1 * apache2-tls13-debugsource-2.4.66-35.81.1 * apache2-tls13-example-pages-2.4.66-35.81.1 * apache2-tls13-worker-debuginfo-2.4.66-35.81.1 * apache2-debugsource-2.4.66-35.81.1 * apache2-example-pages-2.4.66-35.81.1 * apache2-tls13-debuginfo-2.4.66-35.81.1 * apache2-worker-debuginfo-2.4.66-35.81.1 * apache2-tls13-utils-2.4.66-35.81.1 * apache2-tls13-prefork-2.4.66-35.81.1 * apache2-tls13-worker-2.4.66-35.81.1 * apache2-utils-debuginfo-2.4.66-35.81.1 * apache2-tls13-2.4.66-35.81.1 * apache2-utils-2.4.66-35.81.1 * apache2-prefork-2.4.66-35.81.1 * apache2-tls13-utils-debuginfo-2.4.66-35.81.1 * apache2-debuginfo-2.4.66-35.81.1 * apache2-tls13-prefork-debuginfo-2.4.66-35.81.1 * apache2-2.4.66-35.81.1 * apache2-prefork-debuginfo-2.4.66-35.81.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * apache2-tls13-doc-2.4.66-35.81.1 * apache2-doc-2.4.66-35.81.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * apache2-tls13-devel-2.4.66-35.81.1 * apache2-devel-2.4.66-35.81.1 * apache2-worker-2.4.66-35.81.1 * apache2-tls13-debugsource-2.4.66-35.81.1 * apache2-tls13-example-pages-2.4.66-35.81.1 * apache2-tls13-worker-debuginfo-2.4.66-35.81.1 * apache2-debugsource-2.4.66-35.81.1 * apache2-example-pages-2.4.66-35.81.1 * apache2-prefork-debuginfo-2.4.66-35.81.1 * apache2-tls13-debuginfo-2.4.66-35.81.1 * apache2-worker-debuginfo-2.4.66-35.81.1 * apache2-tls13-utils-2.4.66-35.81.1 * apache2-tls13-prefork-2.4.66-35.81.1 * apache2-tls13-worker-2.4.66-35.81.1 * apache2-utils-debuginfo-2.4.66-35.81.1 * apache2-tls13-2.4.66-35.81.1 * apache2-prefork-2.4.66-35.81.1 * apache2-tls13-utils-debuginfo-2.4.66-35.81.1 * apache2-debuginfo-2.4.66-35.81.1 * apache2-tls13-prefork-debuginfo-2.4.66-35.81.1 * apache2-2.4.66-35.81.1 * apache2-utils-2.4.66-35.81.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * apache2-tls13-doc-2.4.66-35.81.1 * apache2-doc-2.4.66-35.81.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29167.html * https://www.suse.com/security/cve/CVE-2026-29170.html * https://www.suse.com/security/cve/CVE-2026-34355.html * https://www.suse.com/security/cve/CVE-2026-34356.html * https://www.suse.com/security/cve/CVE-2026-42535.html * https://www.suse.com/security/cve/CVE-2026-42536.html * https://www.suse.com/security/cve/CVE-2026-43951.html * https://www.suse.com/security/cve/CVE-2026-44119.html * https://www.suse.com/security/cve/CVE-2026-44185.html * https://www.suse.com/security/cve/CVE-2026-44186.html * https://www.suse.com/security/cve/CVE-2026-44631.html * https://www.suse.com/security/cve/CVE-2026-48913.html * https://www.suse.com/security/cve/CVE-2026-49975.html * https://bugzilla.suse.com/show_bug.cgi?id=1267503 * https://bugzilla.suse.com/show_bug.cgi?id=1267955 * https://bugzilla.suse.com/show_bug.cgi?id=1267956 * https://bugzilla.suse.com/show_bug.cgi?id=1267962 * https://bugzilla.suse.com/show_bug.cgi?id=1267963 * https://bugzilla.suse.com/show_bug.cgi?id=1267965 * https://bugzilla.suse.com/show_bug.cgi?id=1267969 * https://bugzilla.suse.com/show_bug.cgi?id=1267970 * https://bugzilla.suse.com/show_bug.cgi?id=1267971 * https://bugzilla.suse.com/show_bug.cgi?id=1267972 * https://bugzilla.suse.com/show_bug.cgi?id=1267976 * https://bugzilla.suse.com/show_bug.cgi?id=1267977 * https://bugzilla.suse.com/show_bug.cgi?id=1267978 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:30:04 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:30:04 -0000 Subject: SUSE-RU-2026:22392-1: moderate: Recommended update for openssl-ibmca Message-ID: <178292340439.5373.12069095174570085378@bea6e15a6baf> # Recommended update for openssl-ibmca Announcement ID: SUSE-RU-2026:22392-1 Release Date: 2026-06-22T14:12:11Z Rating: moderate References: * jsc#PED-14607 Affected Products: * SUSE Linux Enterprise Server 16.0 An update that contains one feature can now be installed. ## Description: This update for openssl-ibmca fixes the following issues: * Amended the .spec file (jsc#PED-14607) * Removing the *.la files * Upgrade openssl-ibmca to version 2.5.0 * Provider: Add support for OSSL_PKEY_PARAM_RSA_DERIVE_FROM_PQ on import * Provider: Add support for SignMessage and VerifyMessage API for ECDSA and RSA * Provider: Allow the DHKEM-IKM option for EC keygen, but use fallback provider * Provider: Allow ECDSA deterministic signatures, but use fallback * Engine: Enable external AES-GCM IV when libica is in FIPS mode * Bug fixes * Removed obsolete patches ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1021=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (s390x) * openssl-ibmca-2.5.0-160000.1.1 * openssl-ibmca-debuginfo-2.5.0-160000.1.1 * openssl-ibmca-debugsource-2.5.0-160000.1.1 ## References: * https://jira.suse.com/browse/PED-14607 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:30:24 -0000 Subject: SUSE-SU-2026:22391-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Message-ID: <178292342472.5373.14409702749916742648@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22391-1 Release Date: 2026-06-26T08:14:10Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1087=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1087=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_31-default-3-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-debuginfo-3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_31-default-3-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-debuginfo-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:30:41 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:30:41 -0000 Subject: SUSE-SU-2026:22390-1: important: Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Message-ID: <178292344120.5373.849366672216796045@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22390-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1075=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1075=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_8-default-9-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-9-160000.1.1 * kernel-livepatch-SLE16_Update_3-debugsource-9-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_8-default-9-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-9-160000.1.1 * kernel-livepatch-SLE16_Update_3-debugsource-9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:30:58 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:30:58 -0000 Subject: SUSE-SU-2026:22389-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178292345800.5373.12438984451391383883@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22389-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1074=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1074=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_29-default-4-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-debuginfo-4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_29-default-4-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-debuginfo-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:31:12 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:31:12 -0000 Subject: SUSE-SU-2026:22388-1: important: Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Message-ID: <178292347296.5373.15522988367106939350@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22388-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.28.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1073=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1073=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_7-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-5-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_7-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:31:30 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:31:30 -0000 Subject: SUSE-SU-2026:22387-1: important: Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Message-ID: <178292349000.5373.10380566586791514971@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22387-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.27.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1072=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1072=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_6-debugsource-6-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-6-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-debuginfo-6-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_6-debugsource-6-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-6-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-debuginfo-6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:31:46 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:31:46 -0000 Subject: SUSE-SU-2026:22386-1: important: Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Message-ID: <178292350670.5373.12213909098707183452@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22386-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1071=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1071=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_9-default-debuginfo-8-160000.1.1 * kernel-livepatch-SLE16_Update_4-debugsource-8-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-8-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_9-default-debuginfo-8-160000.1.1 * kernel-livepatch-SLE16_Update_4-debugsource-8-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:32:02 -0000 Subject: SUSE-SU-2026:22385-1: important: Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Message-ID: <178292352282.5373.18287010790633628675@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22385-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.7.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1070=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1070=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_2-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-debuginfo-10-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-10-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_7-default-10-160000.1.1 * kernel-livepatch-SLE16_Update_2-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-debuginfo-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:21 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:32:21 -0000 Subject: SUSE-SU-2026:22384-1: important: Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Message-ID: <178292354140.5373.15906411421805813111@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22384-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.6.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1069=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1069=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_6-default-debuginfo-12-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-12-160000.1.1 * kernel-livepatch-SLE16_Update_1-debugsource-12-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_6-default-debuginfo-12-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-12-160000.1.1 * kernel-livepatch-SLE16_Update_1-debugsource-12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:37 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:32:37 -0000 Subject: SUSE-SU-2026:22383-1: important: Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Message-ID: <178292355714.5373.17628060897495511378@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22383-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1068=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1068=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_5-default-debuginfo-14-160000.4.3 * kernel-livepatch-SLE16_Update_0-debugsource-14-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-14-160000.4.3 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_0-debugsource-14-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-14-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-debuginfo-14-160000.4.3 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:43 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:32:43 -0000 Subject: SUSE-SU-2026:22382-1: important: Security update for giflib Message-ID: <178292356373.5373.10317997759382849034@bea6e15a6baf> # Security update for giflib Announcement ID: SUSE-SU-2026:22382-1 Release Date: 2026-06-28T09:26:36Z Rating: important References: * bsc#1259836 Cross-References: * CVE-2026-26740 CVSS scores: * CVE-2026-26740 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-26740 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-26740 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-26740 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for giflib fixes the following issue * CVE-2026-26740: heap out-of-bounds read when processing a specially crafted GIF file containing a GCE block with a truncated extension byte count (bsc#1259836). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1098=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1098=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * giflib-devel-5.2.2-160000.4.1 * giflib-progs-5.2.2-160000.4.1 * giflib-progs-debuginfo-5.2.2-160000.4.1 * giflib-debugsource-5.2.2-160000.4.1 * libgif7-debuginfo-5.2.2-160000.4.1 * libgif7-5.2.2-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * giflib-devel-5.2.2-160000.4.1 * giflib-progs-5.2.2-160000.4.1 * giflib-debugsource-5.2.2-160000.4.1 * giflib-progs-debuginfo-5.2.2-160000.4.1 * libgif7-debuginfo-5.2.2-160000.4.1 * libgif7-5.2.2-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26740.html * https://bugzilla.suse.com/show_bug.cgi?id=1259836 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:49 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:32:49 -0000 Subject: SUSE-SU-2026:22381-1: moderate: Security update for alsa Message-ID: <178292356932.5373.12445089062135315881@bea6e15a6baf> # Security update for alsa Announcement ID: SUSE-SU-2026:22381-1 Release Date: 2026-06-28T08:50:00Z Rating: moderate References: * bsc#1268853 Cross-References: * CVE-2026-56109 CVSS scores: * CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56109 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for alsa fixes the following issue * CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory (bsc#1268853). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1097=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1097=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libatopology2-1.2.14-160000.3.1 * libasound2-1.2.14-160000.3.1 * alsa-topology-devel-1.2.14-160000.3.1 * libasound2-debuginfo-1.2.14-160000.3.1 * libatopology2-debuginfo-1.2.14-160000.3.1 * alsa-devel-1.2.14-160000.3.1 * alsa-debugsource-1.2.14-160000.3.1 * alsa-1.2.14-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * alsa-docs-1.2.14-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libasound2-1.2.14-160000.3.1 * libasound2-debuginfo-1.2.14-160000.3.1 * alsa-devel-1.2.14-160000.3.1 * alsa-debugsource-1.2.14-160000.3.1 * alsa-1.2.14-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * alsa-topology-devel-1.2.14-160000.3.1 * libatopology2-1.2.14-160000.3.1 * libatopology2-debuginfo-1.2.14-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * alsa-docs-1.2.14-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56109.html * https://bugzilla.suse.com/show_bug.cgi?id=1268853 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:55 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:32:55 -0000 Subject: SUSE-SU-2026:22380-1: low: Security update for loupe Message-ID: <178292357502.5373.4816999531766914453@bea6e15a6baf> # Security update for loupe Announcement ID: SUSE-SU-2026:22380-1 Release Date: 2026-06-28T08:41:36Z Rating: low References: * bsc#1249009 Cross-References: * CVE-2025-58160 CVSS scores: * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for loupe fixes the following issue * CVE-2025-58160: tracing-subscriber: untrusted input containing ANSI escape sequences can lead to terminal manipulation (bsc#1249009). Changes for loupe: * Update to version 48.2: * Check if the is-hidden property is available before reading it. * Considerably increased speed for listing other images in folders, especially for remote locations. This allows for switching to other images to become available much quicker. * Fix panics, probably occuring when using an action like 'copy', and then closing the window. The crash causes all other windows to close. * The creation date for images that don't provide a timezone was displayed as if the recorded date and time was in UTC. * Zooming in would not work via the zoom menu, if the resulting zoom state would still fit the image inside the window. * Update to version 48.1: * Crash when closing the window, probably in the exact moment when the animnation for hiding controls starts. * Editing does not work correctly if PNGs or JPEGs are already rotated via an Exif orientation entry before editing. * Printed pages don't contain anything or garbled output. This is a temporary workaround for , using the cairo renderer for the rotation and scaling of the image in the print preparation. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1096=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1096=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * loupe-debugsource-48.2-160000.1.1 * loupe-debuginfo-48.2-160000.1.1 * loupe-48.2-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * loupe-lang-48.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * loupe-debugsource-48.2-160000.1.1 * loupe-debuginfo-48.2-160000.1.1 * loupe-48.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * loupe-lang-48.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1249009 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:33:00 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:33:00 -0000 Subject: SUSE-RU-2026:22379-1: low: Recommended update for xfsprogs Message-ID: <178292358094.5373.3578346106206686342@bea6e15a6baf> # Recommended update for xfsprogs Announcement ID: SUSE-RU-2026:22379-1 Release Date: 2026-06-28T05:46:14Z Rating: low References: * bsc#1267877 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for xfsprogs fixes the following issues: Changes in xfsprogs: * mkfs: Disable some flag features by default as suggested (bsc#1267877). * Disable by default exchange-range and parent-pointers features ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1095=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1095=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * xfsprogs-6.19.0-160000.2.1 * xfsprogs-scrub-6.19.0-160000.2.1 * libhandle1-6.19.0-160000.2.1 * libhandle1-debuginfo-6.19.0-160000.2.1 * xfsprogs-devel-6.19.0-160000.2.1 * xfsprogs-debuginfo-6.19.0-160000.2.1 * xfsprogs-debugsource-6.19.0-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * xfsprogs-6.19.0-160000.2.1 * xfsprogs-scrub-6.19.0-160000.2.1 * libhandle1-6.19.0-160000.2.1 * libhandle1-debuginfo-6.19.0-160000.2.1 * xfsprogs-devel-6.19.0-160000.2.1 * xfsprogs-debuginfo-6.19.0-160000.2.1 * xfsprogs-debugsource-6.19.0-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267877 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:33:53 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:33:53 -0000 Subject: SUSE-SU-2026:22378-1: important: Security update for ImageMagick Message-ID: <178292363312.5373.9952623314767754160@bea6e15a6baf> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:22378-1 Release Date: 2026-06-26T09:13:30Z Rating: important References: * bsc#1265048 * bsc#1265373 * bsc#1268092 * bsc#1268094 * bsc#1268095 * bsc#1268096 * bsc#1268101 * bsc#1268102 * bsc#1268103 * bsc#1268105 * bsc#1268107 * bsc#1268108 * bsc#1268110 * bsc#1268111 * bsc#1268112 * bsc#1268113 * bsc#1268114 * bsc#1268116 * bsc#1268117 * bsc#1268119 * bsc#1268120 * bsc#1268121 * bsc#1268122 * bsc#1268123 * bsc#1268124 * bsc#1268125 * bsc#1268126 * bsc#1268645 * bsc#1268879 * bsc#1268880 * bsc#1269063 * bsc#1269064 Cross-References: * CVE-2026-40169 * CVE-2026-42050 * CVE-2026-42326 * CVE-2026-45031 * CVE-2026-45358 * CVE-2026-45359 * CVE-2026-45624 * CVE-2026-45664 * CVE-2026-46520 * CVE-2026-46521 * CVE-2026-46522 * CVE-2026-46523 * CVE-2026-46557 * CVE-2026-46559 * CVE-2026-46692 * CVE-2026-46693 * CVE-2026-47165 * CVE-2026-47166 * CVE-2026-48724 * CVE-2026-48733 * CVE-2026-48734 * CVE-2026-48994 * CVE-2026-49218 * CVE-2026-53460 * CVE-2026-53461 * CVE-2026-53463 * CVE-2026-53464 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56370 * CVE-2026-56371 * CVE-2026-56376 CVSS scores: * CVE-2026-40169 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40169 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42326 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42326 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-42326 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45031 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45031 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45358 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45358 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-45358 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45359 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45359 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45624 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45624 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45664 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45664 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45664 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46520 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46520 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46521 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46557 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46559 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46559 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-46559 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46692 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46692 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46693 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46693 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46693 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-47165 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-47166 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-48724 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48724 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48724 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48733 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48733 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48733 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48734 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48994 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-49218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53460 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53461 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53463 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53463 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-53464 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53464 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53464 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56370 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56370 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56370 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56370 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 0.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 0.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56376 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56376 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56376 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 32 vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues Security issues: * CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048). * CVE-2026-42326: Information disclosure via malicious IPTC input file (bsc#1268092). * CVE-2026-45031: Denial of Service due to resource policy bypass in PSD decoder (bsc#1268094). * CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102). * CVE-2026-45359: Information Disclosure via Invalid Connected-Components Value (bsc#1268095). * CVE-2026-45624: Data exposure due to image processing vulnerability (bsc#1268096). * CVE-2026-45664: Denial of Service due to excessive resource use in MNG coder (bsc#1268101). * CVE-2026-46520: Denial of Service via out-of-bounds write when processing multiple images (bsc#1268112). * CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124). * CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126). * CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125). * CVE-2026-46557: stack overflow can occur in the fx operation by passing a crafted argument due to a missing depth check (bsc#1268123). * CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 (bsc#1268121). * CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). * CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute- cache service (bsc#1268117). * CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114). * CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). * CVE-2026-48724: Heap Buffer Underwrite in Floyd-Steinberg depth dithering (bsc#1268116). * CVE-2026-48733: Infinite Loop in subimage-search with crafted image (bsc#1268119). * CVE-2026-48734: Stack Overflow in MVG decoder (bsc#1268122). * CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111). * CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110). * CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108). * CVE-2026-53461: out of bounds heap write due to an incorrect loop in the ICON decoder (bsc#1268107). * CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105). * CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser (bsc#1268103). * CVE-2026-56367: ImageMagick contains an integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out- of-bounds read (bsc#1268645). * CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing connected-components:* artifacts with invalid indices (bsc#1269063). * CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). Non security issue: * ImageMagick update 7.1.2.0-160000.9.1 is broken for softlinks (bsc#1265373). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1093=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1093=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * ImageMagick-config-7-SUSE-7.1.2.0-160000.10.1 * ImageMagick-doc-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.10.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libMagick++-7_Q16HDRI5-7.1.2.0-160000.10.1 * libMagick++-devel-7.1.2.0-160000.10.1 * ImageMagick-devel-7.1.2.0-160000.10.1 * ImageMagick-extra-7.1.2.0-160000.10.1 * ImageMagick-7.1.2.0-160000.10.1 * perl-PerlMagick-7.1.2.0-160000.10.1 * ImageMagick-debugsource-7.1.2.0-160000.10.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.10.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.10.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.10.1 * ImageMagick-debuginfo-7.1.2.0-160000.10.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.10.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.10.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.10.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.10.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libMagick++-7_Q16HDRI5-7.1.2.0-160000.10.1 * libMagick++-devel-7.1.2.0-160000.10.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.10.1 * ImageMagick-extra-7.1.2.0-160000.10.1 * ImageMagick-devel-7.1.2.0-160000.10.1 * perl-PerlMagick-7.1.2.0-160000.10.1 * ImageMagick-debugsource-7.1.2.0-160000.10.1 * ImageMagick-7.1.2.0-160000.10.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.10.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.10.1 * ImageMagick-debuginfo-7.1.2.0-160000.10.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.10.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.10.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.10.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.10.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * ImageMagick-config-7-SUSE-7.1.2.0-160000.10.1 * ImageMagick-doc-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40169.html * https://www.suse.com/security/cve/CVE-2026-42050.html * https://www.suse.com/security/cve/CVE-2026-42326.html * https://www.suse.com/security/cve/CVE-2026-45031.html * https://www.suse.com/security/cve/CVE-2026-45358.html * https://www.suse.com/security/cve/CVE-2026-45359.html * https://www.suse.com/security/cve/CVE-2026-45624.html * https://www.suse.com/security/cve/CVE-2026-45664.html * https://www.suse.com/security/cve/CVE-2026-46520.html * https://www.suse.com/security/cve/CVE-2026-46521.html * https://www.suse.com/security/cve/CVE-2026-46522.html * https://www.suse.com/security/cve/CVE-2026-46523.html * https://www.suse.com/security/cve/CVE-2026-46557.html * https://www.suse.com/security/cve/CVE-2026-46559.html * https://www.suse.com/security/cve/CVE-2026-46692.html * https://www.suse.com/security/cve/CVE-2026-46693.html * https://www.suse.com/security/cve/CVE-2026-47165.html * https://www.suse.com/security/cve/CVE-2026-47166.html * https://www.suse.com/security/cve/CVE-2026-48724.html * https://www.suse.com/security/cve/CVE-2026-48733.html * https://www.suse.com/security/cve/CVE-2026-48734.html * https://www.suse.com/security/cve/CVE-2026-48994.html * https://www.suse.com/security/cve/CVE-2026-49218.html * https://www.suse.com/security/cve/CVE-2026-53460.html * https://www.suse.com/security/cve/CVE-2026-53461.html * https://www.suse.com/security/cve/CVE-2026-53463.html * https://www.suse.com/security/cve/CVE-2026-53464.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56370.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56376.html * https://bugzilla.suse.com/show_bug.cgi?id=1265048 * https://bugzilla.suse.com/show_bug.cgi?id=1265373 * https://bugzilla.suse.com/show_bug.cgi?id=1268092 * https://bugzilla.suse.com/show_bug.cgi?id=1268094 * https://bugzilla.suse.com/show_bug.cgi?id=1268095 * https://bugzilla.suse.com/show_bug.cgi?id=1268096 * https://bugzilla.suse.com/show_bug.cgi?id=1268101 * https://bugzilla.suse.com/show_bug.cgi?id=1268102 * https://bugzilla.suse.com/show_bug.cgi?id=1268103 * https://bugzilla.suse.com/show_bug.cgi?id=1268105 * https://bugzilla.suse.com/show_bug.cgi?id=1268107 * https://bugzilla.suse.com/show_bug.cgi?id=1268108 * https://bugzilla.suse.com/show_bug.cgi?id=1268110 * https://bugzilla.suse.com/show_bug.cgi?id=1268111 * https://bugzilla.suse.com/show_bug.cgi?id=1268112 * https://bugzilla.suse.com/show_bug.cgi?id=1268113 * https://bugzilla.suse.com/show_bug.cgi?id=1268114 * https://bugzilla.suse.com/show_bug.cgi?id=1268116 * https://bugzilla.suse.com/show_bug.cgi?id=1268117 * https://bugzilla.suse.com/show_bug.cgi?id=1268119 * https://bugzilla.suse.com/show_bug.cgi?id=1268120 * https://bugzilla.suse.com/show_bug.cgi?id=1268121 * https://bugzilla.suse.com/show_bug.cgi?id=1268122 * https://bugzilla.suse.com/show_bug.cgi?id=1268123 * https://bugzilla.suse.com/show_bug.cgi?id=1268124 * https://bugzilla.suse.com/show_bug.cgi?id=1268125 * https://bugzilla.suse.com/show_bug.cgi?id=1268126 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1268880 * https://bugzilla.suse.com/show_bug.cgi?id=1269063 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:03 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:34:03 -0000 Subject: SUSE-SU-2026:22377-1: important: Security update for tar Message-ID: <178292364340.5373.17199562086305047283@bea6e15a6baf> # Security update for tar Announcement ID: SUSE-SU-2026:22377-1 Release Date: 2026-06-26T09:13:30Z Rating: important References: * bsc#1261900 * bsc#1265450 * bsc#1267189 Cross-References: * CVE-2025-45582 * CVE-2026-5704 CVSS scores: * CVE-2025-45582 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-45582 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-45582 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L * CVE-2026-5704 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-5704 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-5704 ( NVD ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-5704 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for tar fixes the following issues * CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900). * Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1092=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1092=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * tar-debugsource-1.35-160000.4.1 * tar-rmt-debuginfo-1.35-160000.4.1 * tar-debuginfo-1.35-160000.4.1 * tar-1.35-160000.4.1 * tar-rmt-1.35-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tar-backup-scripts-1.35-160000.4.1 * tar-lang-1.35-160000.4.1 * tar-doc-1.35-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tar-backup-scripts-1.35-160000.4.1 * tar-lang-1.35-160000.4.1 * tar-doc-1.35-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * tar-debugsource-1.35-160000.4.1 * tar-rmt-debuginfo-1.35-160000.4.1 * tar-debuginfo-1.35-160000.4.1 * tar-1.35-160000.4.1 * tar-rmt-1.35-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-45582.html * https://www.suse.com/security/cve/CVE-2026-5704.html * https://bugzilla.suse.com/show_bug.cgi?id=1261900 * https://bugzilla.suse.com/show_bug.cgi?id=1265450 * https://bugzilla.suse.com/show_bug.cgi?id=1267189 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:15 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:34:15 -0000 Subject: SUSE-SU-2026:22376-1: important: Security update for google-guest-agent Message-ID: <178292365529.5373.17854368980954024266@bea6e15a6baf> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:22376-1 Release Date: 2026-06-26T08:17:18Z Rating: important References: * bsc#1243254 * bsc#1243505 * bsc#1260264 * bsc#1266171 * bsc#1266603 Cross-References: * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266171). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266171). Changes for google-guest-agent: * Update to version 20260529.00 * Dependency updates (#616) * from version 20260522.00 * Fix improper umask calculation on socket creation (#614) * from version 20260520.01 * Update OWNERS (#609) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) (bsc#1260264, CVE-2026-33186) * Update to version 20250506.01 (bsc#1243254, bsc#1243505) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1091=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1091=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * google-guest-agent-20260529.00-160000.1.1 * google-guest-agent-debuginfo-20260529.00-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * google-guest-agent-20260529.00-160000.1.1 * google-guest-agent-debuginfo-20260529.00-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1243254 * https://bugzilla.suse.com/show_bug.cgi?id=1243505 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1266171 * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:19 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:34:19 -0000 Subject: SUSE-RU-2026:22375-1: moderate: Recommended update for plexus-archiver, apache-commons-compress Message-ID: <178292365939.5373.16347431015356700364@bea6e15a6baf> # Recommended update for plexus-archiver, apache-commons-compress Announcement ID: SUSE-RU-2026:22375-1 Release Date: 2026-06-26T08:17:17Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for plexus-archiver, apache-commons-compress fixes the following issues: Changes in plexus-archiver: * we now have the dependencies to be able to build the zstd support Changes in apache-commons-compress: Update to 1.28.0 * New Features * Add GzipParameters.getModificationInstant() * Add GzipParameters.setModificationInstant(Instant) * Add GzipParameters.OS, setOS(OS), getOS() * Add GzipParameters.toString() * COMPRESS-638: Add GzipParameters.setFileNameCharset(Charset) and getFileNameCharset() to override the default ISO-8859-1 Charset * Add support for gzip extra subfields, see GzipParameters.setExtra(HeaderExtraField) * Add CompressFilterOutputStream and refactor to use * Add ZipFile.stream() * GzipCompressorInputStream reads the modification time (MTIME) and stores its value incorrectly multiplied by 1,000 * GzipCompressorInputStream writes the modification time (MTIME) the value incorrectly divided by 1,000 * Add optional FHCRC to GZIP header * Add GzipCompressorInputStream.Builder allowing to customize the file name and comment Charsets * Add GzipCompressorInputStream.Builder .setOnMemberStart(IOConsumer) to monitor member parsing * Add GzipCompressorInputStream.Builder .setOnMemberEnd(IOConsumer) to monitor member parsing * Add PMD check to default Maven goal * Add SevenZFile.Builder.setMaxMemoryLimitKiB(int) * Add MemoryLimitException.MemoryLimitException(long, int, Throwable) and deprecate MemoryLimitException .MemoryLimitException(long, int, Exception) * COMPRESS-692: Add support for zstd compression in zip archives * Add support for XZ compression in ZIP archives * COMPRESS-695: Add ZipArchiveInputStream .createZstdInputStream(InputStream) to provide a different InputStream implementation for Zstandard (Zstd) * Add org.apache.commons.compress.harmony.pack200 .Pack200Exception.Pack200Exception(String, Throwable) * COMPRESS-697: Move BitStream.nextBit() method to BitInputStream * Add org.apache.commons.compress.compressors.lzma .LZMACompressorInputStream.builder/Builder() * Add org.apache.commons.compress.compressors.lzma .LZMACompressorOutputStream.builder/Builder() * Add org.apache.commons.compress.compressors.xz .XZCompressorInputStream.builder/Builder() * Add org.apache.commons.compress.compressors.xz .XZCompressorOutputStream.builder/Builder() * Add org.apache.commons.compress.compressors.xz .ZstdCompressorOutputStream.builder/Builder() * Add org.apache.commons.compress.compressors.xz.ZstdConstants * Add org.apache.commons.compress.archivers.ArchiveException .requireNonNull(T, Supplier) * Add org.apache.commons.compress.compressors .CompressorException as the root for all custom exceptions ArchiveException and CompressorException * Add ArchiveException.ArchiveException(String, Throwable) * Add ArchiveException.ArchiveException(Throwable) * Add org.apache.commons.compress.archivers.sevenz .SevenZArchiveEntry.isEmptyStream() * Add generics for org.apache.commons.compress.compressors .CompressorStreamProvider.createCompressorOutputStream(String, T) * Fixed Bugs * COMPRESS-686: Better exception messages in SeekableInMemoryByteChannel * COMPRESS-691: ZipArchiveOutputStream.addRawArchiveEntry() should check is2PhaseSource * ArchiveException extends IOException * CompressorException extends IOException * Update outdated descriptions in IOUtils and IOUtilsTest * Remove unused local variable in ZipFile * Optimize ZipEightByteInteger * ZipEightByteInteger.toString() now returns a number string without text prefix, like BigInteger * Throw an IllegalArgumentException when a file name or comment in gzip parameters encodes to a byte array with a 0 byte * Update outdated links in ZipMethod Javadoc * Deprecate ZipUtil.signedByteToUnsignedInt(byte) in favor of Byte.toUnsignedInt(byte) * ZipArchiveOutputStream.close() does not close its underlying output stream * ZipArchiveOutputStream.close() does not close its underlying output stream * Don't use deprecated code in TarArchiveInputStream * Don't use deprecated code in TarFile * CpioArchiveInputStream.read(byte[], int, int) now throws an IOException on a data pad count mismatch * CpioArchiveInputStream.readNewEntry(boolean) now throws an IOException on a header pad count mismatch * CpioArchiveInputStream.readOldBinaryEntry(boolean) now throws an IOException on a header pad count mismatch * Fix Javadoc and names in the org.apache.commons.compress .archivers.sevenz package to specify kibibyte scale in memory limits * Fix Javadoc and names in the org.apache.commons.compress .compressors.lzw package to specify kibibyte scale in memory limits * Fix Javadoc and names in the org.apache.commons.compress .compressors.z package to specify kibibyte scale in memory limits * Refactor LZ77Compressor block classes to reduce duplication * Package-private and private classes can be final * Deprecate ArjArchiveEntry.HostOs.HostOs() * Drop coveralls reference (no longer needed) * Some ZIP operations won't read all data from a non-blocking file channel * COMPRESS-696: ZipArchiveInputStream.getCompressedCount() throws NullPointerException if called before getNextEntry() * org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getConstantPoolEntry(int, long) now throws Pack200Exception instead of Error and does better range checking of the index argument * org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getInitMethodPoolEntry(int, long, String) now throws Pack200Exception instead of Error and does better range checking of the index argument * org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getInitMethodPoolEntry(int, long, String) now throws Pack200Exception instead of Error on bad constant pool type input * org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getClassSpecificPoolEntry(int, long, String) now throws Pack200Exception instead of Error on bad constant pool type input * org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getClassPoolEntry(String) now throws Pack200Exception instead of Error on some bad inputs and states * org.apache.commons.compress.harmony.unpack200.bytecode .ByteCode.extractOperands(OperandManager, Segment, int) now throws Pack200Exception instead of Error on some bad inputs and states * org.apache.commons.compress.harmony.unpack200.bytecode.forms .ByteCodeForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states * org.apache.commons.compress.harmony.unpack200.bytecode .CodeAttribute.CodeAttribute(int, int, byte[], Segment, OperandManager, List) now throws Pack200Exception instead of Error on some bad inputs and states * org.apache.commons.compress.harmony.unpack200.bytecode.forms .IMethodRefForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states * org.apache.commons.compress.harmony.unpack200.bytecode.forms .MultiANewArrayForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states * org.apache.commons.compress.harmony.unpack200.bytecode.forms .NewClassRefForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states * org.apache.commons.compress.harmony.unpack200.bytecode.forms .ReferenceForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states * Deprecate org.apache.commons.compress.harmony.pack200 .CanonicalCodecFamilies.CanonicalCodecFamilies() * Deprecate FileNameUtils#getBaseName(Path) * Deprecate FileNameUtils#getExtension(Path) * org.apache.commons.compress.harmony.unpack200.Archive.unpack() should not log to system out (the console) * [site] Fix minor zip docs type: remove extraneous 'a' * Throw a better exception in org.apache.commons.compress .archivers.sevenz.SevenZFile.readFilesInfo(ByteBuffer, Archive) * MemoryLimitException now extends CompressException instead of IOException (CompressException extends IOException) * DumpArchiveException now extends ArchiveException instead of IOException (ArchiveException extends CompressException) * PasswordRequiredException now extends CompressException instead of IOException (CompressException extends IOException) * Pack200Exception now extends CompressException instead of IOException (CompressException extends IOException) * ArArchiveInputStream.getBSDLongName(String) now throws its EOFException with a message * ZipEncodingHelper.getZipEncoding(*) can throw NullPointerException and IllegalArgumentException on bad input instead of returning a value using the default Charset * Javadoc improvements throughout * COMPRESS-699: ArchiveStreamFactory.detect(inputStream) ArchiveException for TAR regression * COMPRESS-700: Can't detect file flutter_awesome_buttons-0.1.0.tar as a TAR file * Deprecate org.apache.commons.compress.utils.TimeUtils .toUnixTime(FileTime) in favor of org.apache.commons.io.file .attribute.FileTimes.toUnixTime(FileTime) * Deprecate org.apache.commons.compress.utils.TimeUtils .truncateToHundredNanos(FileTime) * Changes * Bump org.apache.commons:commons-parent from 72 to 85 * Bump com.github.luben:zstd-jni from 1.5.6-4 to 1.5.7-4 * Bump org.apache.commons:commons-lang3 from 3.16.0 to 3.18.0 * Bump commons-io:commons-io from 2.16.1 to 2.20.0 * Bump com.github.marschall:memoryfilesystem from 2.8.0 to 2.8.1 * Bump org.ow2.asm:asm from 9.7 to 9.7.1 * Bump commons-codec:commons-codec from 1.17.1 to 1.19.0 * Removed * COMPRESS-638: GzipCompressorOutputStream no longer percent-endcodes in US-ASCII a file name or comment that the Charset in GzipParameters.setFileNameCharset(Charset) cannot encode * Remove ZstdCompressorOutputStream.toString(), it was misleading by returning the delegate's toString() * Changes of version 1.27.1 * Fixed Bugs * COMPRESS-686: Compression into BZip2 format has unexpected end of file when using a BufferedOutputStream * Changes * Bump org.apache.commons:commons-lang3 from 3.15.0 to 3.16.0 * Changes of version 1.27.0 * New Features * Add ArchiveInputStream.forEach(IOConsumer) * Add ArchiveInputStream.iterator() * Add ArchiveOutputStream.isFinished() * Add ArchiveOutputStream.checkFinished() * Fixed Bugs * Fix PMD UnnecessaryFullyQualifiedName and others * COMPRESS-681: Support reading a 7z file that writing archive properties * Upgrade commons-io from 2.15.1 to 2.16.1 * CompressorOutputStream now extends FilterOutputStream * ArchiveOutputStream now extends FilterOutputStream * COMPRESS-685: Update Javadoc description for GzipCompressorInputStream * Replace FileNameUtil.getCompressedFileName(String) use of Locale.ENGLISH with Locale.ROOT * Fix SpotBugs DLS_DEAD_LOCAL_STORE in SevenZFile.readPackInfo(ByteBuffer, Archive) * Fix SpotBugs NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE in ZipFile.openZipChannel(Path, long, OpenOption[]) * Fix SpotBugs UC_USELESS_OBJECT in unpack200.CpBands.parseCpSignature(InputStream) * Fix PMD UselessOverridingMethod in unpack200.bytecode.InnerClassesAttribute * Fix PMD UselessOverridingMethod in unpack200.bytecode.LineNumberTableAttribute * Fix PMD CheckSkipResult in ZipArchiveInputStream.closeEntry() * Changes * COMPRESS-684: Replace assert with Exception * Bump org.apache.commons:commons-parent from 69 to 72 * Bump PMD from 6.x to 7.2.0 * Bump commons-codec:commons-codec from 1.17.0 to 1.17.1 * Bump org.apache.commons:commons-lang3 from 3.14.0 to 3.15.0 * Bump com.github.luben:zstd-jni from 1.5.6-3 to 1.5.6-4 * Bump org.tukaani:xz from 1.9 to 1.10 * Bump org.hamcrest:hamcrest from 2.2 to 3.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1090=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1090=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * plexus-archiver-javadoc-4.11.0-160000.2.1 * apache-commons-compress-javadoc-1.28.0-160000.1.1 * plexus-archiver-4.11.0-160000.2.1 * apache-commons-compress-1.28.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * apache-commons-compress-javadoc-1.28.0-160000.1.1 * apache-commons-compress-1.28.0-160000.1.1 * plexus-archiver-javadoc-4.11.0-160000.2.1 * plexus-archiver-4.11.0-160000.2.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:23 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:34:23 -0000 Subject: SUSE-RU-2026:22374-1: moderate: Recommended update for rsync Message-ID: <178292366314.5373.13214299432421903287@bea6e15a6baf> # Recommended update for rsync Announcement ID: SUSE-RU-2026:22374-1 Release Date: 2026-06-26T08:11:56Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for rsync fixes the following issue: * Remove unused patch from package ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1085=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1085=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * rsync-debuginfo-3.4.1-160000.5.1 * rsync-debugsource-3.4.1-160000.5.1 * rsync-3.4.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * rsync-debuginfo-3.4.1-160000.5.1 * rsync-debugsource-3.4.1-160000.5.1 * rsync-3.4.1-160000.5.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:31 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:34:31 -0000 Subject: SUSE-SU-2026:22373-1: important: Security update for python-tornado6 Message-ID: <178292367135.5373.13671939596514061959@bea6e15a6baf> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:22373-1 Release Date: 2026-06-26T08:00:10Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1089=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1089=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-tornado6-6.5-160000.5.1 * python-tornado6-debugsource-6.5-160000.5.1 * python313-tornado6-debuginfo-6.5-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-tornado6-6.5-160000.5.1 * python-tornado6-debugsource-6.5-160000.5.1 * python313-tornado6-debuginfo-6.5-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:41 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:34:41 -0000 Subject: SUSE-SU-2026:22372-1: important: Security update for python-python-multipart Message-ID: <178292368109.5373.14414840168019496188@bea6e15a6baf> # Security update for python-python-multipart Announcement ID: SUSE-SU-2026:22372-1 Release Date: 2026-06-26T08:00:10Z Rating: important References: * bsc#1268488 * bsc#1268496 * bsc#1268500 * bsc#1268506 Cross-References: * CVE-2026-53537 * CVE-2026-53538 * CVE-2026-53539 * CVE-2026-53540 CVSS scores: * CVE-2026-53537 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53537 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53537 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53537 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53538 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53538 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53538 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53539 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53539 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53539 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53540 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53540 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53540 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for python-python-multipart fixes the following issues * CVE-2026-53537: multipart/form-data with extended parameters can lead to file or parameter smuggling (bsc#1268506). * CVE-2026-53538: urlencoded requests containing semicolons can lead to form field smuggling (bsc#1268496). * CVE-2026-53539: small crafted body can cause a denial of service (bsc#1268500). * CVE-2026-53540: crafted request buffers can lead to degrading availability (bsc#1268488). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1088=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1088=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-python-multipart-0.0.20-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-python-multipart-0.0.20-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53537.html * https://www.suse.com/security/cve/CVE-2026-53538.html * https://www.suse.com/security/cve/CVE-2026-53539.html * https://www.suse.com/security/cve/CVE-2026-53540.html * https://bugzilla.suse.com/show_bug.cgi?id=1268488 * https://bugzilla.suse.com/show_bug.cgi?id=1268496 * https://bugzilla.suse.com/show_bug.cgi?id=1268500 * https://bugzilla.suse.com/show_bug.cgi?id=1268506 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:45 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:34:45 -0000 Subject: SUSE-RU-2026:22371-1: moderate: Recommended update for objectweb-asm Message-ID: <178292368520.5373.8609249933616540037@bea6e15a6baf> # Recommended update for objectweb-asm Announcement ID: SUSE-RU-2026:22371-1 Release Date: 2026-06-26T08:00:10Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for objectweb-asm fixes the following issue: Change in objectweb-asm: * Sync version with factory to 9.10.1 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1086=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1086=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * objectweb-asm-javadoc-9.10.1-160000.1.1 * objectweb-asm-9.10.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * objectweb-asm-javadoc-9.10.1-160000.1.1 * objectweb-asm-9.10.1-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:59 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:34:59 -0000 Subject: SUSE-SU-2026:22370-1: important: Security update for python-Markdown, python-joblib, python-handy-archives, python-apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve Message-ID: <178292369939.5373.3108902637261897402@bea6e15a6baf> # Security update for python-Markdown, python-joblib, python-handy-archives, python-apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve Announcement ID: SUSE-SU-2026:22370-1 Release Date: 2026-06-26T07:41:13Z Rating: important References: * bsc#1256310 * bsc#1256316 * bsc#1258223 * bsc#1261918 * bsc#1263802 * bsc#1268243 * bsc#1268324 Cross-References: * CVE-2026-44889 CVSS scores: * CVE-2026-44889 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-44889 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44889 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and has six fixes can now be installed. ## Description: This update for python-Markdown, python-joblib, python-handy-archives, python- apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve fixes the following issues: Changes in python-Markdown: * Fix tests with latest python version (bsc#1268243) Changes in python-joblib: * Update to 1.5.2: * fixing the resource tracker for python 3.13.7+ * Skip tests failing with Python 3.13.7 Changes in python-handy-archives: * Skip some zip64 tests that fails with latest python interpreter because there are more consistency checks in zipfile (bsc#1256310) Changes in python-apache-libcloud: * Fix tests compatibility with latest Python 3.13 (bsc#1258223, bsc#1261918) Changes in python-WebOb: * Security issues fixed: * CVE-2026-44889: Fixed: Location header normalization during redirect leads to open redirect (bsc#1268324) * Skip boken test with latest cpython interpreters (bsc#1258223) * Skip test failing on Python 3.14 Changes in python-PyGithub: * Fix: [SUSE:SLFO:Main] python-PyGithub fails to build on aarch64, ppc64le, s390x, x86_64 (bsc#1263802) Changes in python-soupsieve: * Fix: [SUSE:SLFO:Main] python-soupsieve:test fails to build on aarch64, ppc64le, s390x, x86_64 (bsc#1256316) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1084=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1084=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-apache-libcloud-3.8.0-160000.3.1 * python313-WebOb-1.8.9-160000.3.1 * python313-soupsieve-2.6-160000.3.1 * python313-PyGithub-2.6.1-160000.3.1 * python313-Markdown-3.8.2-160000.3.1 * python313-handy-archives-0.2.0-160000.3.1 * python-WebOb-doc-1.8.9-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-apache-libcloud-3.8.0-160000.3.1 * python313-WebOb-1.8.9-160000.3.1 * python313-soupsieve-2.6-160000.3.1 * python313-PyGithub-2.6.1-160000.3.1 * python313-Markdown-3.8.2-160000.3.1 * python313-handy-archives-0.2.0-160000.3.1 * python-WebOb-doc-1.8.9-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44889.html * https://bugzilla.suse.com/show_bug.cgi?id=1256310 * https://bugzilla.suse.com/show_bug.cgi?id=1256316 * https://bugzilla.suse.com/show_bug.cgi?id=1258223 * https://bugzilla.suse.com/show_bug.cgi?id=1261918 * https://bugzilla.suse.com/show_bug.cgi?id=1263802 * https://bugzilla.suse.com/show_bug.cgi?id=1268243 * https://bugzilla.suse.com/show_bug.cgi?id=1268324 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:35:09 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:35:09 -0000 Subject: SUSE-SU-2026:22369-1: important: Security update for libaom Message-ID: <178292370936.5373.3087744174264511227@bea6e15a6baf> # Security update for libaom Announcement ID: SUSE-SU-2026:22369-1 Release Date: 2026-06-25T19:32:50Z Rating: important References: * bsc#1268650 * bsc#1268651 * bsc#1268653 * bsc#1268655 Cross-References: * CVE-2026-56208 * CVE-2026-56209 * CVE-2026-56210 * CVE-2026-56211 CVSS scores: * CVE-2026-56208 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56208 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56209 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56209 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56210 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56210 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56211 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56211 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for libaom fixes the following issues * CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap- based buffer overflow and a process crash (bsc#1268650). * CVE-2026-56209: crafted video frames with specific Y-plane pixel values can lead to an arbitrary memory write (bsc#1268651). * CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out- of-bounds heap read (bsc#1268653). * CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to remote code execution (bsc#1268655). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1082=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1082=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libaom3-debuginfo-3.11.0-160000.3.1 * aom-tools-3.11.0-160000.3.1 * aom-tools-debuginfo-3.11.0-160000.3.1 * libaom-debugsource-3.11.0-160000.3.1 * libaom3-3.11.0-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libaom3-debuginfo-3.11.0-160000.3.1 * aom-tools-3.11.0-160000.3.1 * aom-tools-debuginfo-3.11.0-160000.3.1 * libaom-debugsource-3.11.0-160000.3.1 * libaom3-3.11.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56208.html * https://www.suse.com/security/cve/CVE-2026-56209.html * https://www.suse.com/security/cve/CVE-2026-56210.html * https://www.suse.com/security/cve/CVE-2026-56211.html * https://bugzilla.suse.com/show_bug.cgi?id=1268650 * https://bugzilla.suse.com/show_bug.cgi?id=1268651 * https://bugzilla.suse.com/show_bug.cgi?id=1268653 * https://bugzilla.suse.com/show_bug.cgi?id=1268655 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:35:51 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:35:51 -0000 Subject: SUSE-SU-2026:22368-1: important: Security update for nodejs22 Message-ID: <178292375178.5373.11050312084291668751@bea6e15a6baf> # Security update for nodejs22 Announcement ID: SUSE-SU-2026:22368-1 Release Date: 2026-06-25T13:50:58Z Rating: important References: * bsc#1256576 * bsc#1259853 * bsc#1260455 * bsc#1260462 * bsc#1260463 * bsc#1260480 * bsc#1260482 * bsc#1260494 * bsc#1262274 * bsc#1266318 * bsc#1268097 * bsc#1268477 * bsc#1268479 * bsc#1268481 * bsc#1268482 * bsc#1268554 * bsc#1268555 * bsc#1268592 * bsc#1268593 * bsc#1268598 * bsc#1268605 * bsc#1268606 * bsc#1268608 * bsc#1268609 * bsc#1268611 * bsc#1268618 Cross-References: * CVE-2026-11525 * CVE-2026-12151 * CVE-2026-21637 * CVE-2026-21710 * CVE-2026-21713 * CVE-2026-21714 * CVE-2026-21715 * CVE-2026-21716 * CVE-2026-21717 * CVE-2026-27135 * CVE-2026-40170 * CVE-2026-42338 * CVE-2026-48615 * CVE-2026-48617 * CVE-2026-48618 * CVE-2026-48619 * CVE-2026-48928 * CVE-2026-48930 * CVE-2026-48931 * CVE-2026-48933 * CVE-2026-48934 * CVE-2026-48935 * CVE-2026-48937 * CVE-2026-6733 * CVE-2026-9496 * CVE-2026-9679 CVSS scores: * CVE-2026-11525 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-11525 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-12151 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-21637 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21637 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21637 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21710 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21713 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-21713 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-21713 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-21714 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21714 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21714 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21715 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-21715 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-21715 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-21716 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-21716 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-21716 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-21717 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-21717 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-21717 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27135 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40170 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42338 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-42338 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-48615 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48615 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48617 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48617 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N * CVE-2026-48617 ( NVD ): 1.8 CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N * CVE-2026-48618 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48618 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-48618 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48619 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48928 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48928 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-48928 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48928 ( NVD ): 4.2 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48930 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48930 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-48930 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48930 ( NVD ): 5.6 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-48931 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48931 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48933 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48933 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48934 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48934 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48934 ( NVD ): 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48935 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48935 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48935 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48937 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48937 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6733 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-6733 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-9496 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9496 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9496 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9679 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-9679 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 26 vulnerabilities can now be installed. ## Description: This update for nodejs22 fixes the following issues Update to 22.23.0: * CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS (bsc#1266318). * CVE-2026-9679: undici: undici vulnerable to HTTP header injection via Set- Cookie percent-decoding (bsc#1268477). * CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (bsc#1268481). * CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482). * CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths and can cause a denial of service (bsc#1256576). * CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455). * CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463). * CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480). * CVE-2026-21715: permission model bypass in realpathSync.native can allow file existence disclosure (bsc#1260482). * CVE-2026-21716: promise-based FileHandle methods can be used to modify file permissions and ownership (bsc#1260462). * CVE-2026-21717: crafted request can lead to hash collisions trivially predictable (bsc#1260494). * CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853). * CVE-2026-40170: ngtcp2: qlog parameters_set stack buffer overflow (bsc#1262274). * CVE-2026-42338: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (bsc#1268097). * CVE-2026-48615: Proxy credentials leaked in ERR_PROXY_TUNNEL error message (bsc#1268598). * CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation (bsc#1268554). * CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593). * CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker- controlled ORIGIN frames (bsc#1268618). * CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605). * CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings (bsc#1268606). * CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611). * CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592). * CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to unauthorized connections (bsc#1268608). * CVE-2026-48935: Permission Model bypass via FileHandle.utimes() in the promises API (bsc#1268609). * CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1079=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1079=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * corepack22-22.23.0-160000.1.1 * nodejs22-debuginfo-22.23.0-160000.1.1 * nodejs22-debugsource-22.23.0-160000.1.1 * nodejs22-22.23.0-160000.1.1 * nodejs22-devel-22.23.0-160000.1.1 * npm22-22.23.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * nodejs22-docs-22.23.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * corepack22-22.23.0-160000.1.1 * nodejs22-debuginfo-22.23.0-160000.1.1 * nodejs22-debugsource-22.23.0-160000.1.1 * nodejs22-22.23.0-160000.1.1 * nodejs22-devel-22.23.0-160000.1.1 * npm22-22.23.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * nodejs22-docs-22.23.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11525.html * https://www.suse.com/security/cve/CVE-2026-12151.html * https://www.suse.com/security/cve/CVE-2026-21637.html * https://www.suse.com/security/cve/CVE-2026-21710.html * https://www.suse.com/security/cve/CVE-2026-21713.html * https://www.suse.com/security/cve/CVE-2026-21714.html * https://www.suse.com/security/cve/CVE-2026-21715.html * https://www.suse.com/security/cve/CVE-2026-21716.html * https://www.suse.com/security/cve/CVE-2026-21717.html * https://www.suse.com/security/cve/CVE-2026-27135.html * https://www.suse.com/security/cve/CVE-2026-40170.html * https://www.suse.com/security/cve/CVE-2026-42338.html * https://www.suse.com/security/cve/CVE-2026-48615.html * https://www.suse.com/security/cve/CVE-2026-48617.html * https://www.suse.com/security/cve/CVE-2026-48618.html * https://www.suse.com/security/cve/CVE-2026-48619.html * https://www.suse.com/security/cve/CVE-2026-48928.html * https://www.suse.com/security/cve/CVE-2026-48930.html * https://www.suse.com/security/cve/CVE-2026-48931.html * https://www.suse.com/security/cve/CVE-2026-48933.html * https://www.suse.com/security/cve/CVE-2026-48934.html * https://www.suse.com/security/cve/CVE-2026-48935.html * https://www.suse.com/security/cve/CVE-2026-48937.html * https://www.suse.com/security/cve/CVE-2026-6733.html * https://www.suse.com/security/cve/CVE-2026-9496.html * https://www.suse.com/security/cve/CVE-2026-9679.html * https://bugzilla.suse.com/show_bug.cgi?id=1256576 * https://bugzilla.suse.com/show_bug.cgi?id=1259853 * https://bugzilla.suse.com/show_bug.cgi?id=1260455 * https://bugzilla.suse.com/show_bug.cgi?id=1260462 * https://bugzilla.suse.com/show_bug.cgi?id=1260463 * https://bugzilla.suse.com/show_bug.cgi?id=1260480 * https://bugzilla.suse.com/show_bug.cgi?id=1260482 * https://bugzilla.suse.com/show_bug.cgi?id=1260494 * https://bugzilla.suse.com/show_bug.cgi?id=1262274 * https://bugzilla.suse.com/show_bug.cgi?id=1266318 * https://bugzilla.suse.com/show_bug.cgi?id=1268097 * https://bugzilla.suse.com/show_bug.cgi?id=1268477 * https://bugzilla.suse.com/show_bug.cgi?id=1268479 * https://bugzilla.suse.com/show_bug.cgi?id=1268481 * https://bugzilla.suse.com/show_bug.cgi?id=1268482 * https://bugzilla.suse.com/show_bug.cgi?id=1268554 * https://bugzilla.suse.com/show_bug.cgi?id=1268555 * https://bugzilla.suse.com/show_bug.cgi?id=1268592 * https://bugzilla.suse.com/show_bug.cgi?id=1268593 * https://bugzilla.suse.com/show_bug.cgi?id=1268598 * https://bugzilla.suse.com/show_bug.cgi?id=1268605 * https://bugzilla.suse.com/show_bug.cgi?id=1268606 * https://bugzilla.suse.com/show_bug.cgi?id=1268608 * https://bugzilla.suse.com/show_bug.cgi?id=1268609 * https://bugzilla.suse.com/show_bug.cgi?id=1268611 * https://bugzilla.suse.com/show_bug.cgi?id=1268618 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:01 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:01 -0000 Subject: SUSE-SU-2026:22367-1: important: Security update for docker Message-ID: <178292376168.5373.15767093384068894059@bea6e15a6baf> # Security update for docker Announcement ID: SUSE-SU-2026:22367-1 Release Date: 2026-06-25T12:44:41Z Rating: important References: * bsc#1262346 * bsc#1265782 * bsc#1266625 * bsc#1267827 Cross-References: * CVE-2026-33814 * CVE-2026-39821 * CVE-2026-39984 * CVE-2026-41567 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39984 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39984 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39984 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41567 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). * CVE-2026-39984: github.com/sigstore/timestamp-authority/v2/pkg/verification: improper certificate validation can be used to bypass some authorization controls (bsc#1262346). * CVE-2026-41567: arbitrary code execution with full daemon privileges when a user uploads a compressed archive into that container (bsc#1267827). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1081=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1081=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-160000.7.1 * docker-buildx-0.33.0-160000.7.1 * docker-debuginfo-29.4.0_ce-160000.7.1 * SUSE Linux Enterprise Server 16.0 (noarch) * docker-rootless-extras-29.4.0_ce-160000.7.1 * docker-fish-completion-29.4.0_ce-160000.7.1 * docker-zsh-completion-29.4.0_ce-160000.7.1 * docker-bash-completion-29.4.0_ce-160000.7.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * docker-rootless-extras-29.4.0_ce-160000.7.1 * docker-bash-completion-29.4.0_ce-160000.7.1 * docker-zsh-completion-29.4.0_ce-160000.7.1 * docker-fish-completion-29.4.0_ce-160000.7.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * docker-29.4.0_ce-160000.7.1 * docker-buildx-0.33.0-160000.7.1 * docker-debuginfo-29.4.0_ce-160000.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39984.html * https://www.suse.com/security/cve/CVE-2026-41567.html * https://bugzilla.suse.com/show_bug.cgi?id=1262346 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 * https://bugzilla.suse.com/show_bug.cgi?id=1267827 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:05 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:05 -0000 Subject: SUSE-RU-2026:22366-1: moderate: Recommended update for agama-products, agama Message-ID: <178292376577.5373.2884336510274119745@bea6e15a6baf> # Recommended update for agama-products, agama Announcement ID: SUSE-RU-2026:22366-1 Release Date: 2026-06-25T12:22:25Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for agama-products, agama fixes the following issues: Changes in agama-products: * Always use an empty array for optional_patterns in products definitions. Changes in agama: * Consider the old init scripts location for backward compatibility. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1077=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1077=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * agama-scripts-17+617.fad444ba8-160000.11.1 * agama-debugsource-17+617.fad444ba8-160000.11.1 * agama-debuginfo-17+617.fad444ba8-160000.11.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * agama-debugsource-17+617.fad444ba8-160000.11.1 * agama-scripts-17+617.fad444ba8-160000.11.1 * agama-debuginfo-17+617.fad444ba8-160000.11.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:11 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:11 -0000 Subject: SUSE-SU-2026:22365-1: important: Security update for openCryptoki Message-ID: <178292377168.5373.14739701254440025639@bea6e15a6baf> # Security update for openCryptoki Announcement ID: SUSE-SU-2026:22365-1 Release Date: 2026-06-25T11:51:43Z Rating: important References: * bsc#1268745 * jsc#PED-14609 Cross-References: * CVE-2026-22791 * CVE-2026-23893 * CVE-2026-40253 CVSS scores: * CVE-2026-22791 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-22791 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-22791 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-22791 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-23893 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-23893 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and contains one feature can now be installed. ## Description: This update for openCryptoki fixes the following issues Upgrade openCryptoki to version 3.27 (jsc#PED-14609): * Add base support for PKCS#11 v3.2. * Add support for PKCS#11 v3.2 C_VerifySignature[Init|Update|Final]. * Add support for PKCS#11 v3.2 C_EncapsulateKey/C_DecapsulateKey. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with RSA- PKCS and RSA-OAEP mechanisms. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the ECDH mechanism. * Soft/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the DH-PKCS mechanism. * Soft: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or the OQS-provider must be configured). * CCA: Add support for PKCS#11 v3.2 ML-DSA key type and mechanisms (requires CCA v8.4 or later) * EP11: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16). * p11sak: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types. * Soft/ICA: Add support for PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * p11sak: Add support for key wrapping with PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 mechanism CKM_PUB_KEY_FROM_PRIV_KEY. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.0 Edwards and Montgomery key types and mechanisms. * Soft/ICA: Support CKM_ECDH_AES_KEY_WRAP also for Montgomery keys. * p11sak: Add support for PKCS#11 v3.0 Edwards and Montgomery key types. * Soft: Add support for CKM_ECDH1_COFACTOR_DERIVE. * CCA: Add support for additional RSA public exponent values 5, 17, or 257. * p11sak: Add option to list-key command to show EP11 session IDs. * Make the maximum number of token objects supported configurable. * Fixes for CVE-2026-40253, CVE-2026-23893, and CVE-2026-22791. * Bug fixes. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1080=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1080=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * openCryptoki-devel-3.27.0-160000.1.1 * openCryptoki-64bit-debuginfo-3.27.0-160000.1.1 * openCryptoki-debuginfo-3.27.0-160000.1.1 * openCryptoki-3.27.0-160000.1.1 * openCryptoki-debugsource-3.27.0-160000.1.1 * openCryptoki-64bit-3.27.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openCryptoki-devel-3.27.0-160000.1.1 * openCryptoki-64bit-debuginfo-3.27.0-160000.1.1 * openCryptoki-debuginfo-3.27.0-160000.1.1 * openCryptoki-3.27.0-160000.1.1 * openCryptoki-debugsource-3.27.0-160000.1.1 * openCryptoki-64bit-3.27.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22791.html * https://www.suse.com/security/cve/CVE-2026-23893.html * https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1268745 * https://jira.suse.com/browse/PED-14609 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:19 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:19 -0000 Subject: SUSE-SU-2026:22364-1: important: Security update for libssh2_org Message-ID: <178292377970.5373.10086754230348303851@bea6e15a6baf> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:22364-1 Release Date: 2026-06-25T11:51:43Z Rating: important References: * bsc#1268530 * bsc#1268531 Cross-References: * CVE-2026-55199 * CVE-2026-55200 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55200 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55200 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55200 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55200 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libssh2_org fixes the following issues * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). * CVE-2026-55200: out-of-Bounds write via Unchecked packet_length in transport.c (bsc#1268531). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1078=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1078=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libssh2-1-debuginfo-1.11.1-160000.4.1 * libssh2-devel-1.11.1-160000.4.1 * libssh2_org-debugsource-1.11.1-160000.4.1 * libssh2-1-1.11.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libssh2-devel-1.11.1-160000.4.1 * libssh2_org-debugsource-1.11.1-160000.4.1 * libssh2-1-debuginfo-1.11.1-160000.4.1 * libssh2-1-1.11.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://www.suse.com/security/cve/CVE-2026-55200.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 * https://bugzilla.suse.com/show_bug.cgi?id=1268531 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:25 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:25 -0000 Subject: SUSE-SU-2026:22363-1: important: Security update for libnfs Message-ID: <178292378526.5373.3933534119856140726@bea6e15a6baf> # Security update for libnfs Announcement ID: SUSE-SU-2026:22363-1 Release Date: 2026-06-25T11:50:17Z Rating: important References: * bsc#1268135 Cross-References: * CVE-2026-53689 CVSS scores: * CVE-2026-53689 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-53689 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for libnfs fixes the following issue * CVE-2026-53689: integer overflow during a connection to a crafted NFS server (bsc#1268135). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1076=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1076=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libnfs-debuginfo-5.0.3-160000.4.1 * libnfs14-5.0.3-160000.4.1 * utils-libnfs-debuginfo-5.0.3-160000.4.1 * libnfs-debugsource-5.0.3-160000.4.1 * libnfs14-debuginfo-5.0.3-160000.4.1 * utils-libnfs-5.0.3-160000.4.1 * libnfs-devel-5.0.3-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libnfs-debuginfo-5.0.3-160000.4.1 * libnfs14-5.0.3-160000.4.1 * utils-libnfs-debuginfo-5.0.3-160000.4.1 * libnfs-debugsource-5.0.3-160000.4.1 * libnfs14-debuginfo-5.0.3-160000.4.1 * utils-libnfs-5.0.3-160000.4.1 * libnfs-devel-5.0.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53689.html * https://bugzilla.suse.com/show_bug.cgi?id=1268135 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:29 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:29 -0000 Subject: SUSE-RU-2026:22362-1: moderate: Recommended update for glib2 Message-ID: <178292378926.5373.14750929908626428346@bea6e15a6baf> # Recommended update for glib2 Announcement ID: SUSE-RU-2026:22362-1 Release Date: 2026-06-24T21:52:58Z Rating: moderate References: * jsc#PED-14839 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for glib2 fixes the following issues: * Install the /usr/share/applications/gnome-mimeapps.list symlink from the package instead of creating it from systemd-tmpfiles since /usr is mounted read-only in immutble systems. * This forces to also install an empty file as the symlink target. * Use systemd-tmpfiles to create the default mimeapps lists instead of writing to /var in %post to fix immutable systems (jsc#PED-14839) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1065=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1065=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * glib2-tools-debuginfo-2.84.4-160000.3.1 * libgmodule-2_0-0-debuginfo-2.84.4-160000.3.1 * glib2-tools-2.84.4-160000.3.1 * libglib-2_0-0-debuginfo-2.84.4-160000.3.1 * libgirepository-2_0-0-debuginfo-2.84.4-160000.3.1 * glib2-devel-debuginfo-2.84.4-160000.3.1 * typelib-1_0-Gio-2_0-2.84.4-160000.3.1 * typelib-1_0-GLib-2_0-2.84.4-160000.3.1 * typelib-1_0-GIRepository-3_0-2.84.4-160000.3.1 * libgirepository-2_0-0-2.84.4-160000.3.1 * libgio-2_0-0-debuginfo-2.84.4-160000.3.1 * glib2-devel-static-2.84.4-160000.3.1 * libgthread-2_0-0-debuginfo-2.84.4-160000.3.1 * libgobject-2_0-0-2.84.4-160000.3.1 * glib2-doc-2.84.4-160000.3.1 * libgmodule-2_0-0-2.84.4-160000.3.1 * libgthread-2_0-0-2.84.4-160000.3.1 * typelib-1_0-GModule-2_0-2.84.4-160000.3.1 * glib2-devel-2.84.4-160000.3.1 * glib2-debugsource-2.84.4-160000.3.1 * libglib-2_0-0-2.84.4-160000.3.1 * libgio-2_0-0-2.84.4-160000.3.1 * libgobject-2_0-0-debuginfo-2.84.4-160000.3.1 * typelib-1_0-GLibUnix-2_0-2.84.4-160000.3.1 * typelib-1_0-GObject-2_0-2.84.4-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * glib2-lang-2.84.4-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * glib2-tools-debuginfo-2.84.4-160000.3.1 * libgmodule-2_0-0-debuginfo-2.84.4-160000.3.1 * glib2-tools-2.84.4-160000.3.1 * libglib-2_0-0-debuginfo-2.84.4-160000.3.1 * libgirepository-2_0-0-debuginfo-2.84.4-160000.3.1 * glib2-devel-debuginfo-2.84.4-160000.3.1 * typelib-1_0-Gio-2_0-2.84.4-160000.3.1 * typelib-1_0-GLib-2_0-2.84.4-160000.3.1 * typelib-1_0-GIRepository-3_0-2.84.4-160000.3.1 * libgirepository-2_0-0-2.84.4-160000.3.1 * libgio-2_0-0-debuginfo-2.84.4-160000.3.1 * glib2-devel-static-2.84.4-160000.3.1 * libgthread-2_0-0-debuginfo-2.84.4-160000.3.1 * libgobject-2_0-0-2.84.4-160000.3.1 * libgmodule-2_0-0-2.84.4-160000.3.1 * glib2-doc-2.84.4-160000.3.1 * libgthread-2_0-0-2.84.4-160000.3.1 * typelib-1_0-GModule-2_0-2.84.4-160000.3.1 * glib2-devel-2.84.4-160000.3.1 * glib2-debugsource-2.84.4-160000.3.1 * libglib-2_0-0-2.84.4-160000.3.1 * libgio-2_0-0-2.84.4-160000.3.1 * libgobject-2_0-0-debuginfo-2.84.4-160000.3.1 * typelib-1_0-GLibUnix-2_0-2.84.4-160000.3.1 * typelib-1_0-GObject-2_0-2.84.4-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * glib2-lang-2.84.4-160000.3.1 ## References: * https://jira.suse.com/browse/PED-14839 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:36 -0000 Subject: SUSE-RU-2026:22361-1: moderate: Recommended update for gvfs Message-ID: <178292379625.5373.10124599947386390246@bea6e15a6baf> # Recommended update for gvfs Announcement ID: SUSE-RU-2026:22361-1 Release Date: 2026-06-24T21:43:07Z Rating: moderate References: * bsc#1261625 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for gvfs fixes the following issues: * Fix crash of cancelled pending operation. (bsc#1261625) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1062=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1062=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gvfs-backends-1.59.90-160000.2.1 * gvfs-debuginfo-1.59.90-160000.2.1 * gvfs-fuse-1.59.90-160000.2.1 * gvfs-fuse-debuginfo-1.59.90-160000.2.1 * gvfs-backends-debuginfo-1.59.90-160000.2.1 * gvfs-debugsource-1.59.90-160000.2.1 * gvfs-1.59.90-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * gvfs-lang-1.59.90-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gvfs-backends-1.59.90-160000.2.1 * gvfs-debuginfo-1.59.90-160000.2.1 * gvfs-fuse-1.59.90-160000.2.1 * gvfs-fuse-debuginfo-1.59.90-160000.2.1 * gvfs-backends-debuginfo-1.59.90-160000.2.1 * gvfs-debugsource-1.59.90-160000.2.1 * gvfs-1.59.90-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * gvfs-lang-1.59.90-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1261625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:44 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:44 -0000 Subject: SUSE-SU-2026:22360-1: important: Security update for python-starlette Message-ID: <178292380451.5373.11104380962372669957@bea6e15a6baf> # Security update for python-starlette Announcement ID: SUSE-SU-2026:22360-1 Release Date: 2026-06-24T21:38:49Z Rating: important References: * bsc#1268389 * bsc#1268517 * bsc#1268520 Cross-References: * CVE-2026-48817 * CVE-2026-54282 * CVE-2026-54283 CVSS scores: * CVE-2026-48817 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48817 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54282 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-54282 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54282 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54282 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54283 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54283 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-starlette fixes the following issues * CVE-2026-48817: arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr` (bsc#1268389). * CVE-2026-54282: request path that lacks a leading forward slash can lead to request.url.hostname manipulation (bsc#1268520). * CVE-2026-54283: urlencoded request body with an oversized data can lead to a denial of service (bsc#1268517). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1066=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1066=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-starlette-0.41.3-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-starlette-0.41.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48817.html * https://www.suse.com/security/cve/CVE-2026-54282.html * https://www.suse.com/security/cve/CVE-2026-54283.html * https://bugzilla.suse.com/show_bug.cgi?id=1268389 * https://bugzilla.suse.com/show_bug.cgi?id=1268517 * https://bugzilla.suse.com/show_bug.cgi?id=1268520 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:50 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:50 -0000 Subject: SUSE-RU-2026:22359-1: moderate: Recommended update for pam Message-ID: <178292381093.5373.11688718221057751334@bea6e15a6baf> # Recommended update for pam Announcement ID: SUSE-RU-2026:22359-1 Release Date: 2026-06-24T21:38:49Z Rating: moderate References: * bsc#1245524 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for pam fixes the following issues: * pam_mkhomedir: building with vendordir option allows fetching skeleton directory from the vendor directory when creating the user home directory (bsc#1245524) * disable unix_chkpwd by default, only used as fallback again * pam_modutil_get*: overwrite password at free ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1064=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1064=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * pam-1.7.1-160000.4.1 * pam-extra-1.7.1-160000.4.1 * pam-debuginfo-1.7.1-160000.4.1 * pam-devel-1.7.1-160000.4.1 * pam-extra-debuginfo-1.7.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * pam-manpages-1.7.1-160000.4.1 * pam-doc-1.7.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x) * pam-debugsource-1.7.1-160000.4.1 * pam-full-src-debugsource-1.7.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * pam-1.7.1-160000.4.1 * pam-debuginfo-1.7.1-160000.4.1 * pam-extra-1.7.1-160000.4.1 * pam-devel-1.7.1-160000.4.1 * pam-extra-debuginfo-1.7.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le) * pam-debugsource-1.7.1-160000.4.1 * pam-full-src-debugsource-1.7.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * pam-manpages-1.7.1-160000.4.1 * pam-doc-1.7.1-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1245524 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:56 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:36:56 -0000 Subject: SUSE-SU-2026:22358-1: important: Security update for dracut Message-ID: <178292381640.5373.2968025323766155431@bea6e15a6baf> # Security update for dracut Announcement ID: SUSE-SU-2026:22358-1 Release Date: 2026-06-24T21:37:46Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.722.gdd9d67ff5: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1067=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1067=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dracut-tools-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-ima-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-extra-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-fips-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-debugsource-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-debuginfo-059+suse.722.gdd9d67ff5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dracut-tools-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-ima-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-extra-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-fips-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-debugsource-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-debuginfo-059+suse.722.gdd9d67ff5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:06 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:37:06 -0000 Subject: SUSE-RU-2026:22357-1: moderate: Recommended update for supportutils Message-ID: <178292382631.5373.13828148782752016125@bea6e15a6baf> # Recommended update for supportutils Announcement ID: SUSE-RU-2026:22357-1 Release Date: 2026-06-24T21:37:46Z Rating: moderate References: * bsc#1256709 * bsc#1257383 * bsc#1258069 * bsc#1259520 * jsc#PED-7324 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature and has four fixes can now be installed. ## Description: This update for supportutils fixes the following issues: * Changes to version 3.2.14: * Integrates supportutils-scrub for data obfuscation, use -j (PED-7324, bsc#1259520) * Santize env.txt * ha.txt: Collect hacluster passwd entry * Added systemd cat unit.service output * Added softirqs to proc (bsc#1258069) * Check for /usr/lib/pam.d * Ignore deprecated crash variable message * Update supportconfig with note about bpftool * Added /boot/grub2/grubenv (bsc#1257383) * Verify procps pkg * scplugin.rc is restored in package 3.2.12.1 for continued compatibility. There is no furture development for scplugin.rc. Use supportconfig.rc. Package version 3.2.12.2 does not have scplugin.rc. (bsc#1256709) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1063=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1063=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * supportutils-3.2.14.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * supportutils-3.2.14.2-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1256709 * https://bugzilla.suse.com/show_bug.cgi?id=1257383 * https://bugzilla.suse.com/show_bug.cgi?id=1258069 * https://bugzilla.suse.com/show_bug.cgi?id=1259520 * https://jira.suse.com/browse/PED-7324 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:11 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:37:11 -0000 Subject: SUSE-SU-2026:22356-1: moderate: Security update for python-idna Message-ID: <178292383182.5373.15488792174959178267@bea6e15a6baf> # Security update for python-idna Announcement ID: SUSE-SU-2026:22356-1 Release Date: 2026-06-24T21:37:46Z Rating: moderate References: * bsc#1265413 Cross-References: * CVE-2026-45409 CVSS scores: * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-idna fixes the following issue * CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1061=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1061=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-idna-3.10-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-idna-3.10-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45409.html * https://bugzilla.suse.com/show_bug.cgi?id=1265413 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:17 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:37:17 -0000 Subject: SUSE-SU-2026:22355-1: low: Security update for libgcrypt Message-ID: <178292383742.5373.8324606706656222644@bea6e15a6baf> # Security update for libgcrypt Announcement ID: SUSE-SU-2026:22355-1 Release Date: 2026-06-24T21:36:29Z Rating: low References: * bsc#1262693 Cross-References: * CVE-2026-41990 CVSS scores: * CVE-2026-41990 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-41990 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-41990 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue * CVE-2026-41990: lack of bound check can lead to mishandling of Dilithium signing (bsc#1262693). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1060=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1060=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libgcrypt-devel-1.12.1-160000.2.1 * libgcrypt20-1.12.1-160000.2.1 * libgcrypt20-debuginfo-1.12.1-160000.2.1 * libgcrypt-debugsource-1.12.1-160000.2.1 * libgcrypt-devel-debuginfo-1.12.1-160000.2.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libgcrypt20-x86-64-v3-debuginfo-1.12.1-160000.2.1 * libgcrypt20-x86-64-v3-1.12.1-160000.2.1 * libgcrypt-devel-x86-64-v3-1.12.1-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libgcrypt-devel-1.12.1-160000.2.1 * libgcrypt20-1.12.1-160000.2.1 * libgcrypt20-debuginfo-1.12.1-160000.2.1 * libgcrypt-debugsource-1.12.1-160000.2.1 * libgcrypt-devel-debuginfo-1.12.1-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libgcrypt20-x86-64-v3-debuginfo-1.12.1-160000.2.1 * libgcrypt20-x86-64-v3-1.12.1-160000.2.1 * libgcrypt-devel-x86-64-v3-1.12.1-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41990.html * https://bugzilla.suse.com/show_bug.cgi?id=1262693 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:22 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:37:22 -0000 Subject: SUSE-RU-2026:22354-1: moderate: Recommended update for nvidia-open-driver-G07-signed Message-ID: <178292384281.5373.7673837612114141181@bea6e15a6baf> # Recommended update for nvidia-open-driver-G07-signed Announcement ID: SUSE-RU-2026:22354-1 Release Date: 2026-06-24T19:51:44Z Rating: moderate References: * bsc#1268792 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for nvidia-open-driver-G07-signed fixes the following issues: * update non-CUDA variant to 595.84 (bsc#1268792) * changes to build also against the nvidia kernel, which is planned to be available for SLE16.1-aarch64 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1059=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1059=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * nvidia-open-driver-G07-signed-cuda-debugsource-610.43.02-160000.1.2 * nvidia-open-driver-G07-signed-debugsource-595.84-160000.1.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-610.43.02_k6.12.0_160000.35-160000.1.2 * nvidia-open-driver-G07-signed-cuda-default-devel-610.43.02-160000.1.2 * nvidia-open-driver-G07-signed-kmp-default-debuginfo-595.84_k6.12.0_160000.35-160000.1.1 * nvidia-open-driver-G07-signed-kmp-default-595.84_k6.12.0_160000.35-160000.1.1 * nvidia-open-driver-G07-signed-default-devel-595.84-160000.1.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-debuginfo-610.43.02_k6.12.0_160000.35-160000.1.2 * SUSE Linux Enterprise Server 16.0 (aarch64) * nvidia-open-driver-G07-signed-cuda-64kb-devel-610.43.02-160000.1.2 * nvidia-open-driver-G07-signed-64kb-devel-595.84-160000.1.1 * nvidia-open-driver-G07-signed-kmp-64kb-debuginfo-595.84_k6.12.0_160000.35-160000.1.1 * nvidia-open-driver-G07-signed-kmp-64kb-595.84_k6.12.0_160000.35-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * nvidia-open-driver-G07-signed-cuda-debugsource-610.43.02-160000.1.2 * nvidia-open-driver-G07-signed-debugsource-595.84-160000.1.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-610.43.02_k6.12.0_160000.35-160000.1.2 * nvidia-open-driver-G07-signed-cuda-default-devel-610.43.02-160000.1.2 * nvidia-open-driver-G07-signed-kmp-default-debuginfo-595.84_k6.12.0_160000.35-160000.1.1 * nvidia-open-driver-G07-signed-kmp-default-595.84_k6.12.0_160000.35-160000.1.1 * nvidia-open-driver-G07-signed-default-devel-595.84-160000.1.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-debuginfo-610.43.02_k6.12.0_160000.35-160000.1.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268792 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:28 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:37:28 -0000 Subject: SUSE-SU-2026:22353-1: moderate: Security update for perl-libwww-perl Message-ID: <178292384810.5373.2089899686092444609@bea6e15a6baf> # Security update for perl-libwww-perl Announcement ID: SUSE-SU-2026:22353-1 Release Date: 2026-06-24T19:41:53Z Rating: moderate References: * bsc#1265156 Cross-References: * CVE-2026-8368 CVSS scores: * CVE-2026-8368 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-8368 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-libwww-perl fixes the following issue * CVE-2026-8368: authorization and proxy-authorization headers are leaked on cross-origin redirects (bsc#1265156). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1058=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1058=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * perl-libwww-perl-6.770.0-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * perl-libwww-perl-6.770.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8368.html * https://bugzilla.suse.com/show_bug.cgi?id=1265156 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:37:36 -0000 Subject: SUSE-SU-2026:22352-1: moderate: Security update for openssh Message-ID: <178292385675.5373.6969509992970023395@bea6e15a6baf> # Security update for openssh Announcement ID: SUSE-SU-2026:22352-1 Release Date: 2026-06-24T15:22:37Z Rating: moderate References: * bsc#1259642 * bsc#1261441 * bsc#1264568 Cross-References: * CVE-2026-3497 * CVE-2026-35388 CVSS scores: * CVE-2026-3497 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-3497 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-3497 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3497 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-3497 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35388 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-35388 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-35388 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-35388 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for openssh fixes the following issues Security fixes: * CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642). * CVE-2026-35388: omitted connection multiplexing confirmation for proxy-mode multiplexing sessions (bsc#1261441). * openssh potential security issue when validating mac or ciphers (bsc#1264568). Other fixes: * Improve %prep LDAP regex to preserve subdirectories (e.g., openbsd-compat/) and handle optional [ab]/ prefixes. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1057=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1057=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * openssh-10.0p2-160000.6.1 * openssh-common-10.0p2-160000.6.1 * openssh-debuginfo-10.0p2-160000.6.1 * openssh-askpass-gnome-debuginfo-10.0p2-160000.6.1 * openssh-cavs-debuginfo-10.0p2-160000.6.1 * openssh-server-10.0p2-160000.6.1 * openssh-clients-10.0p2-160000.6.1 * openssh-debugsource-10.0p2-160000.6.1 * openssh-cavs-10.0p2-160000.6.1 * openssh-askpass-gnome-debugsource-10.0p2-160000.6.1 * openssh-server-debuginfo-10.0p2-160000.6.1 * openssh-clients-debuginfo-10.0p2-160000.6.1 * openssh-server-config-rootlogin-10.0p2-160000.6.1 * openssh-common-debuginfo-10.0p2-160000.6.1 * openssh-askpass-gnome-10.0p2-160000.6.1 * openssh-helpers-10.0p2-160000.6.1 * openssh-helpers-debuginfo-10.0p2-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openssh-10.0p2-160000.6.1 * openssh-common-10.0p2-160000.6.1 * openssh-cavs-debuginfo-10.0p2-160000.6.1 * openssh-debuginfo-10.0p2-160000.6.1 * openssh-askpass-gnome-debuginfo-10.0p2-160000.6.1 * openssh-server-10.0p2-160000.6.1 * openssh-clients-10.0p2-160000.6.1 * openssh-debugsource-10.0p2-160000.6.1 * openssh-cavs-10.0p2-160000.6.1 * openssh-askpass-gnome-debugsource-10.0p2-160000.6.1 * openssh-server-debuginfo-10.0p2-160000.6.1 * openssh-clients-debuginfo-10.0p2-160000.6.1 * openssh-server-config-rootlogin-10.0p2-160000.6.1 * openssh-common-debuginfo-10.0p2-160000.6.1 * openssh-askpass-gnome-10.0p2-160000.6.1 * openssh-helpers-10.0p2-160000.6.1 * openssh-helpers-debuginfo-10.0p2-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3497.html * https://www.suse.com/security/cve/CVE-2026-35388.html * https://bugzilla.suse.com/show_bug.cgi?id=1259642 * https://bugzilla.suse.com/show_bug.cgi?id=1261441 * https://bugzilla.suse.com/show_bug.cgi?id=1264568 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:37:42 -0000 Subject: SUSE-SU-2026:22351-1: important: Security update for MozillaFirefox Message-ID: <178292386255.5373.3305302590148542682@bea6e15a6baf> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:22351-1 Release Date: 2026-06-24T08:25:21Z Rating: important References: * bsc#1268071 Cross-References: * CVE-2026-12289 * CVE-2026-12290 * CVE-2026-12291 * CVE-2026-12292 * CVE-2026-12294 * CVE-2026-12295 * CVE-2026-12296 * CVE-2026-12297 * CVE-2026-12298 * CVE-2026-12299 * CVE-2026-12302 * CVE-2026-12304 * CVE-2026-12305 * CVE-2026-12306 * CVE-2026-12307 * CVE-2026-12308 * CVE-2026-12309 * CVE-2026-12310 * CVE-2026-12311 * CVE-2026-12312 * CVE-2026-12313 * CVE-2026-12314 * CVE-2026-12315 * CVE-2026-12324 * CVE-2026-12325 * CVE-2026-12327 * CVE-2026-12328 * CVE-2026-12329 * CVE-2026-12330 CVSS scores: * CVE-2026-12289 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12289 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-12292 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12294 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12298 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12302 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12302 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12304 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12304 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12305 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12305 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12306 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12306 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12309 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12309 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12310 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12310 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12311 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12311 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12312 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12313 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12313 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12314 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12314 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12315 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12315 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12324 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12324 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12325 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12325 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12327 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12327 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12329 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12330 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12330 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 29 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issue Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): * CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. * CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12291: Use-after-free in the Networking: HTTP component. * CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. * CVE-2026-12294: Sandbox escape in the DOM: Workers component. * CVE-2026-12295: Sandbox escape in the DOM: Navigation component. * CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. * CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. * CVE-2026-12302: Mitigation bypass in the DOM: Security component. * CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. * CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12315: Mitigation bypass in the DOM: Security component. * CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. * CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1056=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1056=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-160000.1.1 * MozillaFirefox-debuginfo-140.12.0-160000.1.1 * MozillaFirefox-140.12.0-160000.1.1 * MozillaFirefox-translations-common-140.12.0-160000.1.1 * MozillaFirefox-debugsource-140.12.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * MozillaFirefox-devel-140.12.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * MozillaFirefox-translations-other-140.12.0-160000.1.1 * MozillaFirefox-debuginfo-140.12.0-160000.1.1 * MozillaFirefox-140.12.0-160000.1.1 * MozillaFirefox-translations-common-140.12.0-160000.1.1 * MozillaFirefox-debugsource-140.12.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * MozillaFirefox-devel-140.12.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12289.html * https://www.suse.com/security/cve/CVE-2026-12290.html * https://www.suse.com/security/cve/CVE-2026-12291.html * https://www.suse.com/security/cve/CVE-2026-12292.html * https://www.suse.com/security/cve/CVE-2026-12294.html * https://www.suse.com/security/cve/CVE-2026-12295.html * https://www.suse.com/security/cve/CVE-2026-12296.html * https://www.suse.com/security/cve/CVE-2026-12297.html * https://www.suse.com/security/cve/CVE-2026-12298.html * https://www.suse.com/security/cve/CVE-2026-12299.html * https://www.suse.com/security/cve/CVE-2026-12302.html * https://www.suse.com/security/cve/CVE-2026-12304.html * https://www.suse.com/security/cve/CVE-2026-12305.html * https://www.suse.com/security/cve/CVE-2026-12306.html * https://www.suse.com/security/cve/CVE-2026-12307.html * https://www.suse.com/security/cve/CVE-2026-12308.html * https://www.suse.com/security/cve/CVE-2026-12309.html * https://www.suse.com/security/cve/CVE-2026-12310.html * https://www.suse.com/security/cve/CVE-2026-12311.html * https://www.suse.com/security/cve/CVE-2026-12312.html * https://www.suse.com/security/cve/CVE-2026-12313.html * https://www.suse.com/security/cve/CVE-2026-12314.html * https://www.suse.com/security/cve/CVE-2026-12315.html * https://www.suse.com/security/cve/CVE-2026-12324.html * https://www.suse.com/security/cve/CVE-2026-12325.html * https://www.suse.com/security/cve/CVE-2026-12327.html * https://www.suse.com/security/cve/CVE-2026-12328.html * https://www.suse.com/security/cve/CVE-2026-12329.html * https://www.suse.com/security/cve/CVE-2026-12330.html * https://bugzilla.suse.com/show_bug.cgi?id=1268071 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:50 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:37:50 -0000 Subject: SUSE-RU-2026:22350-1: moderate: Recommended update for pcr-oracle Message-ID: <178292387007.5373.14876151935807942591@bea6e15a6baf> # Recommended update for pcr-oracle Announcement ID: SUSE-RU-2026:22350-1 Release Date: 2026-06-23T15:15:45Z Rating: moderate References: * bsc#1265042 * bsc#1265871 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for pcr-oracle fixes the following issues: * Update to 0.6.3: * Relax TPM self-test attribute checks (bsc#1265871) * Update to 0.6.2: * Update the SBAT offset boundary check (bsc#1265042) * Update to 0.6.1: * Advance the comparison event pointer after comparison * Partially support shim extra files * Locate shim extra files * Synthesize shim extra events * Fix various issues from review by Claude Code and introduce adversarial testing ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1054=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1054=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * pcr-oracle-debuginfo-0.6.3-160000.1.1 * pcr-oracle-debugsource-0.6.3-160000.1.1 * pcr-oracle-0.6.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * pcr-oracle-debuginfo-0.6.3-160000.1.1 * pcr-oracle-debugsource-0.6.3-160000.1.1 * pcr-oracle-0.6.3-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265042 * https://bugzilla.suse.com/show_bug.cgi?id=1265871 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:56 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:37:56 -0000 Subject: SUSE-SU-2026:22349-1: important: Security update for sg3_utils Message-ID: <178292387669.5373.4173268624546381543@bea6e15a6baf> # Security update for sg3_utils Announcement ID: SUSE-SU-2026:22349-1 Release Date: 2026-06-23T13:50:20Z Rating: important References: * bsc#1267823 * bsc#1268201 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for sg3_utils fixes the following issues: * sg_inq: --export output conformance for SCSI name string and ATA fields (bsc#1267823) * rescan-scsi-bus.sh: quote $id_serial in findmultipath call (bsc#1268201) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1053=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1053=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libsgutils-devel-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-debugsource-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-debuginfo-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-1.48~20221101+7.f75279c0-160000.1.1 * libsgutils2-1_48-2-debuginfo-1.48~20221101+7.f75279c0-160000.1.1 * libsgutils2-1_48-2-1.48~20221101+7.f75279c0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libsgutils2-1_48-2-debuginfo-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-debugsource-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-debuginfo-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-1.48~20221101+7.f75279c0-160000.1.1 * libsgutils-devel-1.48~20221101+7.f75279c0-160000.1.1 * libsgutils2-1_48-2-1.48~20221101+7.f75279c0-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267823 * https://bugzilla.suse.com/show_bug.cgi?id=1268201 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:38:02 -0000 Subject: SUSE-RU-2026:22348-1: important: Recommended update for curl Message-ID: <178292388238.5373.15365530697975014821@bea6e15a6baf> # Recommended update for curl Announcement ID: SUSE-RU-2026:22348-1 Release Date: 2026-06-23T13:42:56Z Rating: important References: * bsc#1264971 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for curl fixes the following issues: * Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1052=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1052=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libcurl-devel-8.14.1-160000.7.1 * curl-mini-debugsource-8.14.1-160000.7.1 * curl-debugsource-8.14.1-160000.7.1 * libcurl4-8.14.1-160000.7.1 * curl-8.14.1-160000.7.1 * libcurl4-debuginfo-8.14.1-160000.7.1 * curl-debuginfo-8.14.1-160000.7.1 * libcurl-mini4-8.14.1-160000.7.1 * libcurl-mini4-debuginfo-8.14.1-160000.7.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * curl-zsh-completion-8.14.1-160000.7.1 * libcurl-devel-doc-8.14.1-160000.7.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * curl-mini-debugsource-8.14.1-160000.7.1 * libcurl-devel-8.14.1-160000.7.1 * curl-debugsource-8.14.1-160000.7.1 * libcurl4-8.14.1-160000.7.1 * curl-8.14.1-160000.7.1 * libcurl4-debuginfo-8.14.1-160000.7.1 * curl-debuginfo-8.14.1-160000.7.1 * libcurl-mini4-8.14.1-160000.7.1 * libcurl-mini4-debuginfo-8.14.1-160000.7.1 * SUSE Linux Enterprise Server 16.0 (noarch) * curl-zsh-completion-8.14.1-160000.7.1 * libcurl-devel-doc-8.14.1-160000.7.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1264971 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:18 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:38:18 -0000 Subject: SUSE-SU-2026:22347-1: important: Security update for 7zip Message-ID: <178292389805.5373.6752094512267513562@bea6e15a6baf> # Security update for 7zip Announcement ID: SUSE-SU-2026:22347-1 Release Date: 2026-06-23T12:46:58Z Rating: important References: * bsc#1267421 * bsc#1267858 * bsc#1267859 * bsc#1267860 * bsc#1267861 * bsc#1267862 * bsc#1267863 * bsc#1267864 Cross-References: * CVE-2026-48092 * CVE-2026-48095 * CVE-2026-48101 * CVE-2026-48102 * CVE-2026-48103 * CVE-2026-48104 * CVE-2026-48111 * CVE-2026-48112 CVSS scores: * CVE-2026-48092 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48092 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48092 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-48095 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48095 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48101 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48101 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48102 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48102 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48103 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48103 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48104 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48104 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48104 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48111 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48111 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48112 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48112 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48112 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for 7zip fixes the following issues Update to 26.01: * CVE-2026-48092: Information disclosure in 32-bit builds due to heap memory disclosure (bsc#1267858). * CVE-2026-48095: Heap buffer overflow via NTFS compressed stream buffer under-allocation (bsc#1267421). * CVE-2026-48101: Information Disclosure via uninitialized memory in UEFI capsule parser (bsc#1267859). * CVE-2026-48102: Information disclosure and denial of service via crafted UDF image (bsc#1267860). * CVE-2026-48103: off-by-one heap out-of-bounds read (bsc#1267861). * CVE-2026-48104: Uninitialized heap read in SquashFS archive handler (bsc#1267862). * CVE-2026-48111: off-by-one out-of-bounds read in ParseDepedencyExpression function (bsc#1267863). * CVE-2026-48112: heap out-of-bounds read in BSD SYMDEF parser (bsc#1267864). Changes: * linux version of 7-Zip can use huge pages (2 MB pages). It can increase compression speed for 10% for 7z/xz/LZMA/LZMA2 compression. * new -spo[d|c|r] switch specifies the path generation mode for the output directory for archive extraction. The output directory path is generated from the path specified in the -o{dir_path} switch and the name of the archive being unpacked. -spod : for Linux/Posix/macOS: -o{dir_path} specifies the direct path to the output directory. The asterisk (_) character in {dir_path} will not be replaced by the archive name. -spoc : 7-Zip will concatenate the path specified in -o{dir_path} with the archive name to form the final path to the output directory. -spor : 7-Zip will replace asterisk (_) character in the path specified in the -o{dir_path} with the archive name. This is the default option. * some bugs were fixed. * Update to 26.00: * improved code for ZIP, CPIO, RAR, UFD, QCOW, Compound. * 7-Zip File Manager: improved sorting order of the file list. It uses file name as secondary sorting key.: * 7-Zip File Manager: improved Benchmark to support systems with more than 64 CPU threads. * bug fixed: 7-Zip could not correctly extract TAR archives containing sparse files ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1051=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1051=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * 7zip-26.01-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * 7zip-26.01-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48092.html * https://www.suse.com/security/cve/CVE-2026-48095.html * https://www.suse.com/security/cve/CVE-2026-48101.html * https://www.suse.com/security/cve/CVE-2026-48102.html * https://www.suse.com/security/cve/CVE-2026-48103.html * https://www.suse.com/security/cve/CVE-2026-48104.html * https://www.suse.com/security/cve/CVE-2026-48111.html * https://www.suse.com/security/cve/CVE-2026-48112.html * https://bugzilla.suse.com/show_bug.cgi?id=1267421 * https://bugzilla.suse.com/show_bug.cgi?id=1267858 * https://bugzilla.suse.com/show_bug.cgi?id=1267859 * https://bugzilla.suse.com/show_bug.cgi?id=1267860 * https://bugzilla.suse.com/show_bug.cgi?id=1267861 * https://bugzilla.suse.com/show_bug.cgi?id=1267862 * https://bugzilla.suse.com/show_bug.cgi?id=1267863 * https://bugzilla.suse.com/show_bug.cgi?id=1267864 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:25 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:38:25 -0000 Subject: SUSE-RU-2026:22346-1: moderate: Recommended update for open-vm-tools Message-ID: <178292390511.5373.15599823933844048217@bea6e15a6baf> # Recommended update for open-vm-tools Announcement ID: SUSE-RU-2026:22346-1 Release Date: 2026-06-22T15:16:50Z Rating: moderate References: * bsc#1257312 * bsc#1265304 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for open-vm-tools fixes the following issues: * Update to 13.1.0 release based on build 25218885 (bsc#1265304): * Support for GNOME Toolkit version 4 * New release of the Salt-Minion integration script * Fallback to ignore systemd inhibitors during guest poweroff / reboot * Fix: vmware-vgauth-smoketest: no VGAuthLib.vmsg file * Fix: Inline comment breaks "disable_vmware_customization" check * For a more complete description of what is new in this release: https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/ReleaseNotes.md#whatsnew https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/ReleaseNotes.md#resolved-issues * Fix build with glibc 2.43 (bsc#1257312) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1048=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1048=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * open-vm-tools-sdmp-13.1.0-160000.1.1 * open-vm-tools-13.1.0-160000.1.1 * libvmtools-devel-13.1.0-160000.1.1 * open-vm-tools-sdmp-debuginfo-13.1.0-160000.1.1 * open-vm-tools-debugsource-13.1.0-160000.1.1 * open-vm-tools-desktop-debuginfo-13.1.0-160000.1.1 * open-vm-tools-debuginfo-13.1.0-160000.1.1 * libvmtools0-debuginfo-13.1.0-160000.1.1 * open-vm-tools-containerinfo-debuginfo-13.1.0-160000.1.1 * libvmtools0-13.1.0-160000.1.1 * open-vm-tools-containerinfo-13.1.0-160000.1.1 * open-vm-tools-desktop-13.1.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * open-vm-tools-sdmp-13.1.0-160000.1.1 * open-vm-tools-13.1.0-160000.1.1 * libvmtools-devel-13.1.0-160000.1.1 * open-vm-tools-sdmp-debuginfo-13.1.0-160000.1.1 * open-vm-tools-debugsource-13.1.0-160000.1.1 * open-vm-tools-desktop-debuginfo-13.1.0-160000.1.1 * open-vm-tools-debuginfo-13.1.0-160000.1.1 * open-vm-tools-containerinfo-debuginfo-13.1.0-160000.1.1 * open-vm-tools-containerinfo-13.1.0-160000.1.1 * libvmtools0-13.1.0-160000.1.1 * libvmtools0-debuginfo-13.1.0-160000.1.1 * open-vm-tools-desktop-13.1.0-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257312 * https://bugzilla.suse.com/show_bug.cgi?id=1265304 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:31 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:38:31 -0000 Subject: SUSE-RU-2026:22345-1: moderate: Recommended update for tigervnc Message-ID: <178292391106.5373.7444234295237153434@bea6e15a6baf> # Recommended update for tigervnc Announcement ID: SUSE-RU-2026:22345-1 Release Date: 2026-06-22T15:16:49Z Rating: moderate References: * bsc#1265303 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for tigervnc fixes the following issues: * fixes random crashes with stack overflow (bsc#1265303) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1050=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1050=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * tigervnc-debugsource-1.15.0-160000.4.1 * tigervnc-1.15.0-160000.4.1 * tigervnc-debuginfo-1.15.0-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tigervnc-selinux-1.15.0-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * tigervnc-debugsource-1.15.0-160000.4.1 * tigervnc-1.15.0-160000.4.1 * tigervnc-debuginfo-1.15.0-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tigervnc-selinux-1.15.0-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265303 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:38:36 -0000 Subject: SUSE-SU-2026:22344-1: moderate: Security update for cosign Message-ID: <178292391634.5373.8190561070693743943@bea6e15a6baf> # Security update for cosign Announcement ID: SUSE-SU-2026:22344-1 Release Date: 2026-06-22T15:12:24Z Rating: moderate References: * bsc#1261859 * jsc#SLE-23879 Cross-References: * CVE-2026-39395 CVSS scores: * CVE-2026-39395 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39395 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39395 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-39395 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for cosign fixes the following issues Security issue: * CVE-2026-39395: Incorrect attestation verification due to malformed payloads or mismatched predicate types (bsc#1261859). Non security issue: * Update to version 3.0.5 (jsc#SLE-23879). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1049=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1049=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cosign-3.0.6-160000.1.1 * cosign-debuginfo-3.0.6-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cosign-3.0.6-160000.1.1 * cosign-debuginfo-3.0.6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39395.html * https://bugzilla.suse.com/show_bug.cgi?id=1261859 * https://jira.suse.com/browse/SLE-23879 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:38:42 -0000 Subject: SUSE-SU-2026:22343-1: moderate: Security update for firewalld Message-ID: <178292392201.5373.9799816976075549429@bea6e15a6baf> # Security update for firewalld Announcement ID: SUSE-SU-2026:22343-1 Release Date: 2026-06-22T15:10:04Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issue * CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1045=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1045=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python3-firewall-2.1.2-160000.3.1 * firewalld-2.1.2-160000.3.1 * firewalld-zsh-completion-2.1.2-160000.3.1 * firewalld-bash-completion-2.1.2-160000.3.1 * firewalld-lang-2.1.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python3-firewall-2.1.2-160000.3.1 * firewalld-2.1.2-160000.3.1 * firewalld-zsh-completion-2.1.2-160000.3.1 * firewalld-bash-completion-2.1.2-160000.3.1 * firewalld-lang-2.1.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:47 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:38:47 -0000 Subject: SUSE-RU-2026:22342-1: moderate: Recommended update for nftables Message-ID: <178292392768.5373.428888398952582423@bea6e15a6baf> # Recommended update for nftables Announcement ID: SUSE-RU-2026:22342-1 Release Date: 2026-06-22T15:08:35Z Rating: moderate References: * bsc#1263855 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for nftables fixes the following issues: * fix a NULL pointer dereference crash which can occur when modification of firewall rules happens in parallel e.g. during Docker startup (bsc#1263855). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1046=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1046=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * nftables-debuginfo-1.1.3-160000.3.1 * nftables-debugsource-1.1.3-160000.3.1 * libnftables1-debuginfo-1.1.3-160000.3.1 * nftables-1.1.3-160000.3.1 * libnftables1-1.1.3-160000.3.1 * nftables-devel-1.1.3-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-nftables-1.1.3-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * nftables-debuginfo-1.1.3-160000.3.1 * nftables-debugsource-1.1.3-160000.3.1 * libnftables1-debuginfo-1.1.3-160000.3.1 * nftables-1.1.3-160000.3.1 * libnftables1-1.1.3-160000.3.1 * nftables-devel-1.1.3-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-nftables-1.1.3-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1263855 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:53 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:38:53 -0000 Subject: SUSE-RU-2026:22341-1: moderate: Recommended update for suse-module-tools Message-ID: <178292393343.5373.15107889640098056321@bea6e15a6baf> # Recommended update for suse-module-tools Announcement ID: SUSE-RU-2026:22341-1 Release Date: 2026-06-22T15:08:34Z Rating: moderate References: * bsc#1257055 * jsc#PED-14573 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature and has one fix can now be installed. ## Description: This update for suse-module-tools fixes the following issues: * Update to version 16.0.65: * Remove erofs from the list of blacklisted file systems (jsc#PED-14573) * weak-modules2: don't remove symlinks in the rpm --reinstall case (bsc#1257055) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1047=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1047=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * suse-module-tools-16.0.65-160000.1.1 * suse-module-tools-scriptlets-16.0.65-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * suse-module-tools-16.0.65-160000.1.1 * suse-module-tools-scriptlets-16.0.65-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257055 * https://jira.suse.com/browse/PED-14573 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:07 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:39:07 -0000 Subject: SUSE-SU-2026:22340-1: moderate: Security update for mutt Message-ID: <178292394764.5373.7254557368384788308@bea6e15a6baf> # Security update for mutt Announcement ID: SUSE-SU-2026:22340-1 Release Date: 2026-06-22T14:45:20Z Rating: moderate References: * bsc#1263892 * bsc#1263893 * bsc#1263894 * bsc#1263895 * bsc#1263896 * bsc#1263897 * bsc#1264047 Cross-References: * CVE-2026-43859 * CVE-2026-43860 * CVE-2026-43861 * CVE-2026-43862 * CVE-2026-43863 * CVE-2026-43864 CVSS scores: * CVE-2026-43859 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43859 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43859 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43860 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43860 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43860 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43861 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43861 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43861 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43862 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43862 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43862 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43863 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43863 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-43863 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43864 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43864 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-43864 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for mutt fixes the following issues * CVE-2026-43859: `strfcpy` used instead of `memcpy` for the IMAP `auth_cram` MD5 digest (bsc#1263897). * CVE-2026-43860: truncation of `hash_passwd` by one byte for IMAP `auth_cram` MD5 digest (bsc#1263896). * CVE-2026-43861: missing check for `\0` in `url_pct_decode` (bsc#1263895). * CVE-2026-43862: mishandling of the `imap_auth_gss` security level (bsc#1263894). * CVE-2026-43863: infinite loop in `data_object_to_stream` in `crypt-gpgme.c` (bsc#1263893). * CVE-2026-43864: NULL pointer dereference in function `show_sig_summary` (bsc#1263892). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1028=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1028=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * mutt-doc-2.2.16-160000.2.1 * mutt-lang-2.2.16-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * mutt-debuginfo-2.2.16-160000.2.1 * mutt-debugsource-2.2.16-160000.2.1 * mutt-2.2.16-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * mutt-debuginfo-2.2.16-160000.2.1 * mutt-debugsource-2.2.16-160000.2.1 * mutt-2.2.16-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * mutt-doc-2.2.16-160000.2.1 * mutt-lang-2.2.16-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43859.html * https://www.suse.com/security/cve/CVE-2026-43860.html * https://www.suse.com/security/cve/CVE-2026-43861.html * https://www.suse.com/security/cve/CVE-2026-43862.html * https://www.suse.com/security/cve/CVE-2026-43863.html * https://www.suse.com/security/cve/CVE-2026-43864.html * https://bugzilla.suse.com/show_bug.cgi?id=1263892 * https://bugzilla.suse.com/show_bug.cgi?id=1263893 * https://bugzilla.suse.com/show_bug.cgi?id=1263894 * https://bugzilla.suse.com/show_bug.cgi?id=1263895 * https://bugzilla.suse.com/show_bug.cgi?id=1263896 * https://bugzilla.suse.com/show_bug.cgi?id=1263897 * https://bugzilla.suse.com/show_bug.cgi?id=1264047 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:12 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:39:12 -0000 Subject: SUSE-RU-2026:22339-1: moderate: Recommended update for plexus-classworlds, maven-surefire Message-ID: <178292395210.5373.3966691747794531446@bea6e15a6baf> # Recommended update for plexus-classworlds, maven-surefire Announcement ID: SUSE-RU-2026:22339-1 Release Date: 2026-06-22T14:43:18Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for plexus-classworlds, maven-surefire fixes the following issues: Changes in plexus-classworlds: Upgrade to version 2.12.0: * Bug fixes * Fix loadGlob using OR instead of AND for glob matching Changes in maven-surefire: Upgrade to 3.5.6: * New features and improvements * Introduce reportTestTimestamp option and include timestamp for test sets and test cases * Bug Fixes * Issue #2613 Debugging failsafe tests: Message 'Listening for transport dt_socket at address' is not displayed anymore when using maven.surefire.debug * Ensure that the statistics filename is calculated only once. * Add flakes attribute to use in testsuite report * [BACKPORT 3.5.x] [SUREFIRE-2049] - Fix SHUTDOWN type lost during command serialization. * fix: null guard for context map * Maintenance * 3.5.x/bug/cherry pick embedded mode its * Use surefire 3.5.5 by project itself for testing * Follow Oracle javadoc guidelines Changes in maven-surefire: * Upgrade to 3.5.6 * New features and improvements * Introduce reportTestTimestamp option and include timestamp for test sets and test cases * Bug Fixes * Issue #2613 Debugging failsafe tests: Message 'Listening for transport dt_socket at address' is not displayed anymore when using maven.surefire.debug * Ensure that the statistics filename is calculated only once. * Add flakes attribute to use in testsuite report * [BACKPORT 3.5.x] [SUREFIRE-2049] - Fix SHUTDOWN type lost during command serialization. * fix: null guard for context map * Maintenance * 3.5.x/bug/cherry pick embedded mode its * Use surefire 3.5.5 by project itself for testing * Follow Oracle javadoc guidelines * Dependency updates * Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 * Bump commons-io:commons-io from 2.21.0 to 2.22.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1042=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1042=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * maven-surefire-report-plugin-3.5.6-160000.1.1 * plexus-classworlds-javadoc-2.12.0-160000.1.1 * maven-surefire-provider-junit-3.5.6-160000.1.1 * maven-surefire-plugins-javadoc-3.5.6-160000.1.1 * maven-surefire-plugin-3.5.6-160000.1.1 * maven-surefire-provider-junit5-3.5.6-160000.1.1 * maven-surefire-provider-junit5-javadoc-3.5.6-160000.1.1 * maven-surefire-provider-testng-3.5.6-160000.1.1 * plexus-classworlds-2.12.0-160000.1.1 * maven-surefire-report-parser-3.5.6-160000.1.1 * maven-surefire-3.5.6-160000.1.1 * maven-surefire-javadoc-3.5.6-160000.1.1 * maven-failsafe-plugin-3.5.6-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * maven-surefire-report-plugin-3.5.6-160000.1.1 * plexus-classworlds-javadoc-2.12.0-160000.1.1 * maven-surefire-provider-junit-3.5.6-160000.1.1 * maven-surefire-plugins-javadoc-3.5.6-160000.1.1 * maven-surefire-plugin-3.5.6-160000.1.1 * maven-surefire-provider-testng-3.5.6-160000.1.1 * maven-surefire-provider-junit5-3.5.6-160000.1.1 * maven-surefire-provider-junit5-javadoc-3.5.6-160000.1.1 * plexus-classworlds-2.12.0-160000.1.1 * maven-surefire-report-parser-3.5.6-160000.1.1 * maven-surefire-3.5.6-160000.1.1 * maven-surefire-javadoc-3.5.6-160000.1.1 * maven-failsafe-plugin-3.5.6-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:19 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:39:19 -0000 Subject: SUSE-SU-2026:22338-1: moderate: Security update for avahi Message-ID: <178292395955.5373.11868559955381590414@bea6e15a6baf> # Security update for avahi Announcement ID: SUSE-SU-2026:22338-1 Release Date: 2026-06-22T14:40:15Z Rating: moderate References: * bsc#1257235 * bsc#1261546 Cross-References: * CVE-2026-24401 * CVE-2026-34933 CVSS scores: * CVE-2026-24401 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-24401 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-24401 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-34933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34933 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2026-34933: reachable assertion in `transport_flags_from_domain` can crash the `avahi-daemon` (bsc#1261546). * CVE-2026-24401: unsolicited mDNS responses containing a recursive CNAME record can crash the `avahi-daemon` (bsc#1257235). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1026=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1026=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * avahi-autoipd-0.8-160000.5.1 * libhowl0-debuginfo-0.8-160000.5.1 * libavahi-common3-0.8-160000.5.1 * libavahi-glib-devel-0.8-160000.5.1 * libavahi-client3-debuginfo-0.8-160000.5.1 * libdns_sd-0.8-160000.5.1 * libavahi-glib1-0.8-160000.5.1 * libavahi-core7-0.8-160000.5.1 * libdns_sd-debuginfo-0.8-160000.5.1 * libavahi-ui-gtk3-0-debuginfo-0.8-160000.5.1 * avahi-utils-gtk-0.8-160000.5.1 * libavahi-ui-gtk3-0-0.8-160000.5.1 * avahi-autoipd-debuginfo-0.8-160000.5.1 * typelib-1_0-Avahi-0_6-0.8-160000.5.1 * avahi-debuginfo-0.8-160000.5.1 * libavahi-core7-debuginfo-0.8-160000.5.1 * libavahi-gobject-devel-0.8-160000.5.1 * libavahi-devel-0.8-160000.5.1 * avahi-0.8-160000.5.1 * libavahi-client3-0.8-160000.5.1 * libavahi-common3-debuginfo-0.8-160000.5.1 * libavahi-libevent1-debuginfo-0.8-160000.5.1 * python313-avahi-0.8-160000.5.1 * avahi-utils-debuginfo-0.8-160000.5.1 * libavahi-gobject0-debuginfo-0.8-160000.5.1 * libhowl0-0.8-160000.5.1 * avahi-utils-gtk-debuginfo-0.8-160000.5.1 * avahi-debugsource-0.8-160000.5.1 * avahi-compat-mDNSResponder-devel-0.8-160000.5.1 * libavahi-gobject0-0.8-160000.5.1 * avahi-glib2-debugsource-0.8-160000.5.1 * python3-avahi-gtk-0.8-160000.5.1 * libavahi-glib1-debuginfo-0.8-160000.5.1 * libavahi-libevent1-0.8-160000.5.1 * avahi-utils-0.8-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * avahi-lang-0.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * avahi-autoipd-0.8-160000.5.1 * libhowl0-debuginfo-0.8-160000.5.1 * libavahi-common3-0.8-160000.5.1 * libavahi-glib-devel-0.8-160000.5.1 * libavahi-client3-debuginfo-0.8-160000.5.1 * libdns_sd-0.8-160000.5.1 * libavahi-glib1-0.8-160000.5.1 * libavahi-core7-0.8-160000.5.1 * libdns_sd-debuginfo-0.8-160000.5.1 * libavahi-ui-gtk3-0-debuginfo-0.8-160000.5.1 * avahi-utils-gtk-0.8-160000.5.1 * libavahi-ui-gtk3-0-0.8-160000.5.1 * typelib-1_0-Avahi-0_6-0.8-160000.5.1 * avahi-autoipd-debuginfo-0.8-160000.5.1 * avahi-debuginfo-0.8-160000.5.1 * libavahi-core7-debuginfo-0.8-160000.5.1 * libavahi-devel-0.8-160000.5.1 * avahi-0.8-160000.5.1 * libavahi-gobject-devel-0.8-160000.5.1 * libavahi-client3-0.8-160000.5.1 * python313-avahi-0.8-160000.5.1 * libavahi-common3-debuginfo-0.8-160000.5.1 * libavahi-libevent1-debuginfo-0.8-160000.5.1 * avahi-utils-debuginfo-0.8-160000.5.1 * libavahi-gobject0-debuginfo-0.8-160000.5.1 * libhowl0-0.8-160000.5.1 * avahi-utils-gtk-debuginfo-0.8-160000.5.1 * avahi-debugsource-0.8-160000.5.1 * avahi-compat-mDNSResponder-devel-0.8-160000.5.1 * libavahi-gobject0-0.8-160000.5.1 * avahi-glib2-debugsource-0.8-160000.5.1 * python3-avahi-gtk-0.8-160000.5.1 * libavahi-glib1-debuginfo-0.8-160000.5.1 * libavahi-libevent1-0.8-160000.5.1 * avahi-utils-0.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * avahi-lang-0.8-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-24401.html * https://www.suse.com/security/cve/CVE-2026-34933.html * https://bugzilla.suse.com/show_bug.cgi?id=1257235 * https://bugzilla.suse.com/show_bug.cgi?id=1261546 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:23 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:39:23 -0000 Subject: SUSE-OU-2026:22337-1: moderate: Optional update for php-imagick Message-ID: <178292396354.5373.15068021339339966693@bea6e15a6baf> # Optional update for php-imagick Announcement ID: SUSE-OU-2026:22337-1 Release Date: 2026-06-22T14:38:29Z Rating: moderate References: * jsc#PED-16175 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for php-imagick fixes the following issues: Ship php8-imagick initially. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1043=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1043=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * php8-imagick-debuginfo-3.8.1-160000.1.1 * php8-imagick-debugsource-3.8.1-160000.1.1 * php8-imagick-3.8.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * php8-imagick-debuginfo-3.8.1-160000.1.1 * php8-imagick-debugsource-3.8.1-160000.1.1 * php8-imagick-3.8.1-160000.1.1 ## References: * https://jira.suse.com/browse/PED-16175 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:27 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:39:27 -0000 Subject: SUSE-RU-2026:22336-1: moderate: Recommended update for wicked2nm Message-ID: <178292396746.5373.7385518403542018993@bea6e15a6baf> # Recommended update for wicked2nm Announcement ID: SUSE-RU-2026:22336-1 Release Date: 2026-06-22T14:37:16Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for wicked2nm fixes the following issues: * Update v1.5.0: * Respect create-cid and client-id in interface xml * Require at least one file for migrate and show commands * Perform extra validation for correct xml file * Improve dhcp.update default and user info * Update dependencies * Allow DHCP+staticIP addresses * Fix DHCLIENT_SET_DEFAULT_ROUTE="no" * Handle 'STATIC_FALLBACK' and 'NetworkManager' in netconfig * Implement team to bond migration * Update agama-network to remove dependency on curl * Reenable `update` in cargo vendor service ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1038=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1038=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * wicked2nm-debuginfo-1.5.0-160000.1.1 * wicked2nm-debugsource-1.5.0-160000.1.1 * wicked2nm-1.5.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * wicked2nm-debuginfo-1.5.0-160000.1.1 * wicked2nm-debugsource-1.5.0-160000.1.1 * wicked2nm-1.5.0-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:33 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:39:33 -0000 Subject: SUSE-SU-2026:22335-1: moderate: Security update for postfix Message-ID: <178292397387.5373.5921951424030785527@bea6e15a6baf> # Security update for postfix Announcement ID: SUSE-SU-2026:22335-1 Release Date: 2026-06-22T14:37:16Z Rating: moderate References: * bsc#1264062 Cross-References: * CVE-2026-43964 CVSS scores: * CVE-2026-43964 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43964 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for postfix fixes the following issue * CVE-2026-43964: buffer overread and process crash via an enhanced status code that lacks text after the third number (bsc#1264062). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1032=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1032=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postfix-mysql-debuginfo-3.10.2-160000.3.1 * postfix-postgresql-debuginfo-3.10.2-160000.3.1 * postfix-3.10.2-160000.3.1 * postfix-mysql-3.10.2-160000.3.1 * postfix-debugsource-3.10.2-160000.3.1 * postfix-debuginfo-3.10.2-160000.3.1 * postfix-postgresql-3.10.2-160000.3.1 * postfix-ldap-3.10.2-160000.3.1 * postfix-ldap-debuginfo-3.10.2-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * postfix-doc-3.10.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postfix-mysql-debuginfo-3.10.2-160000.3.1 * postfix-postgresql-debuginfo-3.10.2-160000.3.1 * postfix-3.10.2-160000.3.1 * postfix-debugsource-3.10.2-160000.3.1 * postfix-mysql-3.10.2-160000.3.1 * postfix-postgresql-3.10.2-160000.3.1 * postfix-debuginfo-3.10.2-160000.3.1 * postfix-ldap-3.10.2-160000.3.1 * postfix-ldap-debuginfo-3.10.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * postfix-doc-3.10.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43964.html * https://bugzilla.suse.com/show_bug.cgi?id=1264062 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:37 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:39:37 -0000 Subject: SUSE-RU-2026:22334-1: moderate: Recommended update for rav1e Message-ID: <178292397797.5373.16892544733246932785@bea6e15a6baf> # Recommended update for rav1e Announcement ID: SUSE-RU-2026:22334-1 Release Date: 2026-06-22T14:37:16Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for rav1e fixes the following issues: * Update to version 0.8.1: * Fix bit overflows when writing headers * Update dependencies ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1030=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1030=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * librav1e0_8-debuginfo-0.8.1-160000.1.1 * rav1e-debuginfo-0.8.1-160000.1.1 * rav1e-0.8.1-160000.1.1 * librav1e0_8-0.8.1-160000.1.1 * rav1e-debugsource-0.8.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * librav1e0_8-debuginfo-0.8.1-160000.1.1 * rav1e-debuginfo-0.8.1-160000.1.1 * rav1e-0.8.1-160000.1.1 * librav1e0_8-0.8.1-160000.1.1 * rav1e-debugsource-0.8.1-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:43 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:39:43 -0000 Subject: SUSE-SU-2026:22333-1: important: Security update for 389-ds Message-ID: <178292398337.5373.3550355203725328291@bea6e15a6baf> # Security update for 389-ds Announcement ID: SUSE-SU-2026:22333-1 Release Date: 2026-06-22T14:37:16Z Rating: important References: * bsc#1265898 Cross-References: * CVE-2026-9064 CVSS scores: * CVE-2026-9064 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9064 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for 389-ds fixes the following issue * CVE-2026-9064: unbounded LDAP controls count in `get_ldapmessage_controls_ext()` can lead to amplified CPU time and heap allocation and a denial of service (bsc#1265898). Changes for 389-ds: * Update to version 3.0.6~git337.647f49042: * Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542) * Issue 7531 - Fix LMDB replication regression_m2 failures and core dumps (#7575) * Issue 7496 - fix cherry-pick error * Issue 7490 - Enable USDT probes by default in RPM (#7491) * Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload * Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559) * Issue 7500 - Prevent unsigned integer underflow during stalled import * Issue 7562 - Error: NssSsl.add_cert() got an unexpected keyword argument 'input_file' (#7563) * Issue 7560 - lib389 - Add helper function for checking ASAN files * Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540) * Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values (#7550) * Issue 7440 - Substring index produces empty results and can crash when non- default nsSubStrBegin/nsSubStrEnd lengths are configured (#7441) * Fix test389 imports on older branches * Issue 7267 - MDB_BAD_VALSIZE error when updating index (#7268) * Issue 7327 - dsctl healthcheck DSMOLE0001 inaccurate recommendations with multiple backends (#7328) * Issue 7372 - Reindex adds tombstones to ancestorid causing export failures (#7373) * Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths (#7438) * Issue 6922 - AddressSanitizer: leaks found by acl test suite * Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7556) * Issue 7554 - deref plugin null pointer dereference if ber_init fails * Issue 7493 - RFE - Add ShadowAccount fixup task * Issue 7507 - UI - cleanup style and alignments * Issue 7514 - Crash when doing moddn on very large subtree * Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit * Issue 7496 - Fix latest GCC compiler warnings * Issue 7503 - CVE-2026-9064 - Add a limit to the number controls per operation * Issue 7300 - RFE - Add OS-level thread names to all server threads (#7301) * Issue 7307 - RFE - Expose work queue and worker utilization metrics (#7308) * Issue 7464 - CLI - allow dsidm to work with other user types * Issue 7457 - Refactor memberOf perf test (#7458) * Issue 7452 - UI - password polices - reorganize settings * Issue 7431 - password policy - passwordBadWords is ignored in local policies * Issue 7155 - build_candidate_list - Database error 11 with range search (#7156) * Issue 7426 - logconv.py is out of sync with server-emitted note codes (#7427) * Issue 7417 - UI - global password policy syntax settings missing passwordMaxRepeats * Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7411) * Issue 7088 - Change log level for "Can't locate CSN" error message * Issue 7423 - cleanup pblock after freeing pre/post entries * Issue 7418 - Use-after-free in deferred memberof (#7419) * Issue 7407 - dbscan -k option - fix cherry-pick error * Issue 7407 - dbscan -k option display entries that do not match the specified key * Issue 7404 - fix latest compiler warnings(cherry-pick issue) * Issue 7404 - fix latest compiler warnings * Issue 7394 - UI - Manual typing of ports can leave out digits (#7395) * Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI (#7386) * Issue 7246 - correct formatting of 'Gen as CSN' in dsctl get-nsstate output (#7247) * Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids (#7127) * Issue 7370 - Runtime LSan/TSan injection for pytest (#7371) * Issue 7378 - Make sure suffix entry always gets assigned ID 1 * Issue 7380 - Internal op with negative wtime and large optime (#7381) * Issue 7362 - UI - Some FormSelect onChange parameters are reversed * Issue 7368 - UI - global password policy page is missing passwordmintokenlength * Issue 7366 - Memory leaks in syncrepl plugin during persistent search operations (#7367) * Issue 3658 - UI/CLI - show progress of db tasks * Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix (#7357) * Issue 7271 - Add test for retrocl trimming shutdown crash (#7356) * Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch (#7364) * Issue 7337 - UI - refactor all error handling to use getApiErrorMessge * Issue 1704 - DNA plugin creates invalid shared config entry with port 0 (#7352) * Issue 6753 - Removing ticket 477828 test and porting to DSLdapObject (#6989) * Issue 7348 - CI - Fix failing dsconf security CLI add cert test (#7349) * Issue 7346 - DS does not handle escape char in bind user (#7347) * Issue 7322 - Fix cherry-pick error (reject repl agmt that points to itself) * Issue 7322 - Reject adding a replication agreement that points to itself * Issue 7312 - UI - Database Maximum Size cannot be easily set by typing (#7313) * Issue 7342 - CI - repl config regression (#7343) * Issue 7339 - Return the exact DN during export * Issue - UI - Improve suffix import LDIF table * Issue 7325 - UI - new error parser missing import * Issue 7325 - UI - create an error parser for cockpit spawn errors * Issue 7319 - Action menu for certificates remains in empty certificate list (#7320) * Issue 7265 - CI - fix retro changelog maxage validation test * Issue 7093 - A password policy can be created even when an identical policy already exists (#7283) * Issue 7316 - UI - update npm module immutable * Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in conftest.py (#7234) * Issue 7314 - UI - Add progress steppers to Security, Database, and Replication tabs * Issuei 7281 - UI - Add encryption module management * Issue 7271 - Add new plugin pre-close function check to plugin_invoke_plugin_pb * Issue 7304 - retrocl should not cache DN * Issue 7265 - Add dse modify callback to validate retrocl trimming settings * Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in progress (#7187) * Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch (#7298) * Issue 7291 - Crash when configuring a replica with an incorrect nsds5ReplicaRoot (#7292) * Issue 7271 - implement a pre-close plugin function * Issue 7295 - changelog max age validation cherry-pick error * Issue 7281 - RFE - CLI - add support to managing additional encryption modules * Issue 7265 - changelog maxage validation is not strict enough * Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7285) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1023=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1023=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libsvrcore0-debuginfo-3.0.6~git337.647f49042-160000.1.1 * libsvrcore0-3.0.6~git337.647f49042-160000.1.1 * 389-ds-debugsource-3.0.6~git337.647f49042-160000.1.1 * 389-ds-snmp-debuginfo-3.0.6~git337.647f49042-160000.1.1 * 389-ds-3.0.6~git337.647f49042-160000.1.1 * 389-ds-debuginfo-3.0.6~git337.647f49042-160000.1.1 * 389-ds-devel-3.0.6~git337.647f49042-160000.1.1 * lib389-3.0.6~git337.647f49042-160000.1.1 * 389-ds-snmp-3.0.6~git337.647f49042-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libsvrcore0-debuginfo-3.0.6~git337.647f49042-160000.1.1 * libsvrcore0-3.0.6~git337.647f49042-160000.1.1 * 389-ds-debugsource-3.0.6~git337.647f49042-160000.1.1 * 389-ds-snmp-debuginfo-3.0.6~git337.647f49042-160000.1.1 * 389-ds-3.0.6~git337.647f49042-160000.1.1 * 389-ds-debuginfo-3.0.6~git337.647f49042-160000.1.1 * 389-ds-devel-3.0.6~git337.647f49042-160000.1.1 * lib389-3.0.6~git337.647f49042-160000.1.1 * 389-ds-snmp-3.0.6~git337.647f49042-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9064.html * https://bugzilla.suse.com/show_bug.cgi?id=1265898 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:53 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:39:53 -0000 Subject: SUSE-SU-2026:22332-1: moderate: Security update for util-linux Message-ID: <178292399397.5373.12731506684217445362@bea6e15a6baf> # Security update for util-linux Announcement ID: SUSE-SU-2026:22332-1 Release Date: 2026-06-22T14:34:40Z Rating: moderate References: * bsc#1261606 Cross-References: * CVE-2026-27456 CVSS scores: * CVE-2026-27456 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-27456 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for util-linux fixes the following issue * CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1040=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1040=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libsmartcols1-debuginfo-2.41.1-160000.4.1 * uuidd-debuginfo-2.41.1-160000.4.1 * libmount-devel-static-2.41.1-160000.4.1 * util-linux-2.41.1-160000.4.1 * libuuid-devel-2.41.1-160000.4.1 * libuuid1-debuginfo-2.41.1-160000.4.1 * libsmartcols-devel-static-2.41.1-160000.4.1 * libuuid-devel-static-2.41.1-160000.4.1 * python-libmount-debugsource-2.41.1-160000.4.1 * libblkid-devel-2.41.1-160000.4.1 * python313-libmount-debuginfo-2.41.1-160000.4.1 * libblkid1-2.41.1-160000.4.1 * util-linux-systemd-debuginfo-2.41.1-160000.4.1 * liblastlog2-2-debuginfo-2.41.1-160000.4.1 * lastlog2-2.41.1-160000.4.1 * util-linux-debugsource-2.41.1-160000.4.1 * python313-libmount-2.41.1-160000.4.1 * lastlog2-debuginfo-2.41.1-160000.4.1 * libmount1-2.41.1-160000.4.1 * libfdisk-devel-static-2.41.1-160000.4.1 * util-linux-systemd-debugsource-2.41.1-160000.4.1 * util-linux-debuginfo-2.41.1-160000.4.1 * liblastlog2-2-2.41.1-160000.4.1 * util-linux-tty-tools-debuginfo-2.41.1-160000.4.1 * libfdisk-devel-2.41.1-160000.4.1 * libfdisk1-debuginfo-2.41.1-160000.4.1 * libblkid-devel-static-2.41.1-160000.4.1 * libsmartcols1-2.41.1-160000.4.1 * util-linux-tty-tools-2.41.1-160000.4.1 * libuuid1-2.41.1-160000.4.1 * libmount-devel-2.41.1-160000.4.1 * libfdisk1-2.41.1-160000.4.1 * liblastlog2-devel-2.41.1-160000.4.1 * util-linux-systemd-2.41.1-160000.4.1 * libblkid1-debuginfo-2.41.1-160000.4.1 * libsmartcols-devel-2.41.1-160000.4.1 * uuidd-2.41.1-160000.4.1 * libmount1-debuginfo-2.41.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * util-linux-lang-2.41.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libsmartcols1-debuginfo-2.41.1-160000.4.1 * uuidd-debuginfo-2.41.1-160000.4.1 * libmount-devel-static-2.41.1-160000.4.1 * util-linux-2.41.1-160000.4.1 * libuuid-devel-2.41.1-160000.4.1 * libuuid1-debuginfo-2.41.1-160000.4.1 * libsmartcols-devel-static-2.41.1-160000.4.1 * libuuid-devel-static-2.41.1-160000.4.1 * python-libmount-debugsource-2.41.1-160000.4.1 * libblkid-devel-2.41.1-160000.4.1 * python313-libmount-debuginfo-2.41.1-160000.4.1 * libblkid1-2.41.1-160000.4.1 * util-linux-systemd-debuginfo-2.41.1-160000.4.1 * lastlog2-debuginfo-2.41.1-160000.4.1 * liblastlog2-2-debuginfo-2.41.1-160000.4.1 * util-linux-debugsource-2.41.1-160000.4.1 * python313-libmount-2.41.1-160000.4.1 * lastlog2-2.41.1-160000.4.1 * libmount1-2.41.1-160000.4.1 * libfdisk-devel-static-2.41.1-160000.4.1 * util-linux-systemd-debugsource-2.41.1-160000.4.1 * util-linux-debuginfo-2.41.1-160000.4.1 * liblastlog2-2-2.41.1-160000.4.1 * util-linux-tty-tools-debuginfo-2.41.1-160000.4.1 * libfdisk-devel-2.41.1-160000.4.1 * libfdisk1-debuginfo-2.41.1-160000.4.1 * libblkid-devel-static-2.41.1-160000.4.1 * libsmartcols1-2.41.1-160000.4.1 * util-linux-tty-tools-2.41.1-160000.4.1 * libuuid1-2.41.1-160000.4.1 * libmount-devel-2.41.1-160000.4.1 * libfdisk1-2.41.1-160000.4.1 * liblastlog2-devel-2.41.1-160000.4.1 * util-linux-systemd-2.41.1-160000.4.1 * libblkid1-debuginfo-2.41.1-160000.4.1 * libsmartcols-devel-2.41.1-160000.4.1 * uuidd-2.41.1-160000.4.1 * libmount1-debuginfo-2.41.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * util-linux-lang-2.41.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27456.html * https://bugzilla.suse.com/show_bug.cgi?id=1261606 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:40:02 -0000 Subject: SUSE-SU-2026:22331-1: moderate: Security update for rpcbind Message-ID: <178292400283.5373.5139966432871465584@bea6e15a6baf> # Security update for rpcbind Announcement ID: SUSE-SU-2026:22331-1 Release Date: 2026-06-22T14:34:40Z Rating: moderate References: * bsc#1117217 * bsc#1181400 * bsc#1267212 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has three fixes can now be installed. ## Description: This update for rpcbind fixes the following issues * Update to rpcbind 1.2.9 (bsc#1267212) https://lore.kernel.org/linux- nfs/5cad3ab4-d24a-45fa-b1e9-d57b2c47a5e4 at redhat.com/ * rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist() * rpcbind: Stop unauthenticated oversized allocation in PMAPPROC_CALLIT decode * rpcbind: fix memory leak in read_warmstart() * rpcbind: fix memory leaks in network_init() * rpcbind: fix memory leak in init_transport() * Added -v (print version and compile flags) * rpcinfo: Removed a number of "old-style function definition" warnings * man/rpcbind: Update list of options * Comment out ListenStream=@/run/rpcbind.sock * [nfs/nfs-utils/rpcbind] rpcbind: avoid dereferencing NULL from realloc() * systemd/rpcbind.service.in: Add various hardenings options * man/rpcbind: Add Files section to manpage * Moved rpcbind.lock and default configs to /run instead of /var/run ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1031=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1031=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * rpcbind-debugsource-1.2.9-160000.1.1 * rpcbind-1.2.9-160000.1.1 * rpcbind-debuginfo-1.2.9-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * rpcbind-debugsource-1.2.9-160000.1.1 * rpcbind-1.2.9-160000.1.1 * rpcbind-debuginfo-1.2.9-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1117217 * https://bugzilla.suse.com/show_bug.cgi?id=1181400 * https://bugzilla.suse.com/show_bug.cgi?id=1267212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:11 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:40:11 -0000 Subject: SUSE-SU-2026:22330-1: important: Security update for perl-DBI Message-ID: <178292401126.5373.4128531327656900175@bea6e15a6baf> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:22330-1 Release Date: 2026-06-22T14:30:38Z Rating: important References: * bsc#1267849 * bsc#1267957 Cross-References: * CVE-2026-10879 * CVE-2026-9698 CVSS scores: * CVE-2026-10879 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10879 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10879 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9698 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited- sized buffer (bsc#1267957). * CVE-2026-10879: SQL statements with more than 9 binders can cause an heap overflow (bsc#1267849). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1041=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1041=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-DBI-debugsource-1.647.0-160000.3.1 * perl-DBI-1.647.0-160000.3.1 * perl-DBI-debuginfo-1.647.0-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.647.0-160000.3.1 * perl-DBI-1.647.0-160000.3.1 * perl-DBI-debuginfo-1.647.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10879.html * https://www.suse.com/security/cve/CVE-2026-9698.html * https://bugzilla.suse.com/show_bug.cgi?id=1267849 * https://bugzilla.suse.com/show_bug.cgi?id=1267957 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:16 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:40:16 -0000 Subject: SUSE-SU-2026:22329-1: important: Security update for perl-Config-IniFiles Message-ID: <178292401677.5373.8817855163347278613@bea6e15a6baf> # Security update for perl-Config-IniFiles Announcement ID: SUSE-SU-2026:22329-1 Release Date: 2026-06-22T14:30:38Z Rating: important References: * bsc#1268236 Cross-References: * CVE-2026-11527 CVSS scores: * CVE-2026-11527 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-11527 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Config-IniFiles fixes the following issue * CVE-2026-11527: OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle (bsc#1268236). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1024=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1024=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * perl-Config-IniFiles-3.000003-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * perl-Config-IniFiles-3.000003-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11527.html * https://bugzilla.suse.com/show_bug.cgi?id=1268236 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:26 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:40:26 -0000 Subject: SUSE-SU-2026:22328-1: important: Security update for google-cloud-sap-agent Message-ID: <178292402605.5373.6279863904136223828@bea6e15a6baf> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:22328-1 Release Date: 2026-06-22T14:30:38Z Rating: important References: * bsc#1265764 * bsc#1265991 * bsc#1266604 Cross-References: * CVE-2026-33186 * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265764). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266604). Changes for google-cloud-sap-agent: * Update to version 3.15 * Remove LoggingClient error failure for hanadiskrestore and hanadiskbackup. * Add checks for unexpected arguments in hanadiskbackup and hanadiskrestore. * Update SAP Agent version to 3.15. * Refactor grubBootLoaderX5 to check for BLS support via grub2-mkconfig help. * Update all go dependencies * Check grub2-mkconfig for BLS support on X4 instances. * Add tenant SID collection to supportbundle. * Update golang.org/x/net dependency. This is to address (#444) * Fork tuned.conf to tuned-x5.conf for X5 series configurations * Enable configureX5 in configureinstance. * Create skeleton implementation and tests for X5 configureinstance support. * Enable detection of x5 machine types in configureinstance * Update to version 3.14 (bsc#1265991) * Update Daemon Restart method to pass the correct cancel function to the new handler. * Remove redundant error logging in HANA disk restore. * Fetch and rename Logical Volume during HANA disk restore. * Add usage metrics for CMEK disk restore. * Add multi-region and global KMS keys location checks. * Convert HANA SID to uppercase in hanadiskbackup and hanadiskrestore. * Log warning instead of erroring out on KMS key get failure. * Initialize GCE client in status onetime command. * Validate presence of KMS key in hanadiskrestore. * Add SID parameter to HANA backup/restore path functions. * Add KMS key location validation for HANA disk restore. * Update agent version to 3.14. * Fixes an issue if there is a whitespace around an argument passed in * Add validation to prevent using both CSEK and KMS keys in hanadiskrestore. * Handle disk recreation in HANA disk restore when IOPS, throughput, size, or KMS key are specified. * Refactor disk restore and configuration logic. * Add support for CMEK encryption of restored disks. * Remove obsolete TODOs. * Update to version 3.13 * Replace strings.TrimSuffix with strings.TrimSpace in hanabackup.go * Improve error messages in hanabackup.go. * Add system state logging and logical device verification. * Minor version bump * Improve SAP instance comparison for process metrics collectors to prevent unnecessary restarts of collectors. * Delete supportbundlehandler package. * Remove configurehandler from sapguestactions. * Delete hanadiskbackuphandler from sapguestactions. * Remove Guest Actions and GCBDR Actions from initial daemon start. * Remove `gsutil` check from collection definition. * Delete performancediagnosticshandler package. * Remove unused handlers and shell command execution. * status feature fixes - pass secret name * Fix an issue in system discovery if discovering a network fails, particularly due to an IAM permission error. * Add verification for HANA data volume state after disk restore. * Error handling for rescanVolumegroups and improved logging. * Add link to What's New page in the sapagent README. * Add secret manager IAM checks if secret key is preset in status ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1022=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1022=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * google-cloud-sap-agent-3.15-160000.1.1 * google-cloud-sap-agent-debuginfo-3.15-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * google-cloud-sap-agent-3.15-160000.1.1 * google-cloud-sap-agent-debuginfo-3.15-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1265764 * https://bugzilla.suse.com/show_bug.cgi?id=1265991 * https://bugzilla.suse.com/show_bug.cgi?id=1266604 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:31 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:40:31 -0000 Subject: SUSE-RU-2026:22327-1: moderate: Recommended update for disk-encryption-tool Message-ID: <178292403105.5373.11637648302777692749@bea6e15a6baf> # Recommended update for disk-encryption-tool Announcement ID: SUSE-RU-2026:22327-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for disk-encryption-tool fixes the following issues: * Update to version 1+git20260304.d12960d: * Use UUID= in crypttab * Update to version 1+git20260129.f7df08c: * Fix comment typo * Update to version 1+git20260121.010c05a: * Remove x-growpart.grow flag for encrypted devices * Requires combustion for firstboot.target * Drop x-initrd.attach for cr_etc and cr_var * Update to version 1+git20250729.d86f79f: * Build also for riscv64 * Update to version 1+git20250625.f0b909a: * cr_etc (and cr_var) can be mounted in initrd ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1039=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1039=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * disk-encryption-tool-1+git20260304.d12960d-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * disk-encryption-tool-1+git20260304.d12960d-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:40:36 -0000 Subject: SUSE-SU-2026:22326-1: moderate: Security update for keylime Message-ID: <178292403658.5373.12155680200043467901@bea6e15a6baf> # Security update for keylime Announcement ID: SUSE-SU-2026:22326-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1264265 Cross-References: * CVE-2026-6420 CVSS scores: * CVE-2026-6420 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-6420 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2026-6420 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for keylime fixes the following issue * CVE-2026-6420: use of hardcoded challenge nonce for TPM quote attestation allows for security bypass (bsc#1264265). Changes for keylime: * Update to version 7.14.2. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1037=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1037=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * keylime-tenant-7.14.2-160000.1.1 * keylime-firewalld-7.14.2-160000.1.1 * keylime-tpm_cert_store-7.14.2-160000.1.1 * keylime-config-7.14.2-160000.1.1 * keylime-verifier-7.14.2-160000.1.1 * keylime-logrotate-7.14.2-160000.1.1 * keylime-registrar-7.14.2-160000.1.1 * python313-keylime-7.14.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * keylime-tenant-7.14.2-160000.1.1 * keylime-firewalld-7.14.2-160000.1.1 * keylime-tpm_cert_store-7.14.2-160000.1.1 * keylime-config-7.14.2-160000.1.1 * keylime-verifier-7.14.2-160000.1.1 * keylime-logrotate-7.14.2-160000.1.1 * keylime-registrar-7.14.2-160000.1.1 * python313-keylime-7.14.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6420.html * https://bugzilla.suse.com/show_bug.cgi?id=1264265 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:40:42 -0000 Subject: SUSE-SU-2026:22325-1: moderate: Security update for sed Message-ID: <178292404234.5373.5054178605928557628@bea6e15a6baf> # Security update for sed Announcement ID: SUSE-SU-2026:22325-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1262144 Cross-References: * CVE-2026-5958 CVSS scores: * CVE-2026-5958 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N * CVE-2026-5958 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N * CVE-2026-5958 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for sed fixes the following issue * CVE-2026-5958: a TOCTOU race can allow to read attacker-controlled content and write it to an unintended file (bsc#1262144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1036=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1036=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * sed-debuginfo-4.9-160000.3.1 * sed-4.9-160000.3.1 * sed-debugsource-4.9-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * sed-lang-4.9-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * sed-debuginfo-4.9-160000.3.1 * sed-4.9-160000.3.1 * sed-debugsource-4.9-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * sed-lang-4.9-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5958.html * https://bugzilla.suse.com/show_bug.cgi?id=1262144 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:50 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:40:50 -0000 Subject: SUSE-SU-2026:22324-1: moderate: Security update for libexif Message-ID: <178292405095.5373.3535321153016530969@bea6e15a6baf> # Security update for libexif Announcement ID: SUSE-SU-2026:22324-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1259755 * bsc#1262000 * bsc#1262001 Cross-References: * CVE-2026-32775 * CVE-2026-40385 * CVE-2026-40386 CVSS scores: * CVE-2026-32775 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-32775 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-32775 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40385 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-40386 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for libexif fixes the following issues * CVE-2026-32775: Buffer overwrite via integer underflow in MakerNotes decoding (bsc#1259755). * CVE-2026-40385: information disclosure and crashes via integer overflow in Nikon MakerNote handling (bsc#1262000). * CVE-2026-40386: denial of service and information disclosure via integer underflow in MakerNote decoding (bsc#1262001). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1035=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1035=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libexif12-debuginfo-0.6.26-160000.1.1 * libexif12-0.6.26-160000.1.1 * libexif-debugsource-0.6.26-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libexif12-debuginfo-0.6.26-160000.1.1 * libexif12-0.6.26-160000.1.1 * libexif-debugsource-0.6.26-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32775.html * https://www.suse.com/security/cve/CVE-2026-40385.html * https://www.suse.com/security/cve/CVE-2026-40386.html * https://bugzilla.suse.com/show_bug.cgi?id=1259755 * https://bugzilla.suse.com/show_bug.cgi?id=1262000 * https://bugzilla.suse.com/show_bug.cgi?id=1262001 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:00 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:41:00 -0000 Subject: SUSE-RU-2026:22323-1: moderate: Recommended update for checkmedia Message-ID: <178292406096.5373.255136135668027126@bea6e15a6baf> # Recommended update for checkmedia Announcement ID: SUSE-RU-2026:22323-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1243125 * bsc#1248168 * bsc#1260860 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has three fixes can now be installed. ## Description: This update for checkmedia fixes the following issues: * Update to version 6.6: * include pre-built documentation (bsc#1260860) * simplify spec file * add support for GPT partitions * Update to version 6.5: * set LC_MESSAGES to C when running gpg (bsc#1248168) * fix minor issue when printing app_id * Update to version 6.4: * added --[no-]signature-tag options for explicit handling of the 'signature' tag (bsc#1243125) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1034=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1034=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * checkmedia-debugsource-6.6-160000.1.1 * libmediacheck6-6.6-160000.1.1 * checkmedia-6.6-160000.1.1 * libmediacheck6-debuginfo-6.6-160000.1.1 * checkmedia-debuginfo-6.6-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * checkmedia-debugsource-6.6-160000.1.1 * libmediacheck6-6.6-160000.1.1 * checkmedia-6.6-160000.1.1 * libmediacheck6-debuginfo-6.6-160000.1.1 * checkmedia-debuginfo-6.6-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1243125 * https://bugzilla.suse.com/show_bug.cgi?id=1248168 * https://bugzilla.suse.com/show_bug.cgi?id=1260860 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:09 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:41:09 -0000 Subject: SUSE-SU-2026:22322-1: moderate: Security update for krb5 Message-ID: <178292406908.5373.12635328425217500760@bea6e15a6baf> # Security update for krb5 Announcement ID: SUSE-SU-2026:22322-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1263366 * bsc#1263367 Cross-References: * CVE-2026-40355 * CVE-2026-40356 CVSS scores: * CVE-2026-40355 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40355 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for krb5 fixes the following issues * CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). * CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1033=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1033=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * krb5-client-1.21.3-160000.3.1 * krb5-plugin-preauth-spake-1.21.3-160000.3.1 * krb5-plugin-kdb-ldap-1.21.3-160000.3.1 * krb5-1.21.3-160000.3.1 * krb5-server-1.21.3-160000.3.1 * krb5-plugin-preauth-pkinit-1.21.3-160000.3.1 * krb5-plugin-preauth-spake-debuginfo-1.21.3-160000.3.1 * krb5-server-debuginfo-1.21.3-160000.3.1 * krb5-devel-1.21.3-160000.3.1 * krb5-plugin-kdb-ldap-debuginfo-1.21.3-160000.3.1 * krb5-client-debuginfo-1.21.3-160000.3.1 * krb5-debugsource-1.21.3-160000.3.1 * krb5-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-pkinit-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-otp-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-otp-1.21.3-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * krb5-plugin-preauth-spake-1.21.3-160000.3.1 * krb5-client-1.21.3-160000.3.1 * krb5-plugin-preauth-pkinit-1.21.3-160000.3.1 * krb5-server-1.21.3-160000.3.1 * krb5-1.21.3-160000.3.1 * krb5-plugin-kdb-ldap-1.21.3-160000.3.1 * krb5-plugin-preauth-spake-debuginfo-1.21.3-160000.3.1 * krb5-devel-1.21.3-160000.3.1 * krb5-server-debuginfo-1.21.3-160000.3.1 * krb5-plugin-kdb-ldap-debuginfo-1.21.3-160000.3.1 * krb5-client-debuginfo-1.21.3-160000.3.1 * krb5-debugsource-1.21.3-160000.3.1 * krb5-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-pkinit-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-otp-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-otp-1.21.3-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40355.html * https://www.suse.com/security/cve/CVE-2026-40356.html * https://bugzilla.suse.com/show_bug.cgi?id=1263366 * https://bugzilla.suse.com/show_bug.cgi?id=1263367 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:14 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:41:14 -0000 Subject: SUSE-SU-2026:22321-1: moderate: Security update for python-click Message-ID: <178292407463.5373.13712664823356357227@bea6e15a6baf> # Security update for python-click Announcement ID: SUSE-SU-2026:22321-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1263898 Cross-References: * CVE-2026-7246 CVSS scores: * CVE-2026-7246 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-7246 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-7246 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2026-7246 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-click fixes the following issue * CVE-2026-7246: Arbitrary command execution via command injection in click.edit() (bsc#1263898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1029=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1029=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-click-8.2.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-click-8.2.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-7246.html * https://bugzilla.suse.com/show_bug.cgi?id=1263898 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:22 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:41:22 -0000 Subject: SUSE-SU-2026:22320-1: important: Security update for amazon-ecs-init Message-ID: <178292408272.5373.10619785699826856701@bea6e15a6baf> # Security update for amazon-ecs-init Announcement ID: SUSE-SU-2026:22320-1 Release Date: 2026-06-22T14:30:37Z Rating: important References: * bsc#1265843 * bsc#1266652 Cross-References: * CVE-2026-33814 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for amazon-ecs-init fixes the following issues Update to version 1.103.2: * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265843). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266652). Changes: * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/fsx from 1.53.1 to 1.65.10 in /agent (#4966) * Enhancement - Add semgrep security scan for command injection (#4959) * Enhancement - Bump golang.org/x/tools from 0.39.0 to 0.45.0 in /ecs-agent (#4965), also updates x/net to 0.54.0 (bsc#1266652, CVE-2026-39821) * Enhancement - Add integration test for credential refresher (#4961) * Enhancement - Bump golang.org/x/tools from 0.42.0 to 0.45.0 in /agent (#4873) * Enhancement - Update Go version to 1.25.10 (#4960) * Enhancement - Bump go.etcd.io/bbolt from 1.3.9 to 1.4.3 in /ecs-agent (#4872) * Enhancement - update credentials-fetcher retry comments/tests (#4954) * Enhancement - Enhancement - Add retry mechanism to credentialsfetcher (#4948) * Enhancement - Add IMDS credential refresher (#4953) * Bugfix - fix flaky tests depending on timers (#4955) * Feature - Implement IMDS scanner for task credential retrieval, in the shared library (#4945) * Feature - Add config/capability for IMDS-based task credential retrieval (disabled for now) (#4938) * Feature - Add IMDS credential scanner interface and capability constant for IMDS-based task credential retrieval (#4937) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs from 1.47.3 to 1.65.0 in /agent (#4921) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.63.1 to 1.97.3 in /ecs-init (#4923) from 1.79.2 to 1.97.3 in /agent (#4924) * Enhancement - Bump go.opentelemetry.io/otel/exporters/otlp/ otlptrace/ otlptracehttp from 1.32.0 to 1.43.0 in /agent (#4926) * Enhancement - Truncate log values to make agent logs less verbose (#4940) * Enhancement - Golang bump: 1.25.9 (#4935) * Enhancement - Use env variable to read user input when mounting FSx volumes (#4934) * Enhancement - Enhancement - Replace SSM Dualstack endpoint resolution logic with UseDualStackEndpoint (#4931) * Enhancement - Emit duration metrics for TACS connect/disconnect (#4928) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream from 1.6.10 to 1.7.8 in /agent (#4922) from 1.6.5 to 1.7.8 in /ecs-init (#4925) * Enhancement - Track and emit metric for disconnect time from ACS (#4920) * Enhancement - engine: skip execution role checks when task desired status is stopped (#4918) * Enhancement - Add NeuronDevices type and sysfs-based device discovery (#4919) * Bugfix - Fix release workflow branch handling and add GitHub App token (#4929) * Bugfix - fix(netlib): Conditionally add IPv6 subnet to IPAM config when IPv6 (#4916) * Enhancement - Update SSM exec agent version to 3.3.4108.0 (#4912) * Enhancement - Update Go version to 1.25.8 (#4894) * Enhancement - Apply skip-gpg-check to both ecs-init and ssm agent (#4901) * Enhancement - Bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#4906) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1025=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1025=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * amazon-ecs-init-1.103.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * amazon-ecs-init-1.103.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1265843 * https://bugzilla.suse.com/show_bug.cgi?id=1266652 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:55 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:41:55 -0000 Subject: SUSE-SU-2026:22319-1: moderate: Security update for dnsdist Message-ID: <178292411547.5373.166503415999520635@bea6e15a6baf> # Security update for dnsdist Announcement ID: SUSE-SU-2026:22319-1 Release Date: 2026-06-22T14:30:36Z Rating: moderate References: * bsc#1261236 * bsc#1261237 * bsc#1261238 * bsc#1261239 * bsc#1261240 * bsc#1261241 * bsc#1261243 * bsc#1262536 * bsc#1262537 * bsc#1262538 * bsc#1262539 * bsc#1262540 * bsc#1262541 * bsc#1262542 * bsc#1262543 * bsc#1262544 * bsc#1262545 * bsc#1262546 Cross-References: * CVE-2026-0396 * CVE-2026-0397 * CVE-2026-24028 * CVE-2026-24029 * CVE-2026-24030 * CVE-2026-27853 * CVE-2026-27854 * CVE-2026-33254 * CVE-2026-33257 * CVE-2026-33260 * CVE-2026-33593 * CVE-2026-33594 * CVE-2026-33595 * CVE-2026-33596 * CVE-2026-33597 * CVE-2026-33598 * CVE-2026-33599 * CVE-2026-33602 CVSS scores: * CVE-2026-0396 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-0396 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0396 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0396 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0397 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-0397 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-0397 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-0397 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-24028 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-24028 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24028 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24028 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-24029 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-24029 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24029 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24029 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24030 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-24030 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24030 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24030 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27853 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27854 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27854 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-27854 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-27854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33254 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33257 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33257 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33257 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33260 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33260 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33260 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33593 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33594 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33595 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33595 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33596 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33596 ( NVD ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33597 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33598 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-33598 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-33599 ( NVD ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33599 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-33602 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-33602 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for dnsdist fixes the following issues * CVE-2026-0396: crafted DNS queries can allow to inject HTML content (bsc#1261236). * CVE-2026-0397: CORS misconfiguration can lead to information disclosure (bsc#1261237). * CVE-2026-24028: crafted DNS response packet can lead to an out-of-bounds read (bsc#1261238). * CVE-2026-24029: HTTPS ACL bypass can allow clients to send DoH queries (bsc#1261239). * CVE-2026-24030: allocating too much memory while processing DNS can result in a denial of service (bsc#1261240). * CVE-2026-27853: crafted DNS responses can lead to an out-of-bounds write (bsc#1261241). * CVE-2026-27854: crafted DNS queries can be used to trigger a use-after-free (bsc#1261243). * CVE-2026-33254: Resource exhaustion via DoQ/DoH3 connections (bsc#1262538). * CVE-2026-33257: Insufficient input validation of internal webserver (bsc#1262536). * CVE-2026-33260: Insufficient input validation of internal webserver (bsc#1262537). * CVE-2026-33593: Denial of service via crafted DNSCrypt query (bsc#1262546). * CVE-2026-33594: Outgoing DoH excessive memory allocation (bsc#1262545). * CVE-2026-33595: DoQ/DoH3 excessive memory allocation (bsc#1262544). * CVE-2026-33596: TCP backend stream ID overflow (bsc#1262543). * CVE-2026-33597: PRSD detection denial of service (bsc#1262542). * CVE-2026-33598: Out-of-bounds read in cache inspection via Lua (bsc#1262541). * CVE-2026-33599: Out-of-bounds read in service discovery (bsc#1262540). * CVE-2026-33602: Off-by-one access when processing crafted UDP responses (bsc#1262539). Changes for dnsdist: * Updated to 1.9.13 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1027=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1027=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dnsdist-1.9.13-160000.1.1 * dnsdist-debugsource-1.9.13-160000.1.1 * dnsdist-debuginfo-1.9.13-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dnsdist-1.9.13-160000.1.1 * dnsdist-debugsource-1.9.13-160000.1.1 * dnsdist-debuginfo-1.9.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0396.html * https://www.suse.com/security/cve/CVE-2026-0397.html * https://www.suse.com/security/cve/CVE-2026-24028.html * https://www.suse.com/security/cve/CVE-2026-24029.html * https://www.suse.com/security/cve/CVE-2026-24030.html * https://www.suse.com/security/cve/CVE-2026-27853.html * https://www.suse.com/security/cve/CVE-2026-27854.html * https://www.suse.com/security/cve/CVE-2026-33254.html * https://www.suse.com/security/cve/CVE-2026-33257.html * https://www.suse.com/security/cve/CVE-2026-33260.html * https://www.suse.com/security/cve/CVE-2026-33593.html * https://www.suse.com/security/cve/CVE-2026-33594.html * https://www.suse.com/security/cve/CVE-2026-33595.html * https://www.suse.com/security/cve/CVE-2026-33596.html * https://www.suse.com/security/cve/CVE-2026-33597.html * https://www.suse.com/security/cve/CVE-2026-33598.html * https://www.suse.com/security/cve/CVE-2026-33599.html * https://www.suse.com/security/cve/CVE-2026-33602.html * https://bugzilla.suse.com/show_bug.cgi?id=1261236 * https://bugzilla.suse.com/show_bug.cgi?id=1261237 * https://bugzilla.suse.com/show_bug.cgi?id=1261238 * https://bugzilla.suse.com/show_bug.cgi?id=1261239 * https://bugzilla.suse.com/show_bug.cgi?id=1261240 * https://bugzilla.suse.com/show_bug.cgi?id=1261241 * https://bugzilla.suse.com/show_bug.cgi?id=1261243 * https://bugzilla.suse.com/show_bug.cgi?id=1262536 * https://bugzilla.suse.com/show_bug.cgi?id=1262537 * https://bugzilla.suse.com/show_bug.cgi?id=1262538 * https://bugzilla.suse.com/show_bug.cgi?id=1262539 * https://bugzilla.suse.com/show_bug.cgi?id=1262540 * https://bugzilla.suse.com/show_bug.cgi?id=1262541 * https://bugzilla.suse.com/show_bug.cgi?id=1262542 * https://bugzilla.suse.com/show_bug.cgi?id=1262543 * https://bugzilla.suse.com/show_bug.cgi?id=1262544 * https://bugzilla.suse.com/show_bug.cgi?id=1262545 * https://bugzilla.suse.com/show_bug.cgi?id=1262546 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:59 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:41:59 -0000 Subject: SUSE-RU-2026:22318-1: moderate: Recommended update for binutils Message-ID: <178292411966.5373.10320832429504876841@bea6e15a6baf> # Recommended update for binutils Announcement ID: SUSE-RU-2026:22318-1 Release Date: 2026-06-22T13:33:04Z Rating: moderate References: * jsc#PED-15667 * jsc#PED-15792 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains two features can now be installed. ## Description: This update for binutils fixes the following issues: * Migrate from update-alternatives to libalternatives (jsc#PED-15667). * Update %suse_version greater than 1600 checks (jsc#PED-15792). * Split new libsframe2 package from binutils (shared lib policy). * Make gold subpackage no require binutils in a specific version. * Add binutils workaround premature libsframe uninst for this to temporarily avoid 99-check-remove-rpms getting in the way. * Fix a compile error with new glibc. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1020=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1020=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libctf-nobfd0-debuginfo-2.45-160000.2.1 * libctf0-2.45-160000.2.1 * binutils-debuginfo-2.45-160000.2.1 * binutils-debugsource-2.45-160000.2.1 * libsframe2-2.45-160000.2.1 * binutils-devel-2.45-160000.2.1 * binutils-2.45-160000.2.1 * libsframe2-debuginfo-2.45-160000.2.1 * libctf0-debuginfo-2.45-160000.2.1 * libctf-nobfd0-2.45-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * gprofng-debuginfo-2.45-160000.2.1 * gprofng-2.45-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libctf-nobfd0-debuginfo-2.45-160000.2.1 * libctf0-2.45-160000.2.1 * binutils-devel-2.45-160000.2.1 * binutils-debuginfo-2.45-160000.2.1 * libsframe2-2.45-160000.2.1 * binutils-2.45-160000.2.1 * binutils-debugsource-2.45-160000.2.1 * libsframe2-debuginfo-2.45-160000.2.1 * libctf0-debuginfo-2.45-160000.2.1 * libctf-nobfd0-2.45-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * gprofng-debuginfo-2.45-160000.2.1 * gprofng-2.45-160000.2.1 ## References: * https://jira.suse.com/browse/PED-15667 * https://jira.suse.com/browse/PED-15792 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:42:03 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:42:03 -0000 Subject: SUSE-RU-2026:22317-1: moderate: Recommended update for libkkc Message-ID: <178292412382.5373.787055550335444054@bea6e15a6baf> # Recommended update for libkkc Announcement ID: SUSE-RU-2026:22317-1 Release Date: 2026-06-22T13:17:26Z Rating: moderate References: * jsc#PED-15818 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for libkkc fixes the following issues: * Update libkkc.spec: * Move software COPYING file under %license macro to fit openSUSE Build requirement. * Fix Leap 15.6 build: * also fix %suse_version bump in SUSE 16.1. (jsc#PED-15818) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1019=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1019=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libkkc2-debuginfo-0.3.6~git20240902.ce17a35-160000.2.1 * kkc-data-0.3.6~git20240902.ce17a35-160000.2.1 * libkkc2-0.3.6~git20240902.ce17a35-160000.2.1 * libkkc-debugsource-0.3.6~git20240902.ce17a35-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libkkc-debugsource-0.3.6~git20240902.ce17a35-160000.2.1 * kkc-data-0.3.6~git20240902.ce17a35-160000.2.1 * libkkc2-0.3.6~git20240902.ce17a35-160000.2.1 * libkkc2-debuginfo-0.3.6~git20240902.ce17a35-160000.2.1 ## References: * https://jira.suse.com/browse/PED-15818 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:42:09 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:42:09 -0000 Subject: SUSE-RU-2026:22316-1: moderate: Recommended update for stalld Message-ID: <178292412913.5373.8287046838606028404@bea6e15a6baf> # Recommended update for stalld Announcement ID: SUSE-RU-2026:22316-1 Release Date: 2026-06-22T13:17:26Z Rating: moderate References: * bsc#1259438 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for stalld fixes the following issues: * Create runtime directory via systemd (bsc#1259438) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1018=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1018=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * stalld-1.19.8-160000.3.1 * stalld-debuginfo-1.19.8-160000.3.1 * stalld-debugsource-1.19.8-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * stalld-1.19.8-160000.3.1 * stalld-debuginfo-1.19.8-160000.3.1 * stalld-debugsource-1.19.8-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1259438 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:42:39 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:42:39 -0000 Subject: SUSE-SU-2026:22315-1: important: Security update for openssl-3 Message-ID: <178292415973.5373.9691787899184914620@bea6e15a6baf> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22315-1 Release Date: 2026-06-22T12:26:17Z Rating: important References: * bsc#1259652 * bsc#1266340 * bsc#1266341 * bsc#1266342 * bsc#1266344 * bsc#1266345 * bsc#1266347 * bsc#1266349 * bsc#1266350 * bsc#1266351 * bsc#1266352 * bsc#1266353 * bsc#1266355 * bsc#1266356 * bsc#1266357 Cross-References: * CVE-2026-2673 * CVE-2026-34180 * CVE-2026-34182 * CVE-2026-34183 * CVE-2026-42764 * CVE-2026-42766 * CVE-2026-42767 * CVE-2026-42768 * CVE-2026-42769 * CVE-2026-42770 * CVE-2026-45445 * CVE-2026-45446 * CVE-2026-45447 * CVE-2026-7383 * CVE-2026-9076 CVSS scores: * CVE-2026-2673 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-2673 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2673 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34180 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34180 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34180 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34182 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34182 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34183 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34183 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34183 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42764 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42764 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42764 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42766 ( SUSE ): 6.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42766 ( SUSE ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42766 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42768 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-42768 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N * CVE-2026-42768 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42769 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42769 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42769 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42770 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42770 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42770 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45445 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45445 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45445 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45446 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-45446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-45446 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-45447 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45447 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45447 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45447 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7383 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7383 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7383 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9076 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-9076 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-9076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for openssl-3 fixes the following issues * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652). * CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). * CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). * CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342). * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). * CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345). * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347). * CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). * CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351). * CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352). * CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353). * CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355). * CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356). * CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1017=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1017=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * openssl-3-debuginfo-3.5.0-160000.8.1 * libopenssl3-3.5.0-160000.8.1 * openssl-3-debugsource-3.5.0-160000.8.1 * libopenssl3-debuginfo-3.5.0-160000.8.1 * libopenssl-3-devel-3.5.0-160000.8.1 * openssl-3-3.5.0-160000.8.1 * libopenssl-3-fips-provider-3.5.0-160000.8.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.8.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.8.1 * libopenssl3-x86-64-v3-3.5.0-160000.8.1 * libopenssl3-x86-64-v3-debuginfo-3.5.0-160000.8.1 * libopenssl-3-fips-provider-x86-64-v3-debuginfo-3.5.0-160000.8.1 * SUSE Linux Enterprise Server 16.0 (noarch) * openssl-3-doc-3.5.0-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openssl-3-debuginfo-3.5.0-160000.8.1 * libopenssl3-3.5.0-160000.8.1 * openssl-3-debugsource-3.5.0-160000.8.1 * libopenssl3-debuginfo-3.5.0-160000.8.1 * libopenssl-3-devel-3.5.0-160000.8.1 * openssl-3-3.5.0-160000.8.1 * libopenssl-3-fips-provider-3.5.0-160000.8.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.8.1 * libopenssl3-x86-64-v3-3.5.0-160000.8.1 * libopenssl3-x86-64-v3-debuginfo-3.5.0-160000.8.1 * libopenssl-3-fips-provider-x86-64-v3-debuginfo-3.5.0-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * openssl-3-doc-3.5.0-160000.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2673.html * https://www.suse.com/security/cve/CVE-2026-34180.html * https://www.suse.com/security/cve/CVE-2026-34182.html * https://www.suse.com/security/cve/CVE-2026-34183.html * https://www.suse.com/security/cve/CVE-2026-42764.html * https://www.suse.com/security/cve/CVE-2026-42766.html * https://www.suse.com/security/cve/CVE-2026-42767.html * https://www.suse.com/security/cve/CVE-2026-42768.html * https://www.suse.com/security/cve/CVE-2026-42769.html * https://www.suse.com/security/cve/CVE-2026-42770.html * https://www.suse.com/security/cve/CVE-2026-45445.html * https://www.suse.com/security/cve/CVE-2026-45446.html * https://www.suse.com/security/cve/CVE-2026-45447.html * https://www.suse.com/security/cve/CVE-2026-7383.html * https://www.suse.com/security/cve/CVE-2026-9076.html * https://bugzilla.suse.com/show_bug.cgi?id=1259652 * https://bugzilla.suse.com/show_bug.cgi?id=1266340 * https://bugzilla.suse.com/show_bug.cgi?id=1266341 * https://bugzilla.suse.com/show_bug.cgi?id=1266342 * https://bugzilla.suse.com/show_bug.cgi?id=1266344 * https://bugzilla.suse.com/show_bug.cgi?id=1266345 * https://bugzilla.suse.com/show_bug.cgi?id=1266347 * https://bugzilla.suse.com/show_bug.cgi?id=1266349 * https://bugzilla.suse.com/show_bug.cgi?id=1266350 * https://bugzilla.suse.com/show_bug.cgi?id=1266351 * https://bugzilla.suse.com/show_bug.cgi?id=1266352 * https://bugzilla.suse.com/show_bug.cgi?id=1266353 * https://bugzilla.suse.com/show_bug.cgi?id=1266355 * https://bugzilla.suse.com/show_bug.cgi?id=1266356 * https://bugzilla.suse.com/show_bug.cgi?id=1266357 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:42:43 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:42:43 -0000 Subject: SUSE-RU-2026:22314-1: moderate: Recommended update for rust Message-ID: <178292416394.5373.5186305317564868988@bea6e15a6baf> # Recommended update for rust Announcement ID: SUSE-RU-2026:22314-1 Release Date: 2026-06-22T11:43:19Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for rust fixes the following issues: Changes in rust: * Update to version 1.96.0 - for details see the rust1.96 package ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1014=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1014=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cargo-1.96.0-160000.1.1 * cargo1.96-1.96.0-160000.1.1 * cargo1.96-debuginfo-1.96.0-160000.1.1 * rust1.96-debuginfo-1.96.0-160000.1.1 * rust-1.96.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 nosrc ppc64le s390x x86_64) * rust1.96-1.96.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cargo-1.96.0-160000.1.1 * cargo1.96-1.96.0-160000.1.1 * cargo1.96-debuginfo-1.96.0-160000.1.1 * rust1.96-debuginfo-1.96.0-160000.1.1 * rust-1.96.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (nosrc ppc64le x86_64) * rust1.96-1.96.0-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:42:49 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:42:49 -0000 Subject: SUSE-SU-2026:22313-1: important: Security update for gsasl Message-ID: <178292416928.5373.4189767353313098998@bea6e15a6baf> # Security update for gsasl Announcement ID: SUSE-SU-2026:22313-1 Release Date: 2026-06-22T09:25:40Z Rating: important References: * bsc#1266371 Cross-References: * CVE-2026-48829 CVSS scores: * CVE-2026-48829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for gsasl fixes the following issues: Changes in gsasl: * CVE-2026-48829: DIGEST-MD5: Fix NULL pointer dereference in parser (bsc#1266371) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1016=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1016=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gsasl-devel-2.2.1-160000.3.1 * gsasl-debugsource-2.2.1-160000.3.1 * gsasl-debuginfo-2.2.1-160000.3.1 * libgsasl18-2.2.1-160000.3.1 * gsasl-2.2.1-160000.3.1 * libgsasl18-debuginfo-2.2.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * gsasl-lang-2.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gsasl-devel-2.2.1-160000.3.1 * gsasl-debugsource-2.2.1-160000.3.1 * gsasl-debuginfo-2.2.1-160000.3.1 * libgsasl18-2.2.1-160000.3.1 * gsasl-2.2.1-160000.3.1 * libgsasl18-debuginfo-2.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * gsasl-lang-2.2.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48829.html * https://bugzilla.suse.com/show_bug.cgi?id=1266371 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:03 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:43:03 -0000 Subject: SUSE-RU-2026:22312-1: moderate: Recommended update for go1.24, go1.23, go1.22, go1.21 Message-ID: <178292418394.5373.5749676398733101524@bea6e15a6baf> # Recommended update for go1.24, go1.23, go1.22, go1.21 Announcement ID: SUSE-RU-2026:22312-1 Release Date: 2026-06-22T08:32:17Z Rating: moderate References: * bsc#1245878 * bsc#1247816 * bsc#1248082 * bsc#1264390 * bsc#1264391 * bsc#1264392 * bsc#1264393 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has seven fixes can now be installed. ## Description: This update for go1.24, go1.23, go1.22, go1.21 fixes the following issues: Changes in go1.24: * Use libalternatives only on suse_version >= 1610 and keep update- alternatives support for older distributions. * Drop the update-alternatives migration path for libalternatives builds. * Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.24 dependency on update-alternatives fixes bsc#1264393 Changes in go1.23: * Use libalternatives only on suse_version >= 1610 and keep update- alternatives support for older distributions. * Drop the update-alternatives migration path for libalternatives builds. * Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.23 dependency on update-alternatives fixes bsc#1264392 * Packaging improvements: * Remove conditional gccgo bootstrap sections and gcc-go patch. gccgo cannot be used in any version newer than go1.21. Removal simplifies go1.x package code. * go1.21 can optionally be bootstrapped with gccgo and serve as the inital version of go1.x. * go1.21 will be the initial version of Go in the bootstrap chain until gcc gccgo is updated to support a language level newer than go1.18. * Refs boo#1247816 bootstrap go1.21 with gccgo * Refs boo#1248082 drop unused gccgo bootstrap code in go1.22+ Changes in go1.22: * Use libalternatives only on suse_version >= 1610 and keep update- alternatives support for older distributions. * Drop the update-alternatives migration path for libalternatives builds. * Packaging: Enable libalternatives for SLE16.1 and Tumbleweed ( boo#1245878) * Drop go1.22 dependency on update-alternatives fixes bsc#1264391 * Packaging improvements: * Remove conditional gccgo bootstrap sections and gcc-go patch. gccgo cannot be used in any version newer than go1.21. Removal simplifies go1.x package code. * go1.21 can optionally be bootstrapped with gccgo and serve as the inital version of go1.x. * go1.21 will be the initial version of Go in the bootstrap chain until gcc gccgo is updated to support a language level newer than go1.18. * Refs boo#1247816 bootstrap go1.21 with gccgo * Refs boo#1248082 drop unused gccgo bootstrap code in go1.22+ Changes in go1.21: * Use libalternatives only on suse_version >= 1610 and keep update- alternatives support for older distributions. * Drop the update-alternatives migration path for libalternatives builds. * Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.21 dependency on update-alternatives fixes bsc#1264390 * Prepare for removing old go versions from Factory: * Switch default for go1.21 to bootstrap with gcc-go using %bcond_without gccgo_go121 * Building go1.21 with gcc-go by default removes need for prjconf * Refs boo#1247816 bootstrap go1.21 with gccgo ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1013=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1013=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * go1.24-debuginfo-1.24.13-160000.2.1 * go1.24-libstd-debuginfo-1.24.13-160000.2.1 * go1.24-libstd-1.24.13-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.24-doc-1.24.13-160000.2.1 * go1.24-race-1.24.13-160000.2.1 * go1.24-1.24.13-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * go1.24-debuginfo-1.24.13-160000.2.1 * go1.24-libstd-debuginfo-1.24.13-160000.2.1 * go1.24-libstd-1.24.13-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.24-doc-1.24.13-160000.2.1 * go1.24-race-1.24.13-160000.2.1 * go1.24-1.24.13-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1247816 * https://bugzilla.suse.com/show_bug.cgi?id=1248082 * https://bugzilla.suse.com/show_bug.cgi?id=1264390 * https://bugzilla.suse.com/show_bug.cgi?id=1264391 * https://bugzilla.suse.com/show_bug.cgi?id=1264392 * https://bugzilla.suse.com/show_bug.cgi?id=1264393 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:14 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:43:14 -0000 Subject: SUSE-RU-2026:22311-1: important: Recommended update for jline3, jansi, libdb-4_8, java-25-openjdk, java-21-openjdk, java-17-openjdk Message-ID: <178292419400.5373.11428458602088781181@bea6e15a6baf> # Recommended update for jline3, jansi, libdb-4_8, java-25-openjdk, java-21-openjdk, java-17-openjdk Announcement ID: SUSE-RU-2026:22311-1 Release Date: 2026-06-22T08:32:17Z Rating: important References: * bsc#1264396 * bsc#1264397 * bsc#1264398 * bsc#1267355 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has four fixes can now be installed. ## Description: This update for jline3, jansi, libdb-4_8, java-25-openjdk, java-21-openjdk, java-17-openjdk fixes the following issues: Changes in jline3: * Sync with factory * Use the variable from aaa_base * Allow building with JDKs using `libalternatives` instead of `update- alternatives` Changes in jansi: * Sync with factory * Use the variable from aaa_base * Allow building with JDKs using `libalternatives` instead of `update- alternatives` Changes in libdb-4_8: * Fix build for LoongArch64 * Fix code to detect/enable 64-bit integral type support for sequences. The m4 macros were not complying with GCC 14's strictness. Changes in libdb_java-4_8: * Allow building with JDK using `libalternatives` instead of `update- alternatives` Changes in java-25-openjdk: * Make post scripts less noisy (bsc#1267355) * Use libalternatives instead of update-alternatives for distributions where libalternatives is available (bsc#1264398) Changes in java-21-openjdk: * Make post scripts less noisy (bsc#1267355) * Use libalternatives instead of update-alternatives for distributions where libalternatives is available (bsc#1264397) Changes in java-17-openjdk: * Make post scripts less noisy (bsc#1267355) * Use libalternatives instead of update-alternatives for distributions where libalternatives is available (bsc#1264396) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1009=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1009=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * jline3-curses-3.30.13-160000.2.1 * jline3-terminal-jna-3.30.13-160000.2.1 * db48-doc-4.8.30-160000.3.1 * jline3-terminal-jansi-3.30.13-160000.2.1 * jline3-console-ui-3.30.13-160000.2.1 * jansi-javadoc-2.4.3-160000.2.1 * java-17-openjdk-javadoc-17.0.19.0-160000.2.1 * jline3-remote-telnet-3.30.13-160000.2.1 * java-25-openjdk-javadoc-25.0.3.0-160000.2.1 * jline3-jansi-core-3.30.13-160000.2.1 * jline3-javadoc-3.30.13-160000.2.1 * jline3-reader-3.30.13-160000.2.1 * jline3-terminal-jni-3.30.13-160000.2.1 * jline3-terminal-3.30.13-160000.2.1 * jline3-builtins-3.30.13-160000.2.1 * java-21-openjdk-javadoc-21.0.11.0-160000.2.1 * jline3-console-3.30.13-160000.2.1 * jline3-style-3.30.13-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * java-17-openjdk-devel-debuginfo-17.0.19.0-160000.2.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-160000.2.1 * java-25-openjdk-debuginfo-25.0.3.0-160000.2.1 * java-25-openjdk-demo-25.0.3.0-160000.2.1 * java-25-openjdk-jmods-25.0.3.0-160000.2.1 * java-17-openjdk-17.0.19.0-160000.2.1 * java-25-openjdk-devel-debuginfo-25.0.3.0-160000.2.1 * java-21-openjdk-src-21.0.11.0-160000.2.1 * java-25-openjdk-devel-25.0.3.0-160000.2.1 * libdb-4_8-devel-4.8.30-160000.3.1 * jline3-debugsource-3.30.13-160000.2.1 * java-21-openjdk-devel-21.0.11.0-160000.2.1 * libdb_java-4_8-debugsource-4.8.30-160000.3.1 * java-17-openjdk-demo-17.0.19.0-160000.2.1 * java-25-openjdk-headless-25.0.3.0-160000.2.1 * java-25-openjdk-25.0.3.0-160000.2.1 * java-25-openjdk-headless-debuginfo-25.0.3.0-160000.2.1 * java-21-openjdk-headless-21.0.11.0-160000.2.1 * jansi-debuginfo-2.4.3-160000.2.1 * java-21-openjdk-demo-21.0.11.0-160000.2.1 * java-21-openjdk-21.0.11.0-160000.2.1 * jline3-native-debuginfo-3.30.13-160000.2.1 * libdb-4_8-debuginfo-4.8.30-160000.3.1 * java-17-openjdk-headless-debuginfo-17.0.19.0-160000.2.1 * libdb_java-4_8-debuginfo-4.8.30-160000.3.1 * java-17-openjdk-devel-17.0.19.0-160000.2.1 * jansi-2.4.3-160000.2.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-160000.2.1 * java-17-openjdk-debuginfo-17.0.19.0-160000.2.1 * java-17-openjdk-headless-17.0.19.0-160000.2.1 * db48-utils-4.8.30-160000.3.1 * jline3-jansi-3.30.13-160000.2.1 * jline3-3.30.13-160000.2.1 * libdb-4_8-debugsource-4.8.30-160000.3.1 * db48-utils-debuginfo-4.8.30-160000.3.1 * java-17-openjdk-jmods-17.0.19.0-160000.2.1 * libdb-4_8-4.8.30-160000.3.1 * java-17-openjdk-src-17.0.19.0-160000.2.1 * java-21-openjdk-jmods-21.0.11.0-160000.2.1 * java-21-openjdk-debuginfo-21.0.11.0-160000.2.1 * libdb_java-4_8-4.8.30-160000.3.1 * java-25-openjdk-src-25.0.3.0-160000.2.1 * jline3-native-3.30.13-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libdb-4_8-x86-64-v3-4.8.30-160000.3.1 * libdb-4_8-x86-64-v3-debuginfo-4.8.30-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-devel-debuginfo-17.0.19.0-160000.2.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-160000.2.1 * java-25-openjdk-demo-25.0.3.0-160000.2.1 * java-25-openjdk-debuginfo-25.0.3.0-160000.2.1 * java-25-openjdk-jmods-25.0.3.0-160000.2.1 * java-17-openjdk-17.0.19.0-160000.2.1 * java-25-openjdk-devel-debuginfo-25.0.3.0-160000.2.1 * java-21-openjdk-src-21.0.11.0-160000.2.1 * java-25-openjdk-devel-25.0.3.0-160000.2.1 * libdb-4_8-devel-4.8.30-160000.3.1 * jline3-debugsource-3.30.13-160000.2.1 * java-21-openjdk-devel-21.0.11.0-160000.2.1 * libdb_java-4_8-debugsource-4.8.30-160000.3.1 * java-17-openjdk-demo-17.0.19.0-160000.2.1 * java-25-openjdk-headless-25.0.3.0-160000.2.1 * java-25-openjdk-25.0.3.0-160000.2.1 * java-25-openjdk-headless-debuginfo-25.0.3.0-160000.2.1 * java-21-openjdk-headless-21.0.11.0-160000.2.1 * jansi-debuginfo-2.4.3-160000.2.1 * java-21-openjdk-demo-21.0.11.0-160000.2.1 * libdb-4_8-debuginfo-4.8.30-160000.3.1 * java-21-openjdk-21.0.11.0-160000.2.1 * jline3-native-debuginfo-3.30.13-160000.2.1 * java-17-openjdk-headless-debuginfo-17.0.19.0-160000.2.1 * libdb_java-4_8-debuginfo-4.8.30-160000.3.1 * java-17-openjdk-devel-17.0.19.0-160000.2.1 * jansi-2.4.3-160000.2.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-160000.2.1 * java-17-openjdk-debuginfo-17.0.19.0-160000.2.1 * java-17-openjdk-headless-17.0.19.0-160000.2.1 * db48-utils-4.8.30-160000.3.1 * jline3-jansi-3.30.13-160000.2.1 * jline3-3.30.13-160000.2.1 * libdb-4_8-debugsource-4.8.30-160000.3.1 * db48-utils-debuginfo-4.8.30-160000.3.1 * java-21-openjdk-debuginfo-21.0.11.0-160000.2.1 * libdb-4_8-4.8.30-160000.3.1 * java-17-openjdk-src-17.0.19.0-160000.2.1 * java-21-openjdk-jmods-21.0.11.0-160000.2.1 * java-17-openjdk-jmods-17.0.19.0-160000.2.1 * libdb_java-4_8-4.8.30-160000.3.1 * java-25-openjdk-src-25.0.3.0-160000.2.1 * jline3-native-3.30.13-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * jline3-curses-3.30.13-160000.2.1 * jline3-terminal-jna-3.30.13-160000.2.1 * db48-doc-4.8.30-160000.3.1 * jline3-terminal-jansi-3.30.13-160000.2.1 * jansi-javadoc-2.4.3-160000.2.1 * jline3-console-ui-3.30.13-160000.2.1 * java-17-openjdk-javadoc-17.0.19.0-160000.2.1 * jline3-remote-telnet-3.30.13-160000.2.1 * java-25-openjdk-javadoc-25.0.3.0-160000.2.1 * jline3-jansi-core-3.30.13-160000.2.1 * jline3-terminal-jni-3.30.13-160000.2.1 * jline3-javadoc-3.30.13-160000.2.1 * jline3-reader-3.30.13-160000.2.1 * jline3-terminal-3.30.13-160000.2.1 * jline3-builtins-3.30.13-160000.2.1 * java-21-openjdk-javadoc-21.0.11.0-160000.2.1 * jline3-console-3.30.13-160000.2.1 * jline3-style-3.30.13-160000.2.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libdb-4_8-x86-64-v3-4.8.30-160000.3.1 * libdb-4_8-x86-64-v3-debuginfo-4.8.30-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1264396 * https://bugzilla.suse.com/show_bug.cgi?id=1264397 * https://bugzilla.suse.com/show_bug.cgi?id=1264398 * https://bugzilla.suse.com/show_bug.cgi?id=1267355 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:17 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:43:17 -0000 Subject: SUSE-RU-2026:22310-1: moderate: Recommended update for libsodium Message-ID: <178292419789.5373.4307499009324615569@bea6e15a6baf> # Recommended update for libsodium Announcement ID: SUSE-RU-2026:22310-1 Release Date: 2026-06-22T07:55:18Z Rating: moderate References: * jsc#PED-16206 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for libsodium fixes the following issues: Changes in libsodium: Update to 1.0.22: (jsc#PED-16206) * Post-quantum key encapsulation is now available. ML-KEM768, the NIST- standardized lattice-based KEM, is accessible through the crypto_kem_mlkem768_*() functions. * X-Wing, a hybrid KEM combining ML-KEM768 with X25519 for protection against both classical and quantum adversaries, is available through the crypto_kem_*() functions. X-Wing is the recommended KEM for most applications. * SHA-3 hash functions are now available as crypto_hash_sha3256__() and crypto_hash_sha3512__(), with both one-shot and streaming APIs. * Performance: NEON optimizations for Argon2 on ARM platforms. * Performance: SHA3 (Keccak1600) now leverages ARM SHA3 instructions when available on ARM platforms. * Performance: WebAssembly SIMD implementations of Argon2 have been added. * XOF state alignment has been relaxed. * crypto_core_keccak1600_state has been added. * Export missing crypto_ipcrypt_nd_keygen() helper function. * crypto_auth_hmacsha256_init and crypto_auth_hmacsha512_init now accept NULL key pointers (with a zero key length), for consistency with other _init functions. * Fixed compilation with GCC on aarch64 and gcc 4.x. * On aarch64, aes256-gcm is now enabled even when not using clang, including MSVC. * Libsodium can be directly used as a dependency in a Zig project. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1012=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1012=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libsodium-devel-1.0.22-160000.1.1 * libsodium-debugsource-1.0.22-160000.1.1 * libsodium26-debuginfo-1.0.22-160000.1.1 * libsodium26-1.0.22-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libsodium-devel-1.0.22-160000.1.1 * libsodium-debugsource-1.0.22-160000.1.1 * libsodium26-debuginfo-1.0.22-160000.1.1 * libsodium26-1.0.22-160000.1.1 ## References: * https://jira.suse.com/browse/PED-16206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:23 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:43:23 -0000 Subject: SUSE-RU-2026:22309-1: moderate: Recommended update for go Message-ID: <178292420334.5373.12009855217043218894@bea6e15a6baf> # Recommended update for go Announcement ID: SUSE-RU-2026:22309-1 Release Date: 2026-06-22T07:54:21Z Rating: moderate References: * bsc#1255111 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for go fixes the following issues: Changes in go: * Update to current stable go1.26 (boo#1255111) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1015=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1015=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go-doc-1.26-160000.1.1 * go-1.26-160000.1.1 * go-race-1.26-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go-doc-1.26-160000.1.1 * go-1.26-160000.1.1 * go-race-1.26-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1255111 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:27 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:43:27 -0000 Subject: SUSE-OU-2026:22308-1: moderate: Optional update for supportutils-scrub Message-ID: <178292420754.5373.17428675427967078489@bea6e15a6baf> # Optional update for supportutils-scrub Announcement ID: SUSE-OU-2026:22308-1 Release Date: 2026-06-22T07:54:21Z Rating: moderate References: * jsc#PED-15597 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for supportutils-scrub fixes the following issues: Adds a log scrubber for supportutils. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1011=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1011=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * supportutils-scrub-1.5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * supportutils-scrub-1.5-160000.1.1 ## References: * https://jira.suse.com/browse/PED-15597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:34 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:43:34 -0000 Subject: SUSE-RU-2026:22307-1: moderate: Recommended update for selinux-policy Message-ID: <178292421468.5373.9495626557227269193@bea6e15a6baf> # Recommended update for selinux-policy Announcement ID: SUSE-RU-2026:22307-1 Release Date: 2026-06-21T02:17:53Z Rating: moderate References: * bsc#1243148 * bsc#1265386 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for selinux-policy fixes the following issues: * Allow wireguard to setup DNS using dns_hatchet (bsc#1243148) * Add fs_dontaudit_relabelfrom_tmpfs_files() interface * Add sysnet_mount_file() interface * Add sysnet_dontaudit_file_relabelto() interface * Dontaudit tlp_t requesting dac_read_search (bsc#1265386) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1008=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1008=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * selinux-policy-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-doc-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-minimum-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-targeted-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-devel-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-sandbox-20250627+git385.2b2068bc0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * selinux-policy-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-doc-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-minimum-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-targeted-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-devel-20250627+git385.2b2068bc0-160000.1.1 * selinux-policy-sandbox-20250627+git385.2b2068bc0-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1243148 * https://bugzilla.suse.com/show_bug.cgi?id=1265386 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:44 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:43:44 -0000 Subject: SUSE-SU-2026:22306-1: important: Security update for tiff Message-ID: <178292422492.5373.7718214270425670717@bea6e15a6baf> # Security update for tiff Announcement ID: SUSE-SU-2026:22306-1 Release Date: 2026-06-21T02:12:54Z Rating: important References: * bsc#1248278 * bsc#1257123 * bsc#1260411 Cross-References: * CVE-2018-7456 * CVE-2023-0800 * CVE-2023-0801 * CVE-2023-0802 * CVE-2023-0803 * CVE-2023-0804 * CVE-2025-8851 * CVE-2026-4775 CVSS scores: * CVE-2018-7456 ( SUSE ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-7456 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0800 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0800 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0800 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0801 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0801 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0801 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0802 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0802 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0802 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0803 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0803 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0803 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0804 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0804 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0804 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8851 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-8851 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-8851 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8851 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-4775 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4775 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues Security issues: * CVE-2025-8851: libtiff: LibTIFF Stack-based buffer overflow (bsc#1248278). * CVE-2026-4775: signed integer overflow in the `putcontig8bitYCbCr44tile` function (bsc#1260411). Non security issue: * QGIS can't export with GDAL- LERC codec, LERC library not found anywhere in the system (bsc#1257123). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1007=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1007=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libtiff6-4.7.1-160000.2.1 * libtiff-devel-4.7.1-160000.2.1 * libtiff6-debuginfo-4.7.1-160000.2.1 * tiff-debugsource-4.7.1-160000.2.1 * tiff-debuginfo-4.7.1-160000.2.1 * tiff-4.7.1-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libtiff6-4.7.1-160000.2.1 * libtiff-devel-4.7.1-160000.2.1 * libtiff6-debuginfo-4.7.1-160000.2.1 * tiff-debugsource-4.7.1-160000.2.1 * tiff-debuginfo-4.7.1-160000.2.1 * tiff-4.7.1-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2018-7456.html * https://www.suse.com/security/cve/CVE-2023-0800.html * https://www.suse.com/security/cve/CVE-2023-0801.html * https://www.suse.com/security/cve/CVE-2023-0802.html * https://www.suse.com/security/cve/CVE-2023-0803.html * https://www.suse.com/security/cve/CVE-2023-0804.html * https://www.suse.com/security/cve/CVE-2025-8851.html * https://www.suse.com/security/cve/CVE-2026-4775.html * https://bugzilla.suse.com/show_bug.cgi?id=1248278 * https://bugzilla.suse.com/show_bug.cgi?id=1257123 * https://bugzilla.suse.com/show_bug.cgi?id=1260411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:51 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:43:51 -0000 Subject: SUSE-SU-2026:22305-1: important: Security update for helm Message-ID: <178292423137.5373.5705628817634477113@bea6e15a6baf> # Security update for helm Announcement ID: SUSE-SU-2026:22305-1 Release Date: 2026-06-21T00:44:54Z Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: * Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 * chore(deps): bump github.com/distribution/distribution/v3 * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 * chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1006=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1006=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * helm-zsh-completion-3.21.1-160000.1.2 * helm-fish-completion-3.21.1-160000.1.1 * helm-zsh-completion-3.21.1-160000.1.1 * helm-bash-completion-3.21.1-160000.1.1 * helm-fish-completion-3.21.1-160000.1.2 * helm-bash-completion-3.21.1-160000.1.2 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * helm-3.21.1-160000.1.1 * helm-debuginfo-3.21.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (s390x) * helm-debuginfo-3.21.1-160000.1.2 * helm-3.21.1-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * helm-3.21.1-160000.1.1 * helm-debuginfo-3.21.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * helm-fish-completion-3.21.1-160000.1.1 * helm-zsh-completion-3.21.1-160000.1.1 * helm-bash-completion-3.21.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:57 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:43:57 -0000 Subject: SUSE-RU-2026:22304-1: moderate: Recommended update for gdb Message-ID: <178292423713.5373.72562106427328793@bea6e15a6baf> # Recommended update for gdb Announcement ID: SUSE-RU-2026:22304-1 Release Date: 2026-06-20T18:57:06Z Rating: moderate References: * bsc#1261254 * jsc#PED-15928 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature and has one fix can now be installed. ## Description: This update for gdb fixes the following issues: * Reduce scope of debuginfo query workaround. No longer require "set debuginfod enabled off" in .gdbearlyinit or similar to be able to use "gdb -tui" (bsc#1261254). * Report helpful error on ptrace permission denied due to yama/selinux (jsc#PED-15928). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1002=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1002=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gdb-debuginfo-16.3-160000.5.1 * gdb-16.3-160000.5.1 * gdbserver-debuginfo-16.3-160000.5.1 * gdb-debugsource-16.3-160000.5.1 * gdbserver-16.3-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gdb-debuginfo-16.3-160000.5.1 * gdb-16.3-160000.5.1 * gdbserver-debuginfo-16.3-160000.5.1 * gdb-debugsource-16.3-160000.5.1 * gdbserver-16.3-160000.5.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1261254 * https://jira.suse.com/browse/PED-15928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:02 -0000 Subject: SUSE-RU-2026:22303-1: moderate: Recommended update for hwinfo Message-ID: <178292424267.5373.1477673624263257099@bea6e15a6baf> # Recommended update for hwinfo Announcement ID: SUSE-RU-2026:22303-1 Release Date: 2026-06-20T18:28:53Z Rating: moderate References: * bsc#1267348 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for hwinfo fixes the following issues: * Update to version 25.4: * fix redundant conditions in smbios memory device map * fix memory leaks (bsc#1267348) * fix(core): free modinfo_ext instead of modinfo in hd_free_hd_data * fix: fix sizeof in joystick allocation to use struct size instead of pointer size (bsc#1267348) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-998=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-998=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * hwinfo-debugsource-25.4-160000.1.1 * libhd25-25.4-160000.1.1 * hwinfo-devel-debuginfo-25.4-160000.1.1 * hwinfo-25.4-160000.1.1 * libhd25-debuginfo-25.4-160000.1.1 * hwinfo-devel-25.4-160000.1.1 * hwinfo-debuginfo-25.4-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * hwinfo-debugsource-25.4-160000.1.1 * libhd25-25.4-160000.1.1 * hwinfo-devel-debuginfo-25.4-160000.1.1 * hwinfo-25.4-160000.1.1 * libhd25-debuginfo-25.4-160000.1.1 * hwinfo-devel-25.4-160000.1.1 * hwinfo-debuginfo-25.4-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:09 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:09 -0000 Subject: SUSE-SU-2026:22302-1: moderate: Security update for glycin-loaders Message-ID: <178292424953.5373.11350493902648828439@bea6e15a6baf> # Security update for glycin-loaders Announcement ID: SUSE-SU-2026:22302-1 Release Date: 2026-06-20T18:27:34Z Rating: moderate References: * bsc#1248035 * bsc#1249010 Cross-References: * CVE-2025-55159 * CVE-2025-58160 CVSS scores: * CVE-2025-55159 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-55159 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-55159 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for glycin-loaders fixes the following issues * CVE-2025-55159: slab: incorrect bounds check in get_disjoint_mut function can lead to undefined behavior or potential crash due to out-of-bounds access (bsc#1248035). * CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249010). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-999=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-999=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * typelib-1_0-GlyGtk4_1-1.2.1-160000.3.1 * libglycin-1-0-1.2.1-160000.3.1 * typelib-1_0-Gly_1-1.2.1-160000.3.1 * glycin-loaders-1.2.1-160000.3.1 * libglycin-gtk4-1-0-1.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * typelib-1_0-GlyGtk4_1-1.2.1-160000.3.1 * libglycin-1-0-1.2.1-160000.3.1 * typelib-1_0-Gly_1-1.2.1-160000.3.1 * glycin-loaders-1.2.1-160000.3.1 * libglycin-gtk4-1-0-1.2.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-55159.html * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1248035 * https://bugzilla.suse.com/show_bug.cgi?id=1249010 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:15 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:15 -0000 Subject: SUSE-RU-2026:22301-1: moderate: Recommended update for libselinux Message-ID: <178292425543.5373.17039517375142679697@bea6e15a6baf> # Recommended update for libselinux Announcement ID: SUSE-RU-2026:22301-1 Release Date: 2026-06-20T18:17:58Z Rating: moderate References: * bsc#1232226 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for libselinux fixes the following issues: * Backport patch for restorecon to log error on readonly fs (bsc#1232226) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-996=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-996=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libselinux-bindings-debugsource-3.8.1-160000.4.1 * selinux-tools-3.8.1-160000.4.1 * libselinux-devel-3.8.1-160000.4.1 * libselinux1-debuginfo-3.8.1-160000.4.1 * libselinux-debugsource-3.8.1-160000.4.1 * python313-selinux-debuginfo-3.8.1-160000.4.1 * ruby-selinux-3.8.1-160000.4.1 * python313-selinux-3.8.1-160000.4.1 * selinux-tools-debuginfo-3.8.1-160000.4.1 * libselinux1-3.8.1-160000.4.1 * ruby-selinux-debuginfo-3.8.1-160000.4.1 * libselinux-devel-static-3.8.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libselinux-bindings-debugsource-3.8.1-160000.4.1 * selinux-tools-3.8.1-160000.4.1 * libselinux-devel-3.8.1-160000.4.1 * libselinux1-debuginfo-3.8.1-160000.4.1 * libselinux-debugsource-3.8.1-160000.4.1 * python313-selinux-debuginfo-3.8.1-160000.4.1 * ruby-selinux-3.8.1-160000.4.1 * python313-selinux-3.8.1-160000.4.1 * libselinux1-3.8.1-160000.4.1 * selinux-tools-debuginfo-3.8.1-160000.4.1 * ruby-selinux-debuginfo-3.8.1-160000.4.1 * libselinux-devel-static-3.8.1-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1232226 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:20 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:20 -0000 Subject: SUSE-SU-2026:22300-1: important: Security update for python-pip Message-ID: <178292426089.5373.12885557770706147825@bea6e15a6baf> # Security update for python-pip Announcement ID: SUSE-SU-2026:22300-1 Release Date: 2026-06-20T18:17:57Z Rating: important References: * bsc#1266669 Cross-References: * CVE-2026-8643 CVSS scores: * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-pip fixes the following issue * CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1005=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1005=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-pip-25.0.1-160000.5.1 * python313-pip-wheel-25.0.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-pip-25.0.1-160000.5.1 * python313-pip-wheel-25.0.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1266669 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:26 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:26 -0000 Subject: SUSE-RU-2026:22299-1: moderate: Recommended update for OpenIPMI Message-ID: <178292426620.5373.7164946676552617897@bea6e15a6baf> # Recommended update for OpenIPMI Announcement ID: SUSE-RU-2026:22299-1 Release Date: 2026-06-20T18:16:21Z Rating: moderate References: * bsc#1252941 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for OpenIPMI fixes the following issue: Change in OpenIPMI: * Adopt path to executable in systemd service file (bsc#1252941) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1001=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1001=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libOpenIPMI0-debuginfo-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-2.0.36.56+git.0a3a991-160000.3.1 * libOpenIPMIui1-debuginfo-2.0.36.56+git.0a3a991-160000.3.1 * libOpenIPMI0-2.0.36.56+git.0a3a991-160000.3.1 * libOpenIPMIui1-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-python3-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-devel-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-debuginfo-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-python3-debuginfo-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-debugsource-2.0.36.56+git.0a3a991-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libOpenIPMI0-debuginfo-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-2.0.36.56+git.0a3a991-160000.3.1 * libOpenIPMIui1-debuginfo-2.0.36.56+git.0a3a991-160000.3.1 * libOpenIPMI0-2.0.36.56+git.0a3a991-160000.3.1 * libOpenIPMIui1-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-devel-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-python3-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-debuginfo-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-python3-debuginfo-2.0.36.56+git.0a3a991-160000.3.1 * OpenIPMI-debugsource-2.0.36.56+git.0a3a991-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1252941 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:32 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:32 -0000 Subject: SUSE-RU-2026:22298-1: moderate: Recommended update for gtk-vnc Message-ID: <178292427291.5373.17846704538625323547@bea6e15a6baf> # Recommended update for gtk-vnc Announcement ID: SUSE-RU-2026:22298-1 Release Date: 2026-06-20T18:14:55Z Rating: moderate References: * bsc#1266272 * bsc#1266372 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for gtk-vnc fixes the following issues: * Fix "virt-manager" is crashing (bsc#1266272) * Fix: virt-manager SIGSEGV after few minutes in on_primary_owner_change (bsc#1266372) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-997=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-997=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gtk-vnc-debugsource-1.5.0-160000.4.1 * typelib-1_0-GVnc-1_0-1.5.0-160000.4.1 * libgvnc-1_0-0-debuginfo-1.5.0-160000.4.1 * typelib-1_0-GtkVnc-2_0-1.5.0-160000.4.1 * gtk-vnc-debuginfo-1.5.0-160000.4.1 * libgtk-vnc-2_0-0-1.5.0-160000.4.1 * libgtk-vnc-2_0-0-debuginfo-1.5.0-160000.4.1 * libgvnc-1_0-0-1.5.0-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gtk-vnc-debugsource-1.5.0-160000.4.1 * typelib-1_0-GVnc-1_0-1.5.0-160000.4.1 * libgvnc-1_0-0-debuginfo-1.5.0-160000.4.1 * typelib-1_0-GtkVnc-2_0-1.5.0-160000.4.1 * gtk-vnc-debuginfo-1.5.0-160000.4.1 * libgtk-vnc-2_0-0-1.5.0-160000.4.1 * libgtk-vnc-2_0-0-debuginfo-1.5.0-160000.4.1 * libgvnc-1_0-0-1.5.0-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1266272 * https://bugzilla.suse.com/show_bug.cgi?id=1266372 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:38 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:38 -0000 Subject: SUSE-SU-2026:22297-1: moderate: Security update for glib-networking Message-ID: <178292427826.5373.3133138827381941196@bea6e15a6baf> # Security update for glib-networking Announcement ID: SUSE-SU-2026:22297-1 Release Date: 2026-06-20T18:14:55Z Rating: moderate References: * bsc#1267979 Cross-References: * CVE-2026-10028 CVSS scores: * CVE-2026-10028 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-10028 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-10028 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for glib-networking fixes the following issue * CVE-2026-10028: two certificates which are each signed by the other can lead to an infinite loop (bsc#1267979). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-995=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-995=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * glib-networking-debugsource-2.80.1-160000.3.1 * glib-networking-2.80.1-160000.3.1 * glib-networking-debuginfo-2.80.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * glib-networking-lang-2.80.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * glib-networking-lang-2.80.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * glib-networking-debugsource-2.80.1-160000.3.1 * glib-networking-2.80.1-160000.3.1 * glib-networking-debuginfo-2.80.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10028.html * https://bugzilla.suse.com/show_bug.cgi?id=1267979 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:42 -0000 Subject: SUSE-RU-2026:22296-1: moderate: Recommended update for ltrace Message-ID: <178292428220.5373.9452274475141729395@bea6e15a6baf> # Recommended update for ltrace Announcement ID: SUSE-RU-2026:22296-1 Release Date: 2026-06-20T18:14:55Z Rating: moderate References: * jsc#PED-15928 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for ltrace fixes the following issues: * Give a hint when ltrace -p fails on a system where yama is active (jsc#PED-15928). * update to 0.8.1: * Bugfixes * include config.h in more cases to fix LTO builds * Update to ltrace 0.8.0: * Each DSO can now ship an ltrace config file (called prototype library) that ltrace will open when that DSO is loaded to process image * The option -F was retrofitted to be a colon-separated list of prototype libraries, and directories to look for prototype libraries in * Wide character strings are supported in prototypes * Sole void function parameter is now considered obsolete * Prototypes are now read from DWARF debug info, if available * RISC-V initial support included * MIPS and MIPSel are now handled by the same backend * ARMv6, ARMv7 and ARMv8 (AArch64) are supported, including full fetch backend * Imagination Technologies Meta is now supported * PowerPC64 ELFv2 little-endian ABI is now supported including full fetch backend * Cadence Tensilica Xtensa is now supported * LoongArch is now supported * On Linux, tracing of IFUNC symbols is supported * -w output now shows full library path * Enable build on loongarch64 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1003=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1003=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * ltrace-0.8.1-160000.1.1 * ltrace-debugsource-0.8.1-160000.1.1 * ltrace-debuginfo-0.8.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * ltrace-0.8.1-160000.1.1 * ltrace-debugsource-0.8.1-160000.1.1 * ltrace-debuginfo-0.8.1-160000.1.1 ## References: * https://jira.suse.com/browse/PED-15928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:46 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:46 -0000 Subject: SUSE-RU-2026:22295-1: moderate: Recommended update for netcfg Message-ID: <178292428621.5373.13801344308068553036@bea6e15a6baf> # Recommended update for netcfg Announcement ID: SUSE-RU-2026:22295-1 Release Date: 2026-06-20T18:12:39Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for netcfg fixes the following issues: * Clarify /etc/services removal message ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1000=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1000=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * netcfg-11.6-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * netcfg-11.6-160000.3.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:51 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:51 -0000 Subject: SUSE-SU-2026:22294-1: moderate: Security update for ncurses Message-ID: <178292429169.5373.9678673367198634126@bea6e15a6baf> # Security update for ncurses Announcement ID: SUSE-SU-2026:22294-1 Release Date: 2026-06-20T18:11:34Z Rating: moderate References: * bsc#1259924 Cross-References: * CVE-2025-69720 CVSS scores: * CVE-2025-69720 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-69720 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2025-69720 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-69720 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2025-69720 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for ncurses fixes the following issue: * CVE-2025-69720: buffer overflow in function `analyze_string()`of `progs/infocmp.c` (bsc#1259924). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1004=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1004=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * terminfo-screen-6.5.20250531-160000.3.1 * ncurses-devel-debuginfo-6.5.20250531-160000.3.1 * ncurses-examples-debuginfo-6.5.20250531-160000.3.1 * ncurses-utils-6.5.20250531-160000.3.1 * ncurses-devel-6.5.20250531-160000.3.1 * libncurses5-6.5.20250531-160000.3.1 * libncurses5-debuginfo-6.5.20250531-160000.3.1 * ncurses-examples-6.5.20250531-160000.3.1 * ncurses-debugsource-6.5.20250531-160000.3.1 * libncurses6-debuginfo-6.5.20250531-160000.3.1 * libncurses6-6.5.20250531-160000.3.1 * terminfo-iterm-6.5.20250531-160000.3.1 * tack-1.11.20250503-160000.3.1 * tack-debuginfo-1.11.20250503-160000.3.1 * terminfo-6.5.20250531-160000.3.1 * terminfo-base-6.5.20250531-160000.3.1 * ncurses-utils-debuginfo-6.5.20250531-160000.3.1 * ncurses-devel-static-6.5.20250531-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * terminfo-screen-6.5.20250531-160000.3.1 * ncurses-examples-debuginfo-6.5.20250531-160000.3.1 * ncurses-devel-debuginfo-6.5.20250531-160000.3.1 * ncurses-utils-6.5.20250531-160000.3.1 * ncurses-devel-6.5.20250531-160000.3.1 * ncurses-examples-6.5.20250531-160000.3.1 * libncurses5-debuginfo-6.5.20250531-160000.3.1 * libncurses5-6.5.20250531-160000.3.1 * ncurses-debugsource-6.5.20250531-160000.3.1 * libncurses6-debuginfo-6.5.20250531-160000.3.1 * libncurses6-6.5.20250531-160000.3.1 * terminfo-iterm-6.5.20250531-160000.3.1 * tack-1.11.20250503-160000.3.1 * tack-debuginfo-1.11.20250503-160000.3.1 * terminfo-6.5.20250531-160000.3.1 * terminfo-base-6.5.20250531-160000.3.1 * ncurses-utils-debuginfo-6.5.20250531-160000.3.1 * ncurses-devel-static-6.5.20250531-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-69720.html * https://bugzilla.suse.com/show_bug.cgi?id=1259924 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:57 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:44:57 -0000 Subject: SUSE-SU-2026:2719-1: important: Security update for pacemaker Message-ID: <178292429725.5373.3604181721223016022@bea6e15a6baf> # Security update for pacemaker Announcement ID: SUSE-SU-2026:2719-1 Release Date: 2026-07-01T11:33:19Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial-of-service via integer overflow in remote message decompression (bsc#1268381). Changes for pacemaker: * Update to version 2.1.10+20260618.4bca25e3c1: * libcrmcommon: Add additional checks to pcmk__remote_message_xml. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcib: Remove an unnecessary coverity suppression. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Fix an integer overflow in pcmk__remote_send_xml. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Limit the max size of a remote message. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Fix integer overflow in remote message code. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Add sanity checks to localized_remote_header. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Fix a glib logging build error * libcrmcommon, libpacemaker: Don't assign const char * to char * ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-2719=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * pacemaker-cli-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-remote-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-cli-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-remote-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-libs-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-debugsource-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-libs-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-devel-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (noarch) * pacemaker-schemas-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * python3-pacemaker-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-cts-2.1.10+20260618.4bca25e3c1-150700.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:45:09 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 16:45:09 -0000 Subject: SUSE-SU-2026:2718-1: moderate: Security update for cups Message-ID: <178292430938.5373.16094717646537753068@bea6e15a6baf> # Security update for cups Announcement ID: SUSE-SU-2026:2718-1 Release Date: 2026-07-01T10:23:34Z Rating: moderate References: * bsc#1261569 * bsc#1261570 * bsc#1261571 * bsc#1261572 * bsc#1261742 Cross-References: * CVE-2026-27447 * CVE-2026-34978 * CVE-2026-34979 * CVE-2026-34980 * CVE-2026-39316 CVSS scores: * CVE-2026-27447 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N * CVE-2026-27447 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N * CVE-2026-27447 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N * CVE-2026-34978 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34978 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34979 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34979 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34980 ( SUSE ): 6.4 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-34980 ( NVD ): 6.1 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34980 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39316 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39316 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39316 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for cups fixes the following issues * CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572). * CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571). * CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570). * CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (bsc#1261569). * CVE-2026-39316: dangling subscription pointer can lead to a denial of service (bsc#1261742). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2718=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * cups-libs-debuginfo-32bit-1.7.5-20.67.1 * cups-debugsource-1.7.5-20.67.1 * cups-client-1.7.5-20.67.1 * cups-libs-32bit-1.7.5-20.67.1 * cups-libs-1.7.5-20.67.1 * cups-devel-1.7.5-20.67.1 * cups-debuginfo-1.7.5-20.67.1 * cups-libs-debuginfo-1.7.5-20.67.1 * cups-1.7.5-20.67.1 * cups-client-debuginfo-1.7.5-20.67.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27447.html * https://www.suse.com/security/cve/CVE-2026-34978.html * https://www.suse.com/security/cve/CVE-2026-34979.html * https://www.suse.com/security/cve/CVE-2026-34980.html * https://www.suse.com/security/cve/CVE-2026-39316.html * https://bugzilla.suse.com/show_bug.cgi?id=1261569 * https://bugzilla.suse.com/show_bug.cgi?id=1261570 * https://bugzilla.suse.com/show_bug.cgi?id=1261571 * https://bugzilla.suse.com/show_bug.cgi?id=1261572 * https://bugzilla.suse.com/show_bug.cgi?id=1261742 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 20:33:15 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 20:33:15 -0000 Subject: SUSE-SU-2026:2722-1: important: Security update for the Linux Kernel Message-ID: <178293799571.141.543695513262316442@c0b3d623d882> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2722-1 Release Date: 2026-07-01T13:35:37Z Rating: important References: * bsc#1256668 * bsc#1260531 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263057 * bsc#1263123 * bsc#1263124 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264137 * bsc#1264239 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266840 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267251 * bsc#1267361 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267651 * bsc#1267654 * bsc#1267685 * bsc#1267744 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-23392 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31560 * CVE-2026-31592 * CVE-2026-31593 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46162 * CVE-2026-46172 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23392 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23392 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31560 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31593 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31593 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31593 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * Legacy Module 15-SP7 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves 66 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already- launched/encrypted vCPU (bsc#1263124). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). * ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non- serdev device (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git- fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/amdkfd: always resume_all after suspend_all (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/gpuvm: Do not prepare NULL objects (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/imagination: Count paired job fence as dependency in prepare_job() (git- fixes). * drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). * drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * ice: ptp: do not WARN when controlling PF is unavailable (bsc#1267251). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * scripts/submit_branch: add SLE15-SP7 submission script * serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git- fixes). * serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git- fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2722=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2722=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2722=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-2722=1 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-2722=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2722=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2722=1 Please note that this is the initial kernel livepatch without fixes itself, this package is later updated by separate standalone kernel livepatch updates. ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.63.1 * kernel-default-livepatch-6.4.0-150700.53.63.1 * kernel-livepatch-SLE15-SP7_Update_17-debugsource-1-150700.15.3.1 * kernel-default-debuginfo-6.4.0-150700.53.63.1 * kernel-livepatch-6_4_0-150700_53_63-default-1-150700.15.3.1 * kernel-default-livepatch-devel-6.4.0-150700.53.63.1 * kernel-livepatch-6_4_0-150700_53_63-default-debuginfo-1-150700.15.3.1 * SUSE Linux Enterprise Live Patching 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.63.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * gfs2-kmp-default-6.4.0-150700.53.63.1 * dlm-kmp-default-debuginfo-6.4.0-150700.53.63.1 * kernel-default-debugsource-6.4.0-150700.53.63.1 * ocfs2-kmp-default-debuginfo-6.4.0-150700.53.63.1 * cluster-md-kmp-default-debuginfo-6.4.0-150700.53.63.1 * kernel-default-debuginfo-6.4.0-150700.53.63.1 * ocfs2-kmp-default-6.4.0-150700.53.63.1 * cluster-md-kmp-default-6.4.0-150700.53.63.1 * dlm-kmp-default-6.4.0-150700.53.63.1 * gfs2-kmp-default-debuginfo-6.4.0-150700.53.63.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-devel-debuginfo-6.4.0-150700.53.63.1 * kernel-default-debugsource-6.4.0-150700.53.63.1 * kernel-default-devel-6.4.0-150700.53.63.1 * kernel-default-debuginfo-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-150700.53.63.1.150700.17.37.1 * Basesystem Module 15-SP7 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (aarch64 nosrc) * kernel-64kb-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (noarch) * kernel-devel-6.4.0-150700.53.63.1 * kernel-macros-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (s390x) * kernel-zfcpdump-debuginfo-6.4.0-150700.53.63.1 * kernel-zfcpdump-debugsource-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (aarch64) * kernel-64kb-devel-6.4.0-150700.53.63.1 * kernel-64kb-debuginfo-6.4.0-150700.53.63.1 * kernel-64kb-devel-debuginfo-6.4.0-150700.53.63.1 * kernel-64kb-debugsource-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (nosrc s390x) * kernel-zfcpdump-6.4.0-150700.53.63.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debuginfo-6.4.0-150700.53.63.1 * kernel-default-debugsource-6.4.0-150700.53.63.1 * reiserfs-kmp-default-6.4.0-150700.53.63.1 * reiserfs-kmp-default-debuginfo-6.4.0-150700.53.63.1 * Legacy Module 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.63.1 * Public Cloud Module 15-SP7 (aarch64 x86_64) * kernel-azure-debugsource-6.4.0-150700.53.63.1 * kernel-azure-devel-6.4.0-150700.53.63.1 * kernel-azure-debuginfo-6.4.0-150700.53.63.1 * kernel-azure-devel-debuginfo-6.4.0-150700.53.63.1 * Public Cloud Module 15-SP7 (aarch64 nosrc x86_64) * kernel-azure-6.4.0-150700.53.63.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-150700.53.63.1 * kernel-obs-build-debugsource-6.4.0-150700.53.63.1 * kernel-syms-6.4.0-150700.53.63.1 * Development Tools Module 15-SP7 (noarch nosrc) * kernel-docs-6.4.0-150700.53.63.1 * Development Tools Module 15-SP7 (noarch) * kernel-source-6.4.0-150700.53.63.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.63.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * kernel-default-debugsource-6.4.0-150700.53.63.1 * kernel-default-debuginfo-6.4.0-150700.53.63.1 * kernel-default-extra-debuginfo-6.4.0-150700.53.63.1 * kernel-default-extra-6.4.0-150700.53.63.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-23392.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31560.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31593.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46162.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1260531 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263057 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263124 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266840 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 20:33:23 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 20:33:23 -0000 Subject: SUSE-SU-2026:2721-1: important: Security update for dracut Message-ID: <178293800329.141.12706702063436590436@c0b3d623d882> # Security update for dracut Announcement ID: SUSE-SU-2026:2721-1 Release Date: 2026-07-01T13:15:53Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 055+suse.402.g2720eea: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2721=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2721=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2721=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2721=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2721=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2721=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-tools-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 * dracut-extra-055+suse.402.g2720eea-150500.3.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 20:33:29 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 01 Jul 2026 20:33:29 -0000 Subject: SUSE-SU-2026:2720-1: important: Security update for dracut Message-ID: <178293800954.141.9157759005952584417@c0b3d623d882> # Security update for dracut Announcement ID: SUSE-SU-2026:2720-1 Release Date: 2026-07-01T13:15:19Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 055+suse.365.g79144c5: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2720=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2720=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2720=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2720=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2720=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2720=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2720=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2720=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2720=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * dracut-extra-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-tools-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 08:30:11 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 02 Jul 2026 08:30:11 -0000 Subject: SUSE-SU-2026:2724-1: moderate: Security update for python-python-dotenv Message-ID: <178298101145.204.12144430407561021871@373793e7b316> # Security update for python-python-dotenv Announcement ID: SUSE-SU-2026:2724-1 Release Date: 2026-07-01T18:09:54Z Rating: moderate References: * bsc#1262423 Cross-References: * CVE-2026-28684 CVSS scores: * CVE-2026-28684 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28684 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H * CVE-2026-28684 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-python-dotenv fixes the following issue: * CVE-2026-28684: follow symbolic links when rewriting `.env` files (bsc#1262423) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2724=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2724=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-python-dotenv-1.0.0-150400.9.6.1 * openSUSE Leap 15.4 (noarch) * python311-python-dotenv-1.0.0-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-28684.html * https://bugzilla.suse.com/show_bug.cgi?id=1262423 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 08:30:20 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 02 Jul 2026 08:30:20 -0000 Subject: SUSE-SU-2026:2723-1: moderate: Security update for python311 Message-ID: <178298102090.204.17849673230714620934@373793e7b316> # Security update for python311 Announcement ID: SUSE-SU-2026:2723-1 Release Date: 2026-07-01T18:09:22Z Rating: moderate References: * bsc#1258364 * bsc#1261970 Cross-References: * CVE-2026-3446 CVSS scores: * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python311 fixes the following issues: Security issues fixed: * CVE-2026-3446: base64 decoding stops at first padded quad by default and ignores other information that could be processed (bsc#1261970). Other updates and bugfixes: * Rewrite structure of Python interpreter packages. `python3*` symbols should be now provided by real `python3` packages and its subpackages instead of the virtual provides (bsc#1258364). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2723=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2723=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-core-debugsource-3.11.15-150400.9.88.1 * python311-testsuite-3.11.15-150400.9.88.1 * python311-curses-debuginfo-3.11.15-150400.9.88.1 * python311-doc-devhelp-3.11.15-150400.9.88.1 * python311-dbm-3.11.15-150400.9.88.1 * python311-testsuite-debuginfo-3.11.15-150400.9.88.1 * python311-idle-3.11.15-150400.9.88.1 * python311-debugsource-3.11.15-150400.9.88.1 * python311-tools-3.11.15-150400.9.88.1 * libpython3_11-1_0-3.11.15-150400.9.88.1 * python311-base-3.11.15-150400.9.88.1 * python311-doc-3.11.15-150400.9.88.1 * python311-curses-3.11.15-150400.9.88.1 * python311-devel-3.11.15-150400.9.88.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.88.1 * python311-3.11.15-150400.9.88.1 * python311-tk-debuginfo-3.11.15-150400.9.88.1 * python311-tk-3.11.15-150400.9.88.1 * python311-dbm-debuginfo-3.11.15-150400.9.88.1 * python311-debuginfo-3.11.15-150400.9.88.1 * python311-base-debuginfo-3.11.15-150400.9.88.1 * openSUSE Leap 15.4 (x86_64) * libpython3_11-1_0-32bit-debuginfo-3.11.15-150400.9.88.1 * python311-32bit-debuginfo-3.11.15-150400.9.88.1 * python311-base-32bit-debuginfo-3.11.15-150400.9.88.1 * python311-32bit-3.11.15-150400.9.88.1 * libpython3_11-1_0-32bit-3.11.15-150400.9.88.1 * python311-base-32bit-3.11.15-150400.9.88.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpython3_11-1_0-64bit-debuginfo-3.11.15-150400.9.88.1 * python311-base-64bit-debuginfo-3.11.15-150400.9.88.1 * python311-64bit-3.11.15-150400.9.88.1 * libpython3_11-1_0-64bit-3.11.15-150400.9.88.1 * python311-64bit-debuginfo-3.11.15-150400.9.88.1 * python311-base-64bit-3.11.15-150400.9.88.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-base-3.11.15-150400.9.88.1 * python311-3.11.15-150400.9.88.1 * libpython3_11-1_0-3.11.15-150400.9.88.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3446.html * https://bugzilla.suse.com/show_bug.cgi?id=1258364 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 20:30:10 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 02 Jul 2026 20:30:10 -0000 Subject: SUSE-SU-2026:2727-1: important: Security update for gstreamer-plugins-good Message-ID: <178302421065.377.17791350110576243@1451accf52c7> # Security update for gstreamer-plugins-good Announcement ID: SUSE-SU-2026:2727-1 Release Date: 2026-07-02T14:04:42Z Rating: important References: * bsc#1234421 * bsc#1268449 Cross-References: * CVE-2024-47540 * CVE-2026-53705 CVSS scores: * CVE-2024-47540 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47540 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47540 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53705 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-good fixes the following issues * CVE-2024-47540: uninitialized stack memory in Matroska/WebM demuxer (bsc#1234421). * CVE-2026-53705: Heap buffer overflow in WavPack decoder via integer overflow (bsc#1268449). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2727=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2727=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-debugsource-1.8.3-16.19.1 * gstreamer-plugins-good-1.8.3-16.19.1 * gstreamer-plugins-good-debuginfo-1.8.3-16.19.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * gstreamer-plugins-good-lang-1.8.3-16.19.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gstreamer-plugins-good-debugsource-1.8.3-16.19.1 * gstreamer-plugins-good-1.8.3-16.19.1 * gstreamer-plugins-good-debuginfo-1.8.3-16.19.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * gstreamer-plugins-good-lang-1.8.3-16.19.1 ## References: * https://www.suse.com/security/cve/CVE-2024-47540.html * https://www.suse.com/security/cve/CVE-2026-53705.html * https://bugzilla.suse.com/show_bug.cgi?id=1234421 * https://bugzilla.suse.com/show_bug.cgi?id=1268449 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 20:30:19 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 02 Jul 2026 20:30:19 -0000 Subject: SUSE-SU-2026:2726-1: important: Security update for python-tornado Message-ID: <178302421955.377.1708035932061454359@1451accf52c7> # Security update for python-tornado Announcement ID: SUSE-SU-2026:2726-1 Release Date: 2026-07-02T13:55:02Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2726=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2726=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2726=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2726=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2726=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2726=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2726=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2726=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2726=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2726=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2726=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2726=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2726=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2726=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2726=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2726=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 20:30:30 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 02 Jul 2026 20:30:30 -0000 Subject: SUSE-SU-2026:2725-1: important: Security update for python-tornado6 Message-ID: <178302423016.377.10711975475405979726@1451accf52c7> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:2725-1 Release Date: 2026-07-02T13:52:50Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2725=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2725=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2725=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2725=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2725=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2725=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2725=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2725=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2725=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:30:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:30:07 -0000 Subject: SUSE-RU-2026:22439-1: important: Recommended update for cloud-init Message-ID: <178306740769.117.1617908178257816467@2afce7b7fe24> # Recommended update for cloud-init Announcement ID: SUSE-RU-2026:22439-1 Release Date: 2026-07-01T09:45:17Z Rating: important References: * bsc#1267422 Affected Products: * SUSE Linux Micro 6.0 An update that has one fix can now be installed. ## Description: This update for cloud-init fixes the following issues: * Fix: Cloud init failures observed [ thread::1hcnhpN0LIaV02LMM-IqGis:: ] (bsc#1267422) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-777=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * cloud-init-config-suse-25.1.3-3.1 * cloud-init-25.1.3-3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267422 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:30:14 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:30:14 -0000 Subject: SUSE-SU-2026:22438-1: moderate: Security update for libssh2_org Message-ID: <178306741465.117.10386879522780857912@2afce7b7fe24> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:22438-1 Release Date: 2026-07-01T09:39:44Z Rating: moderate References: * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libssh2_org fixes the following issue * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-775=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libssh2_org-debugsource-1.11.0-3.1 * libssh2-1-debuginfo-1.11.0-3.1 * libssh2-1-1.11.0-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:30:21 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:30:21 -0000 Subject: SUSE-SU-2026:22437-1: moderate: Security update for openssl-3 Message-ID: <178306742167.117.14452325848928343400@2afce7b7fe24> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22437-1 Release Date: 2026-07-01T09:35:35Z Rating: moderate References: * bsc#1266350 Cross-References: * CVE-2026-42767 CVSS scores: * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-3 fixes the following issue * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-776=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * openssl-3-debuginfo-3.1.4-15.1 * openssl-3-3.1.4-15.1 * libopenssl-3-devel-3.1.4-15.1 * libopenssl3-debuginfo-3.1.4-15.1 * openssl-3-debugsource-3.1.4-15.1 * libopenssl-3-fips-provider-3.1.4-15.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-15.1 * libopenssl3-3.1.4-15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:32:12 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:32:12 -0000 Subject: SUSE-SU-2026:22436-1: important: Security update for the Linux Kernel Message-ID: <178306753210.117.3668952048663261514@2afce7b7fe24> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22436-1 Release Date: 2026-06-30T23:13:02Z Rating: important References: * bsc#1256668 * bsc#1261256 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263123 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264239 * bsc#1264263 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31592 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46197 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 71 vulnerabilities and has two fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-496=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * kernel-default-debuginfo-6.4.0-48.1 * kernel-default-debugsource-6.4.0-48.1 * SUSE Linux Micro 6.0 (aarch64 x86_64) * kernel-default-base-6.4.0-48.1.21.25 * SUSE Linux Micro 6.0 (aarch64 nosrc s390x x86_64) * kernel-default-6.4.0-48.1 * SUSE Linux Micro 6.0 (noarch) * kernel-macros-6.4.0-48.1 * kernel-devel-6.4.0-48.1 * kernel-source-6.4.0-48.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-kvmsmall-6.4.0-48.1 * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-default-livepatch-6.4.0-48.1 * SUSE Linux Micro 6.0 (x86_64) * kernel-kvmsmall-debuginfo-6.4.0-48.1 * kernel-kvmsmall-debugsource-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:32:16 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:32:16 -0000 Subject: SUSE-RU-2026:22435-1: moderate: Recommended update for kernel-livepatch-MICRO-6-0-RT_Update_25 Message-ID: <178306753659.117.9918525798766483842@2afce7b7fe24> # Recommended update for kernel-livepatch-MICRO-6-0-RT_Update_25 Announcement ID: SUSE-RU-2026:22435-1 Release Date: 2026-06-30T23:10:56Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_25 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 RT kernel update 25. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-499=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_25-debugsource-1-1.1 * kernel-livepatch-6_4_0-48-rt-1-1.1 * kernel-livepatch-6_4_0-48-rt-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:32:20 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:32:20 -0000 Subject: SUSE-RU-2026:22434-1: moderate: Recommended update for kernel-livepatch-MICRO-6-0_Update_25 Message-ID: <178306754046.117.7314949464831075370@2afce7b7fe24> # Recommended update for kernel-livepatch-MICRO-6-0_Update_25 Announcement ID: SUSE-RU-2026:22434-1 Release Date: 2026-06-30T23:10:56Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_25 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 25. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-497=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_25-debugsource-1-1.1 * kernel-livepatch-6_4_0-48-default-1-1.1 * kernel-livepatch-6_4_0-48-default-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:36:47 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:36:47 -0000 Subject: SUSE-SU-2026:22433-1: important: Security update for the Linux Kernel Message-ID: <178306780702.117.17082954628787994765@2afce7b7fe24> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22433-1 Release Date: 2026-06-30T17:26:45Z Rating: important References: * bsc#1248235 * bsc#1255416 * bsc#1256668 * bsc#1258538 * bsc#1260502 * bsc#1260584 * bsc#1261256 * bsc#1261619 * bsc#1261791 * bsc#1262085 * bsc#1262392 * bsc#1262606 * bsc#1262615 * bsc#1262617 * bsc#1262619 * bsc#1262620 * bsc#1262622 * bsc#1262624 * bsc#1262634 * bsc#1262649 * bsc#1262656 * bsc#1262663 * bsc#1262668 * bsc#1262674 * bsc#1262748 * bsc#1262755 * bsc#1262798 * bsc#1262993 * bsc#1263006 * bsc#1263068 * bsc#1263115 * bsc#1263123 * bsc#1263137 * bsc#1263143 * bsc#1263152 * bsc#1263178 * bsc#1263319 * bsc#1263562 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263724 * bsc#1263769 * bsc#1263774 * bsc#1263790 * bsc#1263879 * bsc#1263880 * bsc#1263883 * bsc#1263930 * bsc#1263932 * bsc#1263934 * bsc#1263945 * bsc#1263993 * bsc#1263996 * bsc#1264000 * bsc#1264011 * bsc#1264045 * bsc#1264063 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264093 * bsc#1264116 * bsc#1264124 * bsc#1264137 * bsc#1264145 * bsc#1264184 * bsc#1264239 * bsc#1264243 * bsc#1264245 * bsc#1264255 * bsc#1264263 * bsc#1264266 * bsc#1264300 * bsc#1264409 * bsc#1264430 * bsc#1264437 * bsc#1264444 * bsc#1264449 * bsc#1264470 * bsc#1264476 * bsc#1264484 * bsc#1264549 * bsc#1264551 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264669 * bsc#1264671 * bsc#1264672 * bsc#1264716 * bsc#1264719 * bsc#1264720 * bsc#1264722 * bsc#1264726 * bsc#1264741 * bsc#1264763 * bsc#1264765 * bsc#1264805 * bsc#1264989 * bsc#1265020 * bsc#1265044 * bsc#1265073 * bsc#1265103 * bsc#1265110 * bsc#1265128 * bsc#1265143 * bsc#1265170 * bsc#1265240 * bsc#1265579 * bsc#1265628 * bsc#1265928 * bsc#1265960 * bsc#1266001 * bsc#1266009 * bsc#1266214 * bsc#1266238 * bsc#1266290 * bsc#1266307 * bsc#1266390 * bsc#1266394 * bsc#1266395 * bsc#1266397 * bsc#1266400 * bsc#1266402 * bsc#1266414 * bsc#1266452 * bsc#1266696 * bsc#1266697 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266711 * bsc#1266720 * bsc#1266759 * bsc#1266765 * bsc#1266767 * bsc#1266810 * bsc#1266816 * bsc#1266826 * bsc#1266827 * bsc#1266878 * bsc#1266889 * bsc#1266895 * bsc#1266901 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266927 * bsc#1266933 * bsc#1266969 * bsc#1266972 * bsc#1267205 * bsc#1267208 * bsc#1267214 * bsc#1267218 * bsc#1267220 * bsc#1267222 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267531 * bsc#1267621 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267652 * bsc#1267654 * bsc#1267663 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267726 * bsc#1267732 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-38549 * CVE-2025-68324 * CVE-2025-68822 * CVE-2026-23303 * CVE-2026-23327 * CVE-2026-23359 * CVE-2026-23438 * CVE-2026-23444 * CVE-2026-31396 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31446 * CVE-2026-31448 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31454 * CVE-2026-31455 * CVE-2026-31464 * CVE-2026-31469 * CVE-2026-31473 * CVE-2026-31480 * CVE-2026-31492 * CVE-2026-31493 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-3150 * CVE-2026-31500 * CVE-2026-31516 * CVE-2026-31518 * CVE-2026-31546 * CVE-2026-31555 * CVE-2026-31590 * CVE-2026-31592 * CVE-2026-31596 * CVE-2026-31613 * CVE-2026-31614 * CVE-2026-31629 * CVE-2026-31655 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31671 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31678 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31703 * CVE-2026-31752 * CVE-2026-31758 * CVE-2026-31759 * CVE-2026-31767 * CVE-2026-31771 * CVE-2026-43013 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43026 * CVE-2026-43028 * CVE-2026-43030 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43040 * CVE-2026-43049 * CVE-2026-43052 * CVE-2026-43053 * CVE-2026-43054 * CVE-2026-43059 * CVE-2026-43065 * CVE-2026-43066 * CVE-2026-43068 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43109 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43206 * CVE-2026-43234 * CVE-2026-43239 * CVE-2026-43249 * CVE-2026-43252 * CVE-2026-43261 * CVE-2026-43284 * CVE-2026-43296 * CVE-2026-43325 * CVE-2026-43333 * CVE-2026-43338 * CVE-2026-43339 * CVE-2026-43341 * CVE-2026-43345 * CVE-2026-43359 * CVE-2026-43360 * CVE-2026-43361 * CVE-2026-43362 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43411 * CVE-2026-43413 * CVE-2026-43414 * CVE-2026-43455 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43483 * CVE-2026-43491 * CVE-2026-43499 * CVE-2026-43501 * CVE-2026-43503 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45842 * CVE-2026-45843 * CVE-2026-45846 * CVE-2026-45852 * CVE-2026-45856 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45878 * CVE-2026-45886 * CVE-2026-45894 * CVE-2026-45910 * CVE-2026-45932 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45970 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45984 * CVE-2026-46004 * CVE-2026-46005 * CVE-2026-46021 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46043 * CVE-2026-46079 * CVE-2026-46083 * CVE-2026-46090 * CVE-2026-46094 * CVE-2026-46101 * CVE-2026-46110 * CVE-2026-46111 * CVE-2026-46113 * CVE-2026-46114 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46157 * CVE-2026-46159 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46176 * CVE-2026-46181 * CVE-2026-46197 * CVE-2026-46209 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-38549 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-38549 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-38549 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68324 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23359 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23359 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23359 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31396 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31396 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31396 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31446 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-31448 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31448 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31454 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31455 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31455 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31464 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31464 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-31464 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31473 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31480 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31480 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31480 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31493 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31493 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31493 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3150 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3150 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-3150 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31516 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31518 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31518 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31518 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31613 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31613 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31613 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-31614 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31614 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31614 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31655 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31655 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31655 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31671 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31671 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-31671 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31678 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31703 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31703 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31703 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31767 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31767 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31767 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43013 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43013 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43030 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43030 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43052 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43052 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43052 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43065 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-43065 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-43065 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43066 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43068 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43068 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43068 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43234 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43234 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43249 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43249 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43249 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43252 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43325 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43333 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43333 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43338 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43341 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43359 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43359 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43359 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43361 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43361 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43361 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43362 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-43362 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-43362 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43411 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43411 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43413 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43455 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43499 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43499 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43499 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45842 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45842 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45842 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45843 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45843 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45843 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-45846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45846 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45846 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45852 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45852 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45856 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45856 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45856 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45878 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45878 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45886 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45910 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45910 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45910 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45932 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45984 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45984 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46004 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46021 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46043 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46043 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46043 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46094 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46094 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46094 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46114 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46114 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46114 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46157 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46157 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46157 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46159 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46176 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46181 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 169 vulnerabilities and has 11 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-38549: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (bsc#1248235). * CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). * CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() * CVE-2026-23359: bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584). * CVE-2026-23438: net: mvpp2: guard flow control update with global_tx_fc in buffer switching (bsc#1261619). * CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307). * CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619). * CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624). * CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615). * CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663). * CVE-2026-31480: tracing: Fix potential deadlock in cpu hotplug with osnoise (bsc#1262634). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31493: RDMA/efa: Fix use of completion ctx after free (bsc#1262668). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755). * CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606). * CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769). * CVE-2026-31614: smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). * CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31767: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (bsc#1264124). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43013: net/mlx5: lag: Check for LAG device before creating debugfs (bsc#1264011). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43054: scsi: target: tcm_loop: Drain commands in target_reset handler (bsc#1264063). * CVE-2026-43059: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (bsc#1264184). * CVE-2026-43065: ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243). * CVE-2026-43066: ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245). * CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). * CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43249: 9p/xen: protect xen_9pfs_front_free against concurrent calls (bsc#1264476). * CVE-2026-43252: mptcp: pm: in-kernel: always set ID as avail when rm endp (bsc#1264300). * CVE-2026-43261: arm64: Add support for TSV110 Spectre-BHB mitigation (bsc#1264430). * CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky (bsc#1264805). * CVE-2026-43325: wifi: iwlwifi: mvm: don't send a 6E related command when not supported (bsc#1265110). * CVE-2026-43333: bpf: reject direct access to nullable PTR_TO_BUF pointers (bsc#1264726). * CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill (bsc#1265044). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719). * CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision (bsc#1264720). * CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722). * CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() (bsc#1264672). * CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671). * CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669). * CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (bsc#1265240). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). * CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395). * CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (bsc#1266394). * CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). * CVE-2026-45856: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (bsc#1266720). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767). * CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889). * CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214). * CVE-2026-46004: ALSA: caiaq: Handle probe errors properly (bsc#1267222). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696). * CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531). * CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of- bounds access (bsc#1266927). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46110: net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (bsc#1266759). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46113: KVM: x86/mmu: Add helper to convert SPTE value to its shadow page (bsc#1266969). * CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726). * CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (bsc#1266816). * CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: asihpi: Fix potential OOB array access at reading cache (stable- fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: sc6000: Keep the programmed board state in card-private data (git- fixes). * ALSA: sc6000: Use standard print API (stable-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: ua101: Reject too-short USB descriptors (git-fixes). * ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio (stable-fixes). * ASoC: SOF: Intel: hda-dai: remove dspless special case (stable-fixes). * ASoC: SOF: Intel: hda: Fix NULL pointer dereference (stable-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). * ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). * ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git- fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git- fixes). * Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git- fixes). * Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git- fixes). * Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). * Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). * Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). * Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git- fixes). * Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git- fixes). * Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). * Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). * Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). * Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). * Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). * Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). * Bluetooth: bnep: reject short frames before parsing (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: Allow firmware re-download when version matches (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git- fixes). * Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git- fixes). * Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). * Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git- fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * HID: quirks: really enable the intended work around for appledisplay (git- fixes). * HID: uclogic: Fix regression of input name assignment (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * Improve compatibility with awk 2.4.0 (bsc#1266214). * Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git- fixes). * Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). * Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). * Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git- fixes). * Input: xpad - fix out-of-bounds access for Share button (git-fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: X86: Fix array_index_nospec protection in __pv_send_ipi (git-fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git- fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * RDMA/efa: Check stored completion CTX command ID with received one (git- fixes) * RDMA/efa: Extend admin timeout error print (git-fixes) * RDMA/efa: Fix possible deadlock (git-fixes) * RDMA/efa: Improve admin completion context state machine (git-fixes) * RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). * wicked test: Added missing locking in backport (bsc#1267732). * USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git- fixes). * USB: serial: belkin_sa: validate interrupt status length (git-fixes). * USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git- fixes). * USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). * USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). * USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git- fixes). * USB: serial: safe_serial: fix memory corruption with small endpoint (git- fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) * arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) * auxdisplay: line-display: fix OOB read on zero-length message_store() (git- fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: bla: fix report_work leak on backbone_gw purge (git-fixes). * batman-adv: clear current gateway during teardown (git-fixes). * batman-adv: dat: handle forward allocation error (git-fixes). * batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes). * batman-adv: fix fragment reassembly length accounting (git-fixes). * batman-adv: fix tp_meter counter underflow during shutdown (git-fixes). * batman-adv: frag: disallow unicast fragment in fragment (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid use of uninit sender vars (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * batman-adv: tt: fix negative last_changeset_len (git-fixes). * batman-adv: tt: fix negative tt_buff_len (git-fixes). * bcache: fix uninitialized closure object (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). * comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git- fixes). * drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git- fixes). * drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). * drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). * drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). * drm/amd/display: Validate GPIO pin LUT table size before iterating (stable- fixes). * drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). * drm/amd/pm/si: Disregard vblank time when no displays are connected (git- fixes). * drm/amdgpu/uvd3.1: Do not validate the firmware when already validated (git- fixes). * drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). * drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: fix spelling typos (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git- fixes). * drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). * drm/bridge: megachips: remove bridge when irq request fails (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/hyperv: validate VMBus packet size in receive callback (git-fixes). * drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update() (stable-fixes). * drm/i915: Fix potential UAF in TTM object purge (git-fixes). * drm/i915: Loop over all active pipes in intel_mbus_dbox_update (stable- fixes). * drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dsi: do not dump registers past the mapped region (git-fixes). * drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). * efi: Allocate runtime workqueue before ACPI init (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). * firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). * hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). * hwmon: (pmbus/adm1266) do not clobber GPIO bits before PDIO read in get_multiple (git-fixes). * hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). * hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git- fixes). * hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git- fixes). * hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). * hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). * hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). * hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). * hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). * iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git- fixes). * iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). * iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). * iio: dac: ad5686: fix input raw value check (git-fixes). * iio: dac: max5821: fix return value check in powerdown sync (git-fixes). * iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). * iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). * iio: light: cm3323: fix reg_conf not being initialized correctly (git- fixes). * iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git- fixes). * iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). * iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). * kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mmc: core: Fix host controller programming for fixed driver type (git- fixes). * mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). * mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git- fixes). * mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). * mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: gro: do not merge zcopy skbs (git-fixes). * net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). * net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). * net: mana: Skip redundant detach on already-detached port (git-fixes). * net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). * net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). * net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). * net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). * net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (git-fixes). * phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes). * platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). * platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). * r8152: fix incorrect register write to USB_UPHY_XTAL (git-fixes). * rpm/check-for-config-changes: ignore Rust-related configs (bsc#1258538). * rpm/mkspec: Conditionally set Rust BuildReqs (bsc#1258538). * rpm: Add BuildRequires for Rust enablement (bsc#1258538). * s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1263068). * s390/entry: Scrub r12 register on kernel entry (bsc#1263068). * s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1263068). * sched/rt: Skip currently executing CPU in rto_next_cpu() (bsc#1262649). * security/keys: fix missed RCU read section on lookup (stable-fixes). * serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git- fixes). * serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * smb: client: correctly handle ErrorContextData as a flexible array (git- fixes) * smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). * spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). * spi: st-ssc4: switch to use modern name (stable-fixes). * spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * string: add mem_is_zero() helper to check if memory area is all zeros (stable-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). * thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git- fixes). * tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). * tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). * usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). * usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). * usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). * usb: dwc2: Fix use after free in debug code (git-fixes). * usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). * usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). * usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). * usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). * usb: gadget: net2280: Fix double free in probe error path (git-fixes). * usb: usbtmc: check URB actual_length for interrupt-IN notifications (git- fixes). * usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git- fixes). * usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath10k: skip WMI and beacon transmission when device is wedged (git- fixes). * wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). * wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). * wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). * wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). * wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). * wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git- fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: nl80211: reject oversized EMA RNR lists (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-498=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * kernel-devel-rt-6.4.0-48.1 * kernel-source-rt-6.4.0-48.1 * SUSE Linux Micro 6.0 (x86_64) * kernel-rt-livepatch-6.4.0-48.1 * kernel-rt-debugsource-6.4.0-48.1 * kernel-rt-debuginfo-6.4.0-48.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-rt-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-38549.html * https://www.suse.com/security/cve/CVE-2025-68324.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-23303.html * https://www.suse.com/security/cve/CVE-2026-23327.html * https://www.suse.com/security/cve/CVE-2026-23359.html * https://www.suse.com/security/cve/CVE-2026-23438.html * https://www.suse.com/security/cve/CVE-2026-23444.html * https://www.suse.com/security/cve/CVE-2026-31396.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31446.html * https://www.suse.com/security/cve/CVE-2026-31448.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31454.html * https://www.suse.com/security/cve/CVE-2026-31455.html * https://www.suse.com/security/cve/CVE-2026-31464.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31473.html * https://www.suse.com/security/cve/CVE-2026-31480.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31493.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-3150.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31516.html * https://www.suse.com/security/cve/CVE-2026-31518.html * https://www.suse.com/security/cve/CVE-2026-31546.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31590.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31613.html * https://www.suse.com/security/cve/CVE-2026-31614.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31655.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31671.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31678.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31703.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31767.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43013.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43026.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43030.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43040.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43052.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43054.html * https://www.suse.com/security/cve/CVE-2026-43059.html * https://www.suse.com/security/cve/CVE-2026-43065.html * https://www.suse.com/security/cve/CVE-2026-43066.html * https://www.suse.com/security/cve/CVE-2026-43068.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-43234.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43249.html * https://www.suse.com/security/cve/CVE-2026-43252.html * https://www.suse.com/security/cve/CVE-2026-43261.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43296.html * https://www.suse.com/security/cve/CVE-2026-43325.html * https://www.suse.com/security/cve/CVE-2026-43333.html * https://www.suse.com/security/cve/CVE-2026-43338.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43341.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43359.html * https://www.suse.com/security/cve/CVE-2026-43360.html * https://www.suse.com/security/cve/CVE-2026-43361.html * https://www.suse.com/security/cve/CVE-2026-43362.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43411.html * https://www.suse.com/security/cve/CVE-2026-43413.html * https://www.suse.com/security/cve/CVE-2026-43414.html * https://www.suse.com/security/cve/CVE-2026-43455.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43483.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43499.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45842.html * https://www.suse.com/security/cve/CVE-2026-45843.html * https://www.suse.com/security/cve/CVE-2026-45846.html * https://www.suse.com/security/cve/CVE-2026-45852.html * https://www.suse.com/security/cve/CVE-2026-45856.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45878.html * https://www.suse.com/security/cve/CVE-2026-45886.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45910.html * https://www.suse.com/security/cve/CVE-2026-45932.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45984.html * https://www.suse.com/security/cve/CVE-2026-46004.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46021.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46043.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46083.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46094.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46110.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-46114.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46157.html * https://www.suse.com/security/cve/CVE-2026-46159.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46176.html * https://www.suse.com/security/cve/CVE-2026-46181.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46209.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1248235 * https://bugzilla.suse.com/show_bug.cgi?id=1255416 * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1260502 * https://bugzilla.suse.com/show_bug.cgi?id=1260584 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261619 * https://bugzilla.suse.com/show_bug.cgi?id=1261791 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262606 * https://bugzilla.suse.com/show_bug.cgi?id=1262615 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262619 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262622 * https://bugzilla.suse.com/show_bug.cgi?id=1262624 * https://bugzilla.suse.com/show_bug.cgi?id=1262634 * https://bugzilla.suse.com/show_bug.cgi?id=1262649 * https://bugzilla.suse.com/show_bug.cgi?id=1262656 * https://bugzilla.suse.com/show_bug.cgi?id=1262663 * https://bugzilla.suse.com/show_bug.cgi?id=1262668 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262755 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263006 * https://bugzilla.suse.com/show_bug.cgi?id=1263068 * https://bugzilla.suse.com/show_bug.cgi?id=1263115 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263152 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263562 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263724 * https://bugzilla.suse.com/show_bug.cgi?id=1263769 * https://bugzilla.suse.com/show_bug.cgi?id=1263774 * https://bugzilla.suse.com/show_bug.cgi?id=1263790 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263883 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263932 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263945 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264000 * https://bugzilla.suse.com/show_bug.cgi?id=1264011 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264063 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264093 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264124 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264184 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264243 * https://bugzilla.suse.com/show_bug.cgi?id=1264245 * https://bugzilla.suse.com/show_bug.cgi?id=1264255 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264300 * https://bugzilla.suse.com/show_bug.cgi?id=1264409 * https://bugzilla.suse.com/show_bug.cgi?id=1264430 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264476 * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264551 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264669 * https://bugzilla.suse.com/show_bug.cgi?id=1264671 * https://bugzilla.suse.com/show_bug.cgi?id=1264672 * https://bugzilla.suse.com/show_bug.cgi?id=1264716 * https://bugzilla.suse.com/show_bug.cgi?id=1264719 * https://bugzilla.suse.com/show_bug.cgi?id=1264720 * https://bugzilla.suse.com/show_bug.cgi?id=1264722 * https://bugzilla.suse.com/show_bug.cgi?id=1264726 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264765 * https://bugzilla.suse.com/show_bug.cgi?id=1264805 * https://bugzilla.suse.com/show_bug.cgi?id=1264989 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265044 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265110 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265170 * https://bugzilla.suse.com/show_bug.cgi?id=1265240 * https://bugzilla.suse.com/show_bug.cgi?id=1265579 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1265960 * https://bugzilla.suse.com/show_bug.cgi?id=1266001 * https://bugzilla.suse.com/show_bug.cgi?id=1266009 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266238 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266307 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266394 * https://bugzilla.suse.com/show_bug.cgi?id=1266395 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266400 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266414 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266696 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266711 * https://bugzilla.suse.com/show_bug.cgi?id=1266720 * https://bugzilla.suse.com/show_bug.cgi?id=1266759 * https://bugzilla.suse.com/show_bug.cgi?id=1266765 * https://bugzilla.suse.com/show_bug.cgi?id=1266767 * https://bugzilla.suse.com/show_bug.cgi?id=1266810 * https://bugzilla.suse.com/show_bug.cgi?id=1266816 * https://bugzilla.suse.com/show_bug.cgi?id=1266826 * https://bugzilla.suse.com/show_bug.cgi?id=1266827 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266889 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266901 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266927 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1266969 * https://bugzilla.suse.com/show_bug.cgi?id=1266972 * https://bugzilla.suse.com/show_bug.cgi?id=1267205 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267214 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267220 * https://bugzilla.suse.com/show_bug.cgi?id=1267222 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267652 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267663 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267726 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:36:53 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:36:53 -0000 Subject: SUSE-SU-2026:22432-1: important: Security update for helm Message-ID: <178306781351.117.15712448539338339041@2afce7b7fe24> # Security update for helm Announcement ID: SUSE-SU-2026:22432-1 Release Date: 2026-06-29T10:32:23Z Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: * update to 3.21.2: * chore(deps): bump the k8s-io group with 2 updates 1259634 (dependabot[bot]) * fixes b52e276 (Matheus Pimenta) * chore(deps): bump the k8s-io group across 1 directory with 2 updates 3342dbf (dependabot[bot]) * Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 * chore(deps): bump github.com/distribution/distribution/v3 * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 * chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 * update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-773=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * helm-debuginfo-3.21.2-1.1 * helm-3.21.2-1.1 * SUSE Linux Micro 6.0 (noarch) * helm-bash-completion-3.21.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:36:59 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:36:59 -0000 Subject: SUSE-SU-2026:22431-1: important: Security update for dracut Message-ID: <178306781907.117.15114156577383216595@2afce7b7fe24> # Security update for dracut Announcement ID: SUSE-SU-2026:22431-1 Release Date: 2026-06-29T09:26:08Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.609.g1a2492e: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-772=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * dracut-fips-059+suse.609.g1a2492e-1.1 * dracut-debugsource-059+suse.609.g1a2492e-1.1 * dracut-059+suse.609.g1a2492e-1.1 * dracut-debuginfo-059+suse.609.g1a2492e-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:37:07 -0000 Subject: SUSE-SU-2026:22430-1: important: Security update for python-tornado6 Message-ID: <178306782762.117.13717614792897669290@2afce7b7fe24> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:22430-1 Release Date: 2026-06-26T09:07:54Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-770=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * python311-tornado6-6.4-6.1 * python311-tornado6-debuginfo-6.4-6.1 * python-tornado6-debugsource-6.4-6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:37:13 -0000 Subject: SUSE-SU-2026:22429-1: important: Security update for sg3_utils Message-ID: <178306783384.117.15608452265575246321@2afce7b7fe24> # Security update for sg3_utils Announcement ID: SUSE-SU-2026:22429-1 Release Date: 2026-06-26T09:07:54Z Rating: important References: * bsc#1267823 Affected Products: * SUSE Linux Micro 6.0 An update that has one fix can now be installed. ## Description: This update for sg3_utils fixes the following issue * sg_inq: --export output conformance for SCSI name string and ATA fields (bsc#1267823). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-771=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * sg3_utils-1.48~20221101+2.5a7572d6-1.1 * sg3_utils-debuginfo-1.48~20221101+2.5a7572d6-1.1 * libsgutils2-1_48-2-debuginfo-1.48~20221101+2.5a7572d6-1.1 * libsgutils2-1_48-2-1.48~20221101+2.5a7572d6-1.1 * sg3_utils-debugsource-1.48~20221101+2.5a7572d6-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267823 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:28 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:37:28 -0000 Subject: SUSE-SU-2026:22428-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306784834.117.7739545544010656571@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22428-1 Release Date: 2026-06-25T11:39:25Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-495=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_23-debugsource-2-1.1 * kernel-livepatch-6_4_0-46-default-2-1.1 * kernel-livepatch-6_4_0-46-default-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:41 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:37:41 -0000 Subject: SUSE-SU-2026:22427-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306786137.117.14725031715810489874@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22427-1 Release Date: 2026-06-25T11:39:25Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-494=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-45-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-45-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_22-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:54 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:37:54 -0000 Subject: SUSE-SU-2026:22426-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306787441.117.2836164337367887060@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22426-1 Release Date: 2026-06-25T11:36:36Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-493=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_21-debugsource-2-1.1 * kernel-livepatch-6_4_0-44-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-44-default-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:38:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:38:13 -0000 Subject: SUSE-SU-2026:22425-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306789319.117.16949016729783233012@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22425-1 Release Date: 2026-06-25T11:36:36Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-492=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-43-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:38:21 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:38:21 -0000 Subject: SUSE-SU-2026:22424-1: important: Security update for containerd Message-ID: <178306790162.117.8210214107498892335@2afce7b7fe24> # Security update for containerd Announcement ID: SUSE-SU-2026:22424-1 Release Date: 2026-06-25T09:00:00Z Rating: important References: * bsc#1262948 * bsc#1265794 * bsc#1266640 Cross-References: * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for containerd fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265794). * CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262948). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-769=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * containerd-1.7.29-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1262948 * https://bugzilla.suse.com/show_bug.cgi?id=1265794 * https://bugzilla.suse.com/show_bug.cgi?id=1266640 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:38:33 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:38:33 -0000 Subject: SUSE-SU-2026:22423-1: important: Security update for google-guest-agent Message-ID: <178306791340.117.16478897984799355731@2afce7b7fe24> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:22423-1 Release Date: 2026-06-24T16:10:38Z Rating: important References: * bsc#1243254 * bsc#1243505 * bsc#1260264 * bsc#1266171 * bsc#1266603 Cross-References: * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266171). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266171). Changes: * Update to version 20260529.00 * Dependency updates (#616) * from version 20260522.00 * Fix improper umask calculation on socket creation (#614) * from version 20260520.01 * Update OWNERS (#609) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) (bsc#1260264, CVE-2026-33186) * Update to version 20250506.01 (bsc#1243254, bsc#1243505) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-768=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * google-guest-agent-20260529.00-1.1 * google-guest-agent-debuginfo-20260529.00-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1243254 * https://bugzilla.suse.com/show_bug.cgi?id=1243505 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1266171 * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:38:43 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:38:43 -0000 Subject: SUSE-RU-2026:22422-1: moderate: Recommended update for suseconnect-ng Message-ID: <178306792312.117.14883682188494384497@2afce7b7fe24> # Recommended update for suseconnect-ng Announcement ID: SUSE-RU-2026:22422-1 Release Date: 2026-06-24T16:09:58Z Rating: moderate References: * bsc#1197231 * bsc#1263772 * bsc#1265410 * bsc#1268017 Affected Products: * SUSE Linux Micro 6.0 An update that has four fixes can now be installed. ## Description: This update for suseconnect-ng fixes the following issues: * Update version to 1.22.1: * library: Allow clients to disable the token handling mechanism (jsc#SCC-801) * Ensure updated system certs are included when creating HTTP client connections (bsc#1268017, jsc#SCC-804) * Update version to 1.22: * InstallReleasePackage should consider zypperFilesystemRoot (jsc#SCC-630). * Restore exit code 71 handling when attempting keepalive and not registered (bsc#1263772) * Add collector support for gathering RKE2 and K3s kubernetes provider info if enabled on a system (jsc#TEL-317) * Add email address validation to SUSEConnect -e/--email option. (bsc#1197231) * Add collector support for detecting if system is running pacemaker (jsc#SCC-693) * Avoid double slash at start of request URL path component. (jsc#SCC-775) * Use product identifier when finding product packages during migrations. (jsc#SCC=758, bsc#1265410) * Add opt in/out support for collectors (jsc#TEL-312) * Update config parser for suseconnect to be YAML based (jsc#SCC-730) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-767=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * suseconnect-ng-1.22.1-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1197231 * https://bugzilla.suse.com/show_bug.cgi?id=1263772 * https://bugzilla.suse.com/show_bug.cgi?id=1265410 * https://bugzilla.suse.com/show_bug.cgi?id=1268017 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:38:57 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:38:57 -0000 Subject: SUSE-SU-2026:22421-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306793789.117.10832685630273440499@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22421-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-491=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_17-debugsource-6-1.1 * kernel-livepatch-6_4_0-40-default-6-1.1 * kernel-livepatch-6_4_0-40-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:39:12 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:39:12 -0000 Subject: SUSE-SU-2026:22420-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306795213.117.9904359801556517422@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22420-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-490=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_16-debugsource-7-1.1 * kernel-livepatch-6_4_0-39-default-7-1.1 * kernel-livepatch-6_4_0-39-default-debuginfo-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:39:27 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:39:27 -0000 Subject: SUSE-SU-2026:22419-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306796764.117.17556407965965525798@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22419-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-489=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-38-default-8-1.2 * kernel-livepatch-MICRO-6-0_Update_14-debugsource-8-1.2 * kernel-livepatch-6_4_0-38-default-debuginfo-8-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:39:43 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:39:43 -0000 Subject: SUSE-SU-2026:22418-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306798334.117.5740491942153989760@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22418-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-488=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_13-debugsource-10-1.1 * kernel-livepatch-6_4_0-36-default-10-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:39:58 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:39:58 -0000 Subject: SUSE-SU-2026:22417-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306799812.117.6322620014531927958@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22417-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-487=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-12-1.1 * kernel-livepatch-6_4_0-35-default-debuginfo-12-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:40:12 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:40:12 -0000 Subject: SUSE-SU-2026:22416-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306801229.117.16175938006235888707@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22416-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-486=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-34-default-12-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-12-1.1 * kernel-livepatch-MICRO-6-0_Update_11-debugsource-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:40:27 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:40:27 -0000 Subject: SUSE-SU-2026:22415-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306802725.117.6487157999462563068@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22415-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-485=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-debuginfo-13-1.1 * kernel-livepatch-6_4_0-32-default-13-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:40:40 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:40:40 -0000 Subject: SUSE-SU-2026:22414-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306804056.117.6957175099819682568@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22414-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-481=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-46-rt-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-2-1.1 * kernel-livepatch-6_4_0-46-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:40:56 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:40:56 -0000 Subject: SUSE-SU-2026:22413-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306805607.117.7861722726397151304@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22413-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-480=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-45-rt-debuginfo-2-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-2-1.2 * kernel-livepatch-6_4_0-45-rt-2-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:41:14 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:41:14 -0000 Subject: SUSE-SU-2026:22412-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306807409.117.1501640893949187348@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22412-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-479=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-43-rt-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-2-1.1 * kernel-livepatch-6_4_0-43-rt-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:41:32 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:41:32 -0000 Subject: SUSE-SU-2026:22411-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306809272.117.6636768856935968529@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22411-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-478=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-3-1.1 * kernel-livepatch-6_4_0-42-rt-debuginfo-3-1.1 * kernel-livepatch-6_4_0-42-rt-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:41:45 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:41:45 -0000 Subject: SUSE-SU-2026:22410-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306810582.117.9053456161785272603@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22410-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-477=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-41-rt-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-5-1.1 * kernel-livepatch-6_4_0-41-rt-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:00 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:42:00 -0000 Subject: SUSE-SU-2026:22409-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306812059.117.7870149371604592950@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22409-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-476=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-6-1.1 * kernel-livepatch-6_4_0-40-rt-6-1.1 * kernel-livepatch-6_4_0-40-rt-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:15 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:42:15 -0000 Subject: SUSE-SU-2026:22408-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306813515.117.3655338530432680024@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22408-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-475=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-39-rt-debuginfo-7-1.1 * kernel-livepatch-6_4_0-39-rt-7-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:30 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:42:30 -0000 Subject: SUSE-SU-2026:22407-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306815022.117.6487174429777498330@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22407-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-474=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-38-rt-8-1.1 * kernel-livepatch-6_4_0-38-rt-debuginfo-8-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:45 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:42:45 -0000 Subject: SUSE-SU-2026:22406-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306816501.117.931093371839007042@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22406-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-473=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-37-rt-debuginfo-8-1.1 * kernel-livepatch-6_4_0-37-rt-8-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:59 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:42:59 -0000 Subject: SUSE-SU-2026:22405-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306817972.117.15922404446183685630@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22405-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-472=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-36-rt-debuginfo-12-1.1 * kernel-livepatch-6_4_0-36-rt-12-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:43:15 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:43:15 -0000 Subject: SUSE-SU-2026:22404-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306819560.117.5738779184255275548@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22404-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-471=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-35-rt-13-1.1 * kernel-livepatch-6_4_0-35-rt-debuginfo-13-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:43:30 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:43:30 -0000 Subject: SUSE-SU-2026:22403-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306821088.117.11232112356272548546@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22403-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-470=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-34-rt-17-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-17-1.1 * kernel-livepatch-6_4_0-34-rt-debuginfo-17-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:43:54 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:43:54 -0000 Subject: SUSE-SU-2026:22402-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306823425.117.813763545885418068@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22402-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-467=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-42-default-3-1.1 * kernel-livepatch-6_4_0-42-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_19-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:44:08 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:44:08 -0000 Subject: SUSE-SU-2026:22401-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306824811.117.16379296589318716073@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22401-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-466=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-41-default-5-1.1 * kernel-livepatch-6_4_0-41-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_18-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:44:23 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:44:23 -0000 Subject: SUSE-SU-2026:22400-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306826341.117.9456014640876127640@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22400-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-484=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-31-default-debuginfo-19-1.2 * kernel-livepatch-MICRO-6-0_Update_9-debugsource-19-1.2 * kernel-livepatch-6_4_0-31-default-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:44:38 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:44:38 -0000 Subject: SUSE-SU-2026:22399-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306827832.117.7000305739613809019@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22399-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-30.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-483=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-19-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-19-1.2 * kernel-livepatch-6_4_0-30-default-debuginfo-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:44:53 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:44:53 -0000 Subject: SUSE-SU-2026:22398-1: important: Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306829303.117.8008670644739574083@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22398-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-29.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-482=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-29-default-20-1.2 * kernel-livepatch-MICRO-6-0_Update_7-debugsource-20-1.2 * kernel-livepatch-6_4_0-29-default-debuginfo-20-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:45:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:45:07 -0000 Subject: SUSE-SU-2026:22397-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306830784.117.10675399128926071714@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22397-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-33.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-469=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-33-rt-17-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_9-debugsource-17-1.2 * kernel-livepatch-6_4_0-33-rt-debuginfo-17-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:45:22 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:45:22 -0000 Subject: SUSE-SU-2026:22396-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306832249.117.880532118281105595@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22396-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-468=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-31-rt-debuginfo-19-1.2 * kernel-livepatch-6_4_0-31-rt-19-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_8-debugsource-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:45:28 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:45:28 -0000 Subject: SUSE-SU-2026:22395-1: moderate: Security update for crun Message-ID: <178306832847.117.6149682467951094709@2afce7b7fe24> # Security update for crun Announcement ID: SUSE-SU-2026:22395-1 Release Date: 2026-06-24T08:59:37Z Rating: moderate References: * bsc#1268302 Cross-References: * CVE-2026-47766 CVSS scores: * CVE-2026-47766 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for crun fixes the following issue * CVE-2026-47766: crun follows rootfs /dev symlink while creating default devices (bsc#1268302). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-766=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * crun-debuginfo-1.14-3.1 * crun-1.14-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47766.html * https://bugzilla.suse.com/show_bug.cgi?id=1268302 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:50:06 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:50:06 -0000 Subject: SUSE-SU-2026:22394-1: important: Security update for the Linux Kernel Message-ID: <178306860604.117.1812771326435595732@2afce7b7fe24> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22394-1 Release Date: 2026-06-30T17:26:45Z Rating: important References: * bsc#1248235 * bsc#1255416 * bsc#1256668 * bsc#1258538 * bsc#1260502 * bsc#1260584 * bsc#1261256 * bsc#1261619 * bsc#1261791 * bsc#1262085 * bsc#1262392 * bsc#1262606 * bsc#1262615 * bsc#1262617 * bsc#1262619 * bsc#1262620 * bsc#1262622 * bsc#1262624 * bsc#1262634 * bsc#1262649 * bsc#1262656 * bsc#1262663 * bsc#1262668 * bsc#1262674 * bsc#1262748 * bsc#1262755 * bsc#1262798 * bsc#1262993 * bsc#1263006 * bsc#1263068 * bsc#1263115 * bsc#1263123 * bsc#1263137 * bsc#1263143 * bsc#1263152 * bsc#1263178 * bsc#1263319 * bsc#1263562 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263724 * bsc#1263769 * bsc#1263774 * bsc#1263790 * bsc#1263879 * bsc#1263880 * bsc#1263883 * bsc#1263930 * bsc#1263932 * bsc#1263934 * bsc#1263945 * bsc#1263993 * bsc#1263996 * bsc#1264000 * bsc#1264011 * bsc#1264045 * bsc#1264063 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264093 * bsc#1264116 * bsc#1264124 * bsc#1264137 * bsc#1264145 * bsc#1264184 * bsc#1264239 * bsc#1264243 * bsc#1264245 * bsc#1264255 * bsc#1264263 * bsc#1264266 * bsc#1264300 * bsc#1264409 * bsc#1264430 * bsc#1264437 * bsc#1264444 * bsc#1264449 * bsc#1264470 * bsc#1264476 * bsc#1264484 * bsc#1264549 * bsc#1264551 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264669 * bsc#1264671 * bsc#1264672 * bsc#1264716 * bsc#1264719 * bsc#1264720 * bsc#1264722 * bsc#1264726 * bsc#1264741 * bsc#1264763 * bsc#1264765 * bsc#1264805 * bsc#1264989 * bsc#1265020 * bsc#1265044 * bsc#1265073 * bsc#1265103 * bsc#1265110 * bsc#1265128 * bsc#1265143 * bsc#1265170 * bsc#1265240 * bsc#1265579 * bsc#1265628 * bsc#1265928 * bsc#1265960 * bsc#1266001 * bsc#1266009 * bsc#1266214 * bsc#1266238 * bsc#1266290 * bsc#1266307 * bsc#1266390 * bsc#1266394 * bsc#1266395 * bsc#1266397 * bsc#1266400 * bsc#1266402 * bsc#1266414 * bsc#1266452 * bsc#1266696 * bsc#1266697 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266711 * bsc#1266720 * bsc#1266759 * bsc#1266765 * bsc#1266767 * bsc#1266810 * bsc#1266816 * bsc#1266826 * bsc#1266827 * bsc#1266878 * bsc#1266889 * bsc#1266895 * bsc#1266901 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266927 * bsc#1266933 * bsc#1266969 * bsc#1266972 * bsc#1267205 * bsc#1267208 * bsc#1267214 * bsc#1267218 * bsc#1267220 * bsc#1267222 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267531 * bsc#1267621 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267652 * bsc#1267654 * bsc#1267663 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267726 * bsc#1267732 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-38549 * CVE-2025-68324 * CVE-2025-68822 * CVE-2026-23303 * CVE-2026-23327 * CVE-2026-23359 * CVE-2026-23438 * CVE-2026-23444 * CVE-2026-31396 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31446 * CVE-2026-31448 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31454 * CVE-2026-31455 * CVE-2026-31464 * CVE-2026-31469 * CVE-2026-31473 * CVE-2026-31480 * CVE-2026-31492 * CVE-2026-31493 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-3150 * CVE-2026-31500 * CVE-2026-31516 * CVE-2026-31518 * CVE-2026-31546 * CVE-2026-31555 * CVE-2026-31590 * CVE-2026-31592 * CVE-2026-31596 * CVE-2026-31613 * CVE-2026-31614 * CVE-2026-31629 * CVE-2026-31655 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31671 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31678 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31703 * CVE-2026-31752 * CVE-2026-31758 * CVE-2026-31759 * CVE-2026-31767 * CVE-2026-31771 * CVE-2026-43013 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43026 * CVE-2026-43028 * CVE-2026-43030 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43040 * CVE-2026-43049 * CVE-2026-43052 * CVE-2026-43053 * CVE-2026-43054 * CVE-2026-43059 * CVE-2026-43065 * CVE-2026-43066 * CVE-2026-43068 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43109 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43206 * CVE-2026-43234 * CVE-2026-43239 * CVE-2026-43249 * CVE-2026-43252 * CVE-2026-43261 * CVE-2026-43284 * CVE-2026-43296 * CVE-2026-43325 * CVE-2026-43333 * CVE-2026-43338 * CVE-2026-43339 * CVE-2026-43341 * CVE-2026-43345 * CVE-2026-43359 * CVE-2026-43360 * CVE-2026-43361 * CVE-2026-43362 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43411 * CVE-2026-43413 * CVE-2026-43414 * CVE-2026-43455 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43483 * CVE-2026-43491 * CVE-2026-43499 * CVE-2026-43501 * CVE-2026-43503 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45842 * CVE-2026-45843 * CVE-2026-45846 * CVE-2026-45852 * CVE-2026-45856 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45878 * CVE-2026-45886 * CVE-2026-45894 * CVE-2026-45910 * CVE-2026-45932 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45970 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45984 * CVE-2026-46004 * CVE-2026-46005 * CVE-2026-46021 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46043 * CVE-2026-46079 * CVE-2026-46083 * CVE-2026-46090 * CVE-2026-46094 * CVE-2026-46101 * CVE-2026-46110 * CVE-2026-46111 * CVE-2026-46113 * CVE-2026-46114 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46157 * CVE-2026-46159 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46176 * CVE-2026-46181 * CVE-2026-46197 * CVE-2026-46209 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-38549 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-38549 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-38549 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68324 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23359 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23359 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23359 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31396 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31396 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31396 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31446 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-31448 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31448 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31454 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31455 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31455 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31464 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31464 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-31464 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31473 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31480 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31480 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31480 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31493 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31493 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31493 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3150 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3150 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-3150 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31516 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31518 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31518 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31518 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31613 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31613 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31613 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-31614 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31614 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31614 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31655 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31655 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31655 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31671 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31671 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-31671 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31678 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31703 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31703 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31703 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31767 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31767 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31767 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43013 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43013 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43030 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43030 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43052 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43052 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43052 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43065 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-43065 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-43065 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43066 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43068 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43068 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43068 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43234 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43234 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43249 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43249 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43249 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43252 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43325 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43333 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43333 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43338 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43341 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43359 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43359 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43359 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43361 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43361 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43361 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43362 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-43362 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-43362 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43411 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43411 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43413 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43455 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43499 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43499 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43499 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45842 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45842 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45842 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45843 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45843 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45843 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-45846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45846 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45846 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45852 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45852 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45856 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45856 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45856 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45878 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45878 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45886 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45910 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45910 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45910 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45932 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45984 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45984 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46004 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46021 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46043 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46043 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46043 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46094 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46094 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46094 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46114 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46114 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46114 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46157 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46157 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46157 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46159 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46176 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46181 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 169 vulnerabilities and has 11 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-38549: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (bsc#1248235). * CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). * CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() * CVE-2026-23359: bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584). * CVE-2026-23438: net: mvpp2: guard flow control update with global_tx_fc in buffer switching (bsc#1261619). * CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307). * CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619). * CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624). * CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615). * CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663). * CVE-2026-31480: tracing: Fix potential deadlock in cpu hotplug with osnoise (bsc#1262634). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31493: RDMA/efa: Fix use of completion ctx after free (bsc#1262668). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755). * CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606). * CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769). * CVE-2026-31614: smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). * CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31767: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (bsc#1264124). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43013: net/mlx5: lag: Check for LAG device before creating debugfs (bsc#1264011). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43054: scsi: target: tcm_loop: Drain commands in target_reset handler (bsc#1264063). * CVE-2026-43059: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (bsc#1264184). * CVE-2026-43065: ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243). * CVE-2026-43066: ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245). * CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). * CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43249: 9p/xen: protect xen_9pfs_front_free against concurrent calls (bsc#1264476). * CVE-2026-43252: mptcp: pm: in-kernel: always set ID as avail when rm endp (bsc#1264300). * CVE-2026-43261: arm64: Add support for TSV110 Spectre-BHB mitigation (bsc#1264430). * CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky (bsc#1264805). * CVE-2026-43325: wifi: iwlwifi: mvm: don't send a 6E related command when not supported (bsc#1265110). * CVE-2026-43333: bpf: reject direct access to nullable PTR_TO_BUF pointers (bsc#1264726). * CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill (bsc#1265044). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719). * CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision (bsc#1264720). * CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722). * CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() (bsc#1264672). * CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671). * CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669). * CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (bsc#1265240). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). * CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395). * CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (bsc#1266394). * CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). * CVE-2026-45856: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (bsc#1266720). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767). * CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889). * CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214). * CVE-2026-46004: ALSA: caiaq: Handle probe errors properly (bsc#1267222). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696). * CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531). * CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of- bounds access (bsc#1266927). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46110: net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (bsc#1266759). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46113: KVM: x86/mmu: Add helper to convert SPTE value to its shadow page (bsc#1266969). * CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726). * CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (bsc#1266816). * CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: asihpi: Fix potential OOB array access at reading cache (stable- fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: sc6000: Keep the programmed board state in card-private data (git- fixes). * ALSA: sc6000: Use standard print API (stable-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: ua101: Reject too-short USB descriptors (git-fixes). * ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio (stable-fixes). * ASoC: SOF: Intel: hda-dai: remove dspless special case (stable-fixes). * ASoC: SOF: Intel: hda: Fix NULL pointer dereference (stable-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). * ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). * ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git- fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git- fixes). * Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git- fixes). * Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git- fixes). * Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). * Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). * Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). * Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git- fixes). * Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git- fixes). * Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). * Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). * Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). * Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). * Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). * Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). * Bluetooth: bnep: reject short frames before parsing (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: Allow firmware re-download when version matches (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git- fixes). * Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git- fixes). * Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). * Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git- fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * HID: quirks: really enable the intended work around for appledisplay (git- fixes). * HID: uclogic: Fix regression of input name assignment (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * Improve compatibility with awk 2.4.0 (bsc#1266214). * Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git- fixes). * Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). * Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). * Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git- fixes). * Input: xpad - fix out-of-bounds access for Share button (git-fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: X86: Fix array_index_nospec protection in __pv_send_ipi (git-fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git- fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * RDMA/efa: Check stored completion CTX command ID with received one (git- fixes) * RDMA/efa: Extend admin timeout error print (git-fixes) * RDMA/efa: Fix possible deadlock (git-fixes) * RDMA/efa: Improve admin completion context state machine (git-fixes) * RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). * wicked test: Added missing locking in backport (bsc#1267732). * USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git- fixes). * USB: serial: belkin_sa: validate interrupt status length (git-fixes). * USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git- fixes). * USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). * USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). * USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git- fixes). * USB: serial: safe_serial: fix memory corruption with small endpoint (git- fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) * arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) * auxdisplay: line-display: fix OOB read on zero-length message_store() (git- fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: bla: fix report_work leak on backbone_gw purge (git-fixes). * batman-adv: clear current gateway during teardown (git-fixes). * batman-adv: dat: handle forward allocation error (git-fixes). * batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes). * batman-adv: fix fragment reassembly length accounting (git-fixes). * batman-adv: fix tp_meter counter underflow during shutdown (git-fixes). * batman-adv: frag: disallow unicast fragment in fragment (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid use of uninit sender vars (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * batman-adv: tt: fix negative last_changeset_len (git-fixes). * batman-adv: tt: fix negative tt_buff_len (git-fixes). * bcache: fix uninitialized closure object (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). * comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git- fixes). * drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git- fixes). * drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). * drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). * drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). * drm/amd/display: Validate GPIO pin LUT table size before iterating (stable- fixes). * drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). * drm/amd/pm/si: Disregard vblank time when no displays are connected (git- fixes). * drm/amdgpu/uvd3.1: Do not validate the firmware when already validated (git- fixes). * drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). * drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: fix spelling typos (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git- fixes). * drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). * drm/bridge: megachips: remove bridge when irq request fails (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/hyperv: validate VMBus packet size in receive callback (git-fixes). * drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update() (stable-fixes). * drm/i915: Fix potential UAF in TTM object purge (git-fixes). * drm/i915: Loop over all active pipes in intel_mbus_dbox_update (stable- fixes). * drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dsi: do not dump registers past the mapped region (git-fixes). * drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). * efi: Allocate runtime workqueue before ACPI init (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). * firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). * hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). * hwmon: (pmbus/adm1266) do not clobber GPIO bits before PDIO read in get_multiple (git-fixes). * hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). * hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git- fixes). * hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git- fixes). * hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). * hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). * hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). * hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). * hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). * iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git- fixes). * iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). * iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). * iio: dac: ad5686: fix input raw value check (git-fixes). * iio: dac: max5821: fix return value check in powerdown sync (git-fixes). * iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). * iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). * iio: light: cm3323: fix reg_conf not being initialized correctly (git- fixes). * iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git- fixes). * iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). * iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). * kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mmc: core: Fix host controller programming for fixed driver type (git- fixes). * mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). * mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git- fixes). * mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). * mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: gro: do not merge zcopy skbs (git-fixes). * net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). * net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). * net: mana: Skip redundant detach on already-detached port (git-fixes). * net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). * net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). * net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). * net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). * net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (git-fixes). * phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes). * platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). * platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). * r8152: fix incorrect register write to USB_UPHY_XTAL (git-fixes). * rpm/check-for-config-changes: ignore Rust-related configs (bsc#1258538). * rpm/mkspec: Conditionally set Rust BuildReqs (bsc#1258538). * rpm: Add BuildRequires for Rust enablement (bsc#1258538). * s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1263068). * s390/entry: Scrub r12 register on kernel entry (bsc#1263068). * s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1263068). * sched/rt: Skip currently executing CPU in rto_next_cpu() (bsc#1262649). * security/keys: fix missed RCU read section on lookup (stable-fixes). * serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git- fixes). * serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * smb: client: correctly handle ErrorContextData as a flexible array (git- fixes) * smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). * spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). * spi: st-ssc4: switch to use modern name (stable-fixes). * spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * string: add mem_is_zero() helper to check if memory area is all zeros (stable-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). * thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git- fixes). * tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). * tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). * usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). * usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). * usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). * usb: dwc2: Fix use after free in debug code (git-fixes). * usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). * usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). * usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). * usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). * usb: gadget: net2280: Fix double free in probe error path (git-fixes). * usb: usbtmc: check URB actual_length for interrupt-IN notifications (git- fixes). * usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git- fixes). * usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath10k: skip WMI and beacon transmission when device is wedged (git- fixes). * wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). * wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). * wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). * wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). * wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). * wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git- fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: nl80211: reject oversized EMA RNR lists (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-498=1 ## Package List: * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-rt-devel-debuginfo-6.4.0-48.1 * kernel-rt-devel-6.4.0-48.1 * kernel-rt-debugsource-6.4.0-48.1 * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-rt-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-38549.html * https://www.suse.com/security/cve/CVE-2025-68324.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-23303.html * https://www.suse.com/security/cve/CVE-2026-23327.html * https://www.suse.com/security/cve/CVE-2026-23359.html * https://www.suse.com/security/cve/CVE-2026-23438.html * https://www.suse.com/security/cve/CVE-2026-23444.html * https://www.suse.com/security/cve/CVE-2026-31396.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31446.html * https://www.suse.com/security/cve/CVE-2026-31448.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31454.html * https://www.suse.com/security/cve/CVE-2026-31455.html * https://www.suse.com/security/cve/CVE-2026-31464.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31473.html * https://www.suse.com/security/cve/CVE-2026-31480.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31493.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-3150.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31516.html * https://www.suse.com/security/cve/CVE-2026-31518.html * https://www.suse.com/security/cve/CVE-2026-31546.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31590.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31613.html * https://www.suse.com/security/cve/CVE-2026-31614.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31655.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31671.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31678.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31703.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31767.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43013.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43026.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43030.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43040.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43052.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43054.html * https://www.suse.com/security/cve/CVE-2026-43059.html * https://www.suse.com/security/cve/CVE-2026-43065.html * https://www.suse.com/security/cve/CVE-2026-43066.html * https://www.suse.com/security/cve/CVE-2026-43068.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-43234.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43249.html * https://www.suse.com/security/cve/CVE-2026-43252.html * https://www.suse.com/security/cve/CVE-2026-43261.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43296.html * https://www.suse.com/security/cve/CVE-2026-43325.html * https://www.suse.com/security/cve/CVE-2026-43333.html * https://www.suse.com/security/cve/CVE-2026-43338.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43341.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43359.html * https://www.suse.com/security/cve/CVE-2026-43360.html * https://www.suse.com/security/cve/CVE-2026-43361.html * https://www.suse.com/security/cve/CVE-2026-43362.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43411.html * https://www.suse.com/security/cve/CVE-2026-43413.html * https://www.suse.com/security/cve/CVE-2026-43414.html * https://www.suse.com/security/cve/CVE-2026-43455.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43483.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43499.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45842.html * https://www.suse.com/security/cve/CVE-2026-45843.html * https://www.suse.com/security/cve/CVE-2026-45846.html * https://www.suse.com/security/cve/CVE-2026-45852.html * https://www.suse.com/security/cve/CVE-2026-45856.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45878.html * https://www.suse.com/security/cve/CVE-2026-45886.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45910.html * https://www.suse.com/security/cve/CVE-2026-45932.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45984.html * https://www.suse.com/security/cve/CVE-2026-46004.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46021.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46043.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46083.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46094.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46110.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-46114.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46157.html * https://www.suse.com/security/cve/CVE-2026-46159.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46176.html * https://www.suse.com/security/cve/CVE-2026-46181.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46209.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1248235 * https://bugzilla.suse.com/show_bug.cgi?id=1255416 * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1260502 * https://bugzilla.suse.com/show_bug.cgi?id=1260584 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261619 * https://bugzilla.suse.com/show_bug.cgi?id=1261791 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262606 * https://bugzilla.suse.com/show_bug.cgi?id=1262615 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262619 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262622 * https://bugzilla.suse.com/show_bug.cgi?id=1262624 * https://bugzilla.suse.com/show_bug.cgi?id=1262634 * https://bugzilla.suse.com/show_bug.cgi?id=1262649 * https://bugzilla.suse.com/show_bug.cgi?id=1262656 * https://bugzilla.suse.com/show_bug.cgi?id=1262663 * https://bugzilla.suse.com/show_bug.cgi?id=1262668 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262755 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263006 * https://bugzilla.suse.com/show_bug.cgi?id=1263068 * https://bugzilla.suse.com/show_bug.cgi?id=1263115 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263152 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263562 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263724 * https://bugzilla.suse.com/show_bug.cgi?id=1263769 * https://bugzilla.suse.com/show_bug.cgi?id=1263774 * https://bugzilla.suse.com/show_bug.cgi?id=1263790 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263883 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263932 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263945 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264000 * https://bugzilla.suse.com/show_bug.cgi?id=1264011 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264063 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264093 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264124 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264184 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264243 * https://bugzilla.suse.com/show_bug.cgi?id=1264245 * https://bugzilla.suse.com/show_bug.cgi?id=1264255 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264300 * https://bugzilla.suse.com/show_bug.cgi?id=1264409 * https://bugzilla.suse.com/show_bug.cgi?id=1264430 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264476 * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264551 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264669 * https://bugzilla.suse.com/show_bug.cgi?id=1264671 * https://bugzilla.suse.com/show_bug.cgi?id=1264672 * https://bugzilla.suse.com/show_bug.cgi?id=1264716 * https://bugzilla.suse.com/show_bug.cgi?id=1264719 * https://bugzilla.suse.com/show_bug.cgi?id=1264720 * https://bugzilla.suse.com/show_bug.cgi?id=1264722 * https://bugzilla.suse.com/show_bug.cgi?id=1264726 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264765 * https://bugzilla.suse.com/show_bug.cgi?id=1264805 * https://bugzilla.suse.com/show_bug.cgi?id=1264989 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265044 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265110 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265170 * https://bugzilla.suse.com/show_bug.cgi?id=1265240 * https://bugzilla.suse.com/show_bug.cgi?id=1265579 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1265960 * https://bugzilla.suse.com/show_bug.cgi?id=1266001 * https://bugzilla.suse.com/show_bug.cgi?id=1266009 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266238 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266307 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266394 * https://bugzilla.suse.com/show_bug.cgi?id=1266395 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266400 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266414 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266696 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266711 * https://bugzilla.suse.com/show_bug.cgi?id=1266720 * https://bugzilla.suse.com/show_bug.cgi?id=1266759 * https://bugzilla.suse.com/show_bug.cgi?id=1266765 * https://bugzilla.suse.com/show_bug.cgi?id=1266767 * https://bugzilla.suse.com/show_bug.cgi?id=1266810 * https://bugzilla.suse.com/show_bug.cgi?id=1266816 * https://bugzilla.suse.com/show_bug.cgi?id=1266826 * https://bugzilla.suse.com/show_bug.cgi?id=1266827 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266889 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266901 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266927 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1266969 * https://bugzilla.suse.com/show_bug.cgi?id=1266972 * https://bugzilla.suse.com/show_bug.cgi?id=1267205 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267214 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267220 * https://bugzilla.suse.com/show_bug.cgi?id=1267222 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267652 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267663 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267726 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:52:08 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:52:08 -0000 Subject: SUSE-SU-2026:22393-1: important: Security update for the Linux Kernel Message-ID: <178306872852.117.16423080408733894431@2afce7b7fe24> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22393-1 Release Date: 2026-06-30T23:09:03Z Rating: important References: * bsc#1256668 * bsc#1261256 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263123 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264239 * bsc#1264263 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31592 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46197 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 71 vulnerabilities and has two fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-496=1 ## Package List: * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-default-6.4.0-48.1 * kernel-64kb-6.4.0-48.1 * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * kernel-syms-6.4.0-48.1 * kernel-default-devel-6.4.0-48.1 * kernel-default-debugsource-6.4.0-48.1 * kernel-obs-build-debugsource-6.4.0-48.1 * kernel-obs-build-6.4.0-48.1 * SUSE Linux Micro Extras 6.0 (aarch64) * kernel-64kb-debugsource-6.4.0-48.1 * kernel-64kb-devel-6.4.0-48.1 * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-default-devel-debuginfo-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:52:25 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:52:25 -0000 Subject: SUSE-RU-2026:2734-1: important: Recommended update for rmt-server Message-ID: <178306874554.117.152468606632730057@2afce7b7fe24> # Recommended update for rmt-server Announcement ID: SUSE-RU-2026:2734-1 Release Date: 2026-07-02T18:05:28Z Rating: important References: * bsc#1262706 * bsc#1268149 * bsc#1268301 * bsc#1268303 * bsc#1268305 Affected Products: * Public Cloud Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has five fixes can now be installed. ## Description: This update for rmt-server fixes the following issues: * Version 2.28: * Set arch to unknown for Rancher based products (jsc#SCC-759) * Fix purge for large amount of systems (bsc#1262706) * Change data type to MEDIUMTEXT in profiles table (bsc#1268305) * Remove proxy_byos column * Fix race condition when no system matches (bsc#1268301) * Fix race condition for PAYG (bsc#1268149) * Fix race condition to update a system (bsc#1268303) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2734=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2734=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rmt-server-config-2.28-150700.3.23.1 * rmt-server-2.28-150700.3.23.1 * rmt-server-debugsource-2.28-150700.3.23.1 * rmt-server-debuginfo-2.28-150700.3.23.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rmt-server-pubcloud-2.28-150700.3.23.1 * rmt-server-debugsource-2.28-150700.3.23.1 * rmt-server-debuginfo-2.28-150700.3.23.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1262706 * https://bugzilla.suse.com/show_bug.cgi?id=1268149 * https://bugzilla.suse.com/show_bug.cgi?id=1268301 * https://bugzilla.suse.com/show_bug.cgi?id=1268303 * https://bugzilla.suse.com/show_bug.cgi?id=1268305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:52:36 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:52:36 -0000 Subject: SUSE-SU-2026:2733-1: important: Security update for buildah Message-ID: <178306875610.117.18434447878397556059@2afce7b7fe24> # Security update for buildah Announcement ID: SUSE-SU-2026:2733-1 Release Date: 2026-07-02T18:05:10Z Rating: important References: * bsc#1262953 * bsc#1266191 * bsc#1266648 * bsc#1267179 Cross-References: * CVE-2025-22869 * CVE-2025-27144 * CVE-2025-47913 * CVE-2025-47914 * CVE-2025-52881 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-27144 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47914 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47914 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47914 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-52881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-52881 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-52881 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-52881 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for buildah fixes the following issues * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267179). * CVE-2026-34986: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262953). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266648). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266191). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266191). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266191). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266191). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2733=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2733=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2733=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2733=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2733=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2733=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2733=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2733=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.62.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * buildah-1.35.5-150500.3.62.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * buildah-1.35.5-150500.3.62.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2025-27144.html * https://www.suse.com/security/cve/CVE-2025-47913.html * https://www.suse.com/security/cve/CVE-2025-47914.html * https://www.suse.com/security/cve/CVE-2025-52881.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1262953 * https://bugzilla.suse.com/show_bug.cgi?id=1266191 * https://bugzilla.suse.com/show_bug.cgi?id=1266648 * https://bugzilla.suse.com/show_bug.cgi?id=1267179 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:52:52 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:52:52 -0000 Subject: SUSE-SU-2026:2732-1: moderate: Security update for cups Message-ID: <178306877254.117.15186005523494754105@2afce7b7fe24> # Security update for cups Announcement ID: SUSE-SU-2026:2732-1 Release Date: 2026-07-02T17:41:51Z Rating: moderate References: * bsc#1261569 * bsc#1261570 * bsc#1261571 * bsc#1261572 * bsc#1261742 * bsc#1261743 Cross-References: * CVE-2026-27447 * CVE-2026-34978 * CVE-2026-34979 * CVE-2026-34980 * CVE-2026-39314 * CVE-2026-39316 CVSS scores: * CVE-2026-27447 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N * CVE-2026-27447 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N * CVE-2026-27447 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N * CVE-2026-34978 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34978 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34979 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34979 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34980 ( SUSE ): 6.4 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-34980 ( NVD ): 6.1 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34980 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39314 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39314 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39316 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39316 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39316 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for cups fixes the following issues * CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572). * CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571). * CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570). * CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (bsc#1261569). * CVE-2026-39314: negative `job-password-supported` attribute can lead to a denial of service (bsc#1261743). * CVE-2026-39316: dangling subscription pointer can lead to a denial of service (1261742). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2732=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2732=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2732=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2732=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2732=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2732=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2732=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2732=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2732=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2732=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libcupsimage2-debuginfo-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcupsppdc1-debuginfo-2.2.7-150000.3.93.1 * cups-debugsource-2.2.7-150000.3.93.1 * libcupsmime1-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-2.2.7-150000.3.93.1 * libcupsmime1-2.2.7-150000.3.93.1 * cups-client-debuginfo-2.2.7-150000.3.93.1 * libcupscgi1-debuginfo-2.2.7-150000.3.93.1 * libcupsppdc1-2.2.7-150000.3.93.1 * cups-devel-2.2.7-150000.3.93.1 * libcupsimage2-2.2.7-150000.3.93.1 * libcupscgi1-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * cups-client-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * cups-debuginfo-2.2.7-150000.3.93.1 * cups-debugsource-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * cups-debuginfo-2.2.7-150000.3.93.1 * cups-debugsource-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * cups-ddk-2.2.7-150000.3.93.1 * cups-ddk-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * cups-debuginfo-2.2.7-150000.3.93.1 * cups-debugsource-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * Desktop Applications Module 15-SP7 (x86_64) * libcups2-32bit-debuginfo-2.2.7-150000.3.93.1 * libcups2-32bit-2.2.7-150000.3.93.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27447.html * https://www.suse.com/security/cve/CVE-2026-34978.html * https://www.suse.com/security/cve/CVE-2026-34979.html * https://www.suse.com/security/cve/CVE-2026-34980.html * https://www.suse.com/security/cve/CVE-2026-39314.html * https://www.suse.com/security/cve/CVE-2026-39316.html * https://bugzilla.suse.com/show_bug.cgi?id=1261569 * https://bugzilla.suse.com/show_bug.cgi?id=1261570 * https://bugzilla.suse.com/show_bug.cgi?id=1261571 * https://bugzilla.suse.com/show_bug.cgi?id=1261572 * https://bugzilla.suse.com/show_bug.cgi?id=1261742 * https://bugzilla.suse.com/show_bug.cgi?id=1261743 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:53:00 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:53:00 -0000 Subject: SUSE-SU-2026:2731-1: moderate: Security update for editorconfig-core-c Message-ID: <178306878061.117.230275279248690979@2afce7b7fe24> # Security update for editorconfig-core-c Announcement ID: SUSE-SU-2026:2731-1 Release Date: 2026-07-02T17:36:35Z Rating: moderate References: * bsc#1262131 Cross-References: * CVE-2026-40489 CVSS scores: * CVE-2026-40489 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40489 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for editorconfig-core-c fixes the following issue: * CVE-2026-40489: improper use of `strcpy` can lead to a stack buffer overflow (bsc#1262131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2731=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2731=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libeditorconfig-devel-0.12.6-150600.3.6.1 * editorconfig-core-c-debugsource-0.12.6-150600.3.6.1 * editorconfig-debuginfo-0.12.6-150600.3.6.1 * editorconfig-0.12.6-150600.3.6.1 * libeditorconfig0-debuginfo-0.12.6-150600.3.6.1 * libeditorconfig0-0.12.6-150600.3.6.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libeditorconfig-devel-64bit-0.12.6-150600.3.6.1 * libeditorconfig0-64bit-debuginfo-0.12.6-150600.3.6.1 * libeditorconfig0-64bit-0.12.6-150600.3.6.1 * openSUSE Leap 15.6 (x86_64) * libeditorconfig-devel-32bit-0.12.6-150600.3.6.1 * libeditorconfig0-32bit-debuginfo-0.12.6-150600.3.6.1 * libeditorconfig0-32bit-0.12.6-150600.3.6.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libeditorconfig0-debuginfo-0.12.6-150600.3.6.1 * editorconfig-core-c-debugsource-0.12.6-150600.3.6.1 * libeditorconfig0-0.12.6-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40489.html * https://bugzilla.suse.com/show_bug.cgi?id=1262131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:53:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:53:07 -0000 Subject: SUSE-SU-2026:2729-1: moderate: Security update for python-lxml Message-ID: <178306878718.117.11334596393236360703@2afce7b7fe24> # Security update for python-lxml Announcement ID: SUSE-SU-2026:2729-1 Release Date: 2026-07-02T17:31:24Z Rating: moderate References: * bsc#1263254 Cross-References: * CVE-2026-41066 CVSS scores: * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-lxml fixes the following issue * CVE-2026-41066: information disclosure via untrusted XML input leading to local file read (bsc#1263254). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2729=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2729=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-lxml-devel-4.9.3-150400.8.11.1 * python-lxml-debugsource-4.9.3-150400.8.11.1 * python311-lxml-4.9.3-150400.8.11.1 * python311-lxml-debuginfo-4.9.3-150400.8.11.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-lxml-debugsource-4.9.3-150400.8.11.1 * python311-lxml-4.9.3-150400.8.11.1 * python311-lxml-debuginfo-4.9.3-150400.8.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41066.html * https://bugzilla.suse.com/show_bug.cgi?id=1263254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:53:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 08:53:13 -0000 Subject: SUSE-SU-2026:2728-1: moderate: Security update for python-lxml Message-ID: <178306879323.117.2874032200269400037@2afce7b7fe24> # Security update for python-lxml Announcement ID: SUSE-SU-2026:2728-1 Release Date: 2026-07-02T17:30:54Z Rating: moderate References: * bsc#1263254 Cross-References: * CVE-2026-41066 CVSS scores: * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-lxml fixes the following issue * CVE-2026-41066: information disclosure via untrusted XML input leading to local file read (bsc#1263254). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2728=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python-lxml-debugsource-3.6.1-8.8.1 * python-lxml-debuginfo-3.6.1-8.8.1 * python-lxml-3.6.1-8.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41066.html * https://bugzilla.suse.com/show_bug.cgi?id=1263254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 12:30:15 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 12:30:15 -0000 Subject: SUSE-SU-2026:2739-1: important: Security update for fontforge Message-ID: <178308181563.202.8466799163477787778@dc2e3449a402> # Security update for fontforge Announcement ID: SUSE-SU-2026:2739-1 Release Date: 2026-07-03T08:05:31Z Rating: important References: * bsc#1256013 * bsc#1256025 * bsc#1256032 Cross-References: * CVE-2025-15269 * CVE-2025-15275 * CVE-2025-15279 CVSS scores: * CVE-2025-15269 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15269 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15275 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15275 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15279 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15279 ( NVD ): 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for fontforge fixes the following issues * CVE-2025-15269: Remote Code Execution via Use-After-Free in SFD file parsing (bsc#1256032). * CVE-2025-15275: Arbitrary code execution via SFD file parsing buffer overflow (bsc#1256025). * CVE-2025-15279: Remote Code Execution via heap-based buffer overflow in BMP file parsing (bsc#1256013). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2739=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2739=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2739=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2739=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2739=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2739=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2739=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2739=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2739=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2739=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2739=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15269.html * https://www.suse.com/security/cve/CVE-2025-15275.html * https://www.suse.com/security/cve/CVE-2025-15279.html * https://bugzilla.suse.com/show_bug.cgi?id=1256013 * https://bugzilla.suse.com/show_bug.cgi?id=1256025 * https://bugzilla.suse.com/show_bug.cgi?id=1256032 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 12:30:28 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 12:30:28 -0000 Subject: SUSE-RU-2026:2738-1: important: Recommended update for rmt-server Message-ID: <178308182815.202.17907125038313186764@dc2e3449a402> # Recommended update for rmt-server Announcement ID: SUSE-RU-2026:2738-1 Release Date: 2026-07-03T06:10:56Z Rating: important References: * bsc#1262706 * bsc#1268149 * bsc#1268301 * bsc#1268303 * bsc#1268305 Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has five fixes can now be installed. ## Description: This update for rmt-server fixes the following issues: * Version 2.28: * Set arch to unknown for Rancher based products (jsc#SCC-759) * Fix purge for large amount of systems (bsc#1262706) * Change data type to MEDIUMTEXT in profiles table (bsc#1268305) * Remove proxy_byos column * Fix race condition when no system matches (bsc#1268301) * Fix race condition for PAYG (bsc#1268149) * Fix race condition to update a system (bsc#1268303) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2738=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2738=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2738=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2738=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2738=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2738=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * rmt-server-debuginfo-2.28-150400.3.57.1 * rmt-server-pubcloud-2.28-150400.3.57.1 * rmt-server-debugsource-2.28-150400.3.57.1 * rmt-server-2.28-150400.3.57.1 * rmt-server-config-2.28-150400.3.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * rmt-server-2.28-150400.3.57.1 * rmt-server-config-2.28-150400.3.57.1 * rmt-server-debuginfo-2.28-150400.3.57.1 * rmt-server-debugsource-2.28-150400.3.57.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * rmt-server-pubcloud-2.28-150400.3.57.1 * rmt-server-debuginfo-2.28-150400.3.57.1 * rmt-server-debugsource-2.28-150400.3.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rmt-server-2.28-150400.3.57.1 * rmt-server-config-2.28-150400.3.57.1 * rmt-server-debuginfo-2.28-150400.3.57.1 * rmt-server-debugsource-2.28-150400.3.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rmt-server-2.28-150400.3.57.1 * rmt-server-config-2.28-150400.3.57.1 * rmt-server-debuginfo-2.28-150400.3.57.1 * rmt-server-debugsource-2.28-150400.3.57.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * rmt-server-2.28-150400.3.57.1 * rmt-server-config-2.28-150400.3.57.1 * rmt-server-debuginfo-2.28-150400.3.57.1 * rmt-server-debugsource-2.28-150400.3.57.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1262706 * https://bugzilla.suse.com/show_bug.cgi?id=1268149 * https://bugzilla.suse.com/show_bug.cgi?id=1268301 * https://bugzilla.suse.com/show_bug.cgi?id=1268303 * https://bugzilla.suse.com/show_bug.cgi?id=1268305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 12:30:39 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 12:30:39 -0000 Subject: SUSE-RU-2026:2737-1: important: Recommended update for rmt-server Message-ID: <178308183958.202.1152475948528082511@dc2e3449a402> # Recommended update for rmt-server Announcement ID: SUSE-RU-2026:2737-1 Release Date: 2026-07-03T06:10:09Z Rating: important References: * bsc#1262706 * bsc#1268149 * bsc#1268301 * bsc#1268303 * bsc#1268305 Affected Products: * openSUSE Leap 15.5 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has five fixes can now be installed. ## Description: This update for rmt-server fixes the following issues: * Version 2.28: * Set arch to unknown for Rancher based products (jsc#SCC-759) * Fix purge for large amount of systems (bsc#1262706) * Change data type to MEDIUMTEXT in profiles table (bsc#1268305) * Remove proxy_byos column * Fix race condition when no system matches (bsc#1268301) * Fix race condition for PAYG (bsc#1268149) * Fix race condition to update a system (bsc#1268303) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2737=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2737=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2737=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2737=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-2737=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2737=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2737=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-2737=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2737=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rmt-server-config-2.28-150500.3.50.1 * rmt-server-debuginfo-2.28-150500.3.50.1 * rmt-server-2.28-150500.3.50.1 * rmt-server-debugsource-2.28-150500.3.50.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rmt-server-config-2.28-150500.3.50.1 * rmt-server-debuginfo-2.28-150500.3.50.1 * rmt-server-2.28-150500.3.50.1 * rmt-server-debugsource-2.28-150500.3.50.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * rmt-server-debuginfo-2.28-150500.3.50.1 * rmt-server-debugsource-2.28-150500.3.50.1 * rmt-server-pubcloud-2.28-150500.3.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * rmt-server-config-2.28-150500.3.50.1 * rmt-server-debuginfo-2.28-150500.3.50.1 * rmt-server-2.28-150500.3.50.1 * rmt-server-debugsource-2.28-150500.3.50.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * rmt-server-debuginfo-2.28-150500.3.50.1 * rmt-server-debugsource-2.28-150500.3.50.1 * rmt-server-pubcloud-2.28-150500.3.50.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * rmt-server-config-2.28-150500.3.50.1 * rmt-server-debuginfo-2.28-150500.3.50.1 * rmt-server-2.28-150500.3.50.1 * rmt-server-debugsource-2.28-150500.3.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rmt-server-config-2.28-150500.3.50.1 * rmt-server-debuginfo-2.28-150500.3.50.1 * rmt-server-2.28-150500.3.50.1 * rmt-server-debugsource-2.28-150500.3.50.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * rmt-server-debugsource-2.28-150500.3.50.1 * rmt-server-config-2.28-150500.3.50.1 * rmt-server-pubcloud-2.28-150500.3.50.1 * rmt-server-debuginfo-2.28-150500.3.50.1 * rmt-server-2.28-150500.3.50.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rmt-server-config-2.28-150500.3.50.1 * rmt-server-debuginfo-2.28-150500.3.50.1 * rmt-server-2.28-150500.3.50.1 * rmt-server-debugsource-2.28-150500.3.50.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1262706 * https://bugzilla.suse.com/show_bug.cgi?id=1268149 * https://bugzilla.suse.com/show_bug.cgi?id=1268301 * https://bugzilla.suse.com/show_bug.cgi?id=1268303 * https://bugzilla.suse.com/show_bug.cgi?id=1268305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 12:30:47 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 12:30:47 -0000 Subject: SUSE-RU-2026:2736-1: important: Recommended update for cloud-init Message-ID: <178308184725.202.4364136055128887278@dc2e3449a402> # Recommended update for cloud-init Announcement ID: SUSE-RU-2026:2736-1 Release Date: 2026-07-03T06:01:49Z Rating: important References: * bsc#1267422 Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has one fix can now be installed. ## Description: This update for cloud-init fixes the following issues: * Fix: Cloud init failures observed [ thread::1hcnhpN0LIaV02LMM-IqGis:: ] (bsc#1267422) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-2736=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2736=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-2736=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2736=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2736=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2736=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2736=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2736=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2736=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2736=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2736=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2736=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2736=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2736=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2736=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2736=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * cloud-init-config-suse-25.1.3-150400.15.10.2 * cloud-init-doc-25.1.3-150400.15.10.2 * cloud-init-25.1.3-150400.15.10.2 * openSUSE Leap 15.4 (noarch) * python311-passlib-1.7.4-150400.6.7.1 * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * python311-configobj-5.0.8-150400.12.7.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-configobj-5.0.8-150400.12.7.1 * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-configobj-5.0.8-150400.12.7.1 * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * cloud-init-25.1.3-150400.15.10.2 * cloud-init-config-suse-25.1.3-150400.15.10.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-configobj-5.0.8-150400.12.7.1 * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-configobj-5.0.8-150400.12.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-configobj-5.0.8-150400.12.7.1 * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * Python 3 Module 15-SP7 (noarch) * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-configobj-5.0.8-150400.12.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * cloud-init-25.1.3-150400.15.10.2 * cloud-init-config-suse-25.1.3-150400.15.10.2 * Public Cloud Module 15-SP4 (noarch) * python311-passlib-1.7.4-150400.6.7.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-configobj-5.0.8-150400.12.7.1 * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-configobj-5.0.8-150400.12.7.1 * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-configobj-5.0.8-150400.12.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-configobj-5.0.8-150400.12.7.1 * python311-jsonpatch-1.32-150400.10.7.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cloud-init-config-suse-25.1.3-150400.15.10.2 * cloud-init-25.1.3-150400.15.10.2 * Public Cloud Module 15-SP5 (noarch) * python311-passlib-1.7.4-150400.6.7.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * cloud-init-25.1.3-150400.15.10.2 * cloud-init-config-suse-25.1.3-150400.15.10.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-pyserial-3.5-150400.12.7.1 * python311-jsonpointer-2.3-150400.11.7.1 * python311-configobj-5.0.8-150400.12.7.1 * python311-jsonpatch-1.32-150400.10.7.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267422 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 12:31:10 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 12:31:10 -0000 Subject: SUSE-SU-2026:2735-1: important: Security update for apache2 Message-ID: <178308187076.202.8505660709389102561@dc2e3449a402> # Security update for apache2 Announcement ID: SUSE-SU-2026:2735-1 Release Date: 2026-07-02T22:36:37Z Rating: important References: * bsc#1267503 * bsc#1267955 * bsc#1267956 * bsc#1267962 * bsc#1267963 * bsc#1267965 * bsc#1267969 * bsc#1267970 * bsc#1267971 * bsc#1267972 * bsc#1267976 * bsc#1267977 * bsc#1267978 Cross-References: * CVE-2026-29167 * CVE-2026-29170 * CVE-2026-34355 * CVE-2026-34356 * CVE-2026-42535 * CVE-2026-42536 * CVE-2026-43951 * CVE-2026-44119 * CVE-2026-44185 * CVE-2026-44186 * CVE-2026-44631 * CVE-2026-48913 * CVE-2026-49975 CVSS scores: * CVE-2026-29167 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29167 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29170 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-29170 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34355 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34356 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42535 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42535 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-42535 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42536 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43951 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43951 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-43951 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44119 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44119 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44186 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44186 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44186 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44631 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44631 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48913 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48913 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48913 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-49975 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-49975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978). * CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955). * CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956). * CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962). * CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963). * CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965). * CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969). * CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of service (bsc#1267970). * CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971). * CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free (bsc#1267972). * CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2735=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2735=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2735=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * apache2-worker-2.4.66-150600.5.55.1 * apache2-event-debugsource-2.4.66-150600.5.55.1 * apache2-utils-debugsource-2.4.66-150600.5.55.1 * apache2-event-debuginfo-2.4.66-150600.5.55.1 * apache2-debuginfo-2.4.66-150600.5.55.1 * apache2-devel-2.4.66-150600.5.55.1 * apache2-utils-2.4.66-150600.5.55.1 * apache2-worker-debugsource-2.4.66-150600.5.55.1 * apache2-prefork-2.4.66-150600.5.55.1 * apache2-event-2.4.66-150600.5.55.1 * apache2-prefork-debugsource-2.4.66-150600.5.55.1 * apache2-debugsource-2.4.66-150600.5.55.1 * apache2-worker-debuginfo-2.4.66-150600.5.55.1 * apache2-2.4.66-150600.5.55.1 * apache2-prefork-debuginfo-2.4.66-150600.5.55.1 * apache2-utils-debuginfo-2.4.66-150600.5.55.1 * openSUSE Leap 15.6 (noarch) * apache2-manual-2.4.66-150600.5.55.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * apache2-manual-2.4.66-150600.5.55.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * apache2-worker-2.4.66-150600.5.55.1 * apache2-utils-debugsource-2.4.66-150600.5.55.1 * apache2-debuginfo-2.4.66-150600.5.55.1 * apache2-devel-2.4.66-150600.5.55.1 * apache2-utils-2.4.66-150600.5.55.1 * apache2-worker-debugsource-2.4.66-150600.5.55.1 * apache2-prefork-2.4.66-150600.5.55.1 * apache2-worker-debuginfo-2.4.66-150600.5.55.1 * apache2-debugsource-2.4.66-150600.5.55.1 * apache2-prefork-debugsource-2.4.66-150600.5.55.1 * apache2-2.4.66-150600.5.55.1 * apache2-prefork-debuginfo-2.4.66-150600.5.55.1 * apache2-utils-debuginfo-2.4.66-150600.5.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * apache2-worker-2.4.66-150600.5.55.1 * apache2-utils-debugsource-2.4.66-150600.5.55.1 * apache2-debuginfo-2.4.66-150600.5.55.1 * apache2-devel-2.4.66-150600.5.55.1 * apache2-utils-2.4.66-150600.5.55.1 * apache2-worker-debugsource-2.4.66-150600.5.55.1 * apache2-prefork-2.4.66-150600.5.55.1 * apache2-prefork-debugsource-2.4.66-150600.5.55.1 * apache2-debugsource-2.4.66-150600.5.55.1 * apache2-worker-debuginfo-2.4.66-150600.5.55.1 * apache2-2.4.66-150600.5.55.1 * apache2-prefork-debuginfo-2.4.66-150600.5.55.1 * apache2-utils-debuginfo-2.4.66-150600.5.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * apache2-manual-2.4.66-150600.5.55.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29167.html * https://www.suse.com/security/cve/CVE-2026-29170.html * https://www.suse.com/security/cve/CVE-2026-34355.html * https://www.suse.com/security/cve/CVE-2026-34356.html * https://www.suse.com/security/cve/CVE-2026-42535.html * https://www.suse.com/security/cve/CVE-2026-42536.html * https://www.suse.com/security/cve/CVE-2026-43951.html * https://www.suse.com/security/cve/CVE-2026-44119.html * https://www.suse.com/security/cve/CVE-2026-44185.html * https://www.suse.com/security/cve/CVE-2026-44186.html * https://www.suse.com/security/cve/CVE-2026-44631.html * https://www.suse.com/security/cve/CVE-2026-48913.html * https://www.suse.com/security/cve/CVE-2026-49975.html * https://bugzilla.suse.com/show_bug.cgi?id=1267503 * https://bugzilla.suse.com/show_bug.cgi?id=1267955 * https://bugzilla.suse.com/show_bug.cgi?id=1267956 * https://bugzilla.suse.com/show_bug.cgi?id=1267962 * https://bugzilla.suse.com/show_bug.cgi?id=1267963 * https://bugzilla.suse.com/show_bug.cgi?id=1267965 * https://bugzilla.suse.com/show_bug.cgi?id=1267969 * https://bugzilla.suse.com/show_bug.cgi?id=1267970 * https://bugzilla.suse.com/show_bug.cgi?id=1267971 * https://bugzilla.suse.com/show_bug.cgi?id=1267972 * https://bugzilla.suse.com/show_bug.cgi?id=1267976 * https://bugzilla.suse.com/show_bug.cgi?id=1267977 * https://bugzilla.suse.com/show_bug.cgi?id=1267978 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:30:04 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:30:04 -0000 Subject: SUSE-RU-2026:22492-1: moderate: Recommended update for kernel-livepatch-MICRO-6-0-RT_Update_25 Message-ID: <178309620402.11236.7287837913806985029@4d746be3175e> # Recommended update for kernel-livepatch-MICRO-6-0-RT_Update_25 Announcement ID: SUSE-RU-2026:22492-1 Release Date: 2026-06-30T23:10:56Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.1 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_25 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 RT kernel update 25. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-499=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-48-rt-1-1.1 * kernel-livepatch-6_4_0-48-rt-debuginfo-1-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_25-debugsource-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:30:25 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:30:25 -0000 Subject: SUSE-SU-2026:22491-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309622527.11236.9677474639844359940@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22491-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-481=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-2-1.1 * kernel-livepatch-6_4_0-46-rt-debuginfo-2-1.1 * kernel-livepatch-6_4_0-46-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:30:38 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:30:38 -0000 Subject: SUSE-SU-2026:22490-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309623895.11236.12395029267247042991@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22490-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-480=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-2-1.2 * kernel-livepatch-6_4_0-45-rt-debuginfo-2-1.2 * kernel-livepatch-6_4_0-45-rt-2-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:30:56 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:30:56 -0000 Subject: SUSE-SU-2026:22489-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309625682.11236.13175618229050957476@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22489-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-479=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-43-rt-debuginfo-2-1.1 * kernel-livepatch-6_4_0-43-rt-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:31:15 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:31:15 -0000 Subject: SUSE-SU-2026:22488-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309627549.11236.2744921983930771126@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22488-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-478=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-42-rt-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-3-1.1 * kernel-livepatch-6_4_0-42-rt-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:31:29 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:31:29 -0000 Subject: SUSE-SU-2026:22487-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309628908.11236.18405010917283788824@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22487-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-477=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-41-rt-5-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-5-1.1 * kernel-livepatch-6_4_0-41-rt-debuginfo-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:31:43 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:31:43 -0000 Subject: SUSE-SU-2026:22486-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309630343.11236.9200677379442855807@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22486-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-476=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-40-rt-6-1.1 * kernel-livepatch-6_4_0-40-rt-debuginfo-6-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:31:59 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:31:59 -0000 Subject: SUSE-SU-2026:22485-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309631919.11236.17076594655003729317@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22485-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-475=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-39-rt-7-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-7-1.1 * kernel-livepatch-6_4_0-39-rt-debuginfo-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:32:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:32:13 -0000 Subject: SUSE-SU-2026:22484-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309633378.11236.329272659941452546@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22484-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-474=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-8-1.1 * kernel-livepatch-6_4_0-38-rt-8-1.1 * kernel-livepatch-6_4_0-38-rt-debuginfo-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:32:28 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:32:28 -0000 Subject: SUSE-SU-2026:22483-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309634857.11236.11084157808177469943@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22483-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-473=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-8-1.1 * kernel-livepatch-6_4_0-37-rt-debuginfo-8-1.1 * kernel-livepatch-6_4_0-37-rt-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:32:43 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:32:43 -0000 Subject: SUSE-SU-2026:22482-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309636300.11236.12614531365817438289@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22482-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-472=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-12-1.1 * kernel-livepatch-6_4_0-36-rt-debuginfo-12-1.1 * kernel-livepatch-6_4_0-36-rt-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:32:57 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:32:57 -0000 Subject: SUSE-SU-2026:22481-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309637752.11236.14179825034381725865@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22481-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-471=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-35-rt-debuginfo-13-1.1 * kernel-livepatch-6_4_0-35-rt-13-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:33:11 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:33:11 -0000 Subject: SUSE-SU-2026:22480-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309639186.11236.12506247801381806525@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22480-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-470=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-34-rt-17-1.1 * kernel-livepatch-6_4_0-34-rt-debuginfo-17-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-17-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:33:27 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:33:27 -0000 Subject: SUSE-SU-2026:22479-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309640707.11236.9162836651118443147@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22479-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-33.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-469=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-33-rt-debuginfo-17-1.2 * kernel-livepatch-6_4_0-33-rt-17-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_9-debugsource-17-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:33:41 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:33:41 -0000 Subject: SUSE-SU-2026:22478-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309642155.11236.6437515524779468429@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22478-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-468=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-31-rt-debuginfo-19-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_8-debugsource-19-1.2 * kernel-livepatch-6_4_0-31-rt-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:33:45 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:33:45 -0000 Subject: SUSE-RU-2026:22477-1: moderate: Recommended update for kernel-livepatch-MICRO-6-0_Update_25 Message-ID: <178309642531.11236.6058118458552578889@4d746be3175e> # Recommended update for kernel-livepatch-MICRO-6-0_Update_25 Announcement ID: SUSE-RU-2026:22477-1 Release Date: 2026-06-30T17:18:14Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.1 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_25 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 25. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-497=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_25-debugsource-1-1.1 * kernel-livepatch-6_4_0-48-default-1-1.1 * kernel-livepatch-6_4_0-48-default-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:33:58 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:33:58 -0000 Subject: SUSE-SU-2026:22476-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309643810.11236.14214251636042804282@4d746be3175e> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22476-1 Release Date: 2026-06-25T11:39:19Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-495=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-46-default-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0_Update_23-debugsource-2-1.1 * kernel-livepatch-6_4_0-46-default-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:34:11 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:34:11 -0000 Subject: SUSE-SU-2026:22475-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309645128.11236.7494376704101750232@4d746be3175e> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22475-1 Release Date: 2026-06-25T11:39:19Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-494=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_22-debugsource-2-1.1 * kernel-livepatch-6_4_0-45-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-45-default-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:34:30 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:34:30 -0000 Subject: SUSE-SU-2026:22474-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309647022.11236.2578855252983873212@4d746be3175e> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22474-1 Release Date: 2026-06-25T11:37:22Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-492=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-2-1.1 * kernel-livepatch-6_4_0-43-default-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:34:43 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:34:43 -0000 Subject: SUSE-SU-2026:22473-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309648313.11236.7641085398540762872@4d746be3175e> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22473-1 Release Date: 2026-06-25T11:36:14Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-493=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-44-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-44-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_21-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:34:58 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:34:58 -0000 Subject: SUSE-SU-2026:22472-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309649809.11236.14645213594543110988@4d746be3175e> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22472-1 Release Date: 2026-06-24T09:48:24Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-487=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-12-1.1 * kernel-livepatch-6_4_0-35-default-debuginfo-12-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:35:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:35:13 -0000 Subject: SUSE-SU-2026:22471-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309651373.11236.7528003126002226744@4d746be3175e> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22471-1 Release Date: 2026-06-24T09:46:55Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-490=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-39-default-7-1.1 * kernel-livepatch-6_4_0-39-default-debuginfo-7-1.1 * kernel-livepatch-MICRO-6-0_Update_16-debugsource-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:35:28 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:35:28 -0000 Subject: SUSE-SU-2026:22470-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309652808.11236.646944328302473637@4d746be3175e> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22470-1 Release Date: 2026-06-24T09:46:55Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-488=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_13-debugsource-10-1.1 * kernel-livepatch-6_4_0-36-default-10-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:35:43 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:35:43 -0000 Subject: SUSE-SU-2026:22469-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309654362.11236.5123004914589990401@4d746be3175e> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22469-1 Release Date: 2026-06-24T09:46:55Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-486=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_11-debugsource-12-1.1 * kernel-livepatch-6_4_0-34-default-12-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:35:58 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:35:58 -0000 Subject: SUSE-SU-2026:22468-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309655858.11236.18375745076670514706@4d746be3175e> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22468-1 Release Date: 2026-06-24T09:46:55Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-485=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-13-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-13-1.1 * kernel-livepatch-6_4_0-32-default-debuginfo-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:36:12 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:36:12 -0000 Subject: SUSE-SU-2026:22467-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309657247.11236.1800360904751421626@4d746be3175e> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22467-1 Release Date: 2026-06-24T09:42:58Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-489=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-38-default-debuginfo-8-1.2 * kernel-livepatch-MICRO-6-0_Update_14-debugsource-8-1.2 * kernel-livepatch-6_4_0-38-default-8-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:36:28 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:36:28 -0000 Subject: SUSE-SU-2026:22466-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309658818.11236.11637835516683320931@4d746be3175e> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22466-1 Release Date: 2026-06-24T09:42:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-491=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_17-debugsource-6-1.1 * kernel-livepatch-6_4_0-40-default-6-1.1 * kernel-livepatch-6_4_0-40-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:36:42 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:36:42 -0000 Subject: SUSE-SU-2026:22465-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309660242.11236.8845461723800441506@4d746be3175e> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22465-1 Release Date: 2026-06-24T09:39:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-484=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_9-debugsource-19-1.2 * kernel-livepatch-6_4_0-31-default-debuginfo-19-1.2 * kernel-livepatch-6_4_0-31-default-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:36:56 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:36:56 -0000 Subject: SUSE-SU-2026:22464-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309661651.11236.4670180126125593626@4d746be3175e> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22464-1 Release Date: 2026-06-24T09:39:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-30.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-483=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-debuginfo-19-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-19-1.2 * kernel-livepatch-6_4_0-30-default-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:37:10 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:37:10 -0000 Subject: SUSE-SU-2026:22463-1: important: Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309663049.11236.5841714383903809248@4d746be3175e> # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22463-1 Release Date: 2026-06-24T09:39:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-29.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-482=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_7-debugsource-20-1.2 * kernel-livepatch-6_4_0-29-default-20-1.2 * kernel-livepatch-6_4_0-29-default-debuginfo-20-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:37:28 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:37:28 -0000 Subject: SUSE-SU-2026:22462-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309664849.11236.7409913253539576969@4d746be3175e> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22462-1 Release Date: 2026-06-24T09:32:59Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-467=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_19-debugsource-3-1.1 * kernel-livepatch-6_4_0-42-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-42-default-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:37:51 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:37:51 -0000 Subject: SUSE-SU-2026:22461-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309667110.11236.10987576110869132855@4d746be3175e> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22461-1 Release Date: 2026-06-24T09:32:01Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-466=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-41-default-5-1.1 * kernel-livepatch-6_4_0-41-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_18-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:39:37 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:39:37 -0000 Subject: SUSE-SU-2026:22460-1: important: Security update for the Linux Kernel Message-ID: <178309677768.11236.17174586478055230754@4d746be3175e> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22460-1 Release Date: 2026-06-30T23:09:03Z Rating: important References: * bsc#1256668 * bsc#1261256 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263123 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264239 * bsc#1264263 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31592 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46197 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 71 vulnerabilities and has two fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-496=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-default-livepatch-6.4.0-48.1 * SUSE Linux Micro 6.1 (noarch) * kernel-macros-6.4.0-48.1 * kernel-devel-6.4.0-48.1 * kernel-source-6.4.0-48.1 * SUSE Linux Micro 6.1 (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-48.1.21.25 * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * kernel-default-debuginfo-6.4.0-48.1 * kernel-default-devel-6.4.0-48.1 * kernel-default-debugsource-6.4.0-48.1 * SUSE Linux Micro 6.1 (ppc64le x86_64) * kernel-default-devel-debuginfo-6.4.0-48.1 * SUSE Linux Micro 6.1 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-48.1 * SUSE Linux Micro 6.1 (x86_64) * kernel-kvmsmall-debuginfo-6.4.0-48.1 * kernel-kvmsmall-debugsource-6.4.0-48.1 * SUSE Linux Micro 6.1 (nosrc x86_64) * kernel-kvmsmall-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:39:44 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:39:44 -0000 Subject: SUSE-SU-2026:22459-1: moderate: Security update for pcr-oracle Message-ID: <178309678488.11236.16751850460151512780@4d746be3175e> # Security update for pcr-oracle Announcement ID: SUSE-SU-2026:22459-1 Release Date: 2026-06-30T23:03:29Z Rating: moderate References: * bsc#1265042 * bsc#1265871 Affected Products: * SUSE Linux Micro 6.1 An update that has two fixes can now be installed. ## Description: This update for pcr-oracle fixes the following issues Update to 0.6.3: Security issue: * integer underflow vulnerability in `parse_sbatlevel_section()` (bsc#1265042). Non security issue: * Lockout Authorization error for libvirt-emulated TPM (bsc#1265871). Changes for pcr-oracle: * Relax TPM self-test attribute checks (bsc#1265871) * Update the SBAT offset boundary check (bsc#1265042) * Advance the comparison event pointer after comparison * Partially support shim extra files * Locate shim extra files * Synthesize shim extra events * Fix various issues from review by Claude Code and introduce adversarial testing ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-606=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 x86_64) * pcr-oracle-debugsource-0.6.3-slfo.1.1_1.1 * pcr-oracle-0.6.3-slfo.1.1_1.1 * pcr-oracle-debuginfo-0.6.3-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265042 * https://bugzilla.suse.com/show_bug.cgi?id=1265871 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:02 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:44:02 -0000 Subject: SUSE-SU-2026:22458-1: important: Security update for the Linux Kernel Message-ID: <178309704296.11236.12141662394597062383@4d746be3175e> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22458-1 Release Date: 2026-06-30T17:41:36Z Rating: important References: * bsc#1248235 * bsc#1255416 * bsc#1256668 * bsc#1258538 * bsc#1260502 * bsc#1260584 * bsc#1261256 * bsc#1261619 * bsc#1261791 * bsc#1262085 * bsc#1262392 * bsc#1262606 * bsc#1262615 * bsc#1262617 * bsc#1262619 * bsc#1262620 * bsc#1262622 * bsc#1262624 * bsc#1262634 * bsc#1262649 * bsc#1262656 * bsc#1262663 * bsc#1262668 * bsc#1262674 * bsc#1262748 * bsc#1262755 * bsc#1262798 * bsc#1262993 * bsc#1263006 * bsc#1263068 * bsc#1263115 * bsc#1263123 * bsc#1263137 * bsc#1263143 * bsc#1263152 * bsc#1263178 * bsc#1263319 * bsc#1263562 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263724 * bsc#1263769 * bsc#1263774 * bsc#1263790 * bsc#1263879 * bsc#1263880 * bsc#1263883 * bsc#1263930 * bsc#1263932 * bsc#1263934 * bsc#1263945 * bsc#1263993 * bsc#1263996 * bsc#1264000 * bsc#1264011 * bsc#1264045 * bsc#1264063 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264093 * bsc#1264116 * bsc#1264124 * bsc#1264137 * bsc#1264145 * bsc#1264184 * bsc#1264239 * bsc#1264243 * bsc#1264245 * bsc#1264255 * bsc#1264263 * bsc#1264266 * bsc#1264300 * bsc#1264409 * bsc#1264430 * bsc#1264437 * bsc#1264444 * bsc#1264449 * bsc#1264470 * bsc#1264476 * bsc#1264484 * bsc#1264549 * bsc#1264551 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264669 * bsc#1264671 * bsc#1264672 * bsc#1264716 * bsc#1264719 * bsc#1264720 * bsc#1264722 * bsc#1264726 * bsc#1264741 * bsc#1264763 * bsc#1264765 * bsc#1264805 * bsc#1264989 * bsc#1265020 * bsc#1265044 * bsc#1265073 * bsc#1265103 * bsc#1265110 * bsc#1265128 * bsc#1265143 * bsc#1265170 * bsc#1265240 * bsc#1265579 * bsc#1265628 * bsc#1265928 * bsc#1265960 * bsc#1266001 * bsc#1266009 * bsc#1266214 * bsc#1266238 * bsc#1266290 * bsc#1266307 * bsc#1266390 * bsc#1266394 * bsc#1266395 * bsc#1266397 * bsc#1266400 * bsc#1266402 * bsc#1266414 * bsc#1266452 * bsc#1266696 * bsc#1266697 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266711 * bsc#1266720 * bsc#1266759 * bsc#1266765 * bsc#1266767 * bsc#1266810 * bsc#1266816 * bsc#1266826 * bsc#1266827 * bsc#1266878 * bsc#1266889 * bsc#1266895 * bsc#1266901 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266927 * bsc#1266933 * bsc#1266969 * bsc#1266972 * bsc#1267205 * bsc#1267208 * bsc#1267214 * bsc#1267218 * bsc#1267220 * bsc#1267222 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267531 * bsc#1267621 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267652 * bsc#1267654 * bsc#1267663 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267726 * bsc#1267732 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-38549 * CVE-2025-68324 * CVE-2025-68822 * CVE-2026-23303 * CVE-2026-23327 * CVE-2026-23359 * CVE-2026-23438 * CVE-2026-23444 * CVE-2026-31396 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31446 * CVE-2026-31448 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31454 * CVE-2026-31455 * CVE-2026-31464 * CVE-2026-31469 * CVE-2026-31473 * CVE-2026-31480 * CVE-2026-31492 * CVE-2026-31493 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-3150 * CVE-2026-31500 * CVE-2026-31516 * CVE-2026-31518 * CVE-2026-31546 * CVE-2026-31555 * CVE-2026-31590 * CVE-2026-31592 * CVE-2026-31596 * CVE-2026-31613 * CVE-2026-31614 * CVE-2026-31629 * CVE-2026-31655 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31671 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31678 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31703 * CVE-2026-31752 * CVE-2026-31758 * CVE-2026-31759 * CVE-2026-31767 * CVE-2026-31771 * CVE-2026-43013 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43026 * CVE-2026-43028 * CVE-2026-43030 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43040 * CVE-2026-43049 * CVE-2026-43052 * CVE-2026-43053 * CVE-2026-43054 * CVE-2026-43059 * CVE-2026-43065 * CVE-2026-43066 * CVE-2026-43068 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43109 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43206 * CVE-2026-43234 * CVE-2026-43239 * CVE-2026-43249 * CVE-2026-43252 * CVE-2026-43261 * CVE-2026-43284 * CVE-2026-43296 * CVE-2026-43325 * CVE-2026-43333 * CVE-2026-43338 * CVE-2026-43339 * CVE-2026-43341 * CVE-2026-43345 * CVE-2026-43359 * CVE-2026-43360 * CVE-2026-43361 * CVE-2026-43362 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43411 * CVE-2026-43413 * CVE-2026-43414 * CVE-2026-43455 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43483 * CVE-2026-43491 * CVE-2026-43499 * CVE-2026-43501 * CVE-2026-43503 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45842 * CVE-2026-45843 * CVE-2026-45846 * CVE-2026-45852 * CVE-2026-45856 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45878 * CVE-2026-45886 * CVE-2026-45894 * CVE-2026-45910 * CVE-2026-45932 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45970 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45984 * CVE-2026-46004 * CVE-2026-46005 * CVE-2026-46021 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46043 * CVE-2026-46079 * CVE-2026-46083 * CVE-2026-46090 * CVE-2026-46094 * CVE-2026-46101 * CVE-2026-46110 * CVE-2026-46111 * CVE-2026-46113 * CVE-2026-46114 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46157 * CVE-2026-46159 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46176 * CVE-2026-46181 * CVE-2026-46197 * CVE-2026-46209 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-38549 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-38549 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-38549 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68324 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23359 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23359 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23359 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31396 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31396 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31396 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31446 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-31448 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31448 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31454 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31455 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31455 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31464 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31464 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-31464 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31473 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31480 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31480 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31480 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31493 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31493 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31493 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3150 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3150 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-3150 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31516 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31518 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31518 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31518 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31613 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31613 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31613 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-31614 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31614 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31614 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31655 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31655 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31655 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31671 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31671 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-31671 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31678 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31703 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31703 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31703 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31767 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31767 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31767 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43013 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43013 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43030 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43030 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43052 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43052 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43052 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43065 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-43065 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-43065 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43066 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43068 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43068 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43068 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43234 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43234 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43249 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43249 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43249 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43252 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43325 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43333 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43333 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43338 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43341 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43359 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43359 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43359 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43361 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43361 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43361 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43362 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-43362 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-43362 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43411 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43411 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43413 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43455 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43499 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43499 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43499 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45842 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45842 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45842 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45843 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45843 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45843 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-45846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45846 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45846 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45852 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45852 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45856 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45856 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45856 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45878 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45878 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45886 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45910 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45910 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45910 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45932 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45984 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45984 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46004 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46021 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46043 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46043 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46043 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46094 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46094 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46094 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46114 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46114 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46114 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46157 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46157 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46157 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46159 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46176 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46181 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 169 vulnerabilities and has 11 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-38549: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (bsc#1248235). * CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). * CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() * CVE-2026-23359: bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584). * CVE-2026-23438: net: mvpp2: guard flow control update with global_tx_fc in buffer switching (bsc#1261619). * CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307). * CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619). * CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624). * CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615). * CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663). * CVE-2026-31480: tracing: Fix potential deadlock in cpu hotplug with osnoise (bsc#1262634). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31493: RDMA/efa: Fix use of completion ctx after free (bsc#1262668). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755). * CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606). * CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769). * CVE-2026-31614: smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). * CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31767: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (bsc#1264124). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43013: net/mlx5: lag: Check for LAG device before creating debugfs (bsc#1264011). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43054: scsi: target: tcm_loop: Drain commands in target_reset handler (bsc#1264063). * CVE-2026-43059: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (bsc#1264184). * CVE-2026-43065: ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243). * CVE-2026-43066: ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245). * CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). * CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43249: 9p/xen: protect xen_9pfs_front_free against concurrent calls (bsc#1264476). * CVE-2026-43252: mptcp: pm: in-kernel: always set ID as avail when rm endp (bsc#1264300). * CVE-2026-43261: arm64: Add support for TSV110 Spectre-BHB mitigation (bsc#1264430). * CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky (bsc#1264805). * CVE-2026-43325: wifi: iwlwifi: mvm: don't send a 6E related command when not supported (bsc#1265110). * CVE-2026-43333: bpf: reject direct access to nullable PTR_TO_BUF pointers (bsc#1264726). * CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill (bsc#1265044). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719). * CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision (bsc#1264720). * CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722). * CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() (bsc#1264672). * CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671). * CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669). * CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (bsc#1265240). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). * CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395). * CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (bsc#1266394). * CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). * CVE-2026-45856: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (bsc#1266720). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767). * CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889). * CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214). * CVE-2026-46004: ALSA: caiaq: Handle probe errors properly (bsc#1267222). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696). * CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531). * CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of- bounds access (bsc#1266927). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46110: net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (bsc#1266759). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46113: KVM: x86/mmu: Add helper to convert SPTE value to its shadow page (bsc#1266969). * CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726). * CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (bsc#1266816). * CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: asihpi: Fix potential OOB array access at reading cache (stable- fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: sc6000: Keep the programmed board state in card-private data (git- fixes). * ALSA: sc6000: Use standard print API (stable-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: ua101: Reject too-short USB descriptors (git-fixes). * ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio (stable-fixes). * ASoC: SOF: Intel: hda-dai: remove dspless special case (stable-fixes). * ASoC: SOF: Intel: hda: Fix NULL pointer dereference (stable-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). * ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). * ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git- fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git- fixes). * Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git- fixes). * Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git- fixes). * Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). * Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). * Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). * Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git- fixes). * Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git- fixes). * Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). * Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). * Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). * Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). * Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). * Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). * Bluetooth: bnep: reject short frames before parsing (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: Allow firmware re-download when version matches (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git- fixes). * Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git- fixes). * Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). * Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git- fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * HID: quirks: really enable the intended work around for appledisplay (git- fixes). * HID: uclogic: Fix regression of input name assignment (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * Improve compatibility with awk 2.4.0 (bsc#1266214). * Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git- fixes). * Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). * Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). * Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git- fixes). * Input: xpad - fix out-of-bounds access for Share button (git-fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: X86: Fix array_index_nospec protection in __pv_send_ipi (git-fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git- fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * RDMA/efa: Check stored completion CTX command ID with received one (git- fixes) * RDMA/efa: Extend admin timeout error print (git-fixes) * RDMA/efa: Fix possible deadlock (git-fixes) * RDMA/efa: Improve admin completion context state machine (git-fixes) * RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). * wicked test: Added missing locking in backport (bsc#1267732). * USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git- fixes). * USB: serial: belkin_sa: validate interrupt status length (git-fixes). * USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git- fixes). * USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). * USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). * USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git- fixes). * USB: serial: safe_serial: fix memory corruption with small endpoint (git- fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) * arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) * auxdisplay: line-display: fix OOB read on zero-length message_store() (git- fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: bla: fix report_work leak on backbone_gw purge (git-fixes). * batman-adv: clear current gateway during teardown (git-fixes). * batman-adv: dat: handle forward allocation error (git-fixes). * batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes). * batman-adv: fix fragment reassembly length accounting (git-fixes). * batman-adv: fix tp_meter counter underflow during shutdown (git-fixes). * batman-adv: frag: disallow unicast fragment in fragment (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid use of uninit sender vars (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * batman-adv: tt: fix negative last_changeset_len (git-fixes). * batman-adv: tt: fix negative tt_buff_len (git-fixes). * bcache: fix uninitialized closure object (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). * comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git- fixes). * drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git- fixes). * drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). * drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). * drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). * drm/amd/display: Validate GPIO pin LUT table size before iterating (stable- fixes). * drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). * drm/amd/pm/si: Disregard vblank time when no displays are connected (git- fixes). * drm/amdgpu/uvd3.1: Do not validate the firmware when already validated (git- fixes). * drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). * drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: fix spelling typos (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git- fixes). * drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). * drm/bridge: megachips: remove bridge when irq request fails (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/hyperv: validate VMBus packet size in receive callback (git-fixes). * drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update() (stable-fixes). * drm/i915: Fix potential UAF in TTM object purge (git-fixes). * drm/i915: Loop over all active pipes in intel_mbus_dbox_update (stable- fixes). * drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dsi: do not dump registers past the mapped region (git-fixes). * drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). * efi: Allocate runtime workqueue before ACPI init (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). * firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). * hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). * hwmon: (pmbus/adm1266) do not clobber GPIO bits before PDIO read in get_multiple (git-fixes). * hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). * hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git- fixes). * hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git- fixes). * hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). * hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). * hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). * hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). * hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). * iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git- fixes). * iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). * iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). * iio: dac: ad5686: fix input raw value check (git-fixes). * iio: dac: max5821: fix return value check in powerdown sync (git-fixes). * iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). * iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). * iio: light: cm3323: fix reg_conf not being initialized correctly (git- fixes). * iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git- fixes). * iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). * iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). * kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mmc: core: Fix host controller programming for fixed driver type (git- fixes). * mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). * mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git- fixes). * mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). * mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: gro: do not merge zcopy skbs (git-fixes). * net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). * net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). * net: mana: Skip redundant detach on already-detached port (git-fixes). * net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). * net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). * net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). * net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). * net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (git-fixes). * phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes). * platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). * platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). * r8152: fix incorrect register write to USB_UPHY_XTAL (git-fixes). * rpm/check-for-config-changes: ignore Rust-related configs (bsc#1258538). * rpm/mkspec: Conditionally set Rust BuildReqs (bsc#1258538). * rpm: Add BuildRequires for Rust enablement (bsc#1258538). * s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1263068). * s390/entry: Scrub r12 register on kernel entry (bsc#1263068). * s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1263068). * sched/rt: Skip currently executing CPU in rto_next_cpu() (bsc#1262649). * security/keys: fix missed RCU read section on lookup (stable-fixes). * serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git- fixes). * serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * smb: client: correctly handle ErrorContextData as a flexible array (git- fixes) * smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). * spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). * spi: st-ssc4: switch to use modern name (stable-fixes). * spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * string: add mem_is_zero() helper to check if memory area is all zeros (stable-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). * thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git- fixes). * tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). * tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). * usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). * usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). * usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). * usb: dwc2: Fix use after free in debug code (git-fixes). * usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). * usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). * usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). * usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). * usb: gadget: net2280: Fix double free in probe error path (git-fixes). * usb: usbtmc: check URB actual_length for interrupt-IN notifications (git- fixes). * usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git- fixes). * usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath10k: skip WMI and beacon transmission when device is wedged (git- fixes). * wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). * wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). * wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). * wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). * wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). * wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git- fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: nl80211: reject oversized EMA RNR lists (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-498=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * kernel-source-rt-6.4.0-48.1 * kernel-devel-rt-6.4.0-48.1 * SUSE Linux Micro 6.1 (aarch64 x86_64) * kernel-rt-debugsource-6.4.0-48.1 * kernel-rt-debuginfo-6.4.0-48.1 * kernel-rt-devel-6.4.0-48.1 * SUSE Linux Micro 6.1 (x86_64) * kernel-rt-devel-debuginfo-6.4.0-48.1 * kernel-rt-livepatch-6.4.0-48.1 * SUSE Linux Micro 6.1 (aarch64 nosrc x86_64) * kernel-rt-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-38549.html * https://www.suse.com/security/cve/CVE-2025-68324.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-23303.html * https://www.suse.com/security/cve/CVE-2026-23327.html * https://www.suse.com/security/cve/CVE-2026-23359.html * https://www.suse.com/security/cve/CVE-2026-23438.html * https://www.suse.com/security/cve/CVE-2026-23444.html * https://www.suse.com/security/cve/CVE-2026-31396.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31446.html * https://www.suse.com/security/cve/CVE-2026-31448.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31454.html * https://www.suse.com/security/cve/CVE-2026-31455.html * https://www.suse.com/security/cve/CVE-2026-31464.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31473.html * https://www.suse.com/security/cve/CVE-2026-31480.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31493.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-3150.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31516.html * https://www.suse.com/security/cve/CVE-2026-31518.html * https://www.suse.com/security/cve/CVE-2026-31546.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31590.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31613.html * https://www.suse.com/security/cve/CVE-2026-31614.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31655.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31671.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31678.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31703.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31767.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43013.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43026.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43030.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43040.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43052.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43054.html * https://www.suse.com/security/cve/CVE-2026-43059.html * https://www.suse.com/security/cve/CVE-2026-43065.html * https://www.suse.com/security/cve/CVE-2026-43066.html * https://www.suse.com/security/cve/CVE-2026-43068.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-43234.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43249.html * https://www.suse.com/security/cve/CVE-2026-43252.html * https://www.suse.com/security/cve/CVE-2026-43261.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43296.html * https://www.suse.com/security/cve/CVE-2026-43325.html * https://www.suse.com/security/cve/CVE-2026-43333.html * https://www.suse.com/security/cve/CVE-2026-43338.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43341.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43359.html * https://www.suse.com/security/cve/CVE-2026-43360.html * https://www.suse.com/security/cve/CVE-2026-43361.html * https://www.suse.com/security/cve/CVE-2026-43362.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43411.html * https://www.suse.com/security/cve/CVE-2026-43413.html * https://www.suse.com/security/cve/CVE-2026-43414.html * https://www.suse.com/security/cve/CVE-2026-43455.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43483.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43499.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45842.html * https://www.suse.com/security/cve/CVE-2026-45843.html * https://www.suse.com/security/cve/CVE-2026-45846.html * https://www.suse.com/security/cve/CVE-2026-45852.html * https://www.suse.com/security/cve/CVE-2026-45856.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45878.html * https://www.suse.com/security/cve/CVE-2026-45886.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45910.html * https://www.suse.com/security/cve/CVE-2026-45932.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45984.html * https://www.suse.com/security/cve/CVE-2026-46004.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46021.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46043.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46083.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46094.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46110.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-46114.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46157.html * https://www.suse.com/security/cve/CVE-2026-46159.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46176.html * https://www.suse.com/security/cve/CVE-2026-46181.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46209.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1248235 * https://bugzilla.suse.com/show_bug.cgi?id=1255416 * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1260502 * https://bugzilla.suse.com/show_bug.cgi?id=1260584 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261619 * https://bugzilla.suse.com/show_bug.cgi?id=1261791 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262606 * https://bugzilla.suse.com/show_bug.cgi?id=1262615 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262619 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262622 * https://bugzilla.suse.com/show_bug.cgi?id=1262624 * https://bugzilla.suse.com/show_bug.cgi?id=1262634 * https://bugzilla.suse.com/show_bug.cgi?id=1262649 * https://bugzilla.suse.com/show_bug.cgi?id=1262656 * https://bugzilla.suse.com/show_bug.cgi?id=1262663 * https://bugzilla.suse.com/show_bug.cgi?id=1262668 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262755 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263006 * https://bugzilla.suse.com/show_bug.cgi?id=1263068 * https://bugzilla.suse.com/show_bug.cgi?id=1263115 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263152 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263562 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263724 * https://bugzilla.suse.com/show_bug.cgi?id=1263769 * https://bugzilla.suse.com/show_bug.cgi?id=1263774 * https://bugzilla.suse.com/show_bug.cgi?id=1263790 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263883 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263932 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263945 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264000 * https://bugzilla.suse.com/show_bug.cgi?id=1264011 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264063 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264093 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264124 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264184 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264243 * https://bugzilla.suse.com/show_bug.cgi?id=1264245 * https://bugzilla.suse.com/show_bug.cgi?id=1264255 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264300 * https://bugzilla.suse.com/show_bug.cgi?id=1264409 * https://bugzilla.suse.com/show_bug.cgi?id=1264430 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264476 * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264551 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264669 * https://bugzilla.suse.com/show_bug.cgi?id=1264671 * https://bugzilla.suse.com/show_bug.cgi?id=1264672 * https://bugzilla.suse.com/show_bug.cgi?id=1264716 * https://bugzilla.suse.com/show_bug.cgi?id=1264719 * https://bugzilla.suse.com/show_bug.cgi?id=1264720 * https://bugzilla.suse.com/show_bug.cgi?id=1264722 * https://bugzilla.suse.com/show_bug.cgi?id=1264726 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264765 * https://bugzilla.suse.com/show_bug.cgi?id=1264805 * https://bugzilla.suse.com/show_bug.cgi?id=1264989 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265044 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265110 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265170 * https://bugzilla.suse.com/show_bug.cgi?id=1265240 * https://bugzilla.suse.com/show_bug.cgi?id=1265579 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1265960 * https://bugzilla.suse.com/show_bug.cgi?id=1266001 * https://bugzilla.suse.com/show_bug.cgi?id=1266009 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266238 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266307 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266394 * https://bugzilla.suse.com/show_bug.cgi?id=1266395 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266400 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266414 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266696 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266711 * https://bugzilla.suse.com/show_bug.cgi?id=1266720 * https://bugzilla.suse.com/show_bug.cgi?id=1266759 * https://bugzilla.suse.com/show_bug.cgi?id=1266765 * https://bugzilla.suse.com/show_bug.cgi?id=1266767 * https://bugzilla.suse.com/show_bug.cgi?id=1266810 * https://bugzilla.suse.com/show_bug.cgi?id=1266816 * https://bugzilla.suse.com/show_bug.cgi?id=1266826 * https://bugzilla.suse.com/show_bug.cgi?id=1266827 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266889 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266901 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266927 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1266969 * https://bugzilla.suse.com/show_bug.cgi?id=1266972 * https://bugzilla.suse.com/show_bug.cgi?id=1267205 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267214 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267220 * https://bugzilla.suse.com/show_bug.cgi?id=1267222 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267652 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267663 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267726 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:10 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:44:10 -0000 Subject: SUSE-RU-2026:22457-1: important: Recommended update for cloud-init Message-ID: <178309705010.11236.8444633996281398976@4d746be3175e> # Recommended update for cloud-init Announcement ID: SUSE-RU-2026:22457-1 Release Date: 2026-06-30T11:51:48Z Rating: important References: * bsc#1267422 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for cloud-init fixes the following issues: * Fix: Cloud init failures observed [ thread::1hcnhpN0LIaV02LMM-IqGis:: ] (bsc#1267422) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-608=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * cloud-init-25.1.3-slfo.1.1_3.1 * cloud-init-config-suse-25.1.3-slfo.1.1_3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267422 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:19 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:44:19 -0000 Subject: SUSE-SU-2026:22456-1: important: Security update for docker Message-ID: <178309705958.11236.3931206818743982532@4d746be3175e> # Security update for docker Announcement ID: SUSE-SU-2026:22456-1 Release Date: 2026-06-30T11:42:45Z Rating: important References: * bsc#1262346 * bsc#1265782 * bsc#1266625 * bsc#1267827 Cross-References: * CVE-2026-33814 * CVE-2026-39821 * CVE-2026-39984 * CVE-2026-41567 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39984 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39984 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39984 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41567 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). * CVE-2026-39984: github.com/sigstore/timestamp-authority/v2/pkg/verification: improper certificate validation can be used to bypass some authorization controls (bsc#1262346). * CVE-2026-41567: arbitrary code execution with full daemon privileges when a user uploads a compressed archive into that container (bsc#1267827). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-605=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * docker-debuginfo-29.4.0_ce-slfo.1.1_10.1 * docker-29.4.0_ce-slfo.1.1_10.1 * docker-buildx-0.33.0-slfo.1.1_10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39984.html * https://www.suse.com/security/cve/CVE-2026-41567.html * https://bugzilla.suse.com/show_bug.cgi?id=1262346 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 * https://bugzilla.suse.com/show_bug.cgi?id=1267827 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:26 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:44:26 -0000 Subject: SUSE-SU-2026:22455-1: important: Security update for helm Message-ID: <178309706666.11236.10100395582614848014@4d746be3175e> # Security update for helm Announcement ID: SUSE-SU-2026:22455-1 Release Date: 2026-06-30T11:41:55Z Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: * update to 3.21.2: * chore(deps): bump the k8s-io group with 2 updates 1259634 (dependabot[bot]) * fixes b52e276 (Matheus Pimenta) * chore(deps): bump the k8s-io group across 1 directory with 2 updates 3342dbf (dependabot[bot]) * Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 * chore(deps): bump github.com/distribution/distribution/v3 * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 * chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 * update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-603=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-slfo.1.1_1.1 * helm-3.21.2-slfo.1.1_1.1 * SUSE Linux Micro 6.1 (noarch) * helm-bash-completion-3.21.2-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:32 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:44:32 -0000 Subject: SUSE-SU-2026:22454-1: important: Security update for dnsmasq Message-ID: <178309707234.11236.65192959675848600@4d746be3175e> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:22454-1 Release Date: 2026-06-30T11:27:04Z Rating: important References: * bsc#1268764 Cross-References: * CVE-2026-12725 * CVE-2026-2291 * CVE-2026-6507 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2291 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2291 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2291 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6507 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6507 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues Update to 2.93: * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-604=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * dnsmasq-2.93-slfo.1.1_1.1 * dnsmasq-debuginfo-2.93-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-2291.html * https://www.suse.com/security/cve/CVE-2026-6507.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:39 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:44:39 -0000 Subject: SUSE-SU-2026:22453-1: moderate: Security update for glibc Message-ID: <178309707914.11236.12825264744371798580@4d746be3175e> # Security update for glibc Announcement ID: SUSE-SU-2026:22453-1 Release Date: 2026-06-30T09:54:13Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-601=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * glibc-locale-base-2.38-slfo.1.1_9.1 * glibc-devel-2.38-slfo.1.1_9.1 * glibc-2.38-slfo.1.1_9.1 * glibc-debuginfo-2.38-slfo.1.1_9.1 * glibc-debugsource-2.38-slfo.1.1_9.1 * glibc-locale-base-debuginfo-2.38-slfo.1.1_9.1 * glibc-locale-2.38-slfo.1.1_9.1 * glibc-devel-debuginfo-2.38-slfo.1.1_9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:44 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:44:44 -0000 Subject: SUSE-SU-2026:22452-1: moderate: Security update for libslirp Message-ID: <178309708499.11236.8916819984903339600@4d746be3175e> # Security update for libslirp Announcement ID: SUSE-SU-2026:22452-1 Release Date: 2026-06-30T09:31:12Z Rating: moderate References: * bsc#1268903 Cross-References: * CVE-2026-9539 CVSS scores: * CVE-2026-9539 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9539 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libslirp fixes the following issue * CVE-2026-9539: TCP URG out of bounds heap read information leak (bsc#1268903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-600=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libslirp0-debuginfo-4.8.0+2-slfo.1.1_2.1 * libslirp-debugsource-4.8.0+2-slfo.1.1_2.1 * libslirp0-4.8.0+2-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9539.html * https://bugzilla.suse.com/show_bug.cgi?id=1268903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:51 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:44:51 -0000 Subject: SUSE-SU-2026:22451-1: important: Security update for podman Message-ID: <178309709179.11236.13294631122394789208@4d746be3175e> # Security update for podman Announcement ID: SUSE-SU-2026:22451-1 Release Date: 2026-06-30T09:31:12Z Rating: important References: * bsc#1262856 * bsc#1266125 Cross-References: * CVE-2025-22869 * CVE-2025-47913 * CVE-2025-47914 * CVE-2025-52881 * CVE-2025-6032 * CVE-2025-9566 * CVE-2026-34986 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47914 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47914 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47914 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-52881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-52881 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-52881 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-52881 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2025-6032 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-6032 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-6032 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-9566 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-9566 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-9566 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for podman fixes the following issues * CVE-2026-34986: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262856). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266125). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266125). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266125). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266125). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-598=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * podman-remote-debuginfo-5.4.2-slfo.1.1_5.1 * podmansh-5.4.2-slfo.1.1_5.1 * podman-debuginfo-5.4.2-slfo.1.1_5.1 * podman-5.4.2-slfo.1.1_5.1 * podman-remote-5.4.2-slfo.1.1_5.1 * SUSE Linux Micro 6.1 (noarch) * podman-docker-5.4.2-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2025-47913.html * https://www.suse.com/security/cve/CVE-2025-47914.html * https://www.suse.com/security/cve/CVE-2025-52881.html * https://www.suse.com/security/cve/CVE-2025-6032.html * https://www.suse.com/security/cve/CVE-2025-9566.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1262856 * https://bugzilla.suse.com/show_bug.cgi?id=1266125 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:57 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:44:57 -0000 Subject: SUSE-SU-2026:22450-1: important: Security update for krb5 Message-ID: <178309709740.11236.15614988444291411854@4d746be3175e> # Security update for krb5 Announcement ID: SUSE-SU-2026:22450-1 Release Date: 2026-06-30T09:20:36Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-602=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * krb5-client-debuginfo-1.21.3-slfo.1.1_5.1 * krb5-client-1.21.3-slfo.1.1_5.1 * krb5-debugsource-1.21.3-slfo.1.1_5.1 * krb5-1.21.3-slfo.1.1_5.1 * krb5-debuginfo-1.21.3-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:03 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:45:03 -0000 Subject: SUSE-SU-2026:22449-1: moderate: Security update for openssl-3 Message-ID: <178309710302.11236.3886848415895414869@4d746be3175e> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22449-1 Release Date: 2026-06-30T08:42:14Z Rating: moderate References: * bsc#1266350 Cross-References: * CVE-2026-42767 CVSS scores: * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-3 fixes the following issue * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-599=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libopenssl-3-devel-3.1.4-slfo.1.1_11.1 * openssl-3-3.1.4-slfo.1.1_11.1 * libopenssl3-debuginfo-3.1.4-slfo.1.1_11.1 * openssl-3-debugsource-3.1.4-slfo.1.1_11.1 * libopenssl3-3.1.4-slfo.1.1_11.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-slfo.1.1_11.1 * openssl-3-debuginfo-3.1.4-slfo.1.1_11.1 * libopenssl-3-fips-provider-3.1.4-slfo.1.1_11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:10 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:45:10 -0000 Subject: SUSE-RU-2026:22448-1: moderate: Recommended update for cloud-regionsrv-client Message-ID: <178309711070.11236.411539118912440331@4d746be3175e> # Recommended update for cloud-regionsrv-client Announcement ID: SUSE-RU-2026:22448-1 Release Date: 2026-06-30T07:09:50Z Rating: moderate References: * bsc#1265930 * bsc#1267739 Affected Products: * SUSE Linux Micro 6.1 An update that has two fixes can now be installed. ## Description: This update for cloud-regionsrv-client fixes the following issues: * Update to version 11.0.3: * Write instance data cache file after cleaning the cache when the update server fails (bsc#1265930) * Create the cache directory when populating the cache (bsc#1267739) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-597=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * cloud-regionsrv-client-plugin-gce-2.0.0-slfo.1.1_8.1 * cloud-regionsrv-client-plugin-ec2-2.0.0-slfo.1.1_8.1 * cloud-regionsrv-client-generic-config-1.0.0-slfo.1.1_8.1 * cloud-regionsrv-client-plugin-azure-3.0.0-slfo.1.1_8.1 * cloud-regionsrv-client-11.0.3-slfo.1.1_8.1 * cloud-regionsrv-client-license-watcher-1.0.0-slfo.1.1_8.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265930 * https://bugzilla.suse.com/show_bug.cgi?id=1267739 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:16 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:45:16 -0000 Subject: SUSE-SU-2026:22447-1: important: Security update for libnfs Message-ID: <178309711643.11236.4078721056198539411@4d746be3175e> # Security update for libnfs Announcement ID: SUSE-SU-2026:22447-1 Release Date: 2026-06-29T10:14:53Z Rating: important References: * bsc#1268135 Cross-References: * CVE-2026-53689 CVSS scores: * CVE-2026-53689 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-53689 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libnfs fixes the following issue * CVE-2026-53689: integer overflow during a connection to a crafted NFS server (bsc#1268135). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-595=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libnfs14-5.0.2-slfo.1.1_2.1 * libnfs14-debuginfo-5.0.2-slfo.1.1_2.1 * libnfs-debugsource-5.0.2-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53689.html * https://bugzilla.suse.com/show_bug.cgi?id=1268135 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:24 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:45:24 -0000 Subject: SUSE-SU-2026:22446-1: important: Security update for dracut Message-ID: <178309712422.11236.1439909783417617889@4d746be3175e> # Security update for dracut Announcement ID: SUSE-SU-2026:22446-1 Release Date: 2026-06-29T09:20:34Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.643.g1f1d880: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-596=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * dracut-debuginfo-059+suse.643.g1f1d880-slfo.1.1_1.1 * dracut-fips-059+suse.643.g1f1d880-slfo.1.1_1.1 * dracut-059+suse.643.g1f1d880-slfo.1.1_1.1 * dracut-debugsource-059+suse.643.g1f1d880-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:32 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:45:32 -0000 Subject: SUSE-SU-2026:22445-1: important: Security update for python-tornado6 Message-ID: <178309713232.11236.9513616800060655341@4d746be3175e> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:22445-1 Release Date: 2026-06-26T09:54:16Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-593=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.4-slfo.1.1_5.1 * python311-tornado6-6.4-slfo.1.1_5.1 * python-tornado6-debugsource-6.4-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:42 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:45:42 -0000 Subject: SUSE-RU-2026:22444-1: moderate: Recommended update for suseconnect-ng Message-ID: <178309714228.11236.265022972426951341@4d746be3175e> # Recommended update for suseconnect-ng Announcement ID: SUSE-RU-2026:22444-1 Release Date: 2026-06-25T14:53:02Z Rating: moderate References: * bsc#1197231 * bsc#1263772 * bsc#1265410 * bsc#1268017 Affected Products: * SUSE Linux Micro 6.1 An update that has four fixes can now be installed. ## Description: This update for suseconnect-ng fixes the following issues: * Update version to 1.22.1: * library: Allow clients to disable the token handling mechanism (jsc#SCC-801) * Ensure updated system certs are included when creating HTTP client connections (bsc#1268017, jsc#SCC-804) * Update version to 1.22: * InstallReleasePackage should consider zypperFilesystemRoot (jsc#SCC-630). * Restore exit code 71 handling when attempting keepalive and not registered (bsc#1263772) * Add collector support for gathering RKE2 and K3s kubernetes provider info if enabled on a system (jsc#TEL-317) * Add email address validation to SUSEConnect -e/--email option. (bsc#1197231) * Add collector support for detecting if system is running pacemaker (jsc#SCC-693) * Avoid double slash at start of request URL path component. (jsc#SCC-775) * Use product identifier when finding product packages during migrations. (jsc#SCC=758, bsc#1265410) * Add opt in/out support for collectors (jsc#TEL-312) * Update config parser for suseconnect to be YAML based (jsc#SCC-730) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-592=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * suseconnect-ng-1.22.1-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1197231 * https://bugzilla.suse.com/show_bug.cgi?id=1263772 * https://bugzilla.suse.com/show_bug.cgi?id=1265410 * https://bugzilla.suse.com/show_bug.cgi?id=1268017 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:50 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:45:50 -0000 Subject: SUSE-SU-2026:22443-1: important: Security update for containerd Message-ID: <178309715075.11236.10589270266652922151@4d746be3175e> # Security update for containerd Announcement ID: SUSE-SU-2026:22443-1 Release Date: 2026-06-25T08:46:46Z Rating: important References: * bsc#1262948 * bsc#1265794 * bsc#1266640 Cross-References: * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for containerd fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265794). * CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262948). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-591=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1262948 * https://bugzilla.suse.com/show_bug.cgi?id=1265794 * https://bugzilla.suse.com/show_bug.cgi?id=1266640 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:46:01 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:46:01 -0000 Subject: SUSE-SU-2026:22442-1: important: Security update for google-guest-agent Message-ID: <178309716192.11236.1397400961787446569@4d746be3175e> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:22442-1 Release Date: 2026-06-24T10:44:18Z Rating: important References: * bsc#1243254 * bsc#1243505 * bsc#1260264 * bsc#1266171 * bsc#1266603 Cross-References: * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266171). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266171). Changes: * Update to version 20260529.00 * Dependency updates (#616) * from version 20260522.00 * Fix improper umask calculation on socket creation (#614) * from version 20260520.01 * Update OWNERS (#609) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) (bsc#1260264, CVE-2026-33186) * Update to version 20250506.01 (bsc#1243254, bsc#1243505) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-590=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * google-guest-agent-debuginfo-20260529.00-slfo.1.1_1.1 * google-guest-agent-20260529.00-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1243254 * https://bugzilla.suse.com/show_bug.cgi?id=1243505 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1266171 * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:46:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:46:07 -0000 Subject: SUSE-SU-2026:22441-1: important: Security update for sg3_utils Message-ID: <178309716730.11236.7784707919758720431@4d746be3175e> # Security update for sg3_utils Announcement ID: SUSE-SU-2026:22441-1 Release Date: 2026-06-24T08:19:38Z Rating: important References: * bsc#1267823 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for sg3_utils fixes the following issue * sg_inq: --export output conformance for SCSI name string and ATA fields (bsc#1267823). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-589=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libsgutils2-1_48-2-debuginfo-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 * sg3_utils-debuginfo-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 * sg3_utils-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 * sg3_utils-debugsource-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 * libsgutils2-1_48-2-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267823 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:47:56 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:47:56 -0000 Subject: SUSE-SU-2026:22440-1: important: Security update for the Linux Kernel Message-ID: <178309727677.11236.10305259893219376669@4d746be3175e> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22440-1 Release Date: 2026-06-30T23:09:03Z Rating: important References: * bsc#1256668 * bsc#1261256 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263123 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264239 * bsc#1264263 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31592 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46197 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 * SUSE Linux Micro Extras 6.1 An update that solves 71 vulnerabilities and has two fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-Extras-6.1-kernel-496=1 ## Package List: * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-48.1 * kernel-obs-build-debugsource-6.4.0-48.1 * kernel-syms-6.4.0-48.1 * SUSE Linux Micro Extras 6.1 (aarch64) * kernel-64kb-debugsource-6.4.0-48.1 * kernel-64kb-devel-6.4.0-48.1 * SUSE Linux Micro Extras 6.1 (nosrc) * kernel-64kb-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:08 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:48:08 -0000 Subject: SUSE-SU-2026:2747-1: important: Security update for libarchive Message-ID: <178309728822.11236.10305597603915029505@4d746be3175e> # Security update for libarchive Announcement ID: SUSE-SU-2026:2747-1 Release Date: 2026-07-03T11:46:45Z Rating: important References: * bsc#1253088 * bsc#1259928 * bsc#1259931 * bsc#1261186 Cross-References: * CVE-2025-60753 * CVE-2026-4424 * CVE-2026-4426 * CVE-2026-5121 CVSS scores: * CVE-2025-60753 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-60753 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-60753 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-4424 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-4424 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4424 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4424 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4426 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4426 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4426 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-5121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-5121 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-5121 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for libarchive fixes the following issues * CVE-2025-60753: bsdtar hangs and OOMs with zero-length pattern matches (bsc#1253088). * CVE-2026-4424: information disclosure via heap out-of-bounds read in RAR archive processing (bsc#1259928). * CVE-2026-4426: undefined behavior due to unvalidated operand in shift expression of the zisofs decompression code (bsc#1259931). * CVE-2026-5121: arbitrary code execution via integer overflow in ISO9660 image processing (bsc#1261186). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2747=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2747=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libarchive-debugsource-3.3.3-32.17.1 * libarchive13-3.3.3-32.17.1 * libarchive-devel-3.3.3-32.17.1 * libarchive13-debuginfo-3.3.3-32.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libarchive-debugsource-3.3.3-32.17.1 * libarchive13-3.3.3-32.17.1 * libarchive-devel-3.3.3-32.17.1 * libarchive13-debuginfo-3.3.3-32.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-60753.html * https://www.suse.com/security/cve/CVE-2026-4424.html * https://www.suse.com/security/cve/CVE-2026-4426.html * https://www.suse.com/security/cve/CVE-2026-5121.html * https://bugzilla.suse.com/show_bug.cgi?id=1253088 * https://bugzilla.suse.com/show_bug.cgi?id=1259928 * https://bugzilla.suse.com/show_bug.cgi?id=1259931 * https://bugzilla.suse.com/show_bug.cgi?id=1261186 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:48:13 -0000 Subject: SUSE-SU-2026:2745-1: moderate: Security update for firewalld-legacy Message-ID: <178309729358.11236.15450012999367548672@4d746be3175e> # Security update for firewalld-legacy Announcement ID: SUSE-SU-2026:2745-1 Release Date: 2026-07-03T11:34:34Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld-legacy fixes the following issue * CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2745=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2745=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2745=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2745=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2745=1 ## Package List: * openSUSE Leap 15.6 (noarch) * firewall-applet-1.3.4-150600.13.6.1 * firewalld-1.3.4-150600.13.6.1 * firewalld-lang-1.3.4-150600.13.6.1 * firewall-macros-1.3.4-150600.13.6.1 * python311-firewall-1.3.4-150600.13.6.1 * firewall-config-1.3.4-150600.13.6.1 * firewalld-test-1.3.4-150600.13.6.1 * python3-firewall-1.3.4-150600.13.6.1 * firewalld-zsh-completion-1.3.4-150600.13.6.1 * firewalld-bash-completion-1.3.4-150600.13.6.1 * Basesystem Module 15-SP7 (noarch) * firewalld-1.3.4-150600.13.6.1 * firewalld-lang-1.3.4-150600.13.6.1 * python3-firewall-1.3.4-150600.13.6.1 * firewalld-zsh-completion-1.3.4-150600.13.6.1 * firewalld-bash-completion-1.3.4-150600.13.6.1 * Desktop Applications Module 15-SP7 (noarch) * firewall-applet-1.3.4-150600.13.6.1 * firewall-config-1.3.4-150600.13.6.1 * Python 3 Module 15-SP7 (noarch) * python311-firewall-1.3.4-150600.13.6.1 * Development Tools Module 15-SP7 (noarch) * firewall-macros-1.3.4-150600.13.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:19 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:48:19 -0000 Subject: SUSE-SU-2026:2744-1: important: Security update for gstreamer-plugins-bad Message-ID: <178309729952.11236.9990572980070013325@4d746be3175e> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:2744-1 Release Date: 2026-07-03T11:25:07Z Rating: important References: * bsc#1268401 Cross-References: * CVE-2026-52719 CVSS scores: * CVE-2026-52719 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52719 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52719 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issue * CVE-2026-52719: gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder (bsc#1268401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2744=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2744=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2744=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2744=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2744=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2744=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libgsturidownloader-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstplay-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstVulkan-1_0-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstTranscoder-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.6.1 * libgstva-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-1.24.0-150600.4.6.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-1.24.0-150600.4.6.1 * gstreamer-transcoder-devel-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstVulkanXCB-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstVulkanWayland-1_0-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.6.1 * gstreamer-transcoder-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-transcoder-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-1.24.0-150600.4.6.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libgstplay-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-64bit-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-64bit-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-64bit-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-64bit-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-64bit-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-64bit-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstplay-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-64bit-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-64bit-1.24.0-150600.4.6.1 * openSUSE Leap 15.6 (x86_64) * libgstdxva-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-32bit-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstva-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-32bit-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstplay-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstmse-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstplay-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-32bit-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstva-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstmse-1_0-0-32bit-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-32bit-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-32bit-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * openSUSE Leap 15.6 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libgsturidownloader-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.6.1 * libgstva-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-1.24.0-150600.4.6.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.6.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-1.24.0-150600.4.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libgsturidownloader-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.6.1 * libgstva-1_0-0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-1.24.0-150600.4.6.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.6.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-1.24.0-150600.4.6.1 * Desktop Applications Module 15-SP7 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libgsturidownloader-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.6.1 * libgstva-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-1.24.0-150600.4.6.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.6.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-1.24.0-150600.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.6.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libgstplayer-1_0-0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-52719.html * https://bugzilla.suse.com/show_bug.cgi?id=1268401 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:25 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:48:25 -0000 Subject: SUSE-SU-2026:2743-1: important: Security update for gstreamer-plugins-bad Message-ID: <178309730571.11236.7448734830143863529@4d746be3175e> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:2743-1 Release Date: 2026-07-03T11:23:55Z Rating: important References: * bsc#1268401 Cross-References: * CVE-2026-52719 CVSS scores: * CVE-2026-52719 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52719 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52719 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issue * CVE-2026-52719: gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder (bsc#1268401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2743=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2743=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2743=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2743=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2743=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * gstreamer-transcoder-devel-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-transcoder-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstVulkan-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstVulkanXCB-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstTranscoder-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * gstreamer-transcoder-debuginfo-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * typelib-1_0-GstVulkanWayland-1_0-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libgstbadaudio-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-64bit-debuginfo-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-64bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-64bit-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstva-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstplay-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-64bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-64bit-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstva-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstplay-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-64bit-1.22.0-150500.3.31.1 * openSUSE Leap 15.5 (x86_64) * libgstwayland-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstva-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstva-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstplay-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-32bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstplay-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-32bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-32bit-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-32bit-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-32bit-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-32bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-32bit-1.22.0-150500.3.31.1 * openSUSE Leap 15.5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 ## References: * https://www.suse.com/security/cve/CVE-2026-52719.html * https://bugzilla.suse.com/show_bug.cgi?id=1268401 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:31 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:48:31 -0000 Subject: SUSE-SU-2026:2742-1: important: Security update for pacemaker Message-ID: <178309731175.11236.4374807445559881433@4d746be3175e> # Security update for pacemaker Announcement ID: SUSE-SU-2026:2742-1 Release Date: 2026-07-03T09:20:51Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issue * CVE-2026-10649: denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-2742=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2742=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * pacemaker-remote-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker-devel-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-remote-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debugsource-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * openSUSE Leap 15.4 (noarch) * pacemaker-cts-2.1.2+20211124.ada5c3b36-150400.4.39.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * pacemaker-remote-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debugsource-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker-devel-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-remote-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-2.1.2+20211124.ada5c3b36-150400.4.39.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (noarch) * pacemaker-cts-2.1.2+20211124.ada5c3b36-150400.4.39.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:37 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 16:48:37 -0000 Subject: SUSE-SU-2026:2740-1: moderate: Security update for golang-github-docker-libnetwork Message-ID: <178309731734.11236.8744101288226250592@4d746be3175e> # Security update for golang-github-docker-libnetwork Announcement ID: SUSE-SU-2026:2740-1 Release Date: 2026-07-03T09:07:54Z Rating: moderate References: * bsc#1259566 Cross-References: * CVE-2026-2808 CVSS scores: * CVE-2026-2808 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-2808 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-2808 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for golang-github-docker-libnetwork fixes the following issue * CVE-2026-2808: github.com/hashicorp/consul: unvalidated user-supplied file paths can lead to arbitrary file reads through the Vault Kubernetes authentication provider (bsc#1259566). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2740=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2740=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2740=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2740=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2808.html * https://bugzilla.suse.com/show_bug.cgi?id=1259566 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 20:30:11 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 20:30:11 -0000 Subject: SUSE-SU-2026:2751-1: moderate: Security update for tracker-miners Message-ID: <178311061182.273.13160925929325344295@dc2e3449a402> # Security update for tracker-miners Announcement ID: SUSE-SU-2026:2751-1 Release Date: 2026-07-03T13:58:39Z Rating: moderate References: * bsc#1257606 * bsc#1257607 * bsc#1257608 * bsc#1257609 Cross-References: * CVE-2026-1764 * CVE-2026-1765 * CVE-2026-1766 * CVE-2026-1767 CVSS scores: * CVE-2026-1764 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-1764 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1764 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1765 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1765 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1766 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1766 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1766 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1767 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1767 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1767 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * openSUSE Leap 15.4 An update that solves four vulnerabilities can now be installed. ## Description: This update for tracker-miners fixes the following issues: * CVE-2026-1764: heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files (bsc#1257606). * CVE-2026-1765: denial of service and potential information disclosure via crafted MP3 files (bsc#1257607). * CVE-2026-1766: denial of service and information disclosure via malformed MP3 files (bsc#1257608). * CVE-2026-1767: heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags (bsc#1257609). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2751=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * tracker-miner-files-3.2.2-150400.3.10.1 * tracker-miner-files-debuginfo-3.2.2-150400.3.10.1 * tracker-miners-debuginfo-3.2.2-150400.3.10.1 * tracker-miners-debugsource-3.2.2-150400.3.10.1 * tracker-miners-3.2.2-150400.3.10.1 * openSUSE Leap 15.4 (noarch) * tracker-miners-lang-3.2.2-150400.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1764.html * https://www.suse.com/security/cve/CVE-2026-1765.html * https://www.suse.com/security/cve/CVE-2026-1766.html * https://www.suse.com/security/cve/CVE-2026-1767.html * https://bugzilla.suse.com/show_bug.cgi?id=1257606 * https://bugzilla.suse.com/show_bug.cgi?id=1257607 * https://bugzilla.suse.com/show_bug.cgi?id=1257608 * https://bugzilla.suse.com/show_bug.cgi?id=1257609 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 20:30:20 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 20:30:20 -0000 Subject: SUSE-SU-2026:2750-1: important: Security update for perl-DBI Message-ID: <178311062080.273.17947242742419884472@dc2e3449a402> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:2750-1 Release Date: 2026-07-03T13:34:24Z Rating: important References: * bsc#1267957 Cross-References: * CVE-2026-9698 CVSS scores: * CVE-2026-9698 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9698 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-DBI fixes the following issue * CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited- sized buffer (bsc#1267957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2750=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2750=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2750=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2750=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2750=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2750=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2750=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2750=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9698.html * https://bugzilla.suse.com/show_bug.cgi?id=1267957 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 20:30:28 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 20:30:28 -0000 Subject: SUSE-SU-2026:2749-1: important: Security update for perl-DBI Message-ID: <178311062831.273.1883326676109594227@dc2e3449a402> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:2749-1 Release Date: 2026-07-03T13:04:50Z Rating: important References: * bsc#1267849 * bsc#1267957 Cross-References: * CVE-2026-10879 * CVE-2026-9698 CVSS scores: * CVE-2026-10879 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10879 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10879 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9698 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited- sized buffer (bsc#1267957). * CVE-2026-10879: SQL statements with more than 9 binders can cause an heap overflow (bsc#1267849). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2749=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2749=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2749=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2749=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * perl-DBI-1.647.0-150600.12.11.1 * perl-DBI-debugsource-1.647.0-150600.12.11.1 * perl-DBI-debuginfo-1.647.0-150600.12.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-DBI-1.647.0-150600.12.11.1 * perl-DBI-debugsource-1.647.0-150600.12.11.1 * perl-DBI-debuginfo-1.647.0-150600.12.11.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-DBI-1.647.0-150600.12.11.1 * perl-DBI-debugsource-1.647.0-150600.12.11.1 * perl-DBI-debuginfo-1.647.0-150600.12.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-1.647.0-150600.12.11.1 * perl-DBI-debugsource-1.647.0-150600.12.11.1 * perl-DBI-debuginfo-1.647.0-150600.12.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10879.html * https://www.suse.com/security/cve/CVE-2026-9698.html * https://bugzilla.suse.com/show_bug.cgi?id=1267849 * https://bugzilla.suse.com/show_bug.cgi?id=1267957 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 20:30:34 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 03 Jul 2026 20:30:34 -0000 Subject: SUSE-SU-2026:2748-1: important: Security update for perl-DBI Message-ID: <178311063481.273.9063190979607364595@dc2e3449a402> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:2748-1 Release Date: 2026-07-03T12:33:43Z Rating: important References: * bsc#1267957 Cross-References: * CVE-2026-9698 CVSS scores: * CVE-2026-9698 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9698 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-DBI fixes the following issue * CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited- sized buffer (bsc#1267957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2748=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2748=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-1.628-5.12.1 * perl-DBI-debuginfo-1.628-5.12.1 * perl-DBI-debugsource-1.628-5.12.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * perl-DBI-1.628-5.12.1 * perl-DBI-debuginfo-1.628-5.12.1 * perl-DBI-debugsource-1.628-5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9698.html * https://bugzilla.suse.com/show_bug.cgi?id=1267957 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 08:30:11 -0000 Subject: SUSE-SU-2026:2758-1: moderate: Security update for python-pip Message-ID: <178332661183.513.7935238716998645761@dc2e3449a402> # Security update for python-pip Announcement ID: SUSE-SU-2026:2758-1 Release Date: 2026-07-03T19:35:52Z Rating: moderate References: * bsc#1262429 * bsc#1263442 Cross-References: * CVE-2026-3219 * CVE-2026-6357 CVSS scores: * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-pip fixes the following issues * CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429). * CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2758=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * python3-pip-10.0.1-13.20.1 * python-pip-10.0.1-13.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:17 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 08:30:17 -0000 Subject: SUSE-SU-2026:2757-1: moderate: Security update for openCryptoki Message-ID: <178332661774.513.9226415438736095859@dc2e3449a402> # Security update for openCryptoki Announcement ID: SUSE-SU-2026:2757-1 Release Date: 2026-07-03T19:29:23Z Rating: moderate References: * bsc#1262283 Cross-References: * CVE-2026-40253 CVSS scores: * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for openCryptoki fixes the following issue: * CVE-2026-40253: malformed BER-encoded cryptographic objects can lead to information disclosure and denial of service (bsc#1262283). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2757=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openCryptoki-64bit-debuginfo-3.26.0-150700.5.17.1 * openCryptoki-64bit-3.26.0-150700.5.17.1 * openCryptoki-devel-3.26.0-150700.5.17.1 * openCryptoki-debugsource-3.26.0-150700.5.17.1 * openCryptoki-debuginfo-3.26.0-150700.5.17.1 * openCryptoki-3.26.0-150700.5.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1262283 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:23 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 08:30:23 -0000 Subject: SUSE-SU-2026:2756-1: moderate: Security update for gimp Message-ID: <178332662343.513.3441600395479188825@dc2e3449a402> # Security update for gimp Announcement ID: SUSE-SU-2026:2756-1 Release Date: 2026-07-03T19:25:50Z Rating: moderate References: * bsc#1260837 Cross-References: * CVE-2026-4887 CVSS scores: * CVE-2026-4887 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-4887 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-4887 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gimp fixes the following issue: * CVE-2026-4887: Memory disclosure and denial of service via specially crafted PCX image (bsc#1260837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2756=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2756=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2756=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gimp-2.10.30-150400.3.53.1 * gimp-plugin-aa-2.10.30-150400.3.53.1 * gimp-devel-2.10.30-150400.3.53.1 * libgimpui-2_0-0-2.10.30-150400.3.53.1 * gimp-devel-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-plugin-aa-debuginfo-2.10.30-150400.3.53.1 * gimp-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-2.10.30-150400.3.53.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debugsource-2.10.30-150400.3.53.1 * openSUSE Leap 15.4 (x86_64) * libgimp-2_0-0-32bit-debuginfo-2.10.30-150400.3.53.1 * libgimpui-2_0-0-32bit-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-32bit-2.10.30-150400.3.53.1 * libgimpui-2_0-0-32bit-2.10.30-150400.3.53.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgimp-2_0-0-64bit-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-64bit-2.10.30-150400.3.53.1 * libgimpui-2_0-0-64bit-2.10.30-150400.3.53.1 * libgimpui-2_0-0-64bit-debuginfo-2.10.30-150400.3.53.1 * openSUSE Leap 15.4 (noarch) * gimp-lang-2.10.30-150400.3.53.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * gimp-2.10.30-150400.3.53.1 * gimp-devel-2.10.30-150400.3.53.1 * libgimpui-2_0-0-2.10.30-150400.3.53.1 * gimp-devel-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-2.10.30-150400.3.53.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debugsource-2.10.30-150400.3.53.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (noarch) * gimp-lang-2.10.30-150400.3.53.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * libgimpui-2_0-0-2.10.30-150400.3.53.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-2.10.30-150400.3.53.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debugsource-2.10.30-150400.3.53.1 * SUSE Package Hub 15 15-SP7 (aarch64) * gimp-2.10.30-150400.3.53.1 * gimp-plugin-aa-2.10.30-150400.3.53.1 * gimp-devel-2.10.30-150400.3.53.1 * gimp-devel-debuginfo-2.10.30-150400.3.53.1 * gimp-plugin-aa-debuginfo-2.10.30-150400.3.53.1 * SUSE Package Hub 15 15-SP7 (noarch) * gimp-lang-2.10.30-150400.3.53.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4887.html * https://bugzilla.suse.com/show_bug.cgi?id=1260837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:31 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 08:30:31 -0000 Subject: SUSE-SU-2026:2755-1: moderate: Security update for xdg-dbus-proxy Message-ID: <178332663164.513.1091302140597487598@dc2e3449a402> # Security update for xdg-dbus-proxy Announcement ID: SUSE-SU-2026:2755-1 Release Date: 2026-07-03T19:24:13Z Rating: moderate References: * bsc#1261737 Cross-References: * CVE-2026-34080 CVSS scores: * CVE-2026-34080 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34080 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-dbus-proxy fixes the following issue: * CVE-2026-34080: failure in the policy parser can lead to information disclosure (bsc#1261737). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2755=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2755=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * xdg-dbus-proxy-0.1.5-150600.3.5.1 * xdg-dbus-proxy-debuginfo-0.1.5-150600.3.5.1 * xdg-dbus-proxy-debugsource-0.1.5-150600.3.5.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xdg-dbus-proxy-0.1.5-150600.3.5.1 * xdg-dbus-proxy-debuginfo-0.1.5-150600.3.5.1 * xdg-dbus-proxy-debugsource-0.1.5-150600.3.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34080.html * https://bugzilla.suse.com/show_bug.cgi?id=1261737 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:37 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 08:30:37 -0000 Subject: SUSE-SU-2026:2754-1: moderate: Security update for python3-lxml Message-ID: <178332663767.513.16459562250477685824@dc2e3449a402> # Security update for python3-lxml Announcement ID: SUSE-SU-2026:2754-1 Release Date: 2026-07-03T19:22:12Z Rating: moderate References: * bsc#1263254 Cross-References: * CVE-2026-41066 CVSS scores: * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python3-lxml fixes the following issue * CVE-2026-41066: information disclosure via untrusted XML input leading to local file read (bsc#1263254). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2754=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2754=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2754=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-lxml-devel-4.9.1-150500.3.7.1 * python3-lxml-debuginfo-4.9.1-150500.3.7.1 * python3-lxml-debugsource-4.9.1-150500.3.7.1 * python3-lxml-4.9.1-150500.3.7.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * python3-lxml-devel-4.9.1-150500.3.7.1 * python3-lxml-debuginfo-4.9.1-150500.3.7.1 * python3-lxml-debugsource-4.9.1-150500.3.7.1 * python3-lxml-4.9.1-150500.3.7.1 * openSUSE Leap 15.5 (noarch) * python3-lxml-doc-4.9.1-150500.3.7.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python3-lxml-debuginfo-4.9.1-150500.3.7.1 * python3-lxml-debugsource-4.9.1-150500.3.7.1 * python3-lxml-4.9.1-150500.3.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41066.html * https://bugzilla.suse.com/show_bug.cgi?id=1263254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:43 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 08:30:43 -0000 Subject: SUSE-SU-2026:2752-1: moderate: Security update for python3-lxml Message-ID: <178332664356.513.15451410521704707275@dc2e3449a402> # Security update for python3-lxml Announcement ID: SUSE-SU-2026:2752-1 Release Date: 2026-07-03T19:19:50Z Rating: moderate References: * bsc#1263254 Cross-References: * CVE-2026-41066 CVSS scores: * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python3-lxml fixes the following issue * CVE-2026-41066: Information disclosure via untrusted XML input leading to local file read (bsc#1263254). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2752=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python3-lxml-3.6.1-3.9.1 * python3-lxml-debuginfo-3.6.1-3.9.1 * python3-lxml-debugsource-3.6.1-3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41066.html * https://bugzilla.suse.com/show_bug.cgi?id=1263254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:30:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:30:11 -0000 Subject: SUSE-SU-2026:2775-1: important: Maintenance update for Multi-Linux Manager 4.3 Release Notes Release Notes Message-ID: <178334101136.556.8236924281944249426@dc2e3449a402> # Maintenance update for Multi-Linux Manager 4.3 Release Notes Release Notes Announcement ID: SUSE-SU-2026:2775-1 Release Date: 2026-07-06T07:54:14Z Rating: important References: * bsc#1269253 * bsc#1269534 * jsc#MSQA-1058 Affected Products: * openSUSE Leap 15.4 An update that contains one feature and has two security fixes can now be installed. ## Security update 4.3.19 for Multi-Linux Manager Proxy and Retail Branch Server LTS ### Description: This update fixes the following issues: release-notes-susemanager-proxy: * Update to SUSE Manager 4.3.19 * Bugs mentioned: bsc#1269253, bsc#1269534 ## Security update 4.3.19 for Multi-Linux Manager Server LTS ### Description: This update fixes the following issues: release-notes-susemanager: * Update to SUSE Manager 4.3.19 * Bugs mentioned: bsc#1269253, bsc#1269534 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2775=1 ## Package List: * openSUSE Leap 15.4 (noarch) * release-notes-susemanager-4.3.19-150400.3.157.1 * release-notes-susemanager-proxy-4.3.19-150400.3.113.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269253 * https://bugzilla.suse.com/show_bug.cgi?id=1269534 * https://jira.suse.com/browse/MSQA-1058 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:32:29 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:32:29 -0000 Subject: SUSE-SU-2026:2774-1: important: Maintenance update for Multi-Linux Manager 5.1: Server, Proxy and Retail Branch Server Message-ID: <178334114984.556.13449796112731950458@dc2e3449a402> # Maintenance update for Multi-Linux Manager 5.1: Server, Proxy and Retail Branch Server Announcement ID: SUSE-SU-2026:2774-1 Release Date: 2026-07-06T07:52:26Z Rating: important References: * bsc#1208800 * bsc#1226578 * bsc#1234567 * bsc#1238890 * bsc#1242916 * bsc#1245107 * bsc#1247707 * bsc#1248699 * bsc#1249243 * bsc#1253032 * bsc#1254900 * bsc#1257583 * bsc#1257894 * bsc#1258041 * bsc#1258079 * bsc#1258144 * bsc#1258382 * bsc#1258816 * bsc#1259087 * bsc#1259230 * bsc#1259261 * bsc#1259474 * bsc#1259479 * bsc#1259482 * bsc#1259521 * bsc#1259590 * bsc#1259591 * bsc#1259700 * bsc#1259739 * bsc#1259787 * bsc#1259960 * bsc#1260031 * bsc#1260614 * bsc#1260806 * bsc#1261305 * bsc#1261307 * bsc#1261327 * bsc#1261631 * bsc#1261723 * bsc#1261753 * bsc#1261841 * bsc#1261902 * bsc#1262090 * bsc#1262222 * bsc#1262285 * bsc#1262460 * bsc#1262471 * bsc#1262492 * bsc#1262595 * bsc#1262708 * bsc#1262720 * bsc#1262760 * bsc#1262761 * bsc#1262950 * bsc#1263501 * bsc#1263814 * bsc#1263841 * bsc#1263986 * bsc#1263987 * bsc#1264149 * bsc#1264174 * bsc#1264234 * bsc#1264256 * bsc#1264966 * bsc#1265134 * bsc#1265281 * bsc#1265282 * bsc#1265283 * bsc#1265284 * bsc#1265285 * bsc#1265286 * bsc#1265287 * bsc#1265288 * bsc#1265289 * bsc#1265290 * bsc#1265319 * bsc#1265358 * bsc#1265975 * bsc#1266012 * bsc#1266556 * bsc#1266600 * bsc#1269253 * bsc#1269534 * jsc#MSQA-1056 * jsc#SUMA-320 Cross-References: * CVE-2022-21698 * CVE-2026-28374 * CVE-2026-28376 * CVE-2026-28379 * CVE-2026-28380 * CVE-2026-28383 * CVE-2026-33376 * CVE-2026-33377 * CVE-2026-33378 * CVE-2026-33380 * CVE-2026-33381 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-40179 * CVE-2026-41602 * CVE-2026-42151 * CVE-2026-42154 * CVE-2026-42198 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28374 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28374 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28374 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28376 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28376 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28379 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28380 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-28380 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28383 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28383 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28383 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33376 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33376 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33376 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33377 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33377 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33378 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33378 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33378 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33380 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-33380 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33381 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33381 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40179 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-40179 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-40179 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40179 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42154 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42198 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE * SUSE Multi-Linux Manager Server 5.1 Extension for SLE An update that solves 18 vulnerabilities, contains two features and has 65 security fixes can now be installed. ## Recommended update 5.1.4 for Multi-Linux Manager Proxy ### Description: This update fixes the following issues: Release Notes Highlights: * Update to SUSE Multi-Linux Manager 5.1.4: * Bugs mentioned: bsc#1208800, bsc#1234567, bsc#1238890, bsc#1253032, bsc#1257894 bsc#1258382, bsc#1259474, bsc#1259739, bsc#1260806, bsc#1261902 bsc#1262708, bsc#1264966, bsc#1266012 Container images and uyuni-tools changes: proxy-httpd-image, proxy-salt-broker-image, proxy-salt-broker-image, proxy- squid-image, proxy-ssh-image: * Removed unused repositories proxy-tftpd-image: * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Removed unused repositories uyuni-tools: * Version 5.1.29-0 * Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Removed waitForTraefik function (bsc#1261902) * Fixed inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: spacecmd: * Version 5.1.14-0 * Updated translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin ? Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhanced buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Aligned subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager-build-keys: * Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc uyuni-common-libs: * Version 5.1.6-0 * security(checksums): dropped md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgrpxy upgrade podman` which will use the default image tags. ## Recommended update 5.1.4 for Multi-Linux Manager Retail Branch Server ### Description: This update fixes the following issues: Release Notes Highlights: * Update to SUSE Multi-Linux Manager 5.1.4: * Bugs mentioned: bsc#1208800, bsc#1234567, bsc#1238890, bsc#1253032, bsc#1257894 bsc#1258382, bsc#1259474, bsc#1259739, bsc#1260806, bsc#1261902 bsc#1262708, bsc#1264966, bsc#1266012 Container images and uyuni-tools changes: proxy-httpd-image, proxy-salt-broker-image, proxy-salt-broker-image, proxy- squid-image, proxy-ssh-image: * Removed unused repositories proxy-tftpd-image: * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Removed unused repositories uyuni-tools: * Version 5.1.29-0 * Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Removed waitForTraefik function (bsc#1261902) * Fixed inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: spacecmd: * Version 5.1.14-0 * Updated translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin ? Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhanced buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Aligned subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager-build-keys: * Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc uyuni-common-libs: * Version 5.1.6-0 * security(checksums): dropped md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgrpxy upgrade podman` which will use the default image tags. ## Security update 5.1.4 for Multi-Linux Manager Server ### Description: This update fixes the following issues: Release Notes Highlights: * Update to SUSE Multi-Linux Manager 5.1.4 * Added note about migration for SUSE Linux Enterprise Server 16 on SSH managed minions * Product Migration from SUSE Linux Enterprise Server 15 SP7 to 16.0 * SUSE Liberty Linux 9.6 Support * New API Endpoint - listMigrationTargetsWithChannels * Debian 12 End-of-Life Notice * SUSE Registry URL Change * Security fixes: CVE-2026-34986, CVE-2026-41602, CVE-2026-39821, CVE-2026-42198 CVE-2022-21698, CVE-2026-40179, CVE-2026-42151, CVE-2026-42154 CVE-2026-28374, CVE-2026-28376, CVE-2026-28379, CVE-2026-28380 CVE-2026-28383, CVE-2026-33376, CVE-2026-33377, CVE-2026-33378 CVE-2026-33380, CVE-2026-33381 * Bugs mentioned: bsc#1226578, bsc#1234567, bsc#1238890, bsc#1242916, bsc#1245107 bsc#1247707, bsc#1248699, bsc#1249243, bsc#1253032, bsc#1257583 bsc#1257894, bsc#1258041, bsc#1258079, bsc#1258144, bsc#1258382 bsc#1258816, bsc#1259087, bsc#1259230, bsc#1259261, bsc#1259474 bsc#1259479, bsc#1259482, bsc#1259521, bsc#1259590, bsc#1259591 bsc#1259700, bsc#1259739, bsc#1259787, bsc#1259960, bsc#1260031 bsc#1260614, bsc#1260806, bsc#1261305, bsc#1261307, bsc#1261327 bsc#1261631, bsc#1261723, bsc#1261753, bsc#1261841, bsc#1261902 bsc#1262090, bsc#1262285, bsc#1262460, bsc#1262471, bsc#1262492 bsc#1262595, bsc#1262708, bsc#1262720, bsc#1262761, bsc#1263814 bsc#1263841, bsc#1264149, bsc#1264234, bsc#1264256, bsc#1264966 bsc#1265134, bsc#1265319, bsc#1265358, bsc#1265975, bsc#1266012 bsc#1262950, bsc#1263501, bsc#1266600, bsc#1266556, bsc#1264174 bsc#1262222, bsc#1263986, bsc#1263987, bsc#1265290, bsc#1265289 bsc#1265288, bsc#1265287, bsc#1265286, bsc#1265285, bsc#1265284 bsc#1265283, bsc#1265282, bsc#1265281, bsc#1269253, bsc#1269534 Container images and uyuni-tools changes: server-attestation-image: * Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: * Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Added "susemanager-tools", "susemanager" and "susemanager-tools-salt" packages to server-image server-migration-14-16-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: * Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: * Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: * Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: * Added the distro signature for rhel10 (bsc#1265134) liberate-formula: * Version 0.1.4 * No customer facing changes * Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: * Version 1.4.3 * Added support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: * Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fixed the issue of using non-vendored tornado with Python 3.11 salt: * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: * Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: * Version 5.1.14-0 * Update translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: * Version 5.1.28-0 * Check access rights on two formula API calls (bsc#1269253) * Sanitize uploaded image name (bsc#1269534) * Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fixed CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin ? Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fixed missing translations (bsc#1259787) * Fixed hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fixed enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fixed Remote Commands hang on direct hostname (bsc#1226578) * Fixed Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Added 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Added missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fixed Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fixed CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fixed conflicting cobbler system migrations spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin ? Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) subscription-matcher: * Version 0.44 * Fixed 2 missing part numbers (bsc#1264256) susemanager: * Version 5.1.17-0 * Added SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Removed spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicensed mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: * Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: * Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones * Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD * Added Code 16 to Monitoring documentation (bsc#1263814) * Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) * Rephrased instructions for RBAC in Administration Guide (bsc#1258079) * Added troubleshooting section for BTRFS to Administration Guide (bcs#1258816) * Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) * Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) * Removed mention of CIS profile (bsc#1262460) * Corrected path for Salt minion in Retail Guide (#1262090) * Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) * Removed Google Cloud Compute from PAYG documentation (bsc#1261631) * Added link to proxy creation from client to an existing document in Installation and Upgrade Guide * Updated features table for EL 10 based distributions * Document Debian 13 * Added support for Open Enterprise Server 25.4 * Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) * SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) * Added instructions about accessing git repositories when building images to Administration Guide * Added online database backup instructions to Administration Guide * Fixed comamnd for product deployment in Installation and Upgrade Guide (bsc#1259479) * Added online database backup instructions susemanager-schema: * Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Added index on rhnPackage (checksum_id) (bsc#1258041) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Added 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: * Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fixed GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fixed CPU reporting for ppc64le clients (bsc#1259521) * Fixed refresh of virtual instance information (bsc#1261723) susemanager-sync-data: * Version 5.1.10-0 * Added missing RES-EMS channel family (bsc#1265358) * Version 5.1.9-0 * Added SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: * Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-reportdb-schema: * version 5.1.7-0 * Increased url on table repository (bsc#1259230) uyuni-setup-reportdb: * Version 5.1.5-0 * Fixed delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: * Version 1.0.31-0 * Dropped SUSECloud module as not longer maintainednor used * Version 1.0.30-0 * No customer facing changes How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgradm upgrade podman` which will use the default image tags. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Server 5.1 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Server-SLE-5.1-2026-2774=1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Retail-Branch-Server- SLE-5.1-2026-2774=1 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Proxy-SLE-5.1-2026-2774=1 ## Package List: * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (noarch) * mgrpxy-lang-5.1.29-150700.3.26.1 * mgrpxy-bash-completion-5.1.29-150700.3.26.1 * mgrpxy-zsh-completion-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.12 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrpxy-5.1.29-150700.3.26.1 * mgrpxy-debuginfo-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (x86_64) * suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.25 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-ppc64le-server-postgresql-image-5.1.4-6.24.3 * suse-multi-linux-manager-5.1-ppc64le-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-ppc64le-server-migration-14-16-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-ppc64le-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-ppc64le-server-saline-image-5.1.4-9.20.24 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (x86_64) * suse-multi-linux-manager-5.1-x86_64-server-saline-image-5.1.4-9.20.24 * suse-multi-linux-manager-5.1-x86_64-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-x86_64-server-postgresql-image-5.1.4-6.24.3 * suse-multi-linux-manager-5.1-x86_64-server-migration-14-16-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-x86_64-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-x86_64-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (noarch) * mgrctl-zsh-completion-5.1.29-150700.3.26.1 * mgrctl-lang-5.1.29-150700.3.26.1 * mgradm-bash-completion-5.1.29-150700.3.26.1 * mgrctl-bash-completion-5.1.29-150700.3.26.1 * mgradm-zsh-completion-5.1.29-150700.3.26.1 * mgradm-lang-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-5.1.29-150700.3.26.1 * mgradm-5.1.29-150700.3.26.1 * mgradm-debuginfo-5.1.29-150700.3.26.1 * mgrctl-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (aarch64) * suse-multi-linux-manager-5.1-aarch64-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-aarch64-server-postgresql-image-5.1.4-6.24.3 * suse-multi-linux-manager-5.1-aarch64-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-aarch64-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-aarch64-server-saline-image-5.1.4-9.20.24 * suse-multi-linux-manager-5.1-aarch64-server-migration-14-16-image-5.1.4-8.20.13 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (s390x) * suse-multi-linux-manager-5.1-s390x-server-migration-14-16-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-s390x-server-saline-image-5.1.4-9.20.24 * suse-multi-linux-manager-5.1-s390x-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-s390x-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-s390x-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-s390x-server-postgresql-image-5.1.4-6.24.3 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (noarch) * mgrpxy-lang-5.1.29-150700.3.26.1 * mgrpxy-bash-completion-5.1.29-150700.3.26.1 * mgrpxy-zsh-completion-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.12 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrpxy-debuginfo-5.1.29-150700.3.26.1 * mgrpxy-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (x86_64) * suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.25 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2026-28374.html * https://www.suse.com/security/cve/CVE-2026-28376.html * https://www.suse.com/security/cve/CVE-2026-28379.html * https://www.suse.com/security/cve/CVE-2026-28380.html * https://www.suse.com/security/cve/CVE-2026-28383.html * https://www.suse.com/security/cve/CVE-2026-33376.html * https://www.suse.com/security/cve/CVE-2026-33377.html * https://www.suse.com/security/cve/CVE-2026-33378.html * https://www.suse.com/security/cve/CVE-2026-33380.html * https://www.suse.com/security/cve/CVE-2026-33381.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40179.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-42151.html * https://www.suse.com/security/cve/CVE-2026-42154.html * https://www.suse.com/security/cve/CVE-2026-42198.html * https://bugzilla.suse.com/show_bug.cgi?id=1208800 * https://bugzilla.suse.com/show_bug.cgi?id=1226578 * https://bugzilla.suse.com/show_bug.cgi?id=1234567 * https://bugzilla.suse.com/show_bug.cgi?id=1238890 * https://bugzilla.suse.com/show_bug.cgi?id=1242916 * https://bugzilla.suse.com/show_bug.cgi?id=1245107 * https://bugzilla.suse.com/show_bug.cgi?id=1247707 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1249243 * https://bugzilla.suse.com/show_bug.cgi?id=1253032 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1257894 * https://bugzilla.suse.com/show_bug.cgi?id=1258041 * https://bugzilla.suse.com/show_bug.cgi?id=1258079 * https://bugzilla.suse.com/show_bug.cgi?id=1258144 * https://bugzilla.suse.com/show_bug.cgi?id=1258382 * https://bugzilla.suse.com/show_bug.cgi?id=1258816 * https://bugzilla.suse.com/show_bug.cgi?id=1259087 * https://bugzilla.suse.com/show_bug.cgi?id=1259230 * https://bugzilla.suse.com/show_bug.cgi?id=1259261 * https://bugzilla.suse.com/show_bug.cgi?id=1259474 * https://bugzilla.suse.com/show_bug.cgi?id=1259479 * https://bugzilla.suse.com/show_bug.cgi?id=1259482 * https://bugzilla.suse.com/show_bug.cgi?id=1259521 * https://bugzilla.suse.com/show_bug.cgi?id=1259590 * https://bugzilla.suse.com/show_bug.cgi?id=1259591 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1259787 * https://bugzilla.suse.com/show_bug.cgi?id=1259960 * https://bugzilla.suse.com/show_bug.cgi?id=1260031 * https://bugzilla.suse.com/show_bug.cgi?id=1260614 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1261305 * https://bugzilla.suse.com/show_bug.cgi?id=1261307 * https://bugzilla.suse.com/show_bug.cgi?id=1261327 * https://bugzilla.suse.com/show_bug.cgi?id=1261631 * https://bugzilla.suse.com/show_bug.cgi?id=1261723 * https://bugzilla.suse.com/show_bug.cgi?id=1261753 * https://bugzilla.suse.com/show_bug.cgi?id=1261841 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262090 * https://bugzilla.suse.com/show_bug.cgi?id=1262222 * https://bugzilla.suse.com/show_bug.cgi?id=1262285 * https://bugzilla.suse.com/show_bug.cgi?id=1262460 * https://bugzilla.suse.com/show_bug.cgi?id=1262471 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262595 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262720 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1262761 * https://bugzilla.suse.com/show_bug.cgi?id=1262950 * https://bugzilla.suse.com/show_bug.cgi?id=1263501 * https://bugzilla.suse.com/show_bug.cgi?id=1263814 * https://bugzilla.suse.com/show_bug.cgi?id=1263841 * https://bugzilla.suse.com/show_bug.cgi?id=1263986 * https://bugzilla.suse.com/show_bug.cgi?id=1263987 * https://bugzilla.suse.com/show_bug.cgi?id=1264149 * https://bugzilla.suse.com/show_bug.cgi?id=1264174 * https://bugzilla.suse.com/show_bug.cgi?id=1264234 * https://bugzilla.suse.com/show_bug.cgi?id=1264256 * https://bugzilla.suse.com/show_bug.cgi?id=1264966 * https://bugzilla.suse.com/show_bug.cgi?id=1265134 * https://bugzilla.suse.com/show_bug.cgi?id=1265281 * https://bugzilla.suse.com/show_bug.cgi?id=1265282 * https://bugzilla.suse.com/show_bug.cgi?id=1265283 * https://bugzilla.suse.com/show_bug.cgi?id=1265284 * https://bugzilla.suse.com/show_bug.cgi?id=1265285 * https://bugzilla.suse.com/show_bug.cgi?id=1265286 * https://bugzilla.suse.com/show_bug.cgi?id=1265287 * https://bugzilla.suse.com/show_bug.cgi?id=1265288 * https://bugzilla.suse.com/show_bug.cgi?id=1265289 * https://bugzilla.suse.com/show_bug.cgi?id=1265290 * https://bugzilla.suse.com/show_bug.cgi?id=1265319 * https://bugzilla.suse.com/show_bug.cgi?id=1265358 * https://bugzilla.suse.com/show_bug.cgi?id=1265975 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://bugzilla.suse.com/show_bug.cgi?id=1266556 * https://bugzilla.suse.com/show_bug.cgi?id=1266600 * https://bugzilla.suse.com/show_bug.cgi?id=1269253 * https://bugzilla.suse.com/show_bug.cgi?id=1269534 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/SUMA-320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:33:06 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:33:06 -0000 Subject: SUSE-RU-2026:2773-1: moderate: Recommended update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334118640.556.17359661788750129515@dc2e3449a402> # Recommended update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-RU-2026:2773-1 Release Date: 2026-07-06T07:50:54Z Rating: moderate References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1255418 * bsc#1257583 * bsc#1259700 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 Affected Products: * SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04 2204 An update that contains one feature and has 20 fixes can now be installed. ## Description: This update fixes the following issues: scap-security-guide: * Non customer facing changes spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0): * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0): * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Fixed Report DB CA certificate (bsc#1260806) * Key Update Highlights (v5.2.7-0): * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0): * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Key Update Highlights (v5.2.5-0): * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0): * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) * Fixed testsuite failures ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04 2204 zypper in -t patch SUSE-MultiLinuxManagerTools-Ubuntu-22.04-2026-2773=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04 2204 (all) * spacecmd-5.2.8-220402.3.18.3 * mgrctl-bash-completion-5.2.12-220402.3.18.1 * scap-security-guide-ubuntu-0.1.79-220402.2.12.2 * mgrctl-fish-completion-5.2.12-220402.3.18.1 * mgrctl-zsh-completion-5.2.12-220402.3.18.1 * SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04 2204 (amd64) * mgrctl-5.2.12-220402.3.18.1 * venv-salt-minion-3006.0-220402.3.25.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:33:41 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:33:41 -0000 Subject: SUSE-RU-2026:2772-1: moderate: Recommended update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334122180.556.2031232205352425978@dc2e3449a402> # Recommended update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-RU-2026:2772-1 Release Date: 2026-07-06T07:50:30Z Rating: moderate References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1255418 * bsc#1257583 * bsc#1259700 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 Affected Products: * SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04 2404 An update that contains one feature and has 20 fixes can now be installed. ## Description: This update fixes the following issues: spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0) * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0) * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Fixed Report DB CA certificate (bsc#1260806) * Key Update Highlights (v5.2.7-0) * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0) * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Key Update Highlights (v5.2.5-0) * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0) * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04 2404 zypper in -t patch SUSE-MultiLinuxManagerTools-Ubuntu-24.04-2026-2772=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04 2404 (amd64) * mgrctl-5.2.12-240402.3.18.1 * venv-salt-minion-3006.0-240402.3.25.1 * SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04 2404 (all) * mgrctl-fish-completion-5.2.12-240402.3.18.1 * mgrctl-zsh-completion-5.2.12-240402.3.18.1 * mgrctl-bash-completion-5.2.12-240402.3.18.1 * spacecmd-5.2.8-240402.3.23.3 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:34:17 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:34:17 -0000 Subject: SUSE-RU-2026:2771-1: moderate: Recommended update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334125767.556.13901424209190268180@dc2e3449a402> # Recommended update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-RU-2026:2771-1 Release Date: 2026-07-06T07:50:00Z Rating: moderate References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1255418 * bsc#1257583 * bsc#1259700 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 Affected Products: * SUSE Multi-Linux Manager Client Tools for Debian 12 An update that contains one feature and has 20 fixes can now be installed. ## Description: This update fixes the following issues: spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0): * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0): * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Fixed Report DB CA certificate (bsc#1260806) * Key Update Highlights (v5.2.7-0): * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0): * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Key Update Highlights (v5.2.5-0): * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0): * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for Debian 12 zypper in -t patch SUSE-MultiLinuxManagerTools-Debian-12-2026-2771=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for Debian 12 (all) * mgrctl-bash-completion-5.2.12-120002.3.20.1 * mgrctl-zsh-completion-5.2.12-120002.3.20.1 * mgrctl-fish-completion-5.2.12-120002.3.20.1 * spacecmd-5.2.8-120002.3.20.1 * SUSE Multi-Linux Manager Client Tools for Debian 12 (amd64 arm64) * venv-salt-minion-3006.0-120002.3.27.1 * mgrctl-5.2.12-120002.3.20.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:34:53 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:34:53 -0000 Subject: SUSE-RU-2026:2770-1: moderate: Recommended update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334129395.556.15536354285680315293@dc2e3449a402> # Recommended update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-RU-2026:2770-1 Release Date: 2026-07-06T07:49:31Z Rating: moderate References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1255418 * bsc#1257583 * bsc#1259700 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 Affected Products: * SUSE Multi-Linux Manager Client Tools for Debian 13 An update that contains one feature and has 20 fixes can now be installed. ## Description: This update fixes the following issues: spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0): * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0): * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Fixed Report DB CA certificate (bsc#1260806) * Key Update Highlights (v5.2.7-0): * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0): * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Key Update Highlights (v5.2.5-0): * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0): * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for Debian 13 zypper in -t patch SUSE-MultiLinuxManagerTools-Debian-13-2026-2770=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for Debian 13 (all) * mgrctl-zsh-completion-5.2.12-130002.2.6.1 * spacecmd-5.2.8-130002.2.6.1 * mgrctl-fish-completion-5.2.12-130002.2.6.1 * mgrctl-bash-completion-5.2.12-130002.2.6.1 * SUSE Multi-Linux Manager Client Tools for Debian 13 (amd64 arm64) * venv-salt-minion-3006.0-130002.2.10.1 * mgrctl-5.2.12-130002.2.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:35:05 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:35:05 -0000 Subject: SUSE-RU-2026:2769-1: important: Recommended update 5.1.4 for Multi-Linux Manager Salt Bundle Message-ID: <178334130522.556.16035755253468634050@dc2e3449a402> # Recommended update 5.1.4 for Multi-Linux Manager Salt Bundle Announcement ID: SUSE-RU-2026:2769-1 Release Date: 2026-07-06T07:49:03Z Rating: important References: * bsc#1254900 * bsc#1255418 * bsc#1257583 * bsc#1259700 * jsc#MSQA-1056 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 * SUSE Linux Enterprise Desktop 15 SP1 * SUSE Linux Enterprise Desktop 15 SP2 * SUSE Linux Enterprise Desktop 15 SP3 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP1 * SUSE Linux Enterprise Real Time 15 SP2 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Multi-Linux Manager Client Tools for SLE 15 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 An update that contains one feature and has four fixes can now be installed. ## Description: This update fixes the following issues: venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE 15 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-15-2026-2769=1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2026-2769=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE 15 (aarch64 ppc64le s390x x86_64) * venv-salt-minion-3006.0-150002.5.19.1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (aarch64 ppc64le s390x x86_64) * venv-salt-minion-3006.0-150002.5.19.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://jira.suse.com/browse/MSQA-1056 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:36:07 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:36:07 -0000 Subject: SUSE-SU-2026:2768-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334136739.556.6786084068683433030@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2768-1 Release Date: 2026-07-06T07:48:37Z Rating: important References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1248699 * bsc#1248707 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1259739 * bsc#1260806 * bsc#1260870 * bsc#1260905 * bsc#1261810 * bsc#1261902 * bsc#1262222 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1262950 * bsc#1263157 * bsc#1263501 * bsc#1263823 * bsc#1263986 * bsc#1263987 * bsc#1265281 * bsc#1265282 * bsc#1265283 * bsc#1265284 * bsc#1265285 * bsc#1265286 * bsc#1265287 * bsc#1265288 * bsc#1265289 * bsc#1265290 * bsc#1266012 * bsc#1266556 * bsc#1266600 * bsc#1266608 * bsc#1267153 * jsc#MSQA-1056 * jsc#PED-14816 Cross-References: * CVE-2022-21698 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-28374 * CVE-2026-28376 * CVE-2026-28379 * CVE-2026-28380 * CVE-2026-28383 * CVE-2026-33376 * CVE-2026-33377 * CVE-2026-33378 * CVE-2026-33380 * CVE-2026-33381 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-40179 * CVE-2026-41602 * CVE-2026-42151 * CVE-2026-42154 * CVE-2026-42502 * CVE-2026-42506 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-28374 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28374 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28374 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28376 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28376 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28379 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28380 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-28380 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28383 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28383 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28383 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33376 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33376 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33376 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33377 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33377 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33378 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33378 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33378 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33380 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-33380 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33381 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33381 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40179 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-40179 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-40179 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40179 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42154 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 * SUSE Linux Enterprise Desktop 15 SP1 * SUSE Linux Enterprise Desktop 15 SP2 * SUSE Linux Enterprise Desktop 15 SP3 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP1 * SUSE Linux Enterprise Real Time 15 SP2 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Multi-Linux Manager Client Tools for SLE 15 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 An update that solves 22 vulnerabilities, contains two features and has 17 security fixes can now be installed. ## Description: This update fixes the following issues: dracut-saltboot updated to version 1.2.1: * Key Update Highlights (v1.2.1) * Added wait check for minion start (default 10s), configurable using rd.saltboot.salt_start_timeout option (bsc#1260870) * Decouple salt key wait check to use separate configurable option rd.saltboot.salt_key_timeout, with default 60s * Introduce rd.saltboot namespace for all options, mark old as deprecated golang-github-QubitProducts-exporter_exporter: * Security issues fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-boynux-squid_exporter: * Non customer facing changes golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-alertmanager: * Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: * Key Update Highlights (v1.10.0 to v1.10.2): * New Collectors: Added new collectors for PCIe devices and swaps. * New Metrics: Introduced metrics for Zswap/Zswapped, Systemd Virtualization, and WiFi packets (received/transmitted) * Bug Fixes: Resolved a duplicate collection bug in filesystem mount points, fixed a Zswap metric typo, and patched a logging race condition in systemd. * Changes: Switched mdadm to use sysfs for RAID metrics, and added erofs to the default excluded filesystems list. * Internal Refactoring: filesystem mountinfo parsing refactor (bsc#1261810) golang-github-prometheus-prometheus updated to version 3.5.3: * Security issues fixed: * CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (v3.5.3) (bsc#1263986) * CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the limit (v3.5.3) (bsc#1263987) * CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (v3.5.2) (bsc#1262222). * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (backported patch) (bsc#1266608) * Other changes: * Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (v3.5.3) * Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) * Internal update with non customer facing changes (v3.5.1) grafana updated to version 11.6.14+security-04: * Security issues fixed in v11.6.14+security-04: * CVE-2026-28374: Fixed insecure direct object reference in Annotations API (bsc#1265290) * CVE-2026-28376: Fixed unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) * CVE-2026-28383: Fixed unbounded memory allocation in Grafana plugin resources (bsc#1265286) * CVE-2026-28380: Fixed broken access control in Snapshot API (bsc#1265287) * CVE-2026-33376: Fixed Auth Proxy IPv6 whitelist bypass (bsc#1265285) * CVE-2026-28379: Fixed viewer-triggered race condition in Grafana Live (bsc#1265288) * CVE-2026-33377: Fixed dashboard Editor Privilege Escalation (bsc#1265284) * CVE-2026-33378: Fixed OOM exception in Grafana Data Source Plugin (bsc#1265283) * CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) * CVE-2026-33380: Fixed vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server?s filesystem (bsc#1265282) * Security issues fixed through backported patches: * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) * CVE-2026-34986: Fixed panic in JWE decryption (bsc#1262950) * CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) * CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Fixed multiple issues when parsing HTML files (bsc#1267153) mgr-push updated to version 5.2.4: * Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0) prometheus-blackbox_exporter: * Security issues fixed: * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266556) prometheus-postgres_exporter: * Security issues fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) rhnlib updated to version 5.2.5: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes spacewalk-client-tools updated to version 5.2.6: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0) supportutils-plugin-salt: * Non customer facing changes supportutils-plugin-susemanager-client updated to version 5.2.3: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.3-0) uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0) * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0) * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Internal SANs for db and reportdb are no longer required * Generate the same certificate for server and reportdb * Fixed Report DB CA certificate (bsc#1260806) * Removed waitForTraefik function (bsc#1261902) * Key Update Highlights (v5.2.8-0) * Generate service template only after secrets are created * Key Update Highlights (v5.2.7-0) * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0): * Use podman secrets for SSL on proxy * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Fixed incorrect package dependencies declaration (bsc#1229105) * Prevent cobbler port from being exposed * Bumped zerolog to 1.34 * Ignore spacewalk-service stop return code. * Stop automatically unhealthy container * Use container based server setup instead tools bundled one * Key Update Highlights (v5.2.5-0) * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0) * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes uyuni-common-libs updated to version 5.2.5: * Key Update Highlights (v5.2.5-0): * Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using standard hashlib directly * Other changes: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2026-2768=1 * SUSE Multi-Linux Manager Client Tools for SLE 15 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-15-2026-2768=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (aarch64 ppc64le s390x x86_64) * mgrctl-5.2.12-150002.3.17.1 * golang-github-prometheus-node_exporter-1.10.2-150002.3.6.2 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-150002.3.6.2 * mgrctl-debuginfo-5.2.12-150002.3.17.1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (noarch) * mgrctl-zsh-completion-5.2.12-150002.3.17.1 * mgrctl-lang-5.2.12-150002.3.17.1 * dracut-saltboot-1.2.1-150002.3.9.1 * mgrctl-bash-completion-5.2.12-150002.3.17.1 * SUSE Multi-Linux Manager Client Tools for SLE 15 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-node_exporter-1.10.2-150002.3.6.2 * prometheus-blackbox_exporter-0.26.0-150002.3.11.1 * grafana-debuginfo-11.6.14+security04-150002.4.21.1 * golang-github-prometheus-prometheus-debuginfo-3.5.3-150002.3.13.1 * grafana-11.6.14+security04-150002.4.21.1 * golang-github-prometheus-alertmanager-0.28.1-150002.4.11.1 * golang-github-lusitaniae-apache_exporter-debuginfo-1.0.10-150002.3.9.2 * golang-github-prometheus-prometheus-3.5.3-150002.3.13.1 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-150002.3.6.2 * golang-github-QubitProducts-exporter_exporter-0.4.0-150002.3.6.2 * prometheus-postgres_exporter-0.10.1-150002.3.3.2 * golang-github-prometheus-alertmanager-debuginfo-0.28.1-150002.4.11.1 * prometheus-postgres_exporter-debuginfo-0.10.1-150002.3.3.2 * mgrctl-debuginfo-5.2.12-150002.3.17.1 * golang-github-lusitaniae-apache_exporter-1.0.10-150002.3.9.2 * golang-github-boynux-squid_exporter-1.13.0-150002.3.6.2 * firewalld-prometheus-config-0.1-150002.3.13.1 * golang-github-boynux-squid_exporter-debuginfo-1.13.0-150002.3.6.2 * mgrctl-5.2.12-150002.3.17.1 * SUSE Multi-Linux Manager Client Tools for SLE 15 (noarch) * python3-mgr-push-5.2.4-150002.3.9.1 * python3-spacewalk-client-tools-5.2.6-150002.3.9.1 * mgrctl-zsh-completion-5.2.12-150002.3.17.1 * python3-defusedxml-0.7.1-150002.1.3.1 * spacecmd-5.2.8-150002.3.12.1 * supportutils-plugin-susemanager-client-5.2.3-150002.3.9.1 * dracut-saltboot-1.2.1-150002.3.9.1 * python3-uyuni-common-libs-5.2.5-150002.3.6.1 * mgr-push-5.2.4-150002.3.9.1 * mgrctl-bash-completion-5.2.12-150002.3.17.1 * mgrctl-lang-5.2.12-150002.3.17.1 * spacewalk-client-tools-5.2.6-150002.3.9.1 * python3-rhnlib-5.2.5-150002.3.9.1 * supportutils-plugin-salt-1.2.3-150002.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-28374.html * https://www.suse.com/security/cve/CVE-2026-28376.html * https://www.suse.com/security/cve/CVE-2026-28379.html * https://www.suse.com/security/cve/CVE-2026-28380.html * https://www.suse.com/security/cve/CVE-2026-28383.html * https://www.suse.com/security/cve/CVE-2026-33376.html * https://www.suse.com/security/cve/CVE-2026-33377.html * https://www.suse.com/security/cve/CVE-2026-33378.html * https://www.suse.com/security/cve/CVE-2026-33380.html * https://www.suse.com/security/cve/CVE-2026-33381.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40179.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-42151.html * https://www.suse.com/security/cve/CVE-2026-42154.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260870 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262222 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1262950 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263501 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1263986 * https://bugzilla.suse.com/show_bug.cgi?id=1263987 * https://bugzilla.suse.com/show_bug.cgi?id=1265281 * https://bugzilla.suse.com/show_bug.cgi?id=1265282 * https://bugzilla.suse.com/show_bug.cgi?id=1265283 * https://bugzilla.suse.com/show_bug.cgi?id=1265284 * https://bugzilla.suse.com/show_bug.cgi?id=1265285 * https://bugzilla.suse.com/show_bug.cgi?id=1265286 * https://bugzilla.suse.com/show_bug.cgi?id=1265287 * https://bugzilla.suse.com/show_bug.cgi?id=1265288 * https://bugzilla.suse.com/show_bug.cgi?id=1265289 * https://bugzilla.suse.com/show_bug.cgi?id=1265290 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://bugzilla.suse.com/show_bug.cgi?id=1266556 * https://bugzilla.suse.com/show_bug.cgi?id=1266600 * https://bugzilla.suse.com/show_bug.cgi?id=1266608 * https://bugzilla.suse.com/show_bug.cgi?id=1267153 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-14816 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:36:18 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:36:18 -0000 Subject: SUSE-RU-2026:2767-1: important: Recommended update 5.1.4 for Multi-Linux Manager Salt Bundle Message-ID: <178334137835.556.896578353292427294@dc2e3449a402> # Recommended update 5.1.4 for Multi-Linux Manager Salt Bundle Announcement ID: SUSE-RU-2026:2767-1 Release Date: 2026-07-06T07:48:02Z Rating: important References: * bsc#1254900 * bsc#1255418 * bsc#1257583 * bsc#1259700 * jsc#MSQA-1056 Affected Products: * SUSE Linux Enterprise Desktop 12 * SUSE Linux Enterprise Desktop 12 SP1 * SUSE Linux Enterprise Desktop 12 SP2 * SUSE Linux Enterprise Desktop 12 SP3 * SUSE Linux Enterprise Desktop 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Multi-Linux Manager Client Tools for SLE 12 An update that contains one feature and has four fixes can now be installed. ## Description: This update fixes the following issues: venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE 12 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-12-2026-2767=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE 12 (aarch64 ppc64le s390x x86_64) * venv-salt-minion-3006.0-120002.5.19.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://jira.suse.com/browse/MSQA-1056 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:36:50 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:36:50 -0000 Subject: SUSE-SU-2026:2766-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334141081.556.12144120152038867154@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2766-1 Release Date: 2026-07-06T07:47:40Z Rating: important References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1248699 * bsc#1248707 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261810 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 Cross-References: * CVE-2022-21698 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 12 * SUSE Linux Enterprise Desktop 12 SP1 * SUSE Linux Enterprise Desktop 12 SP2 * SUSE Linux Enterprise Desktop 12 SP3 * SUSE Linux Enterprise Desktop 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Multi-Linux Manager Client Tools for SLE 12 An update that solves one vulnerability, contains one feature and has 18 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248707) golang-github-boynux-squid_exporter: * Non customer facing changes golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-node_exporter: * Update to 1.10.2: * [BUGFIX] meminfo: Fix typo in Zswap metric name * Update to 1.10.1: * [BUGFIX] filesystem: Fix mount points being collected multiple times * [BUGFIX] filesystem: Refactor mountinfo parsing (bsc#1261810) * [BUGFIX] meminfo: Add Zswap/Zswapped metrics * Update to 1.10.0: * [CHANGE] mdadm: Use sysfs for RAID metrics * [CHANGE] filesystem: Add erofs in default excluded fs * [CHANGE] tcpstat: Use std lib binary.NativeEndian * [FEATURE] pcidevice: Add new collector for PCIe devices * [FEATURE] systemd: Add Virtualization metrics * [FEATURE] swaps: Add new collector * [ENHANCEMENT] wifi: Add packet received and transmitted metrics * [ENHANCEMENT] filesystem: Take super options into account for read-only * [ENHANCEMENT] pcidevice: Add additional metrics * [ENHANCEMENT] perf: Add tlb_data metrics * [BUGFIX] diskstats: Simplify condition * [BUGFIX] thermal: Sanitize darwin thermal strings * [BUGFIX] cpufreq: Fix: collector enable * [BUGFIX] ethtool: Fix returning 0 for sanitized metrics * [BUGFIX] systemd: Fix logging race mgr-push: * Version 5.2.4-0 * Non customer facing changes * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Non customer facing changes prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) rhnlib: * Version 5.2.5-0 * Non customer facing changes * Version 5.2.4-0 * Non customer facing changes * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Non customer facing changes spacecmd: * Version 5.2.8-0 * Non customer facing changes * Version 5.2.7-0 * Add proxy_container_config_nossl command * Version 5.2.6-0 * Update translation strings * Version 5.2.5-0 * Update translation strings * Version 5.2.4-0 * Update translation strings * Version 5.2.3-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Version 5.2.2-0 * Update translation strings * Version 5.2.1-0 * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fix methods in api namespace in spacecmd (bsc#1249532) spacewalk-client-tools: * Version 5.2.6-0 * Non customer facing changes * Version 5.2.5-0 * Update translations * Version 5.2.4-0 * Non customer facing changes * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Update translation strings1260806 * Version 5.2.1-0 * Non customer facing changes supportutils-plugin-susemanager-client: * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Non customer facing changes uyuni-tools: * Version 5.2.12-0 * No customer facing changes * Version 5.2.11-0 * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) * Version 5.2.10-0 * Preserve hub replicas during upgrade (bsc#1262708) * Add mgrctl commands "ssh" and "ssh remove_known_host" * Use a startup check with no limit for the main server container bsc#1263157) * Make uyuni-server service dependent on uyuni-db (bsc#1263823) * Internal SANs for db and reportdb are no longer required * Generate the same certificate for server and reportdb * Update the default tag to 5.1.3.1 (bsc#1262760) * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Use correct CA for Report DB (bsc#1260806) * Version 5.2.9-0 * Do not stop container on health check failure Temporary workaround for bsc#1263157 * Version 5.2.8-0 * Generate service template only after secrets are created * Version 5.2.7-0 * Do not require admin secrets on upgrades (bsc#1262409) * Version 5.2.6-0 * Use podman secrets for SSL on proxy * Fix db online backup with new pg_hba settings * mgrctl copy can now infer target name if not set * No need to expose the cobbler port * Add the TFTP port back to the proxy (bsc#1260905) * Fix the macros in the spec file (bsc#1229105) * Disable TFTP by default on the server * Bump zerolog to 1.34 * Ignore spacewalk-service stop return code. * Stop automatically unhealthy container * Use container based server setup instead tools bundled one * Version 5.2.5-0 * Remove migrate command * Remove template script from mgradm: use the one in the image * Split the TFTP server into a separate container * Adjust mgrctl server filter to work with the new helm chart labels * Remove hub register command * Remove the Kubernetes install and upgrade from mgrpxy - Version 5.2.4-0 * Move the SSL checks at the begining of the migration * Remove Kubernetes code for the mgrdam * Use single universal image to migrate between PostgreSQL versions * Version 5.2.3-0 * Update translation strings * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Actually use the --dbupgrade-tag parameter when computing the image URL (bsc#1249400) * Detect custom Apache and Squid config in the /etc/uyuni/proxy folder * Fix generated DB certificate subject alternate names * add --registry-host, --registry-user and --registry-password to pull images from an authenticate registry * deprecate --registry uyuni-common-libs: * Version 5.2.5-0 * Remove legacy md5/sha1 fallback imports from checksum module; use hashlib directly * Version 5.2.4-0 * Build uyuni-common-libs noarch * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Bump version to 5.2.0 ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE 12 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-12-2026-2766=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE 12 (aarch64 ppc64le s390x x86_64) * prometheus-postgres_exporter-0.10.1-120002.3.3.2 * golang-github-prometheus-node_exporter-1.10.2-120002.3.6.3 * mgrctl-debuginfo-5.2.12-120002.3.15.2 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-120002.3.6.3 * golang-github-boynux-squid_exporter-1.13.0-120002.3.6.1 * mgrctl-5.2.12-120002.3.15.2 * prometheus-postgres_exporter-debuginfo-0.10.1-120002.3.3.2 * golang-github-lusitaniae-apache_exporter-debuginfo-1.0.10-120002.3.9.2 * golang-github-QubitProducts-exporter_exporter-0.4.0-120002.3.6.1 * golang-github-lusitaniae-apache_exporter-1.0.10-120002.3.9.2 * golang-github-boynux-squid_exporter-debuginfo-1.13.0-120002.3.6.1 * SUSE Multi-Linux Manager Client Tools for SLE 12 (noarch) * mgr-push-5.2.4-120002.3.9.1 * python-defusedxml-0.6.0-120002.1.3.1 * python2-rhnlib-5.2.5-120002.3.9.1 * mgrctl-lang-5.2.12-120002.3.15.2 * supportutils-plugin-salt-1.2.3-120002.3.3.1 * python2-uyuni-common-libs-5.2.5-120002.3.6.1 * mgrctl-zsh-completion-5.2.12-120002.3.15.2 * spacecmd-5.2.8-120002.3.12.1 * spacewalk-client-tools-5.2.6-120002.3.9.1 * python2-spacewalk-client-tools-5.2.6-120002.3.9.1 * mgrctl-bash-completion-5.2.12-120002.3.15.2 * python2-mgr-push-5.2.4-120002.3.9.1 * supportutils-plugin-susemanager-client-5.2.3-120002.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:37:16 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:37:16 -0000 Subject: SUSE-SU-2026:2765-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334143614.556.17312227493110798520@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2765-1 Release Date: 2026-07-06T07:47:16Z Rating: important References: * bsc#1227579 * bsc#1235516 * bsc#1236516 * bsc#1238686 * bsc#1248699 * bsc#1248707 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1255418 * bsc#1257583 * bsc#1259700 * bsc#1261810 * jsc#MSQA-1056 * jsc#PED-12485 * jsc#PED-7893 * jsc#PED-7928 Cross-References: * CVE-2022-21698 * CVE-2023-45288 * CVE-2025-22870 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Liberty Linux 7 * SUSE Liberty Linux 7 LTSS * SUSE Liberty Linux LTSS 7 for Oracle Linux * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones An update that solves three vulnerabilities, contains four features and has 10 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * Security issue fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: * Security issues fixed: * CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) * CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) * Highlights of other changes and bug fixes: * Backward Compatibility and packaging changes: * Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains * Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility * Version 1.10.2: * Fixed typo in Zswap metric name (meminfo) * Version 1.10.1: * Fixed mount points being collected multiple times (filesystem) * Refactored mountinfo parsing (bsc#1261810) * Added Zswap/Zswapped metrics (meminfo) * Version 1.10.0: * New collectors: PCIe devices, swaps * Added systemd virtualization metrics, AIX metrics * WiFi packet metrics, additional PCIe and TLB metrics * Changed mdadm to use sysfs, added erofs to excluded filesystems * Fixed bugs: cpufreq collector, ethtool metrics * Version 1.9.1: * Fixed missing IRQ on older kernels (pressure) * Version 1.9.0 (jsc#PED-12485): * Switched to Go log/slog for logging * Converted meminfo to use procfs library * New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, * Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations * Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing * Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) * Version 1.8.x: * Fixed CPU pressure metric collection, pressure collector nil reference * Version 1.8.0: * New collectors: xfrm (IPsec), watchdog * Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing * Removed caching of os-release file modtime/filename * Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race * Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): * New: CPU vulnerabilities reporting from sysfs * Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats * Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index * Version 1.6.0: * Deprecated ntp and supervisord collectors * Removed bcache cache_readaheads_totals metrics * Improved offline CPU handling (removed metrics for offline CPUs) * New: softirqs collector * Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges * Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts mgr-push updated to version 5.2.4: * Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0) prometheus-postgres_exporter: * Security issue fixed: * CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) python-simplejson: * Non customer facing changes rhnlib updated to version 5.2.5: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes spacewalk-client-tools updated to version 5.2.6: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0) uyuni-common-libs updated to version 5.2.5: * Key Update Highlights (v5.2.5-0): * Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using standard hashlib directly * Other changes: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-RES-7-2026-2765=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones (aarch64 ppc64le x86_64) * python-simplejson-3.3.1-70002.1.3.1 * venv-salt-minion-3006.0-70002.5.19.1 * prometheus-postgres_exporter-0.10.1-70002.3.3.3 * golang-github-lusitaniae-apache_exporter-1.0.10-70002.3.9.3 * golang-github-prometheus-node_exporter-1.10.2-70002.3.3.3 * golang-github-QubitProducts-exporter_exporter-0.4.0-70002.3.6.2 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones (noarch) * spacewalk-client-tools-5.2.6-70002.3.9.1 * mgr-push-5.2.4-70002.3.9.2 * python2-rhnlib-5.2.5-70002.3.9.1 * python2-uyuni-common-libs-5.2.5-70002.3.6.1 * spacecmd-5.2.8-70002.3.12.1 * python2-spacewalk-client-tools-5.2.6-70002.3.9.1 * python2-mgr-push-5.2.4-70002.3.9.2 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1235516 * https://bugzilla.suse.com/show_bug.cgi?id=1236516 * https://bugzilla.suse.com/show_bug.cgi?id=1238686 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-12485 * https://jira.suse.com/browse/PED-7893 * https://jira.suse.com/browse/PED-7928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:37:57 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:37:57 -0000 Subject: SUSE-SU-2026:2764-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334147749.556.17453344549099930905@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2764-1 Release Date: 2026-07-06T07:46:41Z Rating: important References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1235516 * bsc#1236516 * bsc#1238686 * bsc#1248699 * bsc#1248707 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1257583 * bsc#1259700 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261810 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 * jsc#PED-12485 * jsc#PED-7893 * jsc#PED-7928 Cross-References: * CVE-2022-21698 * CVE-2023-45288 * CVE-2025-22870 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones An update that solves three vulnerabilities, contains four features and has 22 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * Security issue fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: * Security issues fixed: * CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) * CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) * Highlights of other changes and bug fixes: * Backward Compatibility and packaging changes: * Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains * Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility * Version 1.10.2: * Fixed typo in Zswap metric name (meminfo) * Version 1.10.1: * Fixed mount points being collected multiple times (filesystem) * Refactored mountinfo parsing (bsc#1261810) * Added Zswap/Zswapped metrics (meminfo) * Version 1.10.0: * New collectors: PCIe devices, swaps * Added systemd virtualization metrics, AIX metrics * WiFi packet metrics, additional PCIe and TLB metrics * Changed mdadm to use sysfs, added erofs to excluded filesystems * Fixed bugs: cpufreq collector, ethtool metrics * Version 1.9.1: * Fixed missing IRQ on older kernels (pressure) * Version 1.9.0 (jsc#PED-12485): * Switched to Go log/slog for logging * Converted meminfo to use procfs library * New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, * Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations * Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing * Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) * Version 1.8.x: * Fixed CPU pressure metric collection, pressure collector nil reference * Version 1.8.0: * New collectors: xfrm (IPsec), watchdog * Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing * Removed caching of os-release file modtime/filename * Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race * Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): * New: CPU vulnerabilities reporting from sysfs * Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats * Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index * Version 1.6.0: * Deprecated ntp and supervisord collectors * Removed bcache cache_readaheads_totals metrics * Improved offline CPU handling (removed metrics for offline CPUs) * New: softirqs collector * Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges * Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: * Security Fixes: * CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: * Non customer facing changes spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0) * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0) * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Fixed Report DB CA certificate (bsc#1260806) * Key Update Highlights (v5.2.7-0) * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0) * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Key Update Highlights (v5.2.5-0) * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0) * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-EL-8-2026-2764=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones (noarch) * scap-security-guide-redhat-0.1.79-80002.3.9.6 * mgrctl-zsh-completion-5.2.12-80002.3.12.4 * mgrctl-bash-completion-5.2.12-80002.3.12.4 * spacecmd-5.2.8-80002.3.12.4 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones (aarch64 ppc64le x86_64) * prometheus-postgres_exporter-0.10.1-80002.3.3.6 * mgrctl-5.2.12-80002.3.12.4 * golang-github-prometheus-node_exporter-1.10.2-80002.3.3.6 * golang-github-QubitProducts-exporter_exporter-debuginfo-0.4.0-80002.3.6.6 * golang-github-QubitProducts-exporter_exporter-debugsource-0.4.0-80002.3.6.6 * golang-github-QubitProducts-exporter_exporter-0.4.0-80002.3.6.6 * golang-github-lusitaniae-apache_exporter-1.0.10-80002.3.9.6 * venv-salt-minion-3006.0-80002.5.19.1 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1235516 * https://bugzilla.suse.com/show_bug.cgi?id=1236516 * https://bugzilla.suse.com/show_bug.cgi?id=1238686 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-12485 * https://jira.suse.com/browse/PED-7893 * https://jira.suse.com/browse/PED-7928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:38:44 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:38:44 -0000 Subject: SUSE-SU-2026:2763-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334152432.556.7293512188411577410@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2763-1 Release Date: 2026-07-06T07:46:11Z Rating: important References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1235516 * bsc#1236516 * bsc#1238686 * bsc#1248699 * bsc#1248707 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1257583 * bsc#1259700 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261810 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 * jsc#PED-12485 * jsc#PED-7893 * jsc#PED-7928 Cross-References: * CVE-2022-21698 * CVE-2023-45288 * CVE-2025-22870 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones An update that solves three vulnerabilities, contains four features and has 22 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * Security issue fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: * Security issues fixed: * CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) * CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) * Highlights of other changes and bug fixes: * Backward Compatibility and packaging changes: * Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains * Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility * Version 1.10.2: * Fixed typo in Zswap metric name (meminfo) * Version 1.10.1: * Fixed mount points being collected multiple times (filesystem) * Refactored mountinfo parsing (bsc#1261810) * Added Zswap/Zswapped metrics (meminfo) * Version 1.10.0: * New collectors: PCIe devices, swaps * Added systemd virtualization metrics, AIX metrics * WiFi packet metrics, additional PCIe and TLB metrics * Changed mdadm to use sysfs, added erofs to excluded filesystems * Fixed bugs: cpufreq collector, ethtool metrics * Version 1.9.1: * Fixed missing IRQ on older kernels (pressure) * Version 1.9.0 (jsc#PED-12485): * Switched to Go log/slog for logging * Converted meminfo to use procfs library * New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, * Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations * Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing * Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) * Version 1.8.x: * Fixed CPU pressure metric collection, pressure collector nil reference * Version 1.8.0: * New collectors: xfrm (IPsec), watchdog * Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing * Removed caching of os-release file modtime/filename * Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race * Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): * New: CPU vulnerabilities reporting from sysfs * Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats * Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index * Version 1.6.0: * Deprecated ntp and supervisord collectors * Removed bcache cache_readaheads_totals metrics * Improved offline CPU handling (removed metrics for offline CPUs) * New: softirqs collector * Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges * Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: * Security Fixes: * CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: * Non customer facing changes spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes uyuni-tools: uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0) * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0) * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Fixed Report DB CA certificate (bsc#1260806) * Key Update Highlights (v5.2.7-0) * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0) * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Key Update Highlights (v5.2.5-0) * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0) * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-EL-9-2026-2763=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones (aarch64 ppc64le s390x x86_64) * mgrctl-5.2.12-90002.3.12.1 * golang-github-lusitaniae-apache_exporter-1.0.10-90002.3.9.4 * venv-salt-minion-3006.0-90002.5.19.1 * golang-github-QubitProducts-exporter_exporter-debugsource-0.4.0-90002.3.6.4 * golang-github-QubitProducts-exporter_exporter-0.4.0-90002.3.6.4 * golang-github-QubitProducts-exporter_exporter-debuginfo-0.4.0-90002.3.6.4 * prometheus-postgres_exporter-0.10.1-90002.3.3.4 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones (noarch) * spacecmd-5.2.8-90002.3.12.1 * scap-security-guide-redhat-0.1.79-90002.3.9.1 * mgrctl-bash-completion-5.2.12-90002.3.12.1 * mgrctl-zsh-completion-5.2.12-90002.3.12.1 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones (aarch64 ppc64le x86_64) * golang-github-prometheus-node_exporter-1.10.2-90002.3.3.4 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1235516 * https://bugzilla.suse.com/show_bug.cgi?id=1236516 * https://bugzilla.suse.com/show_bug.cgi?id=1238686 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-12485 * https://jira.suse.com/browse/PED-7893 * https://jira.suse.com/browse/PED-7928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:39:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:39:20 -0000 Subject: SUSE-RU-2026:2762-1: important: Recommended update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334156060.556.13289117077859917889@dc2e3449a402> # Recommended update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-RU-2026:2762-1 Release Date: 2026-07-06T07:45:36Z Rating: important References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1255418 * bsc#1257583 * bsc#1259700 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261810 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 Affected Products: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 10, RHEL and clones An update that contains one feature and has 21 fixes can now be installed. ## Description: This update fixes the following issues: golang-github-prometheus-node_exporter: * Initial package release providing version 1.10.2 spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0): * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0): * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Fixed Report DB CA certificate (bsc#1260806) * Key Update Highlights (v5.2.7-0): * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0): * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Key Update Highlights (v5.2.5-0): * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0): * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 10, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-EL-10-2026-2762=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 10, RHEL and clones (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-node_exporter-debuginfo-1.10.2-100002.1.3.1 * golang-github-prometheus-node_exporter-debugsource-1.10.2-100002.1.3.1 * golang-github-prometheus-node_exporter-1.10.2-100002.1.3.1 * venv-salt-minion-3006.0-100002.1.10.1 * mgrctl-5.2.12-100002.1.6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 10, RHEL and clones (noarch) * mgrctl-bash-completion-5.2.12-100002.1.6.1 * spacecmd-5.2.8-100002.1.6.1 * mgrctl-zsh-completion-5.2.12-100002.1.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:39:27 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:39:27 -0000 Subject: SUSE-RU-2026:2761-1: important: Recommended update for resource-agents Message-ID: <178334156774.556.16340084265897781521@dc2e3449a402> # Recommended update for resource-agents Announcement ID: SUSE-RU-2026:2761-1 Release Date: 2026-07-06T06:33:24Z Rating: important References: * bsc#1251836 * bsc#1269009 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Availability Extension 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has two fixes can now be installed. ## Description: This update for resource-agents fixes the following issues: * Fix: L3: Backport upstream commit resource-agents (bsc#1269009) * Fix: ec2 and awsvip resource agent's retry mechanism for AWS monitoring (bsc#1251836) * Add auth_type parameter and AWS Policy based authentication type ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2026-2761=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2761=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * resource-agents-4.12.0+git30.7fd7c8fa-150500.3.23.1 * resource-agents-zfs-4.12.0+git30.7fd7c8fa-150500.3.23.1 * resource-agents-debuginfo-4.12.0+git30.7fd7c8fa-150500.3.23.1 * ldirectord-4.12.0+git30.7fd7c8fa-150500.3.23.1 * resource-agents-debugsource-4.12.0+git30.7fd7c8fa-150500.3.23.1 * openSUSE Leap 15.5 (noarch) * monitoring-plugins-metadata-4.12.0+git30.7fd7c8fa-150500.3.23.1 * SUSE Linux Enterprise High Availability Extension 15 SP5 (aarch64 ppc64le s390x x86_64) * resource-agents-4.12.0+git30.7fd7c8fa-150500.3.23.1 * resource-agents-debugsource-4.12.0+git30.7fd7c8fa-150500.3.23.1 * ldirectord-4.12.0+git30.7fd7c8fa-150500.3.23.1 * resource-agents-debuginfo-4.12.0+git30.7fd7c8fa-150500.3.23.1 * SUSE Linux Enterprise High Availability Extension 15 SP5 (noarch) * monitoring-plugins-metadata-4.12.0+git30.7fd7c8fa-150500.3.23.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1251836 * https://bugzilla.suse.com/show_bug.cgi?id=1269009 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:39:33 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:39:33 -0000 Subject: SUSE-SU-2026:2760-1: important: Security update for libnfs Message-ID: <178334157338.556.15281568542868148044@dc2e3449a402> # Security update for libnfs Announcement ID: SUSE-SU-2026:2760-1 Release Date: 2026-07-06T04:05:32Z Rating: important References: * bsc#1268135 Cross-References: * CVE-2026-53689 CVSS scores: * CVE-2026-53689 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-53689 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libnfs fixes the following issue * CVE-2026-53689: integer overflow during a connection to a crafted NFS server (bsc#1268135). Changes for libnfs: * Add libnfs-CVE-2026-53689.patch: ZDR: check the string size for sanity (bsc#1268135 CVE-2026-53689). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2760=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2760=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2760=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2760=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2760=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2760=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2760=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2760=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2760=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2760=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2760=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2760=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libnfs8-1.11.0-150000.3.3.1 * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53689.html * https://bugzilla.suse.com/show_bug.cgi?id=1268135 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:39:55 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 12:39:55 -0000 Subject: SUSE-SU-2026:2759-1: important: Security update for apache2 Message-ID: <178334159523.556.6114502680902785127@dc2e3449a402> # Security update for apache2 Announcement ID: SUSE-SU-2026:2759-1 Release Date: 2026-07-06T02:04:25Z Rating: important References: * bsc#1267503 * bsc#1267955 * bsc#1267956 * bsc#1267962 * bsc#1267963 * bsc#1267965 * bsc#1267969 * bsc#1267970 * bsc#1267971 * bsc#1267972 * bsc#1267976 * bsc#1267977 * bsc#1267978 Cross-References: * CVE-2026-29167 * CVE-2026-29170 * CVE-2026-34355 * CVE-2026-34356 * CVE-2026-42535 * CVE-2026-42536 * CVE-2026-43951 * CVE-2026-44119 * CVE-2026-44185 * CVE-2026-44186 * CVE-2026-44631 * CVE-2026-48913 * CVE-2026-49975 CVSS scores: * CVE-2026-29167 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29167 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29170 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-29170 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34355 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34356 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42535 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42535 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-42535 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42536 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43951 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43951 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-43951 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44119 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44119 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44186 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44186 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44186 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44631 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44631 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48913 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48913 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48913 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-49975 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-49975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978). * CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955). * CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956). * CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962). * CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963). * CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965). * CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969). * CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of service (bsc#1267970). * CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971). * CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free (bsc#1267972). * CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2759=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2759=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2759=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-prefork-2.4.66-150700.4.23.1 * apache2-debuginfo-2.4.66-150700.4.23.1 * apache2-prefork-debuginfo-2.4.66-150700.4.23.1 * apache2-prefork-debugsource-2.4.66-150700.4.23.1 * apache2-2.4.66-150700.4.23.1 * apache2-debugsource-2.4.66-150700.4.23.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-utils-debuginfo-2.4.66-150700.4.23.1 * apache2-worker-debuginfo-2.4.66-150700.4.23.1 * apache2-worker-2.4.66-150700.4.23.1 * apache2-worker-debugsource-2.4.66-150700.4.23.1 * apache2-devel-2.4.66-150700.4.23.1 * apache2-utils-2.4.66-150700.4.23.1 * apache2-utils-debugsource-2.4.66-150700.4.23.1 * Server Applications Module 15-SP7 (noarch) * apache2-manual-2.4.66-150700.4.23.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-event-debugsource-2.4.66-150700.4.23.1 * apache2-event-2.4.66-150700.4.23.1 * apache2-event-debuginfo-2.4.66-150700.4.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29167.html * https://www.suse.com/security/cve/CVE-2026-29170.html * https://www.suse.com/security/cve/CVE-2026-34355.html * https://www.suse.com/security/cve/CVE-2026-34356.html * https://www.suse.com/security/cve/CVE-2026-42535.html * https://www.suse.com/security/cve/CVE-2026-42536.html * https://www.suse.com/security/cve/CVE-2026-43951.html * https://www.suse.com/security/cve/CVE-2026-44119.html * https://www.suse.com/security/cve/CVE-2026-44185.html * https://www.suse.com/security/cve/CVE-2026-44186.html * https://www.suse.com/security/cve/CVE-2026-44631.html * https://www.suse.com/security/cve/CVE-2026-48913.html * https://www.suse.com/security/cve/CVE-2026-49975.html * https://bugzilla.suse.com/show_bug.cgi?id=1267503 * https://bugzilla.suse.com/show_bug.cgi?id=1267955 * https://bugzilla.suse.com/show_bug.cgi?id=1267956 * https://bugzilla.suse.com/show_bug.cgi?id=1267962 * https://bugzilla.suse.com/show_bug.cgi?id=1267963 * https://bugzilla.suse.com/show_bug.cgi?id=1267965 * https://bugzilla.suse.com/show_bug.cgi?id=1267969 * https://bugzilla.suse.com/show_bug.cgi?id=1267970 * https://bugzilla.suse.com/show_bug.cgi?id=1267971 * https://bugzilla.suse.com/show_bug.cgi?id=1267972 * https://bugzilla.suse.com/show_bug.cgi?id=1267976 * https://bugzilla.suse.com/show_bug.cgi?id=1267977 * https://bugzilla.suse.com/show_bug.cgi?id=1267978 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:30:07 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:30:07 -0000 Subject: SUSE-SU-2026:22510-1: important: Security update for pacemaker Message-ID: <178335540780.4636.15465907897409025325@4d746be3175e> # Security update for pacemaker Announcement ID: SUSE-SU-2026:22510-1 Release Date: 2026-06-29T10:55:21Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1108=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * pacemaker-remote-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-remote-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debugsource-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-devel-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-3.0.0+20250218.64cd85422c-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * pacemaker-schemas-3.0.0+20250218.64cd85422c-160000.4.1 * python3-pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cts-3.0.0+20250218.64cd85422c-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:30:26 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:30:26 -0000 Subject: SUSE-SU-2026:22509-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Message-ID: <178335542651.4636.6388870765214838802@4d746be3175e> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22509-1 Release Date: 2026-06-29T10:33:17Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.30.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1106=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1106=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_9-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-3-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-debuginfo-3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_9-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-3-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-debuginfo-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:30:47 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:30:47 -0000 Subject: SUSE-SU-2026:22508-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Message-ID: <178335544708.4636.9049410857675559460@4d746be3175e> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22508-1 Release Date: 2026-06-29T10:26:40Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1107=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1107=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_32-default-debuginfo-3-160000.1.1 * kernel-livepatch-6_12_0-160000_32-default-3-160000.1.1 * kernel-livepatch-SLE16_Update_11-debugsource-3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_32-default-debuginfo-3-160000.1.1 * kernel-livepatch-SLE16_Update_11-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_32-default-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:02 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:31:02 -0000 Subject: SUSE-SU-2026:22507-1: important: Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Message-ID: <178335546299.4636.15462076942667093748@4d746be3175e> # Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22507-1 Release Date: 2026-06-29T07:44:21Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.26.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1101=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1101=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_26-default-debuginfo-7-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-7-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-7-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_26-default-debuginfo-7-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-7-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:31:11 -0000 Subject: SUSE-SU-2026:22506-1: moderate: Security update for lcms2 Message-ID: <178335547108.4636.8753351889861495675@4d746be3175e> # Security update for lcms2 Announcement ID: SUSE-SU-2026:22506-1 Release Date: 2026-07-01T12:17:04Z Rating: moderate References: * bsc#1263703 * bsc#1264994 Cross-References: * CVE-2026-41254 * CVE-2026-42798 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42798 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-42798 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for lcms2 fixes the following issues * CVE-2026-41254: integer overflow in CubeSize in cmslut.c (bsc#1264994). * CVE-2026-42798: integer overflow in ParseCube in cmscgats.c (bsc#1263703). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1125=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1125=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * liblcms2-doc-2.16-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * liblcms2-devel-2.16-160000.4.1 * liblcms2-2-2.16-160000.4.1 * liblcms2-2-debuginfo-2.16-160000.4.1 * lcms2-2.16-160000.4.1 * lcms2-debugsource-2.16-160000.4.1 * lcms2-debuginfo-2.16-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * liblcms2-2-2.16-160000.4.1 * liblcms2-2-debuginfo-2.16-160000.4.1 * lcms2-2.16-160000.4.1 * liblcms2-devel-2.16-160000.4.1 * lcms2-debugsource-2.16-160000.4.1 * lcms2-debuginfo-2.16-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * liblcms2-doc-2.16-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-42798.html * https://bugzilla.suse.com/show_bug.cgi?id=1263703 * https://bugzilla.suse.com/show_bug.cgi?id=1264994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:16 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:31:16 -0000 Subject: SUSE-RU-2026:22505-1: moderate: Recommended update for patterns-base Message-ID: <178335547657.4636.2510122669892597010@4d746be3175e> # Recommended update for patterns-base Announcement ID: SUSE-RU-2026:22505-1 Release Date: 2026-07-01T12:14:45Z Rating: moderate References: * bsc#1263084 * jsc#PED-15697 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature and has one fix can now be installed. ## Description: This update for patterns-base fixes the following issues: * make kernel_livepatching pattern visible (bsc#1263084) * add fwupd to enhanced base pattern (jsc#PED-15697) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1126=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1126=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * patterns-base-kernel_livepatching-20241218-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * patterns-base-fips-20241218-160000.4.1 * patterns-base-base-20241218-160000.4.1 * patterns-base-documentation-20241218-160000.4.1 * patterns-base-enhanced_base-20241218-160000.4.1 * patterns-base-selinux-20241218-160000.4.1 * patterns-base-basesystem-20241218-160000.4.1 * patterns-base-bootloader-20241218-160000.4.1 * patterns-base-minimal_base-20241218-160000.4.1 * patterns-base-sw_management-20241218-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * patterns-base-fips-20241218-160000.4.1 * patterns-base-kernel_livepatching-20241218-160000.4.1 * patterns-base-base-20241218-160000.4.1 * patterns-base-documentation-20241218-160000.4.1 * patterns-base-enhanced_base-20241218-160000.4.1 * patterns-base-selinux-20241218-160000.4.1 * patterns-base-basesystem-20241218-160000.4.1 * patterns-base-bootloader-20241218-160000.4.1 * patterns-base-minimal_base-20241218-160000.4.1 * patterns-base-sw_management-20241218-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1263084 * https://jira.suse.com/browse/PED-15697 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:27 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:31:27 -0000 Subject: SUSE-SU-2026:22504-1: important: Security update for jackson-annotations, jackson-core, jackson-databind Message-ID: <178335548786.4636.5815053832876868359@4d746be3175e> # Security update for jackson-annotations, jackson-core, jackson-databind Announcement ID: SUSE-SU-2026:22504-1 Release Date: 2026-07-01T09:06:57Z Rating: important References: * bsc#1268603 * bsc#1268897 * bsc#1268898 * bsc#1268899 * bsc#1268902 Cross-References: * CVE-2026-54512 * CVE-2026-54513 * CVE-2026-54514 * CVE-2026-54515 CVSS scores: * CVE-2026-54512 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54512 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54514 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54514 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54515 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54515 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for jackson-annotations, jackson-core, jackson-databind fixes the following issues * CVE-2026-54512: jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation (bsc#1268897). * CVE-2026-54513: jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (bsc#1268898). * CVE-2026-54514: InetSocketAddress deserialization triggers eager DNS resolution (bsc#1268899). * CVE-2026-54515: jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties (bsc#1268902). * document length constraint bypass in blocking, async, and DataInput parsers (bsc#1268603). Changes for jackson-annotations: * Update to 2.18.8 * No changes since 2.17.3 Changes for jackson-core: * Update to 2.18.8 * Changes of 2.18.8 * # 1611: Apply number-length validator on streaming integer path of async parser * Changes of 2.18.7 * # 1570: Fail parsing from 'DataInput' if 'StreamReadConstraints .getMaxDocumentLength()' set (bsc#1268603, GHSA-2m67-wjpj-xhg9) * # 1600: Rework 3rd party licenses in jar * # 1602: 'UTF8DataInputJsonParser' needs to enforce 'StreamReadConstraints.maxNameLength' limit * Changes of 2.18.6 * # 1512: Number-parsing fix for 'UTF8DataInputJsonParser' * # 1548: 'StreamReadConstraints.maxDocumentLength' not checked when creating parser with fixed buffer * # 1555: Enforce 'StreamReadConstraints.maxNumberLength' for non-blocking (async) parser * Changes of 2.18.5 * # 1433: 'JsonParser#getNumberType()' throws 'JsonParseException' when the current token is non-numeric instead of returning null * # 1446: Invalid package reference to "java.lang.foreign" from 'com.fasterxml.jackson.core:jackson-core' (from 'FastDoubleParser') * Changes of 2.18.3 * # 1391: Fix issue where the parser can read back old number state when parsing later numbers * # 1397: Jackson changes additional values to infinite in case of special JSON structures and existing infinite values * # 1398: Fix issue that feature COMBINE_UNICODE_SURROGATES_IN_UTF8 doesn't work when custom characterEscape is used * Changes of 2.18.2 * # 1359: Non-surrogate characters being incorrectly combined when 'JsonWriteFeature.COMBINE_UNICODE_SURROGATES_IN_UTF8' is enabled * Changes of 2.18.1 * # 1353: Use fastdoubleparser 1.0.90 * Changes of 2.18. * # 223: 'UTF8JsonGenerator' writes supplementary characters as a surrogate pair: should use 4-byte encoding * # 1230: Improve performance of 'float' and 'double' parsing from 'TextBuffer' * # 1251: 'InternCache' replace synchronized with 'ReentrantLock' * the cache size limit is no longer strictly enforced for performance reasons but we should never go far about the limit * # 1252: 'ThreadLocalBufferManager' replace synchronized with 'ReentrantLock' * # 1257: Increase InternCache default max size from 100 to 200 * # 1262: Add diagnostic method 'pooledCount()' in 'RecyclerPool' * # 1264: Rename shaded 'ch.randelshofer:fastdoubleparser' classes to prevent use by downstream consumers * # 1271: Deprecate 'LockFreePool' implementation in 2.18 (remove from 3.0) * # 1274: 'NUL'-corrupted keys, values on JSON serialization * # 1277: Add back Java 22 optimisation in FastDoubleParser * # 1284: Optimize 'JsonParser.getDoubleValue()/getFloatValue() /getDecimalValue()' to avoid String allocation * # 1305: Make helper methods of 'WriterBasedJsonGenerator' non-final to allow overriding * # 1310: Add new 'StreamReadConstraints' ('maxTokenCount') to limit maximum number of Tokens allowed per document# * # 1331: Update to FastDoubleParser v1.0.1 to fix 'BigDecimal' decoding proble Changes for jackson-databind: * Update to 2.18.8 * Changes of 2.18.8 * # 5950: Improve 'UUIDeserializer' error handling * # 5951: Improve 'InetSocketAddress' deserialization (bsc#1268899, CVE-2026-54514) * # 5969: '@JsonView' by-passed for some "setterless" creator properties * # 5971: '@JsonView' by-passed for unwrapped creator parameters * # 5974: '@JsonIgnore' on Record property ignored with 'PropertyNamingStrategy' * # 5981: 'BasicPolymorphicTypeValidator' setting 'allowIfSubTypeIsArray()' should validate element type (bsc#1268898, CVE-2026-54513) * # 5988: 'PolymorphicTypeValidator' needs to validate generic type parameters too (bsc#1268897, CVE-2026-54512) * # 5993: 'UPPER_SNAKE_CASE' / 'LOWER_CASE' 'NamingStrategyImpls' fold case using JVM default locale (Turkish-I bug) * Changes of 2.18.4 * # 4628: '@JsonIgnore' and '@JsonProperty.access=READ_ONLY' on Record property ignored for deserialization * # 5049: Duplicate creator property "b" (index 0 vs 1) on simple java record * Changes of 2.18.3 * # 4444: The 'KeyDeserializer' specified in the class with '@JsonDeserialize(keyUsing = ...)' is overwritten by the 'KeyDeserializer' specified in the 'ObjectMapper'. * # 4827: Subclassed Throwable deserialization fails since v2.18.0 - no creator index for property 'cause' * # 4844: Fix wrapped array handling wrt 'null' by 'StdDeserializer' * # 4848: Avoid type pollution in 'StringCollectionDeserializer' * # 4860: 'ConstructorDetector.USE_PROPERTIES_BASED' does not work with multiple constructors since 2.18 * # 4878: When serializing a Map via Converter(StdDelegatingSerializer), a NullPointerException is thrown due to missing key serializer * # 4908: Deserialization behavior change with @JsonCreator and @ConstructorProperties between 2.17 and 2.18 * # 4917: 'BigDecimal' deserialization issue when using '@JsonCreator' * # 4920: Creator properties are ignored on abstract types when collecting bean properties, breaking AsExternalTypeDeserializer * # 4922: Failing '@JsonMerge' with a custom Map * # 4932: Conversion of 'MissingNode' throws 'JsonProcessingException' * Changes of 2.18.2 * # 4733: Wrong serialization of Type Ids for certain types of Enum values * # 4742: Deserialization with Builder, External type id, '@JsonCreator' failing * # 4777: 'StdValueInstantiator.withArgsCreator' is now set for creators with no arguments * # 4783 Possibly wrong behavior of @JsonMerge * # 4787: Wrong 'String.format()' in 'StdDelegatingDeserializer' hides actual error * # 4788: 'EnumFeature.WRITE_ENUMS_TO_LOWERCASE' overrides '@JsonProperty' values * # 4790: Fix '@JsonAnySetter' issue with "setter" method (related to #4639) * # 4807: Improve 'FactoryBasedEnumDeserializer' to work better with XML module * # 4810: Deserialization using '@JsonCreator' with renamed property failing (since 2.18) * Changes of 2.18.1 * # 4508: Deserialized JsonAnySetter field in Kotlin data class is null * # 4639: @JsonAnySetter on field ignoring unrecognized properties if they are declared before the last recognized properties in JSON * # 4718: Should not fail on trying to serialize 'java.time.DateTimeException' * # 4724: Deserialization behavior change with Records, '@JsonCreator' and '@JsonValue' between 2.17 and 2.18 * # 4727: Eclipse having issues due'module-info' class "lost" on 2.18.0 jars * # 4741: When 'Include.NON_DEFAULT' setting is used on POJO, empty values are not included in json if default is 'null' * # 4749: Fixed a problem with 'StdDelegatingSerializer#serializeWithType' looking up the serializer with the wrong argument * Changes of 2.18.0 * # 562: Allow '@JsonAnySetter' to flow through Creators * # 806: Problem with 'NamingStrategy', creator methods with implicit names * # 2977: Incompatible 'FAIL_ON_MISSING_PRIMITIVE_PROPERTIES' and field level '@JsonProperty' * # 3120: Return 'ListIterator' from 'ArrayNode.elements()' * # 3241: 'constructorDetector' seems to invalidate 'defaultSetterInfo' for nullability * # 3439: Java Record '@JsonAnySetter' value is null after deserialization * # 4085: '@JsonView' does not work on class-level for records * # 4119: Exception when deserialization uses a record with a constructor property with 'access=READ_ONLY' * # 4356: 'BeanDeserializerModifier::updateBuilder()' doesn't work for beans with Creator methods * # 4407: 'null' type id handling does not work with 'writeTypePrefix()' * # 4452: '@JsonProperty' not serializing field names properly on '@JsonCreator' in Record * # 4453: Allow JSON Integer to deserialize into a single-arg constructor of parameter type 'double' * # 4456: Rework locking in 'DeserializerCache' * # 4458: Rework synchronized block from 'BeanDeserializerBase' * # 4464: When 'Include.NON_DEFAULT' setting is used, 'isEmpty()' method is not called on the serializer * # 4472: Rework synchronized block in 'TypeDeserializerBase' * # 4483: Remove 'final' on method BeanSerializer.serialize() * # 4515: Rewrite Bean Property Introspection logic in Jackson 2.x * # 4545: Unexpected deserialization behavior with '@JsonCreator', '@JsonProperty' and javac '-parameters' * # 4570: Deprecate 'ObjectMapper.canDeserialize()'/'ObjectMapper .canSerialize()' * # 4580: Add 'MapperFeature .SORT_CREATOR_PROPERTIES_BY_DECLARATION_ORDER' to use Creator properties' declaration order for sorting * # 4584: Provide extension point for detecting "primary" Constructor for Kotlin (and similar) data classes * # 4602: Possible wrong use of _arrayDelegateDeserializer in BeanDeserializerBase::deserializeFromObjectUsingNonDefault() * # 4617: Record property serialization order not preserved * # 4626: '@JsonIgnore' on Record property ignored for deserialization, if there is getter override * # 4630: '@JsonIncludeProperties', '@JsonIgnoreProperties' ignored when serializing Records, if there is getter override * # 4634: '@JsonAnySetter' not working when annotated on both constructor parameter & field * # 4678: Java records don't serialize with 'MapperFeature .REQUIRE_SETTERS_FOR_GETTERS' * # 4688: Should allow deserializing with no-arg '@JsonCreator(mode = DELEGATING)' * # 4694: Deserializing 'BigDecimal' with large number of decimals result in incorrect value * # 4699: Add extra 'writeNumber()' method in 'TokenBuffer' * # 4709: Add 'JacksonCollectors' with 'toArrayNode()' implementation * Fix #5962: Case-insensitive deserialization may use wrong @JsonIgnoreProperties (bsc#1268902, CVE-2026-54515) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1124=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1124=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * jackson-core-2.18.8-160000.1.1 * jackson-databind-javadoc-2.18.8-160000.1.1 * jackson-databind-2.18.8-160000.1.1 * jackson-annotations-2.18.8-160000.1.1 * jackson-annotations-javadoc-2.18.8-160000.1.1 * jackson-core-javadoc-2.18.8-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * jackson-core-2.18.8-160000.1.1 * jackson-databind-javadoc-2.18.8-160000.1.1 * jackson-databind-2.18.8-160000.1.1 * jackson-annotations-2.18.8-160000.1.1 * jackson-annotations-javadoc-2.18.8-160000.1.1 * jackson-core-javadoc-2.18.8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54512.html * https://www.suse.com/security/cve/CVE-2026-54513.html * https://www.suse.com/security/cve/CVE-2026-54514.html * https://www.suse.com/security/cve/CVE-2026-54515.html * https://bugzilla.suse.com/show_bug.cgi?id=1268603 * https://bugzilla.suse.com/show_bug.cgi?id=1268897 * https://bugzilla.suse.com/show_bug.cgi?id=1268898 * https://bugzilla.suse.com/show_bug.cgi?id=1268899 * https://bugzilla.suse.com/show_bug.cgi?id=1268902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:33 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:31:33 -0000 Subject: SUSE-RU-2026:22503-1: moderate: Recommended update for grpc Message-ID: <178335549346.4636.7221898489229408054@4d746be3175e> # Recommended update for grpc Announcement ID: SUSE-RU-2026:22503-1 Release Date: 2026-07-01T09:05:02Z Rating: moderate References: * bsc#1264447 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for grpc fixes the following issue * Update to release 1.60 (bsc#1264447): * Implemented dualstack IPv4 and IPv6 backend support, as per draft gRFC A61. xDS support currently guarded by GRPC_EXPERIMENTAL_XDS_DUALSTACK_ENDPOINTS env var. * Support for setting proxy for addresses. * Add v1 reflection. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1112=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1112=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * grpc-devel-debuginfo-1.60.0-160000.1.1 * upb-devel-1.60.0-160000.1.1 * libupb37-debuginfo-1.60.0-160000.1.1 * grpc-devel-1.60.0-160000.1.1 * grpc-debuginfo-1.60.0-160000.1.1 * libgrpc1_60-1.60.0-160000.1.1 * libgrpc++1_60-debuginfo-1.60.0-160000.1.1 * libgrpc37-1.60.0-160000.1.1 * libgrpc1_60-debuginfo-1.60.0-160000.1.1 * libgrpc++1_60-1.60.0-160000.1.1 * libupb37-1.60.0-160000.1.1 * grpc-debugsource-1.60.0-160000.1.1 * libgrpc37-debuginfo-1.60.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * grpc-devel-debuginfo-1.60.0-160000.1.1 * upb-devel-1.60.0-160000.1.1 * grpc-debuginfo-1.60.0-160000.1.1 * grpc-devel-1.60.0-160000.1.1 * libupb37-debuginfo-1.60.0-160000.1.1 * libgrpc1_60-1.60.0-160000.1.1 * libgrpc++1_60-debuginfo-1.60.0-160000.1.1 * libgrpc37-1.60.0-160000.1.1 * libgrpc1_60-debuginfo-1.60.0-160000.1.1 * libgrpc++1_60-1.60.0-160000.1.1 * libupb37-1.60.0-160000.1.1 * grpc-debugsource-1.60.0-160000.1.1 * libgrpc37-debuginfo-1.60.0-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1264447 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:40 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:31:40 -0000 Subject: SUSE-RU-2026:22502-1: moderate: Recommended update for zstd-jni Message-ID: <178335550015.4636.7391172167453662217@4d746be3175e> # Recommended update for zstd-jni Announcement ID: SUSE-RU-2026:22502-1 Release Date: 2026-06-30T08:35:50Z Rating: moderate References: * bsc#1269480 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for zstd-jni fixes the following issues: Changes in zstd-jni: Update to v1.5.7.11: * no structured changelog provided by upstream * Build with max-page-size of 64K on ppc64le (bsc#1269480) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1111=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1111=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * zstd-jni-1.5.7.11-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * zstd-jni-1.5.7.11-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269480 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:43 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:31:43 -0000 Subject: SUSE-RU-2026:22501-1: moderate: Recommended update for pqcverification-zypp-plugin Message-ID: <178335550381.4636.16836479829436407155@4d746be3175e> # Recommended update for pqcverification-zypp-plugin Announcement ID: SUSE-RU-2026:22501-1 Release Date: 2026-06-29T16:08:16Z Rating: moderate References: * jsc#PED-11925 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for pqcverification-zypp-plugin fixes the following issues: pqcverification-zypp-plugin is shipped as new package. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1110=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1110=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * pqcverification-zypp-plugin-1.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * pqcverification-zypp-plugin-1.0-160000.1.1 ## References: * https://jira.suse.com/browse/PED-11925 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:51 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:31:51 -0000 Subject: SUSE-RU-2026:22500-1: moderate: Recommended update for cloud-regionsrv-client Message-ID: <178335551188.4636.5682849999672278282@4d746be3175e> # Recommended update for cloud-regionsrv-client Announcement ID: SUSE-RU-2026:22500-1 Release Date: 2026-06-29T12:06:38Z Rating: moderate References: * bsc#1265930 * bsc#1267739 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for cloud-regionsrv-client fixes the following issues: * Update to version 11.0.3: * Write instance data cache file after cleaning the cache when the update server fails (bsc#1265930) * Create the cache directory when populating the cache (bsc#1267739) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1109=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1109=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * cloud-regionsrv-client-plugin-azure-3.0.0-160000.5.1 * cloud-regionsrv-client-plugin-gce-2.0.0-160000.5.1 * cloud-regionsrv-client-11.0.3-160000.5.1 * cloud-regionsrv-client-plugin-ec2-2.0.0-160000.5.1 * cloud-regionsrv-client-license-watcher-1.0.0-160000.5.1 * cloud-regionsrv-client-generic-config-1.0.0-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * cloud-regionsrv-client-plugin-azure-3.0.0-160000.5.1 * cloud-regionsrv-client-plugin-gce-2.0.0-160000.5.1 * cloud-regionsrv-client-11.0.3-160000.5.1 * cloud-regionsrv-client-plugin-ec2-2.0.0-160000.5.1 * cloud-regionsrv-client-license-watcher-1.0.0-160000.5.1 * cloud-regionsrv-client-generic-config-1.0.0-160000.5.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265930 * https://bugzilla.suse.com/show_bug.cgi?id=1267739 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:56 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:31:56 -0000 Subject: SUSE-RU-2026:22499-1: moderate: Recommended update for libtcnative-2-0 Message-ID: <178335551606.4636.1959350888106382060@4d746be3175e> # Recommended update for libtcnative-2-0 Announcement ID: SUSE-RU-2026:22499-1 Release Date: 2026-06-29T10:24:54Z Rating: moderate References: * jsc#PED-16024 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for libtcnative-2-0 fixes the following issues: libtcnative-2-0 is shipped as new package. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1105=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1105=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libtcnative-2-0-debugsource-2.0.15-160000.1.1 * libtcnative-2-0-debuginfo-2.0.15-160000.1.1 * libtcnative-2-0-2.0.15-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libtcnative-2-0-debugsource-2.0.15-160000.1.1 * libtcnative-2-0-debuginfo-2.0.15-160000.1.1 * libtcnative-2-0-2.0.15-160000.1.1 ## References: * https://jira.suse.com/browse/PED-16024 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:32:01 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:32:01 -0000 Subject: SUSE-RU-2026:22498-1: moderate: Recommended update for libnvme Message-ID: <178335552136.4636.13802958668319002928@4d746be3175e> # Recommended update for libnvme Announcement ID: SUSE-RU-2026:22498-1 Release Date: 2026-06-29T09:20:40Z Rating: moderate References: * bsc#1262707 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for libnvme fixes the following issues: * fabrics: permit bi-auth with secure concat TLS (bsc#1262707) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1104=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1104=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libnvme-debugsource-1.11+28.g5a8252b6-160000.1.1 * libnvme1-debuginfo-1.11+28.g5a8252b6-160000.1.1 * python3-libnvme-1.11+28.g5a8252b6-160000.1.1 * libnvme-debuginfo-1.11+28.g5a8252b6-160000.1.1 * libnvme-devel-1.11+28.g5a8252b6-160000.1.1 * libnvme-mi1-1.11+28.g5a8252b6-160000.1.1 * libnvme-mi1-debuginfo-1.11+28.g5a8252b6-160000.1.1 * libnvme1-1.11+28.g5a8252b6-160000.1.1 * python3-libnvme-debuginfo-1.11+28.g5a8252b6-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libnvme-debugsource-1.11+28.g5a8252b6-160000.1.1 * libnvme1-debuginfo-1.11+28.g5a8252b6-160000.1.1 * libnvme-debuginfo-1.11+28.g5a8252b6-160000.1.1 * python3-libnvme-1.11+28.g5a8252b6-160000.1.1 * libnvme-mi1-1.11+28.g5a8252b6-160000.1.1 * libnvme-devel-1.11+28.g5a8252b6-160000.1.1 * libnvme-mi1-debuginfo-1.11+28.g5a8252b6-160000.1.1 * libnvme1-1.11+28.g5a8252b6-160000.1.1 * python3-libnvme-debuginfo-1.11+28.g5a8252b6-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1262707 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:32:06 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:32:06 -0000 Subject: SUSE-RU-2026:22497-1: moderate: Recommended update for fuse3 Message-ID: <178335552648.4636.4182659304520880643@4d746be3175e> # Recommended update for fuse3 Announcement ID: SUSE-RU-2026:22497-1 Release Date: 2026-06-29T08:05:18Z Rating: moderate References: * bsc#1256466 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for fuse3 fixes the following issues: * Add dependency from libfuse3-4 to fusermount3 program (bsc#1256466) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1103=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1103=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * fuse3-debugsource-3.16.2-160000.3.1 * fuse3-doc-3.16.2-160000.3.1 * libfuse3-3-debuginfo-3.16.2-160000.3.1 * fuse3-3.16.2-160000.3.1 * libfuse3-3-3.16.2-160000.3.1 * fuse3-devel-3.16.2-160000.3.1 * fuse3-debuginfo-3.16.2-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * fuse3-debugsource-3.16.2-160000.3.1 * fuse3-doc-3.16.2-160000.3.1 * libfuse3-3-debuginfo-3.16.2-160000.3.1 * fuse3-3.16.2-160000.3.1 * libfuse3-3-3.16.2-160000.3.1 * fuse3-devel-3.16.2-160000.3.1 * fuse3-debuginfo-3.16.2-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1256466 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:32:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:32:11 -0000 Subject: SUSE-SU-2026:22496-1: important: Security update for dnsmasq Message-ID: <178335553175.4636.9719437929035162223@4d746be3175e> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:22496-1 Release Date: 2026-06-29T07:41:58Z Rating: important References: * bsc#1268764 Cross-References: * CVE-2026-12725 * CVE-2026-2291 * CVE-2026-6507 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2291 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2291 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2291 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6507 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6507 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues Update to 2.93: * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). Changes for dnsmasq: * CVE-2026-12725, bsc#1268764: Heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies. * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. * CVE-2026-2291: Rework storage allocation for domain names. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1102=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1102=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-160000.1.1 * dnsmasq-utils-2.93-160000.1.1 * dnsmasq-2.93-160000.1.1 * dnsmasq-utils-debuginfo-2.93-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dnsmasq-utils-debuginfo-2.93-160000.1.1 * dnsmasq-utils-2.93-160000.1.1 * dnsmasq-2.93-160000.1.1 * dnsmasq-debuginfo-2.93-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-2291.html * https://www.suse.com/security/cve/CVE-2026-6507.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:32:17 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:32:17 -0000 Subject: SUSE-SU-2026:22495-1: important: Security update for python-mistune Message-ID: <178335553736.4636.3328687476650427434@4d746be3175e> # Security update for python-mistune Announcement ID: SUSE-SU-2026:22495-1 Release Date: 2026-06-29T03:09:12Z Rating: important References: * bsc#1269091 Cross-References: * CVE-2026-49851 CVSS scores: * CVE-2026-49851 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49851 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-49851 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-mistune fixes the following issue * CVE-2026-49851: potential DoS via quadratic-time parsing in parse_link_text (bsc#1269091). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1100=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1100=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-mistune-3.1.3-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-mistune-3.1.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49851.html * https://bugzilla.suse.com/show_bug.cgi?id=1269091 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:32:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:32:21 -0000 Subject: SUSE-RU-2026:22494-1: moderate: Recommended update for junit5 Message-ID: <178335554163.4636.11280125234004865930@4d746be3175e> # Recommended update for junit5 Announcement ID: SUSE-RU-2026:22494-1 Release Date: 2026-06-29T01:42:48Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for junit5 fixes the following issues: Changes in junit5: * Build also the modules junit-platform-engine and junit-platform-launcher within the flavour bootstrap. This does not pull in other dependencies and allows the majority of consumers of junit5 build early against the junit5-minimal package ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1099=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1099=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * junit5-5.14.4-160000.2.1 * junit5-minimal-5.14.4-160000.2.1 * junit5-bom-5.14.4-160000.2.1 * junit5-minimal-javadoc-5.14.4-160000.2.1 * junit5-javadoc-5.14.4-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * junit5-5.14.4-160000.2.1 * junit5-minimal-5.14.4-160000.2.1 * junit5-bom-5.14.4-160000.2.1 * junit5-minimal-javadoc-5.14.4-160000.2.1 * junit5-javadoc-5.14.4-160000.2.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:35:27 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:35:27 -0000 Subject: SUSE-SU-2026:22493-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools and Salt Bundle Message-ID: <178335572718.4636.11207733899976355363@4d746be3175e> # Security update 5.1.4 for Multi-Linux Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22493-1 Release Date: 2026-07-06T08:48:50Z Rating: important References: * bsc#1208800 * bsc#1224788 * bsc#1226578 * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1234567 * bsc#1238890 * bsc#1242916 * bsc#1244925 * bsc#1245107 * bsc#1247707 * bsc#1248699 * bsc#1248707 * bsc#1248848 * bsc#1249243 * bsc#1249400 * bsc#1249532 * bsc#1251305 * bsc#1252974 * bsc#1253032 * bsc#1253174 * bsc#1254400 * bsc#1254401 * bsc#1254866 * bsc#1254867 * bsc#1254900 * bsc#1254997 * bsc#1255418 * bsc#1255764 * bsc#1256070 * bsc#1256331 * bsc#1257029 * bsc#1257031 * bsc#1257041 * bsc#1257042 * bsc#1257044 * bsc#1257046 * bsc#1257100 * bsc#1257108 * bsc#1257181 * bsc#1257583 * bsc#1257894 * bsc#1258041 * bsc#1258079 * bsc#1258144 * bsc#1258382 * bsc#1258816 * bsc#1259087 * bsc#1259230 * bsc#1259240 * bsc#1259261 * bsc#1259474 * bsc#1259479 * bsc#1259482 * bsc#1259521 * bsc#1259590 * bsc#1259591 * bsc#1259611 * bsc#1259630 * bsc#1259700 * bsc#1259734 * bsc#1259735 * bsc#1259739 * bsc#1259787 * bsc#1259804 * bsc#1259808 * bsc#1259960 * bsc#1260026 * bsc#1260031 * bsc#1260589 * bsc#1260614 * bsc#1260806 * bsc#1260905 * bsc#1261305 * bsc#1261307 * bsc#1261327 * bsc#1261631 * bsc#1261723 * bsc#1261753 * bsc#1261810 * bsc#1261841 * bsc#1261902 * bsc#1262222 * bsc#1262285 * bsc#1262409 * bsc#1262460 * bsc#1262471 * bsc#1262492 * bsc#1262595 * bsc#1262708 * bsc#1262720 * bsc#1262760 * bsc#1262761 * bsc#1262950 * bsc#1263157 * bsc#1263501 * bsc#1263814 * bsc#1263823 * bsc#1263841 * bsc#1263986 * bsc#1263987 * bsc#1264149 * bsc#1264234 * bsc#1264256 * bsc#1264966 * bsc#1265134 * bsc#1265281 * bsc#1265282 * bsc#1265283 * bsc#1265284 * bsc#1265285 * bsc#1265286 * bsc#1265287 * bsc#1265288 * bsc#1265289 * bsc#1265290 * bsc#1265319 * bsc#1265358 * bsc#1265975 * bsc#1266012 * bsc#1266556 * bsc#1266600 * bsc#1266608 * bsc#1267153 * bsc#1268381 * jsc#MSQA-1056 * jsc#PED-14816 * jsc#SUMA-320 Cross-References: * CVE-2022-21698 * CVE-2023-52425 * CVE-2024-35195 * CVE-2024-47081 * CVE-2024-52804 * CVE-2025-11468 * CVE-2025-12084 * CVE-2025-12781 * CVE-2025-13462 * CVE-2025-13836 * CVE-2025-13837 * CVE-2025-15282 * CVE-2025-15366 * CVE-2025-15367 * CVE-2025-15444 * CVE-2025-50181 * CVE-2025-6069 * CVE-2025-6075 * CVE-2025-66418 * CVE-2025-66471 * CVE-2025-67724 * CVE-2025-67725 * CVE-2025-67726 * CVE-2025-69277 * CVE-2025-8194 * CVE-2025-8291 * CVE-2026-0672 * CVE-2026-0865 * CVE-2026-10649 * CVE-2026-1299 * CVE-2026-21441 * CVE-2026-2297 * CVE-2026-24049 * CVE-2026-25645 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-27448 * CVE-2026-27459 * CVE-2026-28374 * CVE-2026-28376 * CVE-2026-28379 * CVE-2026-28380 * CVE-2026-28383 * CVE-2026-31958 * CVE-2026-33376 * CVE-2026-33377 * CVE-2026-33378 * CVE-2026-33380 * CVE-2026-33381 * CVE-2026-34986 * CVE-2026-3644 * CVE-2026-39821 * CVE-2026-40179 * CVE-2026-41602 * CVE-2026-42151 * CVE-2026-42154 * CVE-2026-4224 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-4519 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52425 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52425 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52425 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-35195 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2024-47081 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-47081 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-47081 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-52804 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-52804 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-52804 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-11468 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-11468 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-12084 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-12781 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-12781 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-12781 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12781 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13462 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-13462 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13462 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13462 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-13837 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13837 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-13837 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13837 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-15282 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15282 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2025-15282 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15366 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15366 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15367 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15367 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15444 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2025-15444 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-50181 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-50181 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-50181 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-50181 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H * CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2025-6069 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-6075 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-6075 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-6075 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-6075 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-66418 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66418 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66418 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66418 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-66471 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66471 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66471 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66471 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67724 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-67724 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67725 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67725 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67726 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-69277 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-69277 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-69277 ( NVD ): 4.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2025-8194 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-8194 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-8291 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-8291 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-8291 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0672 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0672 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0672 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0865 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0865 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-0865 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-1299 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1299 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-1299 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-21441 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-21441 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-21441 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-21441 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21441 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2297 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-2297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-2297 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-24049 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-24049 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2026-24049 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-24049 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-24049 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-25645 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-25645 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-25645 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-25645 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27448 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27448 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-27448 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27448 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-28374 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28374 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28374 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28376 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28376 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28379 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28380 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-28380 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28383 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28383 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28383 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31958 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31958 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33376 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33376 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33376 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33377 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33377 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33378 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33378 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33378 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33380 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-33380 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33381 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33381 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3644 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3644 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3644 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3644 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40179 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-40179 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-40179 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40179 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42154 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4224 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-4224 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4224 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4224 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-4519 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N * CVE-2026-4519 ( SUSE ): 6.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N * CVE-2026-4519 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4519 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4519 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 * SUSE Linux Enterprise Server High Availability Extension 16.0 * SUSE Linux Micro 6.1 * SUSE Linux Micro 6.2 * SUSE Multi-Linux Manager Client Tools for SLE 16 * SUSE Multi-Linux Manager Proxy 5.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 * SUSE Multi-Linux Manager Server 5.1 An update that solves 61 vulnerabilities, contains three features and has 65 fixes can now be installed. ## Security update 5.1.4 for Multi-Linux Manager Client Tools and Salt Bundle ### Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * Security issues fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-prometheus-node_exporter updated to version 1.10.2: * Key Update Highlights (v1.10.0 to v1.10.2): * New Collectors: Added new collectors for PCIe devices and swaps. * New Metrics: Introduced metrics for Zswap/Zswapped, Systemd Virtualization, and WiFi packets (received/transmitted) * Bug Fixes: Resolved a duplicate collection bug in filesystem mount points, fixed a Zswap metric typo, and patched a logging race condition in systemd. * Changes: Switched mdadm to use sysfs for RAID metrics, and added erofs to the default excluded filesystems list. * Internal Refactoring: filesystem mountinfo parsing refactor (bsc#1261810) golang-github-prometheus-prometheus updated to version 3.5.3: * Security issues fixed: * CVE-2026-42151: AzureAD remote write: Fix OAuth client_secret being exposed in plaintext via /-/config endpoint (v3.5.3) (bsc#1263986) * CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (v3.5.3) (bsc#1263987) * CVE-2026-40179: UI: Fix stored XSS via unescaped le label values in old UI heatmap chart tick labels (v3.5.2) (bsc#1262222) * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (backported patch) (bsc#1266608) * Other changes: * Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (v3.5.3) * Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) * Internal update with non customer facing changes (v3.5.1) grafana updated to version 11.6.14+security-04: * Security issues fixed in v11.6.14+security-04: * CVE-2026-28374: Fixed insecure direct object reference in Annotations API (bsc#1265290) * CVE-2026-28376: Fixed unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) * CVE-2026-28383: Fixed unbounded memory allocation in Grafana plugin resources (bsc#1265286) * CVE-2026-28380: Fixed broken access control in Snapshot API (bsc#1265287) * CVE-2026-33376: Fixed Auth Proxy IPv6 whitelist bypass (bsc#1265285) * CVE-2026-28379: Fixed viewer-triggered race condition in Grafana Live (bsc#1265288) * CVE-2026-33377: Fixed dashboard Editor Privilege Escalation (bsc#1265284) * CVE-2026-33378: Fixed OOM exception in Grafana Data Source Plugin (bsc#1265283) * CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) * CVE-2026-33380: Fixed vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server filesystem (bsc#1265282) * Security issues fixed through backported patches: * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) * CVE-2026-34986: Fixed panic in JWE decryption (bsc#1262950) * CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) * CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Fixed multiple issues when parsing HTML files (bsc#1267153) prometheus-blackbox_exporter: * Security issues fixed: * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266556) prometheus-postgres_exporter: * Security issues fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes supportutils-plugin-susemanager-client updated to version 5.2.3: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.3-0) uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0) * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0) * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Internal SANs for db and reportdb are no longer required * Generate the same certificate for server and reportdb * Fixed Report DB CA certificate (bsc#1260806) * Removed waitForTraefik function (bsc#1261902) * Key Update Highlights (v5.2.8-0) * Generate service template only after secrets are created * Key Update Highlights (v5.2.7-0) * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0): * Use podman secrets for SSL on proxy * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Fixed incorrect package dependencies declaration (bsc#1229105) * Prevent cobbler port from being exposed * Bumped zerolog to 1.34 * Ignore spacewalk-service stop return code. * Stop automatically unhealthy container * Use container based server setup instead tools bundled one * Key Update Highlights (v5.2.5-0) * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0) * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Security update for pacemaker ### Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial of service via integer overflow in remote message decompression (bsc#1268381). ## Recommended update 5.1.4 for Multi-Linux Manager ### Description: This update fixes the following issues: proxy-httpd-image: * Version 5.1.16 * Remove unused repos proxy-salt-broker-image: * Version 5.1.15 * Remove unused repos proxy-squid-image: * Version 5.1.14 * Remove unused repos proxy-ssh-image: * Version 5.1.14 * Remove unused repos proxy-tftpd-image: * Version 5.1.14 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Remove unused repos server-attestation-image: * Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: * Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Add "susemanager-tools", "susemanager" and "susemanager-tools-salt" packages to server-image server-migration-14-16-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: * Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: * Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: * Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: * Added the distro signature for rhel10 (bsc#1265134) liberate-formula: * Version 0.1.4 * No customer facing changes * Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: * Version 1.4.3 * Add support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: * Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fix the issue of using non-vendored tornado with Python 3.11 salt: * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: * Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: * Version 5.1.14-0 * Update translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: * Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fix CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fix missing translations (bsc#1259787) * Fix hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fix enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fix Remote Commands hang on direct hostname (bsc#1226578) * Fix Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Add 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Add missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fix Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * Fix non-ASCII em dash in Pbkdf2Sha256Crypt breaking javadoc build with US- ASCII encoding * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fix CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fix conflicting cobbler system migrations spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Add missing fragment import (bsc#1264966) subscription-matcher: * Version 0.44 * Fix 2 missing part numbers (bsc#1264256) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager: * Version 5.1.17-0 * Add SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Remove spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicense mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: * Add Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: * Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones * Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD * Added Code 16 to Monitoring documentation (bsc#1263814) * Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) * Rephrased instructions for RBAC in Administration Guide (bsc#1258079) * Added troubleshooting section for BTRFS to Administration Guide (bsc#1258816) * Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) * Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) * Removed mention of CIS profile (bsc#1262460) * Corrected path for Salt minion in Retail Guide (#1262090) * Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) * Removed Google Cloud Compute from PAYG documentation (bsc#1261631) * Added link to proxy creation from client to an existing document in Installation and Upgrade Guide * Updated features table for EL 10 based distributions * Document Debian 13 * Added support for Open Enterprise Server 25.4 * Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) * SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) * Added instructions about accessing git repositories when building images to Administration Guide * Added online database backup instructions to Administration Guide * Fixed command for product deployment in Installation and Upgrade Guide (bsc#1259479) * Added online database backup instructions susemanager-schema: * Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Add index on rhnPackage (checksum_id) (bsc#1258041) (gh#uyuni- project/uyuni#11585) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Add 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: * Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fix GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fix CPU reporting for ppc64le clients (bsc#1259521) * Fix refresh of virtual instance information (bsc#1261723) susemanager-sync-data: * Version 5.1.10-0 * Add missing RES-EMS channel family (bsc#1265358) * Version 5.1.9-0 * Add SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: * Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replace deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-setup-reportdb: * Version 5.1.5-0 * Fix delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: * Version 1.0.31-0 * Drop SUSECloud module as not longer maintained nor used * Version 1.0.30-0 * No customer facing changes How to apply this update: SUSE Multi-Linux Manager Server: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. SUSE Multi-Linux Manager Proxy / Retail Branch Server: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy / Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. ## Recommended update 5.1.4 for Multi-Linux Manager ### Description: This update fixes the following issues: proxy-httpd-image: * Version 5.1.16 * Remove unused repos proxy-salt-broker-image: * Version 5.1.15 * Remove unused repos proxy-squid-image: * Version 5.1.14 * Remove unused repos proxy-ssh-image: * Version 5.1.14 * Remove unused repos proxy-tftpd-image: * Version 5.1.14 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Remove unused repos server-attestation-image: * Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: * Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Add "susemanager-tools", "susemanager" and "susemanager-tools-salt" packages to server-image server-migration-14-16-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: * Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: * Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: * Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: * Added the distro signature for rhel10 (bsc#1265134) liberate-formula: * Version 0.1.4 * No customer facing changes * Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: * Version 1.4.3 * Add support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: * Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fix the issue of using non-vendored tornado with Python 3.11 salt: * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: * Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: * Version 5.1.14-0 * Update translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: * Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fix CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fix missing translations (bsc#1259787) * Fix hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fix enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fix Remote Commands hang on direct hostname (bsc#1226578) * Fix Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Add 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Add missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fix Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * Fix non-ASCII em dash in Pbkdf2Sha256Crypt breaking javadoc build with US- ASCII encoding * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fix CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fix conflicting cobbler system migrations spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Add missing fragment import (bsc#1264966) subscription-matcher: * Version 0.44 * Fix 2 missing part numbers (bsc#1264256) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager: * Version 5.1.17-0 * Add SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Remove spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicense mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: * Add Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: * Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones * Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD * Added Code 16 to Monitoring documentation (bsc#1263814) * Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) * Rephrased instructions for RBAC in Administration Guide (bsc#1258079) * Added troubleshooting section for BTRFS to Administration Guide (bsc#1258816) * Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) * Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) * Removed mention of CIS profile (bsc#1262460) * Corrected path for Salt minion in Retail Guide (#1262090) * Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) * Removed Google Cloud Compute from PAYG documentation (bsc#1261631) * Added link to proxy creation from client to an existing document in Installation and Upgrade Guide * Updated features table for EL 10 based distributions * Document Debian 13 * Added support for Open Enterprise Server 25.4 * Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) * SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) * Added instructions about accessing git repositories when building images to Administration Guide * Added online database backup instructions to Administration Guide * Fixed command for product deployment in Installation and Upgrade Guide (bsc#1259479) * Added online database backup instructions susemanager-schema: * Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Add index on rhnPackage (checksum_id) (bsc#1258041) (gh#uyuni- project/uyuni#11585) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Add 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: * Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fix GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fix CPU reporting for ppc64le clients (bsc#1259521) * Fix refresh of virtual instance information (bsc#1261723) susemanager-sync-data: * Version 5.1.10-0 * Add missing RES-EMS channel family (bsc#1265358) * Version 5.1.9-0 * Add SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: * Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replace deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-setup-reportdb: * Version 5.1.5-0 * Fix delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: * Version 1.0.31-0 * Drop SUSECloud module as not longer maintained nor used * Version 1.0.30-0 * No customer facing changes How to apply this update: SUSE Multi-Linux Manager Server: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. SUSE Multi-Linux Manager Proxy / Retail Branch Server: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy / Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. ## Recommended update 5.1.4 for Multi-Linux Manager ### Description: This update fixes the following issues: proxy-httpd-image: * Version 5.1.16 * Remove unused repos proxy-salt-broker-image: * Version 5.1.15 * Remove unused repos proxy-squid-image: * Version 5.1.14 * Remove unused repos proxy-ssh-image: * Version 5.1.14 * Remove unused repos proxy-tftpd-image: * Version 5.1.14 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Remove unused repos server-attestation-image: * Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: * Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Add "susemanager-tools", "susemanager" and "susemanager-tools-salt" packages to server-image server-migration-14-16-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: * Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: * Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: * Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: * Added the distro signature for rhel10 (bsc#1265134) liberate-formula: * Version 0.1.4 * No customer facing changes * Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: * Version 1.4.3 * Add support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: * Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fix the issue of using non-vendored tornado with Python 3.11 salt: * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: * Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: * Version 5.1.14-0 * Update translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: * Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fix CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fix missing translations (bsc#1259787) * Fix hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fix enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fix Remote Commands hang on direct hostname (bsc#1226578) * Fix Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Add 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Add missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fix Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * Fix non-ASCII em dash in Pbkdf2Sha256Crypt breaking javadoc build with US- ASCII encoding * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fix CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fix conflicting cobbler system migrations spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Add missing fragment import (bsc#1264966) subscription-matcher: * Version 0.44 * Fix 2 missing part numbers (bsc#1264256) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager: * Version 5.1.17-0 * Add SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Remove spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicense mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: * Add Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: * Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones * Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD * Added Code 16 to Monitoring documentation (bsc#1263814) * Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) * Rephrased instructions for RBAC in Administration Guide (bsc#1258079) * Added troubleshooting section for BTRFS to Administration Guide (bsc#1258816) * Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) * Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) * Removed mention of CIS profile (bsc#1262460) * Corrected path for Salt minion in Retail Guide (#1262090) * Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) * Removed Google Cloud Compute from PAYG documentation (bsc#1261631) * Added link to proxy creation from client to an existing document in Installation and Upgrade Guide * Updated features table for EL 10 based distributions * Document Debian 13 * Added support for Open Enterprise Server 25.4 * Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) * SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) * Added instructions about accessing git repositories when building images to Administration Guide * Added online database backup instructions to Administration Guide * Fixed command for product deployment in Installation and Upgrade Guide (bsc#1259479) * Added online database backup instructions susemanager-schema: * Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Add index on rhnPackage (checksum_id) (bsc#1258041) (gh#uyuni- project/uyuni#11585) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Add 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: * Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fix GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fix CPU reporting for ppc64le clients (bsc#1259521) * Fix refresh of virtual instance information (bsc#1261723) susemanager-sync-data: * Version 5.1.10-0 * Add missing RES-EMS channel family (bsc#1265358) * Version 5.1.9-0 * Add SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: * Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replace deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-setup-reportdb: * Version 5.1.5-0 * Fix delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: * Version 1.0.31-0 * Drop SUSECloud module as not longer maintained nor used * Version 1.0.30-0 * No customer facing changes How to apply this update: SUSE Multi-Linux Manager Server: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. SUSE Multi-Linux Manager Proxy / Retail Branch Server: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy / Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Proxy 5.1 zypper in -t patch SUSE-Multi-Linux-Manager-5.1-8=1 * SUSE Multi-Linux Manager Server 5.1 zypper in -t patch SUSE-Multi-Linux-Manager-5.1-8=1 SUSE-Multi-Linux- Manager-5.1-8=1 * SUSE Linux Enterprise Server High Availability Extension 16.0 zypper in -t patch SUSE-SLES-HA-16.0-1108=1 * SUSE Multi-Linux Manager Client Tools for SLE 16 zypper in -t patch Multi-Linux-ManagerTools-SLE-16-4=1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 zypper in -t patch SUSE-Multi-Linux-Manager-5.1-8=1 SUSE-Multi-Linux- Manager-5.1-8=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE 16 (aarch64 s390x x86_64) * golang-github-prometheus-alertmanager-0.28.1-160002.2.1 * grafana-11.6.14+security04-160002.1.1 * golang-github-prometheus-prometheus-3.5.3-160002.1.1 * prometheus-postgres_exporter-debuginfo-0.10.1-160002.2.1 * golang-github-prometheus-alertmanager-debuginfo-0.28.1-160002.2.1 * golang-github-prometheus-prometheus-debuginfo-3.5.3-160002.1.1 * mgrctl-5.2.12-160002.1.1 * venv-salt-minion-3006.0-160002.6.1 * golang-github-QubitProducts-exporter_exporter-0.4.0-160002.3.1 * grafana-debuginfo-11.6.14+security04-160002.1.1 * prometheus-blackbox_exporter-0.26.0-160002.2.1 * golang-github-prometheus-node_exporter-1.10.2-160002.1.1 * mgrctl-debuginfo-5.2.12-160002.1.1 * prometheus-postgres_exporter-0.10.1-160002.2.1 * golang-github-QubitProducts-exporter_exporter-debuginfo-0.4.0-160002.3.1 * prometheus-blackbox_exporter-debuginfo-0.26.0-160002.2.1 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-160002.1.1 * SUSE Multi-Linux Manager Client Tools for SLE 16 (noarch) * mgrctl-zsh-completion-5.2.12-160002.1.1 * mgrctl-lang-5.2.12-160002.1.1 * supportutils-plugin-susemanager-client-5.2.3-160002.1.1 * spacecmd-5.2.8-160002.1.1 * mgrctl-bash-completion-5.2.12-160002.1.1 * SUSE Linux Enterprise Server High Availability Extension 16.0 (noarch) * pacemaker-schemas-3.0.0+20250218.64cd85422c-160000.4.1 * python3-pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cts-3.0.0+20250218.64cd85422c-160000.4.1 * SUSE Linux Enterprise Server High Availability Extension 16.0 (ppc64le s390x x86_64) * pacemaker-remote-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-remote-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debugsource-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-devel-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-3.0.0+20250218.64cd85422c-160000.4.1 * SUSE Multi-Linux Manager Server 5.1 (s390x) * suse-multi-linux-manager-5.1-s390x-server-migration-14-16-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-s390x-server-image-5.1.4-8.20.25 * suse-multi-linux-manager-5.1-s390x-server-attestation-image-5.1.4-8.22.7 * suse-multi-linux-manager-5.1-s390x-server-saline-image-5.1.4-9.20.18 * suse-multi-linux-manager-5.1-s390x-server-postgresql-image-5.1.4-6.22.10 * suse-multi-linux-manager-5.1-s390x-server-hub-xmlrpc-api-image-5.1.4-8.20.9 * SUSE Multi-Linux Manager Server 5.1 (noarch) * mgrctl-bash-completion-5.1.29-slfo.1.1.1 * mgradm-lang-5.1.29-slfo.1.1.1 * mgrctl-lang-5.1.29-slfo.1.1.1 * mgrctl-zsh-completion-5.1.29-slfo.1.1.1 * mgradm-bash-completion-5.1.29-slfo.1.1.1 * mgradm-zsh-completion-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Server 5.1 (x86_64) * suse-multi-linux-manager-5.1-x86_64-server-postgresql-image-5.1.4-6.22.10 * suse-multi-linux-manager-5.1-x86_64-server-migration-14-16-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-x86_64-server-attestation-image-5.1.4-8.22.7 * suse-multi-linux-manager-5.1-x86_64-server-image-5.1.4-8.20.25 * suse-multi-linux-manager-5.1-x86_64-server-saline-image-5.1.4-9.20.18 * suse-multi-linux-manager-5.1-x86_64-server-hub-xmlrpc-api-image-5.1.4-8.20.9 * SUSE Multi-Linux Manager Server 5.1 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-5.1.29-slfo.1.1.1 * mgrctl-5.1.29-slfo.1.1.1 * mgradm-debuginfo-5.1.29-slfo.1.1.1 * mgradm-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Server 5.1 (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-server-migration-14-16-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-ppc64le-server-saline-image-5.1.4-9.20.18 * suse-multi-linux-manager-5.1-ppc64le-server-postgresql-image-5.1.4-6.22.10 * suse-multi-linux-manager-5.1-ppc64le-server-attestation-image-5.1.4-8.22.7 * suse-multi-linux-manager-5.1-ppc64le-server-image-5.1.4-8.20.25 * suse-multi-linux-manager-5.1-ppc64le-server-hub-xmlrpc-api-image-5.1.4-8.20.9 * SUSE Multi-Linux Manager Server 5.1 (aarch64) * suse-multi-linux-manager-5.1-aarch64-server-postgresql-image-5.1.4-6.22.10 * suse-multi-linux-manager-5.1-aarch64-server-saline-image-5.1.4-9.20.18 * suse-multi-linux-manager-5.1-aarch64-server-attestation-image-5.1.4-8.22.7 * suse-multi-linux-manager-5.1-aarch64-server-image-5.1.4-8.20.25 * suse-multi-linux-manager-5.1-aarch64-server-migration-14-16-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-aarch64-server-hub-xmlrpc-api-image-5.1.4-8.20.9 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (noarch) * mgrpxy-zsh-completion-5.1.29-slfo.1.1.1 * mgrpxy-lang-5.1.29-slfo.1.1.1 * mgrpxy-bash-completion-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (x86_64) * suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (aarch64 ppc64le s390x x86_64) * mgrpxy-5.1.29-slfo.1.1.1 * mgrpxy-debuginfo-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.17 * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.19 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Proxy 5.1 (x86_64) * suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Proxy 5.1 (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Proxy 5.1 (noarch) * mgrpxy-zsh-completion-5.1.29-slfo.1.1.1 * mgrpxy-bash-completion-5.1.29-slfo.1.1.1 * mgrpxy-lang-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Proxy 5.1 (aarch64 ppc64le s390x x86_64) * mgrpxy-5.1.29-slfo.1.1.1 * mgrpxy-debuginfo-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Proxy 5.1 (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Proxy 5.1 (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.17 * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.19 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2023-52425.html * https://www.suse.com/security/cve/CVE-2024-35195.html * https://www.suse.com/security/cve/CVE-2024-47081.html * https://www.suse.com/security/cve/CVE-2024-52804.html * https://www.suse.com/security/cve/CVE-2025-11468.html * https://www.suse.com/security/cve/CVE-2025-12084.html * https://www.suse.com/security/cve/CVE-2025-12781.html * https://www.suse.com/security/cve/CVE-2025-13462.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-13837.html * https://www.suse.com/security/cve/CVE-2025-15282.html * https://www.suse.com/security/cve/CVE-2025-15366.html * https://www.suse.com/security/cve/CVE-2025-15367.html * https://www.suse.com/security/cve/CVE-2025-15444.html * https://www.suse.com/security/cve/CVE-2025-50181.html * https://www.suse.com/security/cve/CVE-2025-6069.html * https://www.suse.com/security/cve/CVE-2025-6075.html * https://www.suse.com/security/cve/CVE-2025-66418.html * https://www.suse.com/security/cve/CVE-2025-66471.html * https://www.suse.com/security/cve/CVE-2025-67724.html * https://www.suse.com/security/cve/CVE-2025-67725.html * https://www.suse.com/security/cve/CVE-2025-67726.html * https://www.suse.com/security/cve/CVE-2025-69277.html * https://www.suse.com/security/cve/CVE-2025-8194.html * https://www.suse.com/security/cve/CVE-2025-8291.html * https://www.suse.com/security/cve/CVE-2026-0672.html * https://www.suse.com/security/cve/CVE-2026-0865.html * https://www.suse.com/security/cve/CVE-2026-10649.html * https://www.suse.com/security/cve/CVE-2026-1299.html * https://www.suse.com/security/cve/CVE-2026-21441.html * https://www.suse.com/security/cve/CVE-2026-2297.html * https://www.suse.com/security/cve/CVE-2026-24049.html * https://www.suse.com/security/cve/CVE-2026-25645.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-27448.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-28374.html * https://www.suse.com/security/cve/CVE-2026-28376.html * https://www.suse.com/security/cve/CVE-2026-28379.html * https://www.suse.com/security/cve/CVE-2026-28380.html * https://www.suse.com/security/cve/CVE-2026-28383.html * https://www.suse.com/security/cve/CVE-2026-31958.html * https://www.suse.com/security/cve/CVE-2026-33376.html * https://www.suse.com/security/cve/CVE-2026-33377.html * https://www.suse.com/security/cve/CVE-2026-33378.html * https://www.suse.com/security/cve/CVE-2026-33380.html * https://www.suse.com/security/cve/CVE-2026-33381.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-3644.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40179.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-42151.html * https://www.suse.com/security/cve/CVE-2026-42154.html * https://www.suse.com/security/cve/CVE-2026-4224.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-4519.html * https://bugzilla.suse.com/show_bug.cgi?id=1208800 * https://bugzilla.suse.com/show_bug.cgi?id=1224788 * https://bugzilla.suse.com/show_bug.cgi?id=1226578 * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1234567 * https://bugzilla.suse.com/show_bug.cgi?id=1238890 * https://bugzilla.suse.com/show_bug.cgi?id=1242916 * https://bugzilla.suse.com/show_bug.cgi?id=1244925 * https://bugzilla.suse.com/show_bug.cgi?id=1245107 * https://bugzilla.suse.com/show_bug.cgi?id=1247707 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1248848 * https://bugzilla.suse.com/show_bug.cgi?id=1249243 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1251305 * https://bugzilla.suse.com/show_bug.cgi?id=1252974 * https://bugzilla.suse.com/show_bug.cgi?id=1253032 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1254401 * https://bugzilla.suse.com/show_bug.cgi?id=1254866 * https://bugzilla.suse.com/show_bug.cgi?id=1254867 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1254997 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1255764 * https://bugzilla.suse.com/show_bug.cgi?id=1256070 * https://bugzilla.suse.com/show_bug.cgi?id=1256331 * https://bugzilla.suse.com/show_bug.cgi?id=1257029 * https://bugzilla.suse.com/show_bug.cgi?id=1257031 * https://bugzilla.suse.com/show_bug.cgi?id=1257041 * https://bugzilla.suse.com/show_bug.cgi?id=1257042 * https://bugzilla.suse.com/show_bug.cgi?id=1257044 * https://bugzilla.suse.com/show_bug.cgi?id=1257046 * https://bugzilla.suse.com/show_bug.cgi?id=1257100 * https://bugzilla.suse.com/show_bug.cgi?id=1257108 * https://bugzilla.suse.com/show_bug.cgi?id=1257181 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1257894 * https://bugzilla.suse.com/show_bug.cgi?id=1258041 * https://bugzilla.suse.com/show_bug.cgi?id=1258079 * https://bugzilla.suse.com/show_bug.cgi?id=1258144 * https://bugzilla.suse.com/show_bug.cgi?id=1258382 * https://bugzilla.suse.com/show_bug.cgi?id=1258816 * https://bugzilla.suse.com/show_bug.cgi?id=1259087 * https://bugzilla.suse.com/show_bug.cgi?id=1259230 * https://bugzilla.suse.com/show_bug.cgi?id=1259240 * https://bugzilla.suse.com/show_bug.cgi?id=1259261 * https://bugzilla.suse.com/show_bug.cgi?id=1259474 * https://bugzilla.suse.com/show_bug.cgi?id=1259479 * https://bugzilla.suse.com/show_bug.cgi?id=1259482 * https://bugzilla.suse.com/show_bug.cgi?id=1259521 * https://bugzilla.suse.com/show_bug.cgi?id=1259590 * https://bugzilla.suse.com/show_bug.cgi?id=1259591 * https://bugzilla.suse.com/show_bug.cgi?id=1259611 * https://bugzilla.suse.com/show_bug.cgi?id=1259630 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259734 * https://bugzilla.suse.com/show_bug.cgi?id=1259735 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1259787 * https://bugzilla.suse.com/show_bug.cgi?id=1259804 * https://bugzilla.suse.com/show_bug.cgi?id=1259808 * https://bugzilla.suse.com/show_bug.cgi?id=1259960 * https://bugzilla.suse.com/show_bug.cgi?id=1260026 * https://bugzilla.suse.com/show_bug.cgi?id=1260031 * https://bugzilla.suse.com/show_bug.cgi?id=1260589 * https://bugzilla.suse.com/show_bug.cgi?id=1260614 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261305 * https://bugzilla.suse.com/show_bug.cgi?id=1261307 * https://bugzilla.suse.com/show_bug.cgi?id=1261327 * https://bugzilla.suse.com/show_bug.cgi?id=1261631 * https://bugzilla.suse.com/show_bug.cgi?id=1261723 * https://bugzilla.suse.com/show_bug.cgi?id=1261753 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261841 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262222 * https://bugzilla.suse.com/show_bug.cgi?id=1262285 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262460 * https://bugzilla.suse.com/show_bug.cgi?id=1262471 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262595 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262720 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1262761 * https://bugzilla.suse.com/show_bug.cgi?id=1262950 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263501 * https://bugzilla.suse.com/show_bug.cgi?id=1263814 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1263841 * https://bugzilla.suse.com/show_bug.cgi?id=1263986 * https://bugzilla.suse.com/show_bug.cgi?id=1263987 * https://bugzilla.suse.com/show_bug.cgi?id=1264149 * https://bugzilla.suse.com/show_bug.cgi?id=1264234 * https://bugzilla.suse.com/show_bug.cgi?id=1264256 * https://bugzilla.suse.com/show_bug.cgi?id=1264966 * https://bugzilla.suse.com/show_bug.cgi?id=1265134 * https://bugzilla.suse.com/show_bug.cgi?id=1265281 * https://bugzilla.suse.com/show_bug.cgi?id=1265282 * https://bugzilla.suse.com/show_bug.cgi?id=1265283 * https://bugzilla.suse.com/show_bug.cgi?id=1265284 * https://bugzilla.suse.com/show_bug.cgi?id=1265285 * https://bugzilla.suse.com/show_bug.cgi?id=1265286 * https://bugzilla.suse.com/show_bug.cgi?id=1265287 * https://bugzilla.suse.com/show_bug.cgi?id=1265288 * https://bugzilla.suse.com/show_bug.cgi?id=1265289 * https://bugzilla.suse.com/show_bug.cgi?id=1265290 * https://bugzilla.suse.com/show_bug.cgi?id=1265319 * https://bugzilla.suse.com/show_bug.cgi?id=1265358 * https://bugzilla.suse.com/show_bug.cgi?id=1265975 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://bugzilla.suse.com/show_bug.cgi?id=1266556 * https://bugzilla.suse.com/show_bug.cgi?id=1266600 * https://bugzilla.suse.com/show_bug.cgi?id=1266608 * https://bugzilla.suse.com/show_bug.cgi?id=1267153 * https://bugzilla.suse.com/show_bug.cgi?id=1268381 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-14816 * https://jira.suse.com/browse/SUMA-320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:35:39 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 16:35:39 -0000 Subject: SUSE-SU-2026:2777-1: moderate: Security update for cryptsetup, s390-tools Message-ID: <178335573906.4636.17278032215806024147@4d746be3175e> # Security update for cryptsetup, s390-tools Announcement ID: SUSE-SU-2026:2777-1 Release Date: 2026-07-06T08:57:17Z Rating: moderate References: * bsc#1241612 * bsc#1259314 * bsc#1261813 * bsc#1270185 * jsc#PED-14586 * jsc#PED-15860 * jsc#PED-15889 Cross-References: * CVE-2026-41676 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability, contains three features and has three security fixes can now be installed. ## Description: This update for cryptsetup, s390-tools fixes the following issue Security fixes: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270185). Changes for s390-tools: * Upgrade s390-tools to version 2.41.0 (jsc#PED-15860) * Automatically set appropriate MTU for HSCI (bsc#1259314) * Changes of existing tools: * chreipl: Make --bootparms work for ECKD re-IPL * cpacfstats: Add 'unauthorized' state to CPU-MF counters * cpictl: Detect RHCOS using VARIANT_ID * hsci: Automatically set appropriate MTU for HSCI * libutil: Add util_readlink() and util_readlinkat() helpers * libutil: Add util_startswith() to util_str * libutil: Add utility parsing functions * lschp: Add support for structured output (--format) * lsreipl: Suppress 'clear' output if not supported * pvimg: Add '\--format text' support to 'pvimg info' * pvimg: Add '\--print-schema ' option to 'pvimg info' * pvimg: Add '\--show-secrets' flag to 'pvimg info' * pvimg: Provide improved JSON output to 'pvimg info --format json' * pvinfo: Improve User experience on non-SE enabled systems * zipl/ngdump: Ensure ext4 file system is used on dump partition * zkey: Add support for integrity protected disks using HMAC keys * Bug Fixes: * cpumf/pai: Handle different size of perf_event_attr * lscss: Fix memory leak * zipl: Fix dump job on tape devices \--- s390-tools 2.40 includes --- * Add new tools / libraries: * Add project-wide .clang-tidy configuration * libutil: Introduce util_time for time related functionality * libutil: Introduce zsh/bash autocompletion tooling based on util_opt * pvinfo: Tool to display Secure Execution system information * pvverify: Tool to verify host-key documents * Changes of existing tools: * cpumf: Implement zsh and bash autocompletion * dasdfmt: Implement zsh and bash autocompletion * dbginfo.sh: Add NetworkManager and netplan * dbginfo.sh: Add kvm_stat * dbginfo.sh: Adding stp time information * dbginfo.sh: Simplify procfs collection * hyptop: Add physical information row * hyptop: Calculate sample time delta for physical partition * hyptop: Replace long option names using _ with - for consistency For example: --cpu_types > \--cpu-types (Options with _ are still supported for backward compatibility) * libekmfweb: Add function to validate a certificate against the identity key * netboot: Add longer kernel command lines support * udev/rules.d: Make virtio-blk devices non-rotational * udev/rules.d: Set default io scheduler to 'none' for virtio-blk * ziomon: Add support to sample device symlinks (/dev/disk/...) * ziorep_config: Add fcp-lun details to -M option output * ziorep_config: Add port_id and failed attributes to -A option output * netboot: Install on non-s390 architectures * Bug Fixes: * lib(ekmfweb|kmipclient): Use ln without -r * s390-tools: Fix various compilation issues with musl libc * zipl/boot: Fix unused loadparm when SCLP line-mode console is absent \--- s390-tools 2.39 includes --- * Changes of existing tools: * chpstat: Add options to select IEC units for scaling (SI units are default) * chzdev: Introduce --no-module-load option * cpi: Disable CPI for SEL guests by default * dbginfo.sh: Enhance logging on timeout triggered * iucvterm: Install symlink for lsiucvallow.8 man page * lshwc: Add command line flag to specify individual counters * lspai: Add command line flag for delta values * lspai: Add command line flag for short counter names * lspai: Add command line flag to specify individual counters * lspai: Add command line flags for all cpus * lspai: Add command line flags for hexadecimal output * man: Use CR for constant width font * pvimg: Add '\--image-key' option * zdev: Allow dynamic control of module load * zipl/boot: Fix EBCDIC code page 500 conversion and decrease size by 200 bytes * zipl: Add support of heterogeneous mirrors (remove technical limitations on mirrored targets, thus allowing mirrored devices consist of partitions at different offsets on disks of different types and geometry). * zkey: Add support for generating and importing exportable secure keys * Bug Fixes: * chpstat: Fix scaling of DPU utilization calculation * zdev/dracut: Prevent loading of unused kernel modules * zdev: Fix double device configuration on DPM systems * zdev: Fix double device configuration with rd.dasd * zipl_helper.device-mapper: Fix segfault in an error path \--- s390-tools 2.38 includes --- * Add new tools * udev: New rule to set newly hotplugged CPUs online * zmemtopo: Display memory topology information * zpwr: Display power readings of a partition and CPC * Removed tools / features * check_hostkeydoc: Remove installation target * scsi_logging_level: Delete SCSI logging script (available in sg3_utils) * zdump: Drop build_arch for s390 DASD dumps * zdump: Drop non-extended multi-volume DASD dump support * zdump: Drop support of 32-bit dump architecture * zdump: Drop support of non-extended single volume DASD dumpers * zdump: Drop support of obsolete dumps and dumpers * Changes of existing tools / libraries * Various man-pages fixes * check_hostkeydoc: Add deprecation warning * check_hostkeydoc: Move to scripts directory * cpuplugd: Allow cpu hotplugging on systems without polarization * dbginfo.sh: Add Ubuntu snap tool * dbginfo.sh: Add missing config data and logs * dbginfo.sh: Reworking the container section * dbginfo.sh: Update for network commands * dbginfo.sh: Updating info for disks and lvm * libutil: Add machine type definition for machines 9175 and 9176 * lscpumf: Add support for IBM z17 counter sets * lshwc: Add command line flag for run time * lshwc: Add flags to display counter values in hex * lshwc: Add output '\--format' option * lshwc: Add support for delta counter value display * lspai: Add output '\--format' option * lsreipl: Add secure boot state to output * lswhc: Add short names to lshwc output * pv_tools: Add Bash and Zsh completions * pvapconfig: Add '\--unbind' option * pvimg/boot: Print error messages from stage3a bootloader * pvimg: Add support for CCK update * pvsecret: Add support for CCK update * pvsecret: Allow retrieving secrets by index; warn for duplicated entries * pvsecret: Deny adding secrets with duplicated secret IDs * zdev: Add support for virtio devices * zipl: Enhance mirror support * zipl: Implement '\--dry-run' option for all dump jobs * zipl_helper.device-mapper: Support mirrors over NVMe devices * zkey/dracut: Add a dracut config file for zkey * zkey/initramfs: Update initramfs hook to correct drivers and include zkey plugins * zkey: Add support for converting a clear-key LUKS2 volume to use a secure key * Bug Fixes * chpstat: Add missing CMG 5 data fields * chpstat: Fix DPU utilization calculation * libutil/util_file: Handle over-read in util_file_read_fd() * pvattest: Fix successful 'check' evaluation * pvsecret: Fix some edge cases for plaintext keys * zipl_helper.device-mapper: Fix imprecise is_device_mapper() predicate * zkey: Fix EP11 secure key reencipher function * zpcictl: Fix command line parsing for invalid options * Amended the .spec file * "Installing" all shipped rules from etc/udev/rules.d to /usr/lib/udev/rules.d * BuildRequires: cryptsetup-devel > 2.8.2 * Updated the code for IBM z17 machine type 9176: * read_values.c * cputype * Renamed cputype.1 to cputype.8 and amended * Amended read_values.8 * "Improved" the read_values.c: * Added functionalities for '-a' and '-L attributes' * Removed legacy suse_version and sle_version conditionals, standardizing on UsrMerge paths. * Reworked and combined all s390-tools patches (jsc#PED-14586) * Added new combined and reworked patches * Removed obsolete patches * Applied patches (bsc#1261813) * Replace sort_field option with sort * hyptop opts Fix long command line option abbreviations * Removed obsolete patch * Re-vendor-ed vendor.tar.zst Changes for cryptsetup: * Update to 2.8.4: (jsc#PED-15889) * Fix integritysetup resize (grow) of the device if integrity bitmap mode is used. Increasing the integrity device in bitmap mode did not work as integritysetup incorrectly used journal settings that were not applicable. * Fix device size status reports in cryptsetup and integritysetup. If the device uses a sector size larger than 512 bytes, the newly reported byte sizes (introduced in 2.8.0) in the status report were incorrectly displayed. * BITLK: Fix unlocking BitLocker device with recovery passphrase. If the recovery passphrase was present in the first keyslot, the device failed to unlock. This bug was introduced in 2.8.2 with Clear Key support. * Update to 2.8.3: * Stable bug-fix release with minor extensions. * Update to 2.8.2: * BITLK: Fix for BitLocker metadata validation on big-endian systems. * Update to 2.8.1: * Fix status and deactivation of TCRYPT (VeraCrypt compatible) devices that use chained ciphers. * Fix unlocking BITLK (BitLocker compatible) devices with multibyte UTF8 characters in the passphrase. * Do not allow activation of the LUKS2 device if the used keyslot is not encrypted (it uses a null cipher). * Such a configuration cannot be created by cryptsetup, but can be crafted outside of it. * Null cipher is sometimes used to create an empty container for later reencryption. * Only an empty passphrase can activate such a container (the same as in LUKS1). * Do not silently decrease PBKDF parallel cost (threads) if set by an option. * The maximum parallel cost is limited to 4 threads. * Fixes to configuration and installation scripts. * Meson and autoconf tools now properly support --prefix option for temporary directory installation. * Multiple fixes and cleanups to config.h for compatibility between Meson and autoconf. * Fix the luks2-external-tokens-path Meson option to work the same as in autoconf. * Fix Meson install for tool binaries, install fvault2Open man page and include test/fuzz/meson.build in release. * Major update to manual pages. * Try to explain the PBKDF hardcoded limits. * Add a better explanation for automatic integrity tag recalculation. * Mention crypt/verity/integritytab. * Remove or reformulate some misleading warnings present only with old and no longer supported kernels. * Clarify that some commands do not wipe data and unify OPAL reset wording. * Clarify the --label option. * There are also many other grammar and stylistic fixes to unify the man-page style. * Fixes for false-positive and annoying (optional) warnings added in recent compilers. * Update to 2.8.0: * Full release notes in: * https://cdn.kernel.org/pub/linux/utils/cryptsetup/v2.8/v2.8.0-ReleaseNotes * Introduce support for inline mode (use HW sectors with additional hardware metadata space). * Finalize use of keyslot context API. * Make all keyslot context types fully self-contained. * Add --key-description and --new-key-description cryptsetup options. * Support more precise keyslot selection in reencryption initialization. * Allow reencryption to resume using token and volume keys. * Cryptsetup repair command now tries to check LUKS keyslot areas for corruption. * Opal2 SED: PSID keyfile is now expected to be 32 alphanumeric characters. * Opal2: Avoid the Erase method and use Secure Erase for locking range. * Opal2: Fix some error description (in debug only). * Opal2: Do not allow deferred deactivation. * Allow --reduce-device-size and --device-size combination for reencryption (encrypt) action. * Fix the userspace storage backend to support kernel "capi:" cipher specification format. * Disallow conversion from LUKS2 to LUKS1 if kernel "capi:" cipher specification is used. * Explicitly disallow kernel "capi:" cipher specification format for LUKS2 keyslot encryption. * Do not allow conversion of LUKS2 to LUKS1 if an unbound keyslot is present. * cryptsetup: Adjust the XTS key size for kernel "capi:" cipher specification. * Remove keyslot warning about possible failure due to low memory. * Do not limit Argon2 KDF memory cost on systems with more than 4GB of available memory. * Properly report out of memory error for cryptographic backends implementing Argon2. * Avoid KDF2 memory cost overflow on 32-bit platforms. * Do not use page size as a fallback for device block size. * veritysetup: Check hash device size in advance. * Print a better error message for unsupported LUKS2 AEAD device resize. * Optimize LUKS2 metadata writes. * veritysetup: support --error-as-corruption option. * Report all sizes in status and dump command output in the correct units. * Add --integrity-key-size option to cryptsetup. * Support trusted; encrypted keyrings for plain devices. * Support plain format resize with a keyring key. * TCRYPT: Clear mapping of system-encrypted partitions. * TCRYPT: Print all information from the decrypted metadata header in the tcryptDump command. * Always lock the volume key structure in memory. * Do not run direct-io read check on block devices. * Fix a possible segfault in deferred deactivation. * Exclude cipher allocation time from the cryptsetup benchmark. * Add Mbed-TLS optional crypto backend. * Fix the wrong preprocessor use of #ifdef for config.h processed by Meson. * Reorganize license files. The license text files are now in docs/licenses. The COPYING file in the root directory is the default license. * Remove cc-by-sa-4.0.txt as already shipped now in docs/licenses and named as COPYING.CC-BY-SA-4.0. * Libcryptsetup API extensions. The libcryptsetup API is backward compatible with all existing symbols. Due to the self-contained memory allocation, these symbols have the new version: * crypt_keyslot_context_init_by_passphrase; * crypt_keyslot_context_init_by_keyfile; * crypt_keyslot_context_init_by_token; * crypt_keyslot_context_init_by_volume_key; * crypt_keyslot_context_init_by_signed_key; * crypt_keyslot_context_init_by_keyring; * crypt_keyslot_context_init_by_vk_in_keyring; * New symbols: * crypt_format_inline * crypt_get_old_volume_key_size * crypt_reencrypt_init_by_keyslot_context * crypt_safe_memcpy * New defines: * CRYPT_ACTIVATE_HIGH_PRIORITY * CRYPT_ACTIVATE_ERROR_AS_CORRUPTION * CRYPT_ACTIVATE_INLINE_MODE * CRYPT_REENCRYPT_CREATE_NEW_DIGEST * New requirement flag: * CRYPT_REQUIREMENT_INLINE_HW_TAGS * Add a dependency on device-mapper to libcryptsetup12 to install the required device-mapper udev rules. (bsc#1241612) * Update to 2.7.5: * Fix possible online reencryption data corruption (only in 2.7.x). In some situations (initializing a suspended device-mapper device), cryptsetup disabled direct-io device access. This caused unsafe online reencryption operations that could lead to data corruption. The code now adds strict checks (and aborts the operation) and changes direct-io detection code to prevent data corruption. * Fix a clang compilation error in SSH token plugin. As clang linker treats missing symbols as errors, the linker phase for the SSH token failed as the optional cryptsetup_token_buffer_free was not defined. * Fix crypto backend initialization in crypt_format_luks2_opal API call. * Update to 2.7.4: * Detect device busy failure for device-mapper table-referenced devices. * Fix shared activation for dm-verity devices. * Add --shared option for veritysetup open action. * Do not use exclusive flag for the allocated backing loop files. * Fixes for problems found by static analyzers and Valgrind. * Fixes to tests and CI scripts. * Use fdupes to link identical man pages. * Update to 2.7.3: * Do not allow formatting LUKS2 with Opal SED (hardware encryption) if the reported logical sector size for the block device and Opal encryption logical block differs. * Fixes to wiping LUKS2 headers after Opal locking area erase. * Mention the need for possible PSID revert before Opal format for some drives (man page). * Fix Bitlocker-compatible code to ignore newly seen metadata entries. * Fix interactive query retry if LUKS2 unbound keyslot is present. * Detect unsupported zoned devices for LUKS header devices. * Allow "capi" cipher format for benchmark command and fix parsing of plain IV in "capi" format. * Add support for HCTR2 encryption mode. * Source code now uses SPDX license identifiers instead of full license preambles. * Fix missing includes for cryptographic backend that could cause compilation errors for some systems. * Fix tests to work correctly in FIPS mode with recent OpenSSL 3.2. * Fix various (mostly false positive) issues detected by Coverity. * License: Replace legacy 'AND SUSE-GPL-2.0-with-openssl-exception' with 'WITH cryptsetup-OpenSSL-exception' (the official SPDX exception). * update to 2.7.2: * Fix activation of OPAL-only encrypted LUKS device with tokens * Fix formatting of OPAL devices with 4096-byte sector size * Fix incorrect OPAL locking range alignment calculation if used over an unaligned device partition. * Do not check the passphrase quality for OPAL Admin PIN, as this passphrase already exists. * Update license for FAQ document to CC BY-SA 4.0. NOTE: Please note that with OPAL-only (--hw-opal-only) encryption, the configured OPAL administrator PIN (passphrase) allows unlocking all configured locking ranges without LUKS keyslot decryption (without knowledge of LUKS passphrase). Because of many observed problems with compatibility, cryptsetup currently DOES NOT use OPAL single-user mode, which would allow such decoupling of OPAL admin PIN access. * Update to 2.7.1: * Fix interrupted LUKS1 decryption resume. With the replacement of the cryptsetup-reencrypt tool by the cryptsetup reencrypt command, resuming the interrupted LUKS1 decryption operation could fail. LUKS2 was not affected. * Allow --link-vk-to-keyring with --test-passphrase option. This option allows uploading the volume key in a user-specified kernel keyring without activating the device. * Fix crash when --active-name was used in decryption initialization. * Updates and changes to man pages, including indentation, sorting options alphabetically, fixing mistakes in crypt_set_keyring_to_link, and fixing some typos. * Fix compilation with libargon2 when --disable-internal-argon2 was used. * Do not require installed argon2.h header and never compile internal libargon2 code if the crypto library directly supports Argon2. * Fixes to regression tests to support older Linux distributions. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2777=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cryptsetup-2.8.4-150700.6.4.4 * cryptsetup-debuginfo-2.8.4-150700.6.4.4 * libcryptsetup-devel-2.8.4-150700.6.4.4 * cryptsetup-ssh-2.8.4-150700.6.4.4 * libcryptsetup12-2.8.4-150700.6.4.4 * cryptsetup-debugsource-2.8.4-150700.6.4.4 * libcryptsetup12-debuginfo-2.8.4-150700.6.4.4 * cryptsetup-ssh-debuginfo-2.8.4-150700.6.4.4 * Basesystem Module 15-SP7 (s390x x86_64) * s390-tools-2.41.0-150700.4.26.2 * Basesystem Module 15-SP7 (noarch) * s390-tools-genprotimg-data-2.41.0-150700.4.26.2 * cryptsetup-doc-2.8.4-150700.6.4.4 * cryptsetup-lang-2.8.4-150700.6.4.4 * Basesystem Module 15-SP7 (s390x) * s390-tools-debuginfo-2.41.0-150700.4.26.2 * s390-tools-debugsource-2.41.0-150700.4.26.2 * libekmfweb1-2.41.0-150700.4.26.2 * s390-tools-zdsfs-debuginfo-2.41.0-150700.4.26.2 * libkmipclient1-2.41.0-150700.4.26.2 * osasnmpd-2.41.0-150700.4.26.2 * libkmipclient1-debuginfo-2.41.0-150700.4.26.2 * libekmfweb1-devel-2.41.0-150700.4.26.2 * s390-tools-chreipl-fcp-mpath-2.41.0-150700.4.26.2 * s390-tools-hmcdrvfs-debuginfo-2.41.0-150700.4.26.2 * s390-tools-hmcdrvfs-2.41.0-150700.4.26.2 * osasnmpd-debuginfo-2.41.0-150700.4.26.2 * libekmfweb1-debuginfo-2.41.0-150700.4.26.2 * s390-tools-zdsfs-2.41.0-150700.4.26.2 * Basesystem Module 15-SP7 (x86_64) * libcryptsetup12-32bit-debuginfo-2.8.4-150700.6.4.4 * libcryptsetup12-32bit-2.8.4-150700.6.4.4 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1241612 * https://bugzilla.suse.com/show_bug.cgi?id=1259314 * https://bugzilla.suse.com/show_bug.cgi?id=1261813 * https://bugzilla.suse.com/show_bug.cgi?id=1270185 * https://jira.suse.com/browse/PED-14586 * https://jira.suse.com/browse/PED-15860 * https://jira.suse.com/browse/PED-15889 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 20:30:06 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 20:30:06 -0000 Subject: SUSE-SU-2026:2781-1: moderate: Security update for postfix Message-ID: <178336980636.599.221808554255112070@2afce7b7fe24> # Security update for postfix Announcement ID: SUSE-SU-2026:2781-1 Release Date: 2026-07-06T14:12:18Z Rating: moderate References: * bsc#1264062 Cross-References: * CVE-2026-43964 CVSS scores: * CVE-2026-43964 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43964 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Legacy Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for postfix fixes the following issue * CVE-2026-43964: buffer overread and process crash via an enhanced status code that lacks text after the third number (bsc#1264062). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-2781=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2781=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2781=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2781=1 ## Package List: * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postfix-bdb-3.8.4-150600.3.6.1 * postfix-bdb-lmdb-debuginfo-3.8.4-150600.3.6.1 * postfix-bdb-lmdb-3.8.4-150600.3.6.1 * postfix-bdb-debugsource-3.8.4-150600.3.6.1 * postfix-bdb-debuginfo-3.8.4-150600.3.6.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postfix-mysql-debuginfo-3.8.4-150600.3.6.1 * postfix-mysql-3.8.4-150600.3.6.1 * postfix-debugsource-3.8.4-150600.3.6.1 * postfix-debuginfo-3.8.4-150600.3.6.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * postfix-ldap-debuginfo-3.8.4-150600.3.6.1 * postfix-mysql-debuginfo-3.8.4-150600.3.6.1 * postfix-postgresql-3.8.4-150600.3.6.1 * postfix-debugsource-3.8.4-150600.3.6.1 * postfix-bdb-3.8.4-150600.3.6.1 * postfix-debuginfo-3.8.4-150600.3.6.1 * postfix-3.8.4-150600.3.6.1 * postfix-bdb-lmdb-debuginfo-3.8.4-150600.3.6.1 * postfix-bdb-lmdb-3.8.4-150600.3.6.1 * postfix-ldap-3.8.4-150600.3.6.1 * postfix-bdb-debugsource-3.8.4-150600.3.6.1 * postfix-mysql-3.8.4-150600.3.6.1 * postfix-postgresql-debuginfo-3.8.4-150600.3.6.1 * postfix-bdb-debuginfo-3.8.4-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * postfix-devel-3.8.4-150600.3.6.1 * postfix-doc-3.8.4-150600.3.6.1 * Basesystem Module 15-SP7 (noarch) * postfix-devel-3.8.4-150600.3.6.1 * postfix-doc-3.8.4-150600.3.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postfix-ldap-debuginfo-3.8.4-150600.3.6.1 * postfix-ldap-3.8.4-150600.3.6.1 * postfix-debuginfo-3.8.4-150600.3.6.1 * postfix-3.8.4-150600.3.6.1 * postfix-debugsource-3.8.4-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43964.html * https://bugzilla.suse.com/show_bug.cgi?id=1264062 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 20:30:12 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 20:30:12 -0000 Subject: SUSE-SU-2026:2780-1: moderate: Security update for postfix Message-ID: <178336981257.599.15876066599371965690@2afce7b7fe24> # Security update for postfix Announcement ID: SUSE-SU-2026:2780-1 Release Date: 2026-07-06T14:11:50Z Rating: moderate References: * bsc#1264062 Cross-References: * CVE-2026-43964 CVSS scores: * CVE-2026-43964 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43964 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for postfix fixes the following issue * CVE-2026-43964: buffer overread and process crash via an enhanced status code that lacks text after the third number (bsc#1264062). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2780=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * postfix-doc-3.2.10-3.33.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * postfix-mysql-3.2.10-3.33.1 * postfix-devel-3.2.10-3.33.1 * postfix-debuginfo-3.2.10-3.33.1 * postfix-debugsource-3.2.10-3.33.1 * postfix-3.2.10-3.33.1 * postfix-mysql-debuginfo-3.2.10-3.33.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43964.html * https://bugzilla.suse.com/show_bug.cgi?id=1264062 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 20:30:26 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 06 Jul 2026 20:30:26 -0000 Subject: SUSE-SU-2026:2779-1: important: Security update for bind Message-ID: <178336982619.599.2006811522306497641@2afce7b7fe24> # Security update for bind Announcement ID: SUSE-SU-2026:2779-1 Release Date: 2026-07-06T14:07:45Z Rating: important References: * bsc#1265591 * bsc#1265592 * bsc#1265594 Cross-References: * CVE-2026-3039 * CVE-2026-3592 * CVE-2026-5946 CVSS scores: * CVE-2026-3039 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3592 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-3592 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5946 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). * CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records (bsc#1265592). * CVE-2026-5946: Invalid handling of CLASS != IN (bsc#1265594). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2779=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2779=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2779=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2779=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libirs1601-debuginfo-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * bind-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * bind-devel-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * bind-utils-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libbind9-1600-9.16.6-150300.22.59.1 * libbind9-1600-debuginfo-9.16.6-150300.22.59.1 * libns1604-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 * libisccc1600-debuginfo-9.16.6-150300.22.59.1 * libisccc1600-9.16.6-150300.22.59.1 * bind-utils-debuginfo-9.16.6-150300.22.59.1 * bind-chrootenv-9.16.6-150300.22.59.1 * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libns1604-debuginfo-9.16.6-150300.22.59.1 * openSUSE Leap 15.3 (noarch) * python3-bind-9.16.6-150300.22.59.1 * bind-doc-9.16.6-150300.22.59.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * libirs1601-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * libirs1601-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * libirs1601-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3039.html * https://www.suse.com/security/cve/CVE-2026-3592.html * https://www.suse.com/security/cve/CVE-2026-5946.html * https://bugzilla.suse.com/show_bug.cgi?id=1265591 * https://bugzilla.suse.com/show_bug.cgi?id=1265592 * https://bugzilla.suse.com/show_bug.cgi?id=1265594 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 7 08:30:11 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 07 Jul 2026 08:30:11 -0000 Subject: SUSE-SU-2026:2782-1: important: Security update for perl-Cpanel-JSON-XS Message-ID: <178341301150.10238.3285038668432088045@63abed19989d> # Security update for perl-Cpanel-JSON-XS Announcement ID: SUSE-SU-2026:2782-1 Release Date: 2026-07-06T18:01:58Z Rating: important References: * bsc#1267546 * bsc#1267547 Cross-References: * CVE-2026-9334 * CVE-2026-9516 CVSS scores: * CVE-2026-9334 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-9334 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9334 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9516 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9516 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9516 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-Cpanel-JSON-XS fixes the following issues * CVE-2026-9334: type confusion via duplicate object keys when `dupkeys_as_arrayref` is enabled (bsc#1267546). * CVE-2026-9516: denial of service via UTF-8 BOM prefixed input when a decode filter callback throws (bsc#1267547). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2782=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-Cpanel-JSON-XS-debuginfo-4.380.0-150700.3.6.1 * perl-Cpanel-JSON-XS-4.380.0-150700.3.6.1 * perl-Cpanel-JSON-XS-debugsource-4.380.0-150700.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9334.html * https://www.suse.com/security/cve/CVE-2026-9516.html * https://bugzilla.suse.com/show_bug.cgi?id=1267546 * https://bugzilla.suse.com/show_bug.cgi?id=1267547 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 08:30:12 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 08:30:12 -0000 Subject: SUSE-SU-2026:2783-1: important: Security update for kubevirt-1.6 Message-ID: <178349941285.273.8136739113122494108@5ed4f61072e9> # Security update for kubevirt-1.6 Announcement ID: SUSE-SU-2026:2783-1 Release Date: 2026-07-07T15:05:10Z Rating: important References: * bsc#1256434 * bsc#1262265 * bsc#1266733 Cross-References: * CVE-2025-14525 * CVE-2026-35469 * CVE-2026-9804 CVSS scores: * CVE-2025-14525 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-14525 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-14525 ( NVD ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-35469 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9804 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9804 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9804 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for kubevirt-1.6 fixes the following issues: * CVE-2026-9804: Symlink escape in the VMExport dir handler let an attacker controlling an exported PVC read sensitive files (TLS keys, tokens, service- account creds) from the exporter pod. (bsc#1266733) * CVE-2025-14525: A VM reporting many guest-internal interfaces via the guest agent could flood VMI status and fill etcd (denial of service). Caps reported interfaces at 10. (bsc#1256434) * CVE-2026-35469: resource-exhaustion in the SPDY/3 protocol implementation of github.com/moby/spdystream. (GHSA-pc3f-x583-g7j2,bsc#1262265) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2783=1 ## Package List: * Containers Module 15-SP7 (aarch64 x86_64) * kubevirt-1.6-virtctl-debuginfo-1.6.6-150700.15.10.1 * kubevirt-1.6-virtctl-1.6.6-150700.15.10.1 * kubevirt-1.6-manifests-1.6.6-150700.15.10.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14525.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://www.suse.com/security/cve/CVE-2026-9804.html * https://bugzilla.suse.com/show_bug.cgi?id=1256434 * https://bugzilla.suse.com/show_bug.cgi?id=1262265 * https://bugzilla.suse.com/show_bug.cgi?id=1266733 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 12:31:15 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 12:31:15 -0000 Subject: SUSE-SU-2026:22523-1: moderate: Security update for glibc Message-ID: <178351387563.407.1248592251550428584@530c474df1e7> # Security update for glibc Announcement ID: SUSE-SU-2026:22523-1 Release Date: 2026-07-06T13:14:21Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-784=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * glibc-debugsource-2.38-14.1 * glibc-locale-base-2.38-14.1 * glibc-devel-2.38-14.1 * glibc-debuginfo-2.38-14.1 * glibc-locale-2.38-14.1 * glibc-locale-base-debuginfo-2.38-14.1 * glibc-2.38-14.1 * glibc-devel-debuginfo-2.38-14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:32:18 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:32:18 -0000 Subject: SUSE-SU-2026:22522-1: important: Security update for the Linux Kernel Message-ID: <178352833849.452.16876113071222780313@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22522-1 Release Date: 2026-07-06T13:11:38Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-502=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * kernel-devel-rt-6.4.0-49.1 * kernel-source-rt-6.4.0-49.1 * SUSE Linux Micro 6.0 (x86_64) * kernel-rt-livepatch-6.4.0-49.1 * kernel-rt-debuginfo-6.4.0-49.1 * kernel-rt-debugsource-6.4.0-49.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-rt-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:26 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:34:26 -0000 Subject: SUSE-SU-2026:22521-1: important: Security update for the Linux Kernel Message-ID: <178352846628.452.16818843223110044447@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22521-1 Release Date: 2026-07-06T13:11:37Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-501=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-kvmsmall-debugsource-6.4.0-49.1 * kernel-kvmsmall-debuginfo-6.4.0-49.1 * SUSE Linux Micro 6.0 (noarch) * kernel-source-6.4.0-49.1 * kernel-macros-6.4.0-49.1 * kernel-devel-6.4.0-49.1 * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-default-livepatch-6.4.0-49.1 * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * kernel-default-debuginfo-6.4.0-49.1 * kernel-default-debugsource-6.4.0-49.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-kvmsmall-6.4.0-49.1 * SUSE Linux Micro 6.0 (aarch64 nosrc s390x x86_64) * kernel-default-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:34 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:34:34 -0000 Subject: SUSE-RU-2026:22520-1: moderate: Recommended update for cloud-regionsrv-client Message-ID: <178352847401.452.3198424678931974728@57e59d802799> # Recommended update for cloud-regionsrv-client Announcement ID: SUSE-RU-2026:22520-1 Release Date: 2026-07-06T10:08:12Z Rating: moderate References: * bsc#1265930 * bsc#1267739 Affected Products: * SUSE Linux Micro 6.0 An update that has two fixes can now be installed. ## Description: This update for cloud-regionsrv-client fixes the following issues: * Update to version 11.0.3: * Write instance data cache file after cleaning the cache when the update server fails (bsc#1265930) * Create the cache directory when populating the cache (bsc#1267739) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-783=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * cloud-regionsrv-client-generic-config-1.0.0-9.1 * cloud-regionsrv-client-plugin-ec2-2.0.0-9.1 * cloud-regionsrv-client-plugin-gce-2.0.0-9.1 * cloud-regionsrv-client-11.0.3-9.1 * cloud-regionsrv-client-license-watcher-1.0.0-9.1 * cloud-regionsrv-client-plugin-azure-3.0.0-9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265930 * https://bugzilla.suse.com/show_bug.cgi?id=1267739 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:37 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:34:37 -0000 Subject: SUSE-RU-2026:22519-1: moderate: Recommended update for kmod Message-ID: <178352847786.452.13248014979832291175@57e59d802799> # Recommended update for kmod Announcement ID: SUSE-RU-2026:22519-1 Release Date: 2026-07-06T09:55:13Z Rating: moderate References: * jsc#PED-16303 Affected Products: * SUSE Linux Micro 6.0 An update that contains one feature can now be installed. ## Description: This update for kmod fixes the following issues: * Use in-kernel decompression if available (jsc#PED-16303): * libkmod: * Add a separate function to load the file contents when it's needed. When it's not needed on the path of loading modules via finit_module(), there is no need to mmap the file. * Extract 2 functions to handle finit_module vs init_modules differences, with a fallback from the former to the latter. * Don't only set the type as direct, but also keep track of the compression being used. * When creating the context, read /sys/kernel/compression to check what's the compression type supported by the kernel. * Use kernel decompression when available * add fallback MODULE_INIT_COMPRESSED_FILE define ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-782=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libkmod2-30-12.1 * kmod-30-12.1 * libkmod2-debuginfo-30-12.1 * kmod-debuginfo-30-12.1 * kmod-debugsource-30-12.1 ## References: * https://jira.suse.com/browse/PED-16303 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:41 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:34:41 -0000 Subject: SUSE-SU-2026:22518-1: important: Security update for kernel-livepatch-MICRO-6-0_Update_26 Message-ID: <178352848165.452.13846569591964029385@57e59d802799> # Security update for kernel-livepatch-MICRO-6-0_Update_26 Announcement ID: SUSE-SU-2026:22518-1 Release Date: 2026-07-06T09:28:38Z Rating: important References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_26 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 26 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-500=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-49-default-1-1.1 * kernel-livepatch-MICRO-6-0_Update_26-debugsource-1-1.1 * kernel-livepatch-6_4_0-49-default-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:45 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:34:45 -0000 Subject: SUSE-SU-2026:22517-1: moderate: Security update for kernel-livepatch-MICRO-6-0-RT_Update_26 Message-ID: <178352848572.452.6373476448875907283@57e59d802799> # Security update for kernel-livepatch-MICRO-6-0-RT_Update_26 Announcement ID: SUSE-SU-2026:22517-1 Release Date: 2026-07-06T09:18:54Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_26 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 26 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-503=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_26-debugsource-1-1.1 * kernel-livepatch-6_4_0-49-rt-1-1.1 * kernel-livepatch-6_4_0-49-rt-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:53 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:34:53 -0000 Subject: SUSE-SU-2026:22516-1: important: Security update for podman Message-ID: <178352849347.452.3517584589186288976@57e59d802799> # Security update for podman Announcement ID: SUSE-SU-2026:22516-1 Release Date: 2026-07-03T12:53:16Z Rating: important References: * bsc#1262856 * bsc#1266125 Cross-References: * CVE-2024-6104 * CVE-2025-22869 * CVE-2025-27144 * CVE-2025-47913 * CVE-2025-47914 * CVE-2025-52881 * CVE-2025-6032 * CVE-2025-9566 * CVE-2026-34986 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2024-6104 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2024-6104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-27144 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47914 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47914 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47914 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-52881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-52881 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-52881 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-52881 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2025-6032 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-6032 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-6032 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-9566 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-9566 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-9566 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for podman fixes the following issues * CVE-2026-34986: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262856). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266125). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266125). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266125). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266125). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-779=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * podman-docker-4.9.5-12.1 * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * podman-4.9.5-12.1 * podman-remote-debuginfo-4.9.5-12.1 * podmansh-4.9.5-12.1 * podman-remote-4.9.5-12.1 * podman-debuginfo-4.9.5-12.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6104.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2025-27144.html * https://www.suse.com/security/cve/CVE-2025-47913.html * https://www.suse.com/security/cve/CVE-2025-47914.html * https://www.suse.com/security/cve/CVE-2025-52881.html * https://www.suse.com/security/cve/CVE-2025-6032.html * https://www.suse.com/security/cve/CVE-2025-9566.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1262856 * https://bugzilla.suse.com/show_bug.cgi?id=1266125 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:35:00 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:35:00 -0000 Subject: SUSE-SU-2026:22515-1: important: Security update for haproxy Message-ID: <178352850042.452.5200175637295792711@57e59d802799> # Security update for haproxy Announcement ID: SUSE-SU-2026:22515-1 Release Date: 2026-07-03T12:51:57Z Rating: important References: * bsc#1268557 * bsc#1268558 Cross-References: * CVE-2026-55203 * CVE-2026-55204 CVSS scores: * CVE-2026-55203 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-55203 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55203 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N * CVE-2026-55204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues * CVE-2026-55203: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557). * CVE-2026-55204: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-781=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * haproxy-debugsource-2.8.11+git0.01c1056a4-4.1 * haproxy-debuginfo-2.8.11+git0.01c1056a4-4.1 * haproxy-2.8.11+git0.01c1056a4-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55203.html * https://www.suse.com/security/cve/CVE-2026-55204.html * https://bugzilla.suse.com/show_bug.cgi?id=1268557 * https://bugzilla.suse.com/show_bug.cgi?id=1268558 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:35:06 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:35:06 -0000 Subject: SUSE-SU-2026:22514-1: moderate: Security update for libslirp Message-ID: <178352850612.452.12910206784303471705@57e59d802799> # Security update for libslirp Announcement ID: SUSE-SU-2026:22514-1 Release Date: 2026-07-03T12:51:57Z Rating: moderate References: * bsc#1268903 Cross-References: * CVE-2026-9539 CVSS scores: * CVE-2026-9539 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9539 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libslirp fixes the following issue * CVE-2026-9539: TCP URG out of bounds heap read information leak (bsc#1268903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-780=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libslirp-debugsource-4.7.0+44-5.1 * libslirp0-debuginfo-4.7.0+44-5.1 * libslirp0-4.7.0+44-5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9539.html * https://bugzilla.suse.com/show_bug.cgi?id=1268903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:35:16 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:35:16 -0000 Subject: SUSE-SU-2026:22513-1: important: Security update for docker Message-ID: <178352851621.452.15519092799533611872@57e59d802799> # Security update for docker Announcement ID: SUSE-SU-2026:22513-1 Release Date: 2026-07-02T18:48:26Z Rating: important References: * bsc#1262346 * bsc#1265782 * bsc#1266625 * bsc#1267827 Cross-References: * CVE-2026-33814 * CVE-2026-39821 * CVE-2026-39984 * CVE-2026-41567 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39984 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39984 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39984 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41567 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). * CVE-2026-39984: github.com/sigstore/timestamp-authority/v2/pkg/verification: improper certificate validation can be used to bypass some authorization controls (bsc#1262346). * CVE-2026-41567: arbitrary code execution with full daemon privileges when a user uploads a compressed archive into that container (bsc#1267827). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-778=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * docker-buildx-0.33.0-11.1 * docker-debuginfo-29.4.0_ce-11.1 * docker-29.4.0_ce-11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39984.html * https://www.suse.com/security/cve/CVE-2026-41567.html * https://bugzilla.suse.com/show_bug.cgi?id=1262346 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 * https://bugzilla.suse.com/show_bug.cgi?id=1267827 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:37:30 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:37:30 -0000 Subject: SUSE-SU-2026:22512-1: important: Security update for the Linux Kernel Message-ID: <178352865006.452.7505769115492988903@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22512-1 Release Date: 2026-07-06T13:11:38Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-502=1 ## Package List: * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-rt-devel-debuginfo-6.4.0-49.1 * kernel-rt-devel-6.4.0-49.1 * kernel-rt-debugsource-6.4.0-49.1 * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-rt-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:39:39 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:39:39 -0000 Subject: SUSE-SU-2026:22511-1: important: Security update for the Linux Kernel Message-ID: <178352877907.452.9120367132581209051@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22511-1 Release Date: 2026-07-06T13:11:36Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-501=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64) * kernel-64kb-debugsource-6.4.0-49.1 * kernel-64kb-devel-6.4.0-49.1 * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * kernel-obs-build-6.4.0-49.1 * kernel-default-devel-6.4.0-49.1 * kernel-obs-build-debugsource-6.4.0-49.1 * kernel-syms-6.4.0-49.1 * kernel-default-debugsource-6.4.0-49.1 * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-default-6.4.0-49.1 * kernel-64kb-6.4.0-49.1 * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-default-devel-debuginfo-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:39:47 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:39:47 -0000 Subject: SUSE-SU-2026:2794-1: important: Security update for libXfont2 Message-ID: <178352878798.452.14970519802298228476@57e59d802799> # Security update for libXfont2 Announcement ID: SUSE-SU-2026:2794-1 Release Date: 2026-07-08T08:08:25Z Rating: important References: * bsc#1269018 * bsc#1269019 * bsc#1269020 Cross-References: * CVE-2026-56001 * CVE-2026-56002 * CVE-2026-56003 CVSS scores: * CVE-2026-56001 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56001 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56001 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56002 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56002 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56002 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56003 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56003 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56003 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for libXfont2 fixes the following issues * CVE-2026-56001: integer overflow in `BitmapScaleBitmaps` can lead to a heap buffer overflow (bsc#1269018). * CVE-2026-56002: insufficient checks in `pcfReadFont` can lead to a heap buffer overflow (bsc#1269019). * CVE-2026-56003: missing bounds check in `ComputeScaledProperties` can lead to a heap buffer overflow (bsc#1269020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2794=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2794=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2794=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2794=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2794=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2794=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2794=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2794=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2794=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2794=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2794=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x) * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le) * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56001.html * https://www.suse.com/security/cve/CVE-2026-56002.html * https://www.suse.com/security/cve/CVE-2026-56003.html * https://bugzilla.suse.com/show_bug.cgi?id=1269018 * https://bugzilla.suse.com/show_bug.cgi?id=1269019 * https://bugzilla.suse.com/show_bug.cgi?id=1269020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:39:56 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:39:56 -0000 Subject: SUSE-SU-2026:2793-1: important: Security update for libXfont2 Message-ID: <178352879636.452.6947098403830546323@57e59d802799> # Security update for libXfont2 Announcement ID: SUSE-SU-2026:2793-1 Release Date: 2026-07-08T08:06:28Z Rating: important References: * bsc#1269018 * bsc#1269019 * bsc#1269020 Cross-References: * CVE-2026-56001 * CVE-2026-56002 * CVE-2026-56003 CVSS scores: * CVE-2026-56001 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56001 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56001 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56002 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56002 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56002 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56003 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56003 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56003 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for libXfont2 fixes the following issues * CVE-2026-56001: integer overflow in `BitmapScaleBitmaps` can lead to a heap buffer overflow (bsc#1269018). * CVE-2026-56002: insufficient checks in `pcfReadFont` can lead to a heap buffer overflow (bsc#1269019). * CVE-2026-56003: missing bounds check in `ComputeScaledProperties` can lead to a heap buffer overflow (bsc#1269020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2793=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x) * libXfont2-2-debuginfo-2.0.3-3.3.1 * libXfont2-2-2.0.3-3.3.1 * libXfont2-debugsource-2.0.3-3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56001.html * https://www.suse.com/security/cve/CVE-2026-56002.html * https://www.suse.com/security/cve/CVE-2026-56003.html * https://bugzilla.suse.com/show_bug.cgi?id=1269018 * https://bugzilla.suse.com/show_bug.cgi?id=1269019 * https://bugzilla.suse.com/show_bug.cgi?id=1269020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:40:02 -0000 Subject: SUSE-SU-2026:2792-1: important: Security update for xorg-x11-server Message-ID: <178352880241.452.4725037333717909422@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2792-1 Release Date: 2026-07-08T07:55:40Z Rating: important References: * bsc#1268893 Cross-References: * CVE-2026-55999 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for xorg-x11-server fixes the following issue * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2792=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2792=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * xorg-x11-server-extra-1.19.6-10.105.1 * xorg-x11-server-debuginfo-1.19.6-10.105.1 * xorg-x11-server-1.19.6-10.105.1 * xorg-x11-server-extra-debuginfo-1.19.6-10.105.1 * xorg-x11-server-debugsource-1.19.6-10.105.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * xorg-x11-server-extra-1.19.6-10.105.1 * xorg-x11-server-debuginfo-1.19.6-10.105.1 * xorg-x11-server-1.19.6-10.105.1 * xorg-x11-server-extra-debuginfo-1.19.6-10.105.1 * xorg-x11-server-debugsource-1.19.6-10.105.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:09 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:40:09 -0000 Subject: SUSE-SU-2026:2791-1: important: Security update for xorg-x11-server Message-ID: <178352880976.452.15159426810325475527@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2791-1 Release Date: 2026-07-08T07:33:14Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2791=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2791=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2791=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2791=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2791=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-source-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:17 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:40:17 -0000 Subject: SUSE-SU-2026:2789-1: important: Security update for xorg-x11-server Message-ID: <178352881713.452.3437817380837953924@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2789-1 Release Date: 2026-07-08T07:29:10Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2789=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2789=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2789=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2789=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2789=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * xorg-x11-server-source-1.20.3-150400.38.74.1 * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:25 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:40:25 -0000 Subject: SUSE-SU-2026:2788-1: important: Security update for xorg-x11-server Message-ID: <178352882514.452.367103114191042673@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2788-1 Release Date: 2026-07-08T07:22:17Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2788=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2788=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xorg-x11-server-debugsource-21.1.15-150700.5.22.1 * xorg-x11-server-sdk-21.1.15-150700.5.22.1 * xorg-x11-server-debuginfo-21.1.15-150700.5.22.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xorg-x11-server-debugsource-21.1.15-150700.5.22.1 * xorg-x11-server-21.1.15-150700.5.22.1 * xorg-x11-server-Xvfb-debuginfo-21.1.15-150700.5.22.1 * xorg-x11-server-extra-debuginfo-21.1.15-150700.5.22.1 * xorg-x11-server-Xvfb-21.1.15-150700.5.22.1 * xorg-x11-server-debuginfo-21.1.15-150700.5.22.1 * xorg-x11-server-extra-21.1.15-150700.5.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:32 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:40:32 -0000 Subject: SUSE-SU-2026:2787-1: important: Security update for xwayland Message-ID: <178352883202.452.750635894563499206@57e59d802799> # Security update for xwayland Announcement ID: SUSE-SU-2026:2787-1 Release Date: 2026-07-08T07:19:18Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2787=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * xwayland-24.1.5-150700.3.22.1 * xwayland-debugsource-24.1.5-150700.3.22.1 * xwayland-debuginfo-24.1.5-150700.3.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:38 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:40:38 -0000 Subject: SUSE-SU-2026:2786-1: important: Security update for xorg-x11-server Message-ID: <178352883888.452.15873794314564033576@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2786-1 Release Date: 2026-07-08T07:16:51Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2786=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2786=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2786=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * xorg-x11-server-sdk-21.1.11-150600.5.31.1 * xorg-x11-server-extra-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-extra-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-debugsource-21.1.11-150600.5.31.1 * xorg-x11-server-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-21.1.11-150600.5.31.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * xorg-x11-server-sdk-21.1.11-150600.5.31.1 * xorg-x11-server-extra-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-extra-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-debugsource-21.1.11-150600.5.31.1 * xorg-x11-server-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-21.1.11-150600.5.31.1 * xorg-x11-server-source-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-21.1.11-150600.5.31.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * xorg-x11-server-sdk-21.1.11-150600.5.31.1 * xorg-x11-server-extra-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-extra-21.1.11-150600.5.31.1 * xorg-x11-server-debugsource-21.1.11-150600.5.31.1 * xorg-x11-server-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-21.1.11-150600.5.31.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:48 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:40:48 -0000 Subject: SUSE-SU-2026:2785-1: moderate: Security update for systemd, systemd-mini Message-ID: <178352884869.452.511293618661085736@57e59d802799> # Security update for systemd, systemd-mini Announcement ID: SUSE-SU-2026:2785-1 Release Date: 2026-07-08T06:48:14Z Rating: moderate References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability and has three security fixes can now be installed. ## Description: This update for systemd, systemd-mini fixes the following issue Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Import commit eba1930de8 (bsc#1267647). * Import commit 5d46cdd987 (bsc#1261982 bsc#1261983). * Import commit ac1173932c (bsc#1261982). * Import commit c7f3e89374 (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2785=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2785=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2785=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * systemd-sysvinit-246.16-150300.7.74.1 * systemd-mini-246.16-150300.7.74.1 * udev-mini-246.16-150300.7.74.1 * systemd-portable-246.16-150300.7.74.1 * systemd-mini-devel-246.16-150300.7.74.1 * systemd-coredump-debuginfo-246.16-150300.7.74.1 * systemd-container-246.16-150300.7.74.1 * nss-mymachines-debuginfo-246.16-150300.7.74.1 * udev-mini-debuginfo-246.16-150300.7.74.1 * udev-debuginfo-246.16-150300.7.74.1 * systemd-network-debuginfo-246.16-150300.7.74.1 * systemd-mini-debuginfo-246.16-150300.7.74.1 * nss-systemd-debuginfo-246.16-150300.7.74.1 * libudev1-debuginfo-246.16-150300.7.74.1 * systemd-coredump-246.16-150300.7.74.1 * libsystemd0-mini-246.16-150300.7.74.1 * systemd-devel-246.16-150300.7.74.1 * nss-resolve-246.16-150300.7.74.1 * libudev-devel-246.16-150300.7.74.1 * libsystemd0-mini-debuginfo-246.16-150300.7.74.1 * nss-myhostname-246.16-150300.7.74.1 * systemd-246.16-150300.7.74.1 * libsystemd0-debuginfo-246.16-150300.7.74.1 * systemd-mini-sysvinit-246.16-150300.7.74.1 * systemd-doc-246.16-150300.7.74.1 * systemd-mini-container-246.16-150300.7.74.1 * udev-246.16-150300.7.74.1 * nss-systemd-246.16-150300.7.74.1 * libudev-mini1-246.16-150300.7.74.1 * systemd-network-246.16-150300.7.74.1 * nss-resolve-debuginfo-246.16-150300.7.74.1 * systemd-debuginfo-246.16-150300.7.74.1 * nss-mymachines-246.16-150300.7.74.1 * systemd-journal-remote-246.16-150300.7.74.1 * nss-myhostname-debuginfo-246.16-150300.7.74.1 * libudev-mini-devel-246.16-150300.7.74.1 * systemd-debugsource-246.16-150300.7.74.1 * systemd-mini-container-debuginfo-246.16-150300.7.74.1 * systemd-logger-246.16-150300.7.74.1 * libudev-mini1-debuginfo-246.16-150300.7.74.1 * libsystemd0-246.16-150300.7.74.1 * systemd-journal-remote-debuginfo-246.16-150300.7.74.1 * libudev1-246.16-150300.7.74.1 * systemd-container-debuginfo-246.16-150300.7.74.1 * systemd-mini-debugsource-246.16-150300.7.74.1 * systemd-portable-debuginfo-246.16-150300.7.74.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libsystemd0-64bit-debuginfo-246.16-150300.7.74.1 * libsystemd0-64bit-246.16-150300.7.74.1 * libudev-devel-64bit-246.16-150300.7.74.1 * nss-mymachines-64bit-246.16-150300.7.74.1 * nss-myhostname-64bit-246.16-150300.7.74.1 * nss-mymachines-64bit-debuginfo-246.16-150300.7.74.1 * systemd-64bit-246.16-150300.7.74.1 * nss-myhostname-64bit-debuginfo-246.16-150300.7.74.1 * libudev1-64bit-debuginfo-246.16-150300.7.74.1 * libudev1-64bit-246.16-150300.7.74.1 * systemd-64bit-debuginfo-246.16-150300.7.74.1 * openSUSE Leap 15.3 (x86_64) * libsystemd0-32bit-246.16-150300.7.74.1 * libudev1-32bit-246.16-150300.7.74.1 * libudev-devel-32bit-246.16-150300.7.74.1 * nss-mymachines-32bit-246.16-150300.7.74.1 * nss-myhostname-32bit-246.16-150300.7.74.1 * systemd-32bit-debuginfo-246.16-150300.7.74.1 * libsystemd0-32bit-debuginfo-246.16-150300.7.74.1 * nss-mymachines-32bit-debuginfo-246.16-150300.7.74.1 * systemd-32bit-246.16-150300.7.74.1 * nss-myhostname-32bit-debuginfo-246.16-150300.7.74.1 * libudev1-32bit-debuginfo-246.16-150300.7.74.1 * openSUSE Leap 15.3 (noarch) * systemd-lang-246.16-150300.7.74.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * systemd-sysvinit-246.16-150300.7.74.1 * systemd-debugsource-246.16-150300.7.74.1 * systemd-246.16-150300.7.74.1 * libsystemd0-debuginfo-246.16-150300.7.74.1 * libsystemd0-246.16-150300.7.74.1 * udev-246.16-150300.7.74.1 * systemd-container-246.16-150300.7.74.1 * systemd-journal-remote-debuginfo-246.16-150300.7.74.1 * libudev1-246.16-150300.7.74.1 * udev-debuginfo-246.16-150300.7.74.1 * systemd-container-debuginfo-246.16-150300.7.74.1 * systemd-debuginfo-246.16-150300.7.74.1 * libudev1-debuginfo-246.16-150300.7.74.1 * systemd-journal-remote-246.16-150300.7.74.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * systemd-sysvinit-246.16-150300.7.74.1 * systemd-debugsource-246.16-150300.7.74.1 * systemd-246.16-150300.7.74.1 * libsystemd0-debuginfo-246.16-150300.7.74.1 * libsystemd0-246.16-150300.7.74.1 * udev-246.16-150300.7.74.1 * systemd-container-246.16-150300.7.74.1 * systemd-journal-remote-debuginfo-246.16-150300.7.74.1 * libudev1-246.16-150300.7.74.1 * udev-debuginfo-246.16-150300.7.74.1 * systemd-container-debuginfo-246.16-150300.7.74.1 * systemd-debuginfo-246.16-150300.7.74.1 * libudev1-debuginfo-246.16-150300.7.74.1 * systemd-journal-remote-246.16-150300.7.74.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:52 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 16:40:52 -0000 Subject: SUSE-RU-2026:2784-1: moderate: Recommended update for Trento Message-ID: <178352885294.452.2204797826951062213@57e59d802799> # Recommended update for Trento Announcement ID: SUSE-RU-2026:2784-1 Release Date: 2026-07-08T05:38:59Z Rating: moderate References: Affected Products: * SAP Applications Module 15-SP4 * SAP Applications Module 15-SP5 * SAP Applications Module 15-SP6 * SAP Applications Module 15-SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for Trento fixes the following issues: This is a patch release for Trento with fixes of the following components: trento-agent: * Release 3.1.1: * Bumped golang.org/x/net to v0.55.0 * Updated contracts references * Bumped github.com/tidwall/gjson from 1.18.0 to 1.19.0 * Bumped golang.org/x/mod from 0.34.0 to 0.36.0 * Bumped gopkg.in/ini.v1 from 1.67.1 to 1.67.2 trento-web, trento-web-image: * Release 3.1.2 * Fixed loading checks execution detail when catalog is still loading * Enforce using erlang26 on SUSE Linux Enterprise 15 * Update initial dashboard Health summary content for the Application Instances column * Release 3.1.1 * Updated analytics docs link profile form * Flip activity log `from_date` and `to_date` LoggerConfig * Support openAPI styles query string arrays usage mcp-server-trento, mcp-server-trento-image: * Release 1.1.1: * Fixed unhandled array parameters trento-checks, trento-checks-image: * Release 1.3.1: * Changed description of check 9FAAD trento-server-helm: * Release 3.1.1 containing version bumps ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SAP Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP5-2026-2784=1 * SAP Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP6-2026-2784=1 * SAP Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP4-2026-2784=1 * SAP Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP7-2026-2784=1 ## Package List: * SAP Applications Module 15-SP6 (ppc64le s390x x86_64) * mcp-server-trento-1.1.1-150300.1.9.1 * trento-agent-3.1.1-150100.3.27.1 * SAP Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * trento-web-3.1.2-150300.1.25.1 * SAP Applications Module 15-SP6 (noarch) * trento-checks-1.3.1-150300.1.15.1 * SAP Applications Module 15-SP7 (noarch) * trento-checks-1.3.1-150300.1.15.1 * SAP Applications Module 15-SP7 (ppc64le s390x x86_64) * mcp-server-trento-1.1.1-150300.1.9.1 * trento-agent-3.1.1-150100.3.27.1 * SAP Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * trento-web-3.1.2-150300.1.25.1 * SAP Applications Module 15-SP5 (ppc64le s390x x86_64) * mcp-server-trento-1.1.1-150300.1.9.1 * trento-agent-3.1.1-150100.3.27.1 * SAP Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * trento-web-3.1.2-150300.1.25.1 * SAP Applications Module 15-SP5 (noarch) * trento-checks-1.3.1-150300.1.15.1 * SAP Applications Module 15-SP4 (ppc64le s390x x86_64) * mcp-server-trento-1.1.1-150300.1.9.1 * trento-agent-3.1.1-150100.3.27.1 * SAP Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * trento-web-3.1.2-150300.1.25.1 * SAP Applications Module 15-SP4 (noarch) * trento-checks-1.3.1-150300.1.15.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 20:32:46 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 20:32:46 -0000 Subject: SUSE-SU-2026:2800-1: important: Security update for the Linux Kernel Message-ID: <178354276683.547.11597989045194206569@530c474df1e7> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2800-1 Release Date: 2026-07-08T14:59:46Z Rating: important References: * bsc#1236743 * bsc#1255029 * bsc#1259764 * bsc#1261256 * bsc#1261562 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263581 * bsc#1263879 * bsc#1263880 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264084 * bsc#1264116 * bsc#1264145 * bsc#1264228 * bsc#1264230 * bsc#1264231 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264263 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264449 * bsc#1264484 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267381 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267640 * bsc#1267682 * bsc#1267684 * bsc#1267697 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267953 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268049 * bsc#1268159 * bsc#1268237 * bsc#1268307 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269199 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269617 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-15880 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40216 * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31647 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31771 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43094 * CVE-2026-43107 * CVE-2026-43109 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43284 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46120 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46197 * CVE-2026-46214 * CVE-2026-46227 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46315 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46330 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31647 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31647 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43094 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46315 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46330 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46330 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46330 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * Legacy Module 15-SP7 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves 105 vulnerabilities, contains three features and has 12 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764). * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-46330: Revert "net/smc: Introduce TCP ULP support" (bsc#1268049). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable- fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). * drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). * drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * iommu/s390: allow larger region tables (jsc#PED-15880). * iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880). * iommu/s390: handle IOAT registration based on domain (jsc#PED-15880). * iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880). * iommu/s390: set appropriate IOTA region type (jsc#PED-15880). * iommu/s390: support cleanup of additional table regions (jsc#PED-15880). * iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880). * iommu/s390: support map/unmap for additional table regions (jsc#PED-15880). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * page_pool: Move pp_magic check into helper functions (bsc#1261562). * page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). * platform/x86: intel-hid: Protect ACPI notify handler against recursion (git- fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git- fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * s390/pci: check for relaxed translation capability (jsc#PED-15880). * s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880). * s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617). * selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617). * selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617). * selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617). * selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617). * selftests/bpf: Skip tests whose objects were not built (bsc#1269617). * selftests/bpf: Tolerate benchmark build failures (bsc#1269617). * selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617). * selftests/bpf: Tolerate missing files during install (bsc#1269617). * selftests/bpf: Tolerate test file compilation failures (bsc#1269617). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2800=1 Please note that this is the initial kernel livepatch without fixes itself, this package is later updated by separate standalone kernel livepatch updates. * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2800=1 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-2800=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-2800=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2800=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2800=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2800=1 ## Package List: * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * reiserfs-kmp-default-debuginfo-6.4.0-150700.53.66.1 * reiserfs-kmp-default-6.4.0-150700.53.66.1 * Legacy Module 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.66.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.66.1 * ocfs2-kmp-default-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * gfs2-kmp-default-debuginfo-6.4.0-150700.53.66.1 * ocfs2-kmp-default-debuginfo-6.4.0-150700.53.66.1 * gfs2-kmp-default-6.4.0-150700.53.66.1 * dlm-kmp-default-6.4.0-150700.53.66.1 * cluster-md-kmp-default-6.4.0-150700.53.66.1 * dlm-kmp-default-debuginfo-6.4.0-150700.53.66.1 * cluster-md-kmp-default-debuginfo-6.4.0-150700.53.66.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (noarch) * kernel-macros-6.4.0-150700.53.66.1 * kernel-devel-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-devel-6.4.0-150700.53.66.1 * kernel-default-debugsource-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * kernel-default-devel-debuginfo-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64) * kernel-64kb-devel-6.4.0-150700.53.66.1 * kernel-64kb-devel-debuginfo-6.4.0-150700.53.66.1 * kernel-64kb-debugsource-6.4.0-150700.53.66.1 * kernel-64kb-debuginfo-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (nosrc s390x) * kernel-zfcpdump-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (s390x) * kernel-zfcpdump-debugsource-6.4.0-150700.53.66.1 * kernel-zfcpdump-debuginfo-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64 nosrc) * kernel-64kb-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-150700.53.66.1.150700.17.39.1 * SUSE Linux Enterprise Live Patching 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.66.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * kernel-livepatch-6_4_0-150700_53_66-default-debuginfo-1-150700.15.3.1 * kernel-livepatch-6_4_0-150700_53_66-default-1-150700.15.3.1 * kernel-default-livepatch-devel-6.4.0-150700.53.66.1 * kernel-default-livepatch-6.4.0-150700.53.66.1 * kernel-livepatch-SLE15-SP7_Update_18-debugsource-1-150700.15.3.1 * Development Tools Module 15-SP7 (noarch nosrc) * kernel-docs-6.4.0-150700.53.66.2 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-150700.53.66.1 * kernel-syms-6.4.0-150700.53.66.1 * kernel-obs-build-debugsource-6.4.0-150700.53.66.1 * Development Tools Module 15-SP7 (noarch) * kernel-source-6.4.0-150700.53.66.1 * Public Cloud Module 15-SP7 (aarch64 nosrc x86_64) * kernel-azure-6.4.0-150700.53.66.1 * Public Cloud Module 15-SP7 (aarch64 x86_64) * kernel-azure-devel-debuginfo-6.4.0-150700.53.66.1 * kernel-azure-debugsource-6.4.0-150700.53.66.1 * kernel-azure-debuginfo-6.4.0-150700.53.66.1 * kernel-azure-devel-6.4.0-150700.53.66.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * kernel-default-extra-debuginfo-6.4.0-150700.53.66.1 * kernel-default-debugsource-6.4.0-150700.53.66.1 * kernel-default-extra-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.66.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40216.html * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31647.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43094.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46315.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46330.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1236743 * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1259764 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263581 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264231 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267953 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268049 * https://bugzilla.suse.com/show_bug.cgi?id=1268159 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269199 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269617 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-15880 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 20:36:50 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 08 Jul 2026 20:36:50 -0000 Subject: SUSE-SU-2026:2799-1: important: Security update for the Linux Kernel Message-ID: <178354301065.547.5531716052517261320@530c474df1e7> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2799-1 Release Date: 2026-07-08T14:58:17Z Rating: important References: * bsc#1236743 * bsc#1255029 * bsc#1256668 * bsc#1259764 * bsc#1261256 * bsc#1261562 * bsc#1261604 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262618 * bsc#1262620 * bsc#1262655 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263057 * bsc#1263072 * bsc#1263123 * bsc#1263124 * bsc#1263137 * bsc#1263178 * bsc#1263560 * bsc#1263563 * bsc#1263568 * bsc#1263573 * bsc#1263578 * bsc#1263581 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264228 * bsc#1264230 * bsc#1264231 * bsc#1264236 * bsc#1264239 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264263 * bsc#1264266 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264437 * bsc#1264444 * bsc#1264449 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264562 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264612 * bsc#1264734 * bsc#1264741 * bsc#1264748 * bsc#1264763 * bsc#1264814 * bsc#1264974 * bsc#1265103 * bsc#1265113 * bsc#1265143 * bsc#1265211 * bsc#1265421 * bsc#1265628 * bsc#1265629 * bsc#1266008 * bsc#1266290 * bsc#1266390 * bsc#1266396 * bsc#1266397 * bsc#1266698 * bsc#1266700 * bsc#1266704 * bsc#1266705 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266840 * bsc#1266847 * bsc#1266878 * bsc#1266895 * bsc#1266899 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266928 * bsc#1266929 * bsc#1266933 * bsc#1267208 * bsc#1267228 * bsc#1267251 * bsc#1267361 * bsc#1267365 * bsc#1267369 * bsc#1267381 * bsc#1267387 * bsc#1267427 * bsc#1267430 * bsc#1267431 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267635 * bsc#1267637 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267684 * bsc#1267685 * bsc#1267697 * bsc#1267717 * bsc#1267722 * bsc#1267744 * bsc#1267816 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267953 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268159 * bsc#1268237 * bsc#1268307 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269199 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269617 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-15880 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-10263 * CVE-2025-40216 * CVE-2025-40341 * CVE-2025-68822 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31450 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31502 * CVE-2026-31555 * CVE-2026-31560 * CVE-2026-31592 * CVE-2026-31593 * CVE-2026-31647 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31670 * CVE-2026-31674 * CVE-2026-31677 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43034 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43083 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43094 * CVE-2026-43101 * CVE-2026-43107 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43239 * CVE-2026-43284 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43469 * CVE-2026-43472 * CVE-2026-43491 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45848 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45891 * CVE-2026-45894 * CVE-2026-45912 * CVE-2026-45940 * CVE-2026-45948 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-45985 * CVE-2026-46005 * CVE-2026-46028 * CVE-2026-46037 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46101 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46162 * CVE-2026-46172 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46197 * CVE-2026-46214 * CVE-2026-46227 * CVE-2026-46229 * CVE-2026-46244 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46259 * CVE-2026-46266 * CVE-2026-46273 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46315 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-40216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31560 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31593 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31593 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31593 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31647 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43094 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46315 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Real Time Module 15-SP7 An update that solves 168 vulnerabilities, contains three features and has 14 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-10263: arm64: cputype: Add C1-Ultra definitions (bsc#1266290). * CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764). * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: hci_sync: Remove remaining dependencies of hci_request (bsc#1262993). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already- launched/encrypted vCPU (bsc#1263124). * CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). * CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578). * CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46150: fanotify: fix false positive on permission events. * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1265211 bsc#1267651). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git- fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). * ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non- serdev device (git-fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). * drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). * drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git- fixes). * drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: always resume_all after suspend_all (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/gpuvm: Do not prepare NULL objects (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). * drm/imagination: Count paired job fence as dependency in prepare_job() (git- fixes). * drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). * drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * iommu/s390: allow larger region tables (jsc#PED-15880). * iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880). * iommu/s390: handle IOAT registration based on domain (jsc#PED-15880). * iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880). * iommu/s390: set appropriate IOTA region type (jsc#PED-15880). * iommu/s390: support cleanup of additional table regions (jsc#PED-15880). * iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880). * iommu/s390: support map/unmap for additional table regions (jsc#PED-15880). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * page_pool: Move pp_magic check into helper functions (bsc#1261562). * page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). * platform/x86: intel-hid: Protect ACPI notify handler against recursion (git- fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git- fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * s390/pci: check for relaxed translation capability (jsc#PED-15880). * s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880). * s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880). * scripts/submit_branch: add SLE15-SP7 submission script. * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617). * selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617). * selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617). * selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617). * selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617). * selftests/bpf: Skip tests whose objects were not built (bsc#1269617). * selftests/bpf: Tolerate benchmark build failures (bsc#1269617). * selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617). * selftests/bpf: Tolerate missing files during install (bsc#1269617). * selftests/bpf: Tolerate test file compilation failures (bsc#1269617). * serdev: make serdev_bus_type const (stable-fixes). * serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git- fixes). * serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git- fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). * X.509: Fix validation of ASN.1 certificate header (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2799=1 * SUSE Real Time Module 15-SP7 zypper in -t patch SUSE-SLE-Module-RT-15-SP7-2026-2799=1 ## Package List: * SUSE Real Time Module 15-SP7 (x86_64) * ocfs2-kmp-rt-debuginfo-6.4.0-150700.7.62.1 * cluster-md-kmp-rt-6.4.0-150700.7.62.1 * kernel-rt-debugsource-6.4.0-150700.7.62.1 * kernel-syms-rt-6.4.0-150700.7.62.1 * kernel-rt-devel-6.4.0-150700.7.62.1 * cluster-md-kmp-rt-debuginfo-6.4.0-150700.7.62.1 * kernel-rt-devel-debuginfo-6.4.0-150700.7.62.1 * ocfs2-kmp-rt-6.4.0-150700.7.62.1 * gfs2-kmp-rt-6.4.0-150700.7.62.1 * dlm-kmp-rt-debuginfo-6.4.0-150700.7.62.1 * kernel-rt-debuginfo-6.4.0-150700.7.62.1 * gfs2-kmp-rt-debuginfo-6.4.0-150700.7.62.1 * dlm-kmp-rt-6.4.0-150700.7.62.1 * SUSE Real Time Module 15-SP7 (nosrc x86_64) * kernel-rt-6.4.0-150700.7.62.1 * SUSE Real Time Module 15-SP7 (noarch) * kernel-devel-rt-6.4.0-150700.7.62.1 * kernel-source-rt-6.4.0-150700.7.62.1 * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_62-rt-debuginfo-1-150700.1.3.1 * kernel-livepatch-SLE15-SP7-RT_Update_17-debugsource-1-150700.1.3.1 * kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-40216.html * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31560.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31593.html * https://www.suse.com/security/cve/CVE-2026-31647.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43094.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46162.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46315.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1236743 * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1259764 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263057 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263124 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263581 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264231 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265211 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266840 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1267816 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267953 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268159 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269199 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269617 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-15880 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 08:30:14 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 08:30:14 -0000 Subject: SUSE-SU-2026:2804-1: important: Security update for kubevirt Message-ID: <178358581464.683.612049813959311393@aaee731399ed> # Security update for kubevirt Announcement ID: SUSE-SU-2026:2804-1 Release Date: 2026-07-08T19:35:34Z Rating: important References: * bsc#1256434 * bsc#1262265 * bsc#1266733 Cross-References: * CVE-2025-14525 * CVE-2026-35469 * CVE-2026-9804 CVSS scores: * CVE-2025-14525 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-14525 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-14525 ( NVD ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-35469 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9804 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9804 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9804 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for kubevirt fixes the following issues: * CVE-2026-9804: Symlink escape in the VMExport dir handler let an attacker controlling an exported PVC read sensitive files (TLS keys, tokens, service- account creds) from the exporter pod. (bsc#1266733) * CVE-2025-14525: A VM reporting many guest-internal interfaces via the guest agent could flood VMI status and fill etcd (denial of service). Caps reported interfaces at 10. (bsc#1256434) * CVE-2026-35469: resource-exhaustion in the SPDY/3 protocol implementation of github.com/moby/spdystream. (GHSA-pc3f-x583-g7j2,bsc#1262265) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2804=1 ## Package List: * Containers Module 15-SP7 (aarch64 x86_64) * kubevirt-virtctl-1.7.4-150700.3.27.1 * kubevirt-virtctl-debuginfo-1.7.4-150700.3.27.1 * kubevirt-manifests-1.7.4-150700.3.27.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14525.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://www.suse.com/security/cve/CVE-2026-9804.html * https://bugzilla.suse.com/show_bug.cgi?id=1256434 * https://bugzilla.suse.com/show_bug.cgi?id=1262265 * https://bugzilla.suse.com/show_bug.cgi?id=1266733 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 08:30:22 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 08:30:22 -0000 Subject: SUSE-SU-2026:2803-1: important: Security update for dracut Message-ID: <178358582202.683.6711939642607713732@aaee731399ed> # Security update for dracut Announcement ID: SUSE-SU-2026:2803-1 Release Date: 2026-07-08T19:31:32Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.565.g682306ec5: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2803=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2803=1 * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-2803=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2803=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * dracut-tools-059+suse.565.g682306ec5-150600.3.29.1 * dracut-extra-059+suse.565.g682306ec5-150600.3.29.1 * dracut-ima-059+suse.565.g682306ec5-150600.3.29.1 * dracut-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debuginfo-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debugsource-059+suse.565.g682306ec5-150600.3.29.1 * dracut-fips-059+suse.565.g682306ec5-150600.3.29.1 * dracut-mkinitrd-deprecated-059+suse.565.g682306ec5-150600.3.29.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (ppc64le x86_64) * dracut-debuginfo-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debugsource-059+suse.565.g682306ec5-150600.3.29.1 * dracut-mkinitrd-deprecated-059+suse.565.g682306ec5-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * dracut-ima-059+suse.565.g682306ec5-150600.3.29.1 * dracut-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debuginfo-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debugsource-059+suse.565.g682306ec5-150600.3.29.1 * dracut-fips-059+suse.565.g682306ec5-150600.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * dracut-ima-059+suse.565.g682306ec5-150600.3.29.1 * dracut-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debuginfo-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debugsource-059+suse.565.g682306ec5-150600.3.29.1 * dracut-fips-059+suse.565.g682306ec5-150600.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 08:30:57 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 08:30:57 -0000 Subject: SUSE-SU-2026:2802-1: important: Security update for netty, netty-tcnative Message-ID: <178358585750.683.18094936436516110152@aaee731399ed> # Security update for netty, netty-tcnative Announcement ID: SUSE-SU-2026:2802-1 Release Date: 2026-07-08T19:06:45Z Rating: important References: * bsc#1268165 * bsc#1268169 * bsc#1268170 * bsc#1268244 * bsc#1268246 * bsc#1268247 * bsc#1268248 * bsc#1268249 * bsc#1268250 * bsc#1268251 * bsc#1268252 * bsc#1268255 * bsc#1268257 * bsc#1268258 * bsc#1268259 * bsc#1268260 * bsc#1268261 * bsc#1268262 Cross-References: * CVE-2026-44249 * CVE-2026-44250 * CVE-2026-44890 * CVE-2026-44893 * CVE-2026-45416 * CVE-2026-45536 * CVE-2026-45673 * CVE-2026-45674 * CVE-2026-46340 * CVE-2026-47244 * CVE-2026-47691 * CVE-2026-48006 * CVE-2026-48043 * CVE-2026-48059 * CVE-2026-50010 * CVE-2026-50011 * CVE-2026-50020 * CVE-2026-50560 CVSS scores: * CVE-2026-44249 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44249 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44249 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44249 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44250 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44250 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44250 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44250 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44890 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44890 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44890 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44890 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44893 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44893 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44893 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44893 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45416 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45416 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45416 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45416 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45536 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45536 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45673 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N * CVE-2026-45673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-45673 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-45674 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-45674 ( SUSE ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-45674 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-45674 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-45674 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-46340 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46340 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46340 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46340 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47244 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47244 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47244 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47691 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-47691 ( SUSE ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-47691 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-47691 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-47691 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-48006 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48006 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48006 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48043 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48043 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48043 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48043 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48059 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48059 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-50010 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-50010 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50010 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50010 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50011 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-50011 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-50011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-50011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-50020 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-50020 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-50020 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-50560 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-50560 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-50560 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50560 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for netty, netty-tcnative fixes the following issue This update for netty, netty-tcnative fixes the following issues Upgrade netty to upstream version 4.1.135, netty-tcnative to upstream version 2.0.79: * CVE-2026-44249: IPv6 Subnet Filter Bypass via Incorrect Comparator Masking (bsc#1268165). * CVE-2026-44250: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays (bsc#1268169). * CVE-2026-44890: Unbounded Direct Memory Consumption in RedisDecoder (bsc#1268170). * CVE-2026-44893: netty-codec-haproxy: Denial of Service via malformed HAProxy message (bsc#1268244). * CVE-2026-45416: SNI handler pre-allocates up to 16 MiB from nine attacker bytes (bsc#1268246). * CVE-2026-45536: Unix-socket fd receive leaks descriptors when peer sends two at once (bsc#1268247). * CVE-2026-45673: netty-resolver-dns: DNS Cache Poisoning via predictable transaction IDs (bsc#1268248). * CVE-2026-45674: DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (bsc#1268249). * CVE-2026-46340: netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments (bsc#1268250). * CVE-2026-47244: HTTP/2: Advertised MAX_CONCURRENT_STREAMS not enforced (bsc#1268251). * CVE-2026-47691: Insufficient Bailiwick Validation for NS Records (bsc#1268252). * CVE-2026-48006: netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator (bsc#1268255). * CVE-2026-48043: netty-codec-http2: Denial of Service due to resource leak (bsc#1268257). * CVE-2026-48059: netty-codec-haproxy: Denial of Service via memory leak from crafted PROXY protocol headers (bsc#1268258). * CVE-2026-50010: Wrapping plain trust manager silently disables hostname verification (bsc#1268259). * CVE-2026-50011: Unbounded pre-allocation in RedisArrayAggregator from RESP array length (bsc#1268260). * CVE-2026-50020: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted (bsc#1268261). * CVE-2026-50560: Netty susceptible to HTTP/2 Reset Attack with different on- the-wire signature (bsc#1268262). Changes: * MQTT: Allow MQTT 5 CONNECT with password only * ChannelInitializer: correct misleading comment on exceptionCaught route * HTTP/2: Parse request-target path like Vert.x (4.1 backport) * HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted * IpSubnetFilter: Correctly handle ipv6 * Configurable bound on RedisArrayAggregator * Redis: Limit decoded length * DNS: Ensure query id is not predictible * Wrapping plain trust manager silently disables hostname verification * MQTT: Reject malformed no-payload packets with non-zero Remaining Length * HAProxy: Reject HAProxyMessages with malformated TLV and not leak memory * SSL: Use sane defaults as limits for the client hello length and timeout * DNS: Only cache CNAME if part of the queried domain * HTTP/2: Enforce max concurrent streams for misbehaving clients * Dns: Insufficient Bailiwick Validation for NS Records * HTTP2: DelegatingDecompressorFrameListener must release memory in all cases * Pass maxAllocation to Brotli and Zstd decoders * HTTP/2: Treat clients MAX_HEADER_LIST_SIZE as advisory * Add maxWindowLog parameter to ZstdDecoder to bound memory allocation * HAProxy: Fix ByteBuf leak when parsing nested SSL TLVs * Epoll / Kqueue: Correctly handle receive of FD * SCTP: Limit the number of inflight incomplete SCTP messages and the number of fragments * Redis: Correctly release incomplete message on removal when using RedisArrayAggregator * Redis: Limit the maximum number of nested arrays * HTTP: Re-add constructor to HttpProxyHandler that was removed by mistake * Marshalling: Explicit document security requirements * Pin HTTP/RTSP version + method normalization to Locale.US * Adaptive: Fix concurrency issue in adaptive allocator * Pin multipart Content-Type / Content-Transfer-Encoding case folding to Locale.US * Remove dead native declarations * Avoid re-parsing openssl key material with non-cached provider * IpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules are configured but remote peer is using ipv4 * Resolve all localhost addresses without querying DNS servers * HTTP2: Use 100 as default max concurrent streams setting * Route synchronous onLookupComplete exceptions via fireExceptionCaught * Fix MQTT decoder size check after variable header replay ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2802=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2802=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2802=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2802=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2802=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2802=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2802=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2802=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2802=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2802=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2802=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2802=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * netty-javadoc-4.1.135-150200.4.50.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-4.1.135-150200.4.50.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-tcnative-debugsource-2.0.79-150200.3.45.1 * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * netty-tcnative-2.0.79-150200.3.45.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44249.html * https://www.suse.com/security/cve/CVE-2026-44250.html * https://www.suse.com/security/cve/CVE-2026-44890.html * https://www.suse.com/security/cve/CVE-2026-44893.html * https://www.suse.com/security/cve/CVE-2026-45416.html * https://www.suse.com/security/cve/CVE-2026-45536.html * https://www.suse.com/security/cve/CVE-2026-45673.html * https://www.suse.com/security/cve/CVE-2026-45674.html * https://www.suse.com/security/cve/CVE-2026-46340.html * https://www.suse.com/security/cve/CVE-2026-47244.html * https://www.suse.com/security/cve/CVE-2026-47691.html * https://www.suse.com/security/cve/CVE-2026-48006.html * https://www.suse.com/security/cve/CVE-2026-48043.html * https://www.suse.com/security/cve/CVE-2026-48059.html * https://www.suse.com/security/cve/CVE-2026-50010.html * https://www.suse.com/security/cve/CVE-2026-50011.html * https://www.suse.com/security/cve/CVE-2026-50020.html * https://www.suse.com/security/cve/CVE-2026-50560.html * https://bugzilla.suse.com/show_bug.cgi?id=1268165 * https://bugzilla.suse.com/show_bug.cgi?id=1268169 * https://bugzilla.suse.com/show_bug.cgi?id=1268170 * https://bugzilla.suse.com/show_bug.cgi?id=1268244 * https://bugzilla.suse.com/show_bug.cgi?id=1268246 * https://bugzilla.suse.com/show_bug.cgi?id=1268247 * https://bugzilla.suse.com/show_bug.cgi?id=1268248 * https://bugzilla.suse.com/show_bug.cgi?id=1268249 * https://bugzilla.suse.com/show_bug.cgi?id=1268250 * https://bugzilla.suse.com/show_bug.cgi?id=1268251 * https://bugzilla.suse.com/show_bug.cgi?id=1268252 * https://bugzilla.suse.com/show_bug.cgi?id=1268255 * https://bugzilla.suse.com/show_bug.cgi?id=1268257 * https://bugzilla.suse.com/show_bug.cgi?id=1268258 * https://bugzilla.suse.com/show_bug.cgi?id=1268259 * https://bugzilla.suse.com/show_bug.cgi?id=1268260 * https://bugzilla.suse.com/show_bug.cgi?id=1268261 * https://bugzilla.suse.com/show_bug.cgi?id=1268262 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 08:31:12 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 08:31:12 -0000 Subject: SUSE-SU-2026:2801-1: important: Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent Message-ID: <178358587218.683.5657754319738183491@aaee731399ed> # Security update for jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent Announcement ID: SUSE-SU-2026:2801-1 Release Date: 2026-07-08T19:05:27Z Rating: important References: * bsc#1268603 * bsc#1268897 * bsc#1268898 * bsc#1268899 * bsc#1268902 Cross-References: * CVE-2026-54512 * CVE-2026-54513 * CVE-2026-54514 * CVE-2026-54515 CVSS scores: * CVE-2026-54512 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54512 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54514 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54514 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54515 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54515 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities and has one security fix can now be installed. ## Description: This update for jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent fixes the following issues * CVE-2026-54512: jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation (bsc#1268897). * CVE-2026-54513: jackson-databind: array subtype allowlist bypass in BasicPolymorphicTypeValidator (bsc#1268898). * CVE-2026-54514: jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (bsc#1268899). * CVE-2026-54515: jackson-databindi: case-insensitive deserialization bypasses per-property @JsonIgnoreProperties (bsc#1268902). * jackson-core: document length constraint bypass in blocking, async, and DataInput parsers (bsc#1268603). Changes for jackson-annotations: * Update to 2.18.8 * No changes since 2.17.3 Changes for jackson-bom: * Update to 2.18.8 * Changes * # 68: Remove 'junit' 4.x dependency from 'jackson-base' 2.18.x to help junit5 migration * 'base/pom.xml' now creates '${project.version.underscore}' for "cleansed" version of '${project.version}' Changes for jackson-core: * Update to 2.18.8 * Changes of 2.18.8 * # 1611: Apply number-length validator on streaming integer path of async parser * Changes of 2.18.7 * # 1570: Fail parsing from 'DataInput' if 'StreamReadConstraints .getMaxDocumentLength()' set (bsc#1268603, GHSA-2m67-wjpj-xhg9) * # 1600: Rework 3rd party licenses in jar * # 1602: 'UTF8DataInputJsonParser' needs to enforce 'StreamReadConstraints.maxNameLength' limit * Changes of 2.18.6 * # 1512: Number-parsing fix for 'UTF8DataInputJsonParser' * # 1548: 'StreamReadConstraints.maxDocumentLength' not checked when creating parser with fixed buffer * # 1555: Enforce 'StreamReadConstraints.maxNumberLength' for non-blocking (async) parser * Changes of 2.18.5 * # 1433: 'JsonParser#getNumberType()' throws 'JsonParseException' when the current token is non-numeric instead of returning null * # 1446: Invalid package reference to "java.lang.foreign" from 'com.fasterxml.jackson.core:jackson-core' (from 'FastDoubleParser') * Changes of 2.18.3 * # 1391: Fix issue where the parser can read back old number state when parsing later numbers * # 1397: Jackson changes additional values to infinite in case of special JSON structures and existing infinite values * # 1398: Fix issue that feature COMBINE_UNICODE_SURROGATES_IN_UTF8 doesn't work when custom characterEscape is used * Changes of 2.18.2 * # 1359: Non-surrogate characters being incorrectly combined when 'JsonWriteFeature.COMBINE_UNICODE_SURROGATES_IN_UTF8' is enabled * Changes of 2.18.1 * # 1353: Use fastdoubleparser 1.0.90 * Changes of 2.18. * # 223: 'UTF8JsonGenerator' writes supplementary characters as a surrogate pair: should use 4-byte encoding * # 1230: Improve performance of 'float' and 'double' parsing from 'TextBuffer' * # 1251: 'InternCache' replace synchronized with 'ReentrantLock' * the cache size limit is no longer strictly enforced for performance reasons but we should never go far about the limit * # 1252: 'ThreadLocalBufferManager' replace synchronized with 'ReentrantLock' * # 1257: Increase InternCache default max size from 100 to 200 * # 1262: Add diagnostic method 'pooledCount()' in 'RecyclerPool' * # 1264: Rename shaded 'ch.randelshofer:fastdoubleparser' classes to prevent use by downstream consumers * # 1271: Deprecate 'LockFreePool' implementation in 2.18 (remove from 3.0) * # 1274: 'NUL'-corrupted keys, values on JSON serialization * # 1277: Add back Java 22 optimisation in FastDoubleParser * # 1284: Optimize 'JsonParser.getDoubleValue()/getFloatValue() /getDecimalValue()' to avoid String allocation * # 1305: Make helper methods of 'WriterBasedJsonGenerator' non-final to allow overriding * # 1310: Add new 'StreamReadConstraints' ('maxTokenCount') to limit maximum number of Tokens allowed per document# * # 1331: Update to FastDoubleParser v1.0.1 to fix 'BigDecimal' decoding proble Changes for jackson-databind: * Update to 2.18.8 * Changes of 2.18.8 * # 5950: Improve 'UUIDeserializer' error handling * # 5951: Improve 'InetSocketAddress' deserialization (bsc#1268899, CVE-2026-54514) * # 5969: '@JsonView' by-passed for some "setterless" creator properties * # 5971: '@JsonView' by-passed for unwrapped creator parameters * # 5974: '@JsonIgnore' on Record property ignored with 'PropertyNamingStrategy' * # 5981: 'BasicPolymorphicTypeValidator' setting 'allowIfSubTypeIsArray()' should validate element type (bsc#1268898, CVE-2026-54513) * # 5988: 'PolymorphicTypeValidator' needs to validate generic type parameters too (bsc#1268897, CVE-2026-54512) * # 5993: 'UPPER_SNAKE_CASE' / 'LOWER_CASE' 'NamingStrategyImpls' fold case using JVM default locale (Turkish-I bug) * Changes of 2.18.4 * # 4628: '@JsonIgnore' and '@JsonProperty.access=READ_ONLY' on Record property ignored for deserialization * # 5049: Duplicate creator property "b" (index 0 vs 1) on simple java record * Changes of 2.18.3 * # 4444: The 'KeyDeserializer' specified in the class with '@JsonDeserialize(keyUsing = ...)' is overwritten by the 'KeyDeserializer' specified in the 'ObjectMapper'. * # 4827: Subclassed Throwable deserialization fails since v2.18.0 - no creator index for property 'cause' * # 4844: Fix wrapped array handling wrt 'null' by 'StdDeserializer' * # 4848: Avoid type pollution in 'StringCollectionDeserializer' * # 4860: 'ConstructorDetector.USE_PROPERTIES_BASED' does not work with multiple constructors since 2.18 * # 4878: When serializing a Map via Converter(StdDelegatingSerializer), a NullPointerException is thrown due to missing key serializer * # 4908: Deserialization behavior change with @JsonCreator and @ConstructorProperties between 2.17 and 2.18 * # 4917: 'BigDecimal' deserialization issue when using '@JsonCreator' * # 4920: Creator properties are ignored on abstract types when collecting bean properties, breaking AsExternalTypeDeserializer * # 4922: Failing '@JsonMerge' with a custom Map * # 4932: Conversion of 'MissingNode' throws 'JsonProcessingException' * Changes of 2.18.2 * # 4733: Wrong serialization of Type Ids for certain types of Enum values * # 4742: Deserialization with Builder, External type id, '@JsonCreator' failing * # 4777: 'StdValueInstantiator.withArgsCreator' is now set for creators with no arguments * # 4783 Possibly wrong behavior of @JsonMerge * # 4787: Wrong 'String.format()' in 'StdDelegatingDeserializer' hides actual error * # 4788: 'EnumFeature.WRITE_ENUMS_TO_LOWERCASE' overrides '@JsonProperty' values * # 4790: Fix '@JsonAnySetter' issue with "setter" method (related to #4639) * # 4807: Improve 'FactoryBasedEnumDeserializer' to work better with XML module * # 4810: Deserialization using '@JsonCreator' with renamed property failing (since 2.18) * Changes of 2.18.1 * # 4508: Deserialized JsonAnySetter field in Kotlin data class is null * # 4639: @JsonAnySetter on field ignoring unrecognized properties if they are declared before the last recognized properties in JSON * # 4718: Should not fail on trying to serialize 'java.time.DateTimeException' * # 4724: Deserialization behavior change with Records, '@JsonCreator' and '@JsonValue' between 2.17 and 2.18 * # 4727: Eclipse having issues due'module-info' class "lost" on 2.18.0 jars * # 4741: When 'Include.NON_DEFAULT' setting is used on POJO, empty values are not included in json if default is 'null' * # 4749: Fixed a problem with 'StdDelegatingSerializer#serializeWithType' looking up the serializer with the wrong argument * Changes of 2.18.0 * # 562: Allow '@JsonAnySetter' to flow through Creators * # 806: Problem with 'NamingStrategy', creator methods with implicit names * # 2977: Incompatible 'FAIL_ON_MISSING_PRIMITIVE_PROPERTIES' and field level '@JsonProperty' * # 3120: Return 'ListIterator' from 'ArrayNode.elements()' * # 3241: 'constructorDetector' seems to invalidate 'defaultSetterInfo' for nullability * # 3439: Java Record '@JsonAnySetter' value is null after deserialization * # 4085: '@JsonView' does not work on class-level for records * # 4119: Exception when deserialization uses a record with a constructor property with 'access=READ_ONLY' * # 4356: 'BeanDeserializerModifier::updateBuilder()' doesn't work for beans with Creator methods * # 4407: 'null' type id handling does not work with 'writeTypePrefix()' * # 4452: '@JsonProperty' not serializing field names properly on '@JsonCreator' in Record * # 4453: Allow JSON Integer to deserialize into a single-arg constructor of parameter type 'double' * # 4456: Rework locking in 'DeserializerCache' * # 4458: Rework synchronized block from 'BeanDeserializerBase' * # 4464: When 'Include.NON_DEFAULT' setting is used, 'isEmpty()' method is not called on the serializer * # 4472: Rework synchronized block in 'TypeDeserializerBase' * # 4483: Remove 'final' on method BeanSerializer.serialize() * # 4515: Rewrite Bean Property Introspection logic in Jackson 2.x * # 4545: Unexpected deserialization behavior with '@JsonCreator', '@JsonProperty' and javac '-parameters' * # 4570: Deprecate 'ObjectMapper.canDeserialize()'/'ObjectMapper .canSerialize()' * # 4580: Add 'MapperFeature .SORT_CREATOR_PROPERTIES_BY_DECLARATION_ORDER' to use Creator properties' declaration order for sorting * # 4584: Provide extension point for detecting "primary" Constructor for Kotlin (and similar) data classes * # 4602: Possible wrong use of _arrayDelegateDeserializer in BeanDeserializerBase::deserializeFromObjectUsingNonDefault() * # 4617: Record property serialization order not preserved * # 4626: '@JsonIgnore' on Record property ignored for deserialization, if there is getter override * # 4630: '@JsonIncludeProperties', '@JsonIgnoreProperties' ignored when serializing Records, if there is getter override * # 4634: '@JsonAnySetter' not working when annotated on both constructor parameter & field * # 4678: Java records don't serialize with 'MapperFeature .REQUIRE_SETTERS_FOR_GETTERS' * # 4688: Should allow deserializing with no-arg '@JsonCreator(mode = DELEGATING)' * # 4694: Deserializing 'BigDecimal' with large number of decimals result in incorrect value * # 4699: Add extra 'writeNumber()' method in 'TokenBuffer' * # 4709: Add 'JacksonCollectors' with 'toArrayNode()' implementation * Fix #5962: Case-insensitive deserialization may use wrong @JsonIgnoreProperties (bsc#1268902, CVE-2026-54515) * Fix "Not fully interpolated version" error with Maven 4 Changes for jackson-dataformats-binary: * Update to 2.18.8 * Changes of 2.18.8 * # 696: (ion) Incomplete number length validation in Ion decoder (for 'BigDecimal' and/or 'BigInteger') * Changes of 2.18.6 * # 645: (avro) Remove use of Avro 'Schema.Parser() .setValidate()' to allow use of Avro core 1.12.1 (2.x) * # 649: (cbor, smile) 'StreamReadConstraints.maxDocumentLength' not checked when creating parser with fixed buffer * # 651: (smile) Ensure Smile backend supports 'StreamReadConstraints.maxTokenCount' * # 652: (cbor) Ensure CBOR backend supports * Minor fix to 'ProtobufGenerator._reportEnumError()' helper method * Changes of 2.18.5 * # 599: (cbor) Unable to deserialize stringref-enabled CBOR with ignored properties * # 623: (ion) Upgrade 'ion-java' dep to 1.11.11 (from 1.11.10) * Changes of 2.18.4 * # 569: (ion) 'IonParser' fails to parse some 'long' values saying they are out of range when they are not * # 584: (protobuf) Missing 'JsonToken.END_OBJECT' for nested Protobuf Objects * (ion) Upgrade 'ion-java' to 1.11.10 (from 1.11.9) * Changes of 2.18.3 * # 541: (cbor, protobuf, smile) 'SmileParser.getValueAsString()' FIELD_NAME bug * Changes of 2.18.1 * # 518: Should not read past end for CBOR string values * Changes of 2.18.0 * # 167: (avro) Incompatibility with Avro >=1.9.0 (upgrade to Avro 1.11.3) * # 484: (protobuf) Rework synchronization in 'ProtobufMapper' * # 494: (avro) Avro Schema generation: allow mapping Java Enum properties to Avro String values * # 508: (avro) Ignore 'specificData' field on serialization * # 509: IonValueMapper.builder() not implemented, does not register modules * (ion) Upgrade 'ion-java' to 1.11.9 (from 1.11.8) value Changes for jackson-modules-base: * Upgrade to 2.18.8 * No changes since 2.18.0 * Changes of 2.18.0 * # 233: (jaxb) Tolerate JAX-RS 2.2 in jackson-module-jaxb-annotations so that it can be deployed in Liberty alongside features which use 2.2 * # 248: (android-record) jClass annotations and polymorphic types are ignored when deserializing Android Record fields * # 251: (android-record) Constructor is not recognized when a record uses both arrays and generic types Changes for jackson-parent: * Update to 2.18.4 * Changes of 2.18.4 * Update to latest 'oss-parent' (69) * Changes of 2.18.3 * Update to latest 'oss-parent' (68) * Switch to publishing via Sonatype Central Portal repo * Changes of 2.18.2 * Update to latest 'oss-parent' (66); future-proof for Sonatype Central Portal * Changes of 2.18.1 * # 15: Add override to downgrade 'moditect-maven-plugin' from 1.2.2 to 1.1.0 to work around Eclipse issues * Changes of 2.18 * Update to oss-parent 61 (plugin version updates) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2801=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2801=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2801=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2801=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2801=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2801=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2801=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2801=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2801=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2801=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2801=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2801=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * jackson-databind-2.18.8-150200.3.28.2 * jackson-annotations-2.18.8-150200.3.22.3 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * jackson-databind-2.18.8-150200.3.28.2 * jackson-annotations-2.18.8-150200.3.22.3 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * Basesystem Module 15-SP7 (noarch) * jackson-databind-2.18.8-150200.3.28.2 * jackson-annotations-2.18.8-150200.3.22.3 * jackson-core-2.18.8-150200.3.22.3 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-annotations-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * Development Tools Module 15-SP7 (noarch) * jackson-dataformat-cbor-2.18.8-150200.3.21.3 ## References: * https://www.suse.com/security/cve/CVE-2026-54512.html * https://www.suse.com/security/cve/CVE-2026-54513.html * https://www.suse.com/security/cve/CVE-2026-54514.html * https://www.suse.com/security/cve/CVE-2026-54515.html * https://bugzilla.suse.com/show_bug.cgi?id=1268603 * https://bugzilla.suse.com/show_bug.cgi?id=1268897 * https://bugzilla.suse.com/show_bug.cgi?id=1268898 * https://bugzilla.suse.com/show_bug.cgi?id=1268899 * https://bugzilla.suse.com/show_bug.cgi?id=1268902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 12:30:24 -0000 Subject: SUSE-SU-2026:2811-1: important: Security update for python-maturin Message-ID: <178360022438.699.13942199010005666943@5ed4f61072e9> # Security update for python-maturin Announcement ID: SUSE-SU-2026:2811-1 Release Date: 2026-07-09T06:25:49Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.6 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-maturin fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2811=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * python311-maturin-1.4.0-150600.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:30:30 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 12:30:30 -0000 Subject: SUSE-SU-2026:2810-1: moderate: Security update for glib-networking Message-ID: <178360023071.699.12741727110314570984@5ed4f61072e9> # Security update for glib-networking Announcement ID: SUSE-SU-2026:2810-1 Release Date: 2026-07-09T06:14:47Z Rating: moderate References: * bsc#1267979 Cross-References: * CVE-2026-10028 CVSS scores: * CVE-2026-10028 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-10028 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-10028 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for glib-networking fixes the following issue * CVE-2026-10028: two certificates which are each signed by the other can lead to an infinite loop (bsc#1267979). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2810=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2810=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2810=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2810=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2810=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2810=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64_ilp32) * glib-networking-64bit-2.70.1-150400.3.3.1 * glib-networking-64bit-debuginfo-2.70.1-150400.3.3.1 * openSUSE Leap 15.4 (x86_64) * glib-networking-32bit-debuginfo-2.70.1-150400.3.3.1 * glib-networking-32bit-2.70.1-150400.3.3.1 * openSUSE Leap 15.4 (noarch) * glib-networking-lang-2.70.1-150400.3.3.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10028.html * https://bugzilla.suse.com/show_bug.cgi?id=1267979 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:30:41 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 12:30:41 -0000 Subject: SUSE-SU-2026:2809-1: moderate: Security update for systemd Message-ID: <178360024125.699.4548550139738722481@5ed4f61072e9> # Security update for systemd Announcement ID: SUSE-SU-2026:2809-1 Release Date: 2026-07-09T06:08:36Z Rating: moderate References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability and has three security fixes can now be installed. ## Description: This update for systemd fixes the following issue Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Import commit 37508f8ec1 (bsc#1267647). * Import commit c7530fbea3 (bsc#1261982 bsc#1261983). * Import commit 5c4ed461a7 (bsc#1261982). * Import commit 4b963df038 (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2809=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2809=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2809=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2809=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2809=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2809=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * systemd-sysvinit-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-mini-doc-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * libudev-mini1-249.17-150400.8.64.1 * nss-systemd-249.17-150400.8.64.1 * systemd-mini-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-mini-debuginfo-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libudev-mini1-debuginfo-249.17-150400.8.64.1 * systemd-portable-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libsystemd0-mini-debuginfo-249.17-150400.8.64.1 * systemd-experimental-249.17-150400.8.64.1 * systemd-testsuite-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-mini-devel-249.17-150400.8.64.1 * systemd-coredump-debuginfo-249.17-150400.8.64.1 * systemd-mini-container-debuginfo-249.17-150400.8.64.1 * systemd-network-debuginfo-249.17-150400.8.64.1 * systemd-mini-debuginfo-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * systemd-devel-249.17-150400.8.64.1 * nss-systemd-debuginfo-249.17-150400.8.64.1 * systemd-experimental-debuginfo-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * udev-mini-249.17-150400.8.64.1 * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * systemd-testsuite-debuginfo-249.17-150400.8.64.1 * systemd-mini-debugsource-249.17-150400.8.64.1 * systemd-mini-sysvinit-249.17-150400.8.64.1 * systemd-coredump-249.17-150400.8.64.1 * nss-myhostname-249.17-150400.8.64.1 * systemd-doc-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-mini-container-249.17-150400.8.64.1 * nss-myhostname-debuginfo-249.17-150400.8.64.1 * systemd-portable-debuginfo-249.17-150400.8.64.1 * libsystemd0-mini-249.17-150400.8.64.1 * systemd-network-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * openSUSE Leap 15.4 (x86_64) * nss-myhostname-32bit-debuginfo-249.17-150400.8.64.1 * libudev1-32bit-249.17-150400.8.64.1 * libudev1-32bit-debuginfo-249.17-150400.8.64.1 * nss-myhostname-32bit-249.17-150400.8.64.1 * systemd-32bit-249.17-150400.8.64.1 * systemd-32bit-debuginfo-249.17-150400.8.64.1 * libsystemd0-32bit-debuginfo-249.17-150400.8.64.1 * libsystemd0-32bit-249.17-150400.8.64.1 * openSUSE Leap 15.4 (aarch64_ilp32) * nss-myhostname-64bit-debuginfo-249.17-150400.8.64.1 * systemd-64bit-debuginfo-249.17-150400.8.64.1 * libudev1-64bit-249.17-150400.8.64.1 * systemd-64bit-249.17-150400.8.64.1 * nss-myhostname-64bit-249.17-150400.8.64.1 * libudev1-64bit-debuginfo-249.17-150400.8.64.1 * libsystemd0-64bit-249.17-150400.8.64.1 * libsystemd0-64bit-debuginfo-249.17-150400.8.64.1 * openSUSE Leap 15.4 (noarch) * systemd-lang-249.17-150400.8.64.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:30:58 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 12:30:58 -0000 Subject: SUSE-SU-2026:2807-1: important: Security update for rust-keylime Message-ID: <178360025884.699.9547818278766564973@5ed4f61072e9> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:2807-1 Release Date: 2026-07-09T04:47:14Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves eight vulnerabilities and has one security fix can now be installed. ## Description: This update for rust-keylime fixes the following issues * Update to version 0.2.9+49 * Update openssl to 0.10.81 * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-openssl crate (bsc#1270614). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270699). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270842). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-openssl crate (bsc#1270999). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2807=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * rust-keylime-0.2.9+49-150500.3.19.1 * rust-keylime-debuginfo-0.2.9+49-150500.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:31:02 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 12:31:02 -0000 Subject: SUSE-FU-2026:2806-1: moderate: Feature update for libtcnative-2-0 Message-ID: <178360026289.699.10882954464025558878@5ed4f61072e9> # Feature update for libtcnative-2-0 Announcement ID: SUSE-FU-2026:2806-1 Release Date: 2026-07-09T04:08:43Z Rating: moderate References: * jsc#PED-16024 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that contains one feature can now be installed. ## Description: This update for libtcnative-2-0 fixes the following issues: * New package for the Java stack released as libtcnative-2-0 (jsc#PED-16024) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2806=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2806=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2806=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2806=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2806=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2806=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2806=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2806=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-2806=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2806=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2806=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2806=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2806=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * Web and Scripting Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libtcnative-2-0-2.0.15-150400.9.3.1 * libtcnative-2-0-debugsource-2.0.15-150400.9.3.1 * libtcnative-2-0-debuginfo-2.0.15-150400.9.3.1 * libtcnative-2-0-devel-2.0.15-150400.9.3.1 ## References: * https://jira.suse.com/browse/PED-16024 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:31:13 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 12:31:13 -0000 Subject: SUSE-RU-2026:2805-1: moderate: Recommended update for google-guest-oslogin Message-ID: <178360027324.699.1349762146761598646@5ed4f61072e9> # Recommended update for google-guest-oslogin Announcement ID: SUSE-RU-2026:2805-1 Release Date: 2026-07-09T03:40:36Z Rating: moderate References: * bsc#1221342 * bsc#1231775 * bsc#1231776 * bsc#1257010 * jsc#PED-14688 Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that contains one feature and has four fixes can now be installed. ## Description: This update for google-guest-oslogin fixes the following issues: * Update to version 20260430.00 * URLEncode request parameters sent to the metadata server. * Add /var/google-sudoers.d to tmpfile config * The /var/google-users.d directory is pre-created in the Makefile but the google-sudoers.d is not. But the code wil not behave as expected if the directory is not there. Because of the pre-creation missing in Makefile this was missed initially. * Update to version 20260227.00 (bsc#1257010) * Fix broken cache_refresh behavior when groups are disabled. * Implement a binary cache for OS Login passwd entries. This change introduces a new binary cache format for storing OS Login passwd information. * Fix incorrect cache_refresh return value. * Update SELinux module dir as macro to allow root path move from /var/lib/selinux to /etc/selinux (bsc#1221342) * Log the response body when an auth failure occurs. * Check policy uses adminLogin for cloud run. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2805=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2805=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-2805=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2805=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-2805=1 ## Package List: * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * google-guest-oslogin-debugsource-20260430.00-150000.1.59.1 * google-guest-oslogin-debuginfo-20260430.00-150000.1.59.1 * google-guest-oslogin-20260430.00-150000.1.59.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * google-guest-oslogin-debugsource-20260430.00-150000.1.59.1 * google-guest-oslogin-debuginfo-20260430.00-150000.1.59.1 * google-guest-oslogin-20260430.00-150000.1.59.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * google-guest-oslogin-debugsource-20260430.00-150000.1.59.1 * google-guest-oslogin-debuginfo-20260430.00-150000.1.59.1 * google-guest-oslogin-20260430.00-150000.1.59.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * google-guest-oslogin-debugsource-20260430.00-150000.1.59.1 * google-guest-oslogin-debuginfo-20260430.00-150000.1.59.1 * google-guest-oslogin-20260430.00-150000.1.59.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * google-guest-oslogin-20260430.00-150000.1.59.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1221342 * https://bugzilla.suse.com/show_bug.cgi?id=1231775 * https://bugzilla.suse.com/show_bug.cgi?id=1231776 * https://bugzilla.suse.com/show_bug.cgi?id=1257010 * https://jira.suse.com/browse/PED-14688 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 16:30:06 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 16:30:06 -0000 Subject: SUSE-RU-2026:2813-1: moderate: Recommended update for lifecycle-data-sle-live-patching Message-ID: <178361460648.7071.12051825147468475458@b46b234fdc85> # Recommended update for lifecycle-data-sle-live-patching Announcement ID: SUSE-RU-2026:2813-1 Release Date: 2026-07-09T11:40:28Z Rating: moderate References: * bsc#1020320 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has one fix can now be installed. ## Description: This update for lifecycle-data-sle-live-patching fixes the following issues: * Added data for 4_12_14-122_299, 4_12_14-122_302, 4_12_14-122_307, 4_12_14-122_310, 4_12_14-122_317. (bsc#1020320) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2813=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (noarch) * lifecycle-data-sle-live-patching-1-10.179.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1020320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 16:30:14 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 16:30:14 -0000 Subject: SUSE-RU-2026:2812-1: moderate: Recommended update for lifecycle-data-sle-module-live-patching Message-ID: <178361461459.7071.9389583408773922392@b46b234fdc85> # Recommended update for lifecycle-data-sle-module-live-patching Announcement ID: SUSE-RU-2026:2812-1 Release Date: 2026-07-09T11:40:14Z Rating: moderate References: * bsc#1020320 Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for lifecycle-data-sle-module-live-patching fixes the following issues: * Added data for 5_14_21-150400_24_205, 5_14_21-150400_24_209, 5_14_21-150400_24_214, 5_14_21-150400_24_219, 5_14_21-150400_24_222, 5_14_21-150400_24_225, 5_14_21-150500_55_149, 5_14_21-150500_55_163, 5_14_21-150500_55_169, 5_14_21-150500_55_172, 6_4_0-150600_23_100, 6_4_0-150600_23_103, 6_4_0-150600_23_109, 6_4_0-150600_23_112, 6_4_0-150600_23_115, 6_4_0-150600_23_118, 6_4_0-150600_23_95, 6_4_0-150700_53_37, 6_4_0-150700_53_40, 6_4_0-150700_53_45, 6_4_0-150700_53_52, 6_4_0-150700_53_55, 6_4_0-150700_53_60, 6_4_0-150700_53_63, +kernel-livepatch-6_4_0-150700_7_40-rt,_,+kernel- livepatch-6_4_0-150700_7_44-rt,_ , +kernel- livepatch-6_4_0-150700_7_51-rt,_,+kernel-livepatch-6_4_0-150700_7_54-rt,_ , +kernel-livepatch-6_4_0-150700_7_59-rt,*. (bsc#1020320) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2812=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2812=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2812=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2812=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (noarch) * lifecycle-data-sle-module-live-patching-15-150000.4.144.1 * SUSE Linux Enterprise Live Patching 15-SP5 (noarch) * lifecycle-data-sle-module-live-patching-15-150000.4.144.1 * SUSE Linux Enterprise Live Patching 15-SP6 (noarch) * lifecycle-data-sle-module-live-patching-15-150000.4.144.1 * SUSE Linux Enterprise Live Patching 15-SP7 (noarch) * lifecycle-data-sle-module-live-patching-15-150000.4.144.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1020320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 20:30:11 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 20:30:11 -0000 Subject: SUSE-SU-2026:2582-2: important: Security update for MozillaFirefox Message-ID: <178362901167.765.38969049261994805@5ed4f61072e9> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:2582-2 Release Date: 2026-07-09T14:11:02Z Rating: important References: * bsc#1268071 Cross-References: * CVE-2026-12289 * CVE-2026-12290 * CVE-2026-12291 * CVE-2026-12292 * CVE-2026-12294 * CVE-2026-12295 * CVE-2026-12296 * CVE-2026-12297 * CVE-2026-12298 * CVE-2026-12299 * CVE-2026-12302 * CVE-2026-12304 * CVE-2026-12305 * CVE-2026-12306 * CVE-2026-12307 * CVE-2026-12308 * CVE-2026-12309 * CVE-2026-12310 * CVE-2026-12311 * CVE-2026-12312 * CVE-2026-12313 * CVE-2026-12314 * CVE-2026-12315 * CVE-2026-12324 * CVE-2026-12325 * CVE-2026-12327 * CVE-2026-12328 * CVE-2026-12329 * CVE-2026-12330 CVSS scores: * CVE-2026-12289 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12289 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-12292 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12294 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12298 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12302 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12302 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12304 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12304 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12305 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12305 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12306 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12306 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12309 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12309 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12310 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12310 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12311 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12311 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12312 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12313 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12313 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12314 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12314 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12315 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12315 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12324 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12324 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12325 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12325 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12327 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12327 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12329 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12330 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12330 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 29 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: NOTE: This update was retracted as it contained incorrect provides/obsolets on mozilla-nss-certs. Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): * CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. * CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12291: Use-after-free in the Networking: HTTP component. * CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. * CVE-2026-12294: Sandbox escape in the DOM: Workers component. * CVE-2026-12295: Sandbox escape in the DOM: Navigation component. * CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. * CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. * CVE-2026-12302: Mitigation bypass in the DOM: Security component. * CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. * CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12315: Mitigation bypass in the DOM: Security component. * CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. * CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2582=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2582=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2582=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2582=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2582=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2582=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2582=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2582=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2582=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2582=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2582=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * Desktop Applications Module 15-SP7 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12289.html * https://www.suse.com/security/cve/CVE-2026-12290.html * https://www.suse.com/security/cve/CVE-2026-12291.html * https://www.suse.com/security/cve/CVE-2026-12292.html * https://www.suse.com/security/cve/CVE-2026-12294.html * https://www.suse.com/security/cve/CVE-2026-12295.html * https://www.suse.com/security/cve/CVE-2026-12296.html * https://www.suse.com/security/cve/CVE-2026-12297.html * https://www.suse.com/security/cve/CVE-2026-12298.html * https://www.suse.com/security/cve/CVE-2026-12299.html * https://www.suse.com/security/cve/CVE-2026-12302.html * https://www.suse.com/security/cve/CVE-2026-12304.html * https://www.suse.com/security/cve/CVE-2026-12305.html * https://www.suse.com/security/cve/CVE-2026-12306.html * https://www.suse.com/security/cve/CVE-2026-12307.html * https://www.suse.com/security/cve/CVE-2026-12308.html * https://www.suse.com/security/cve/CVE-2026-12309.html * https://www.suse.com/security/cve/CVE-2026-12310.html * https://www.suse.com/security/cve/CVE-2026-12311.html * https://www.suse.com/security/cve/CVE-2026-12312.html * https://www.suse.com/security/cve/CVE-2026-12313.html * https://www.suse.com/security/cve/CVE-2026-12314.html * https://www.suse.com/security/cve/CVE-2026-12315.html * https://www.suse.com/security/cve/CVE-2026-12324.html * https://www.suse.com/security/cve/CVE-2026-12325.html * https://www.suse.com/security/cve/CVE-2026-12327.html * https://www.suse.com/security/cve/CVE-2026-12328.html * https://www.suse.com/security/cve/CVE-2026-12329.html * https://www.suse.com/security/cve/CVE-2026-12330.html * https://bugzilla.suse.com/show_bug.cgi?id=1268071 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 20:30:22 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 20:30:22 -0000 Subject: SUSE-RU-2026:2816-1: important: Recommended update for python-aioresponses, python-google-api-core, python-google-api-python-client, python-google-auth, python-google-auth-httplib2, python-google-cloud-appengine-logging, python-goog Message-ID: <178362902237.765.16373807474308382473@5ed4f61072e9> # Recommended update for python-aioresponses, python-google-api-core, python- google-api-python-client, python-google-auth, python-google-auth-httplib2, python-google-cloud-appengine-logging, python-goog Announcement ID: SUSE-RU-2026:2816-1 Release Date: 2026-07-09T13:16:57Z Rating: important References: * bsc#1161898 * bsc#1221705 Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has two fixes can now be installed. ## Description: This update for python-aioresponses, python-google-api-core, python-google-api- python-client, python-google-auth, python-google-auth-httplib2, python-google- cloud-appengine-logging, python-google-cloud-artifact-registry, python-google- cloud-audit-log, python-google-cloud-build, python-google-cloud-compute, python- google-cloud-core, python-google-cloud-dns, python-google-cloud-domains, python- google-cloud-iam, python-google-cloud-kms, python-google-cloud-kms-inventory, python-google-cloud-logging, python-google-cloud-run, python-google-cloud- secret-manager, python-google-cloud-service-directory, python-google-cloud- spanner, python-google-cloud-storage, python-google-cloud-vpc-access, python- google-crc32c, python-google-resumable-media, python-googleapis-common-protos, python-grpc-google-iam-v1, python-grpc-interceptor, python-mmh3, python-mypy, python-opentelemetry-resourcedetector-gcp, python-poetry-core, python-proto- plus, python-pytest-asyncio, python-syrupy, python-typed-ast, python- uritemplate, python-dnspython, python-trio, python-websocket-client fixes the following issues: Changes in python-aioresponses: * Switch to pyproject macros. * Update to 0.7.8 * feat: integer repeat * fix: case repeat=1 * docs: elaborate on meaning in documentation of repeat argument * use ClientSession base_url and headers * Refactor usage of session base_url and headers * Add tests for base_url and headers from session * Add **repr** to RequestMatch * Upgrade yarl to be compatible with Python 3.12 * fix: review suggestion * fix: fix test * fix: added condition on py3.8 while supporting ClientSession.base_url * fix: flake8 * from version 0.7.7 * added passthrough_unmatched flag for aioresponses class * test for passing unmatched requests * add a readme description about passthrough_unmatched flag * feat: support raise_for_status as callable * Add packaging to requirements.txt * Update `__version__` to latest released version * Fix compat with aiohttp 3.11.0+ * fix: invalid rst code * Add test_pass_through_unmatched_requests to skipped tests * Update Requires from requirements.txt * Add %{?sle15_python_module_pythons} * update to 0.7.6: * refactor: Make mock for writer compatible with 3.9.0b1 and older * fix: aiohttp 3.9 _writer can't await * update to 0.7.5: * replaced pkg_resources with packaging module * Add Python 3.11 support * update to 0.7.4: * bump py36 to ubuntu 20.04 * restore 3.6 * Adjust github actions test workflow * Fix python versions in env list * Add documentation for repeat argument * Add compat module * fix long line by adding line breaks * shorten comment to obey line length limit * split typing and assignment to avoid long line * Avoid type confusion by explicitly typing as `ClientResponse` * ignore false positive mypy warning when `url_or_pattern` is a `Pattern` * add `py.typed` to MANIFEST.in * add `py.typed` file to package data in setup.py * fix version after release was tagged/released * Extend for arguments * Init assert_called * Fix type annotations * update to 0.7.3: * Support binary bodies in responses * fix flake8 * move RequestInfo to compat * drop `.travis.yml` * basic CI using github actions * (feat) add unit tests * (feat) allow for callbacks to be called before raising of exception * add `py.typed` (PEP 561) * Fix setuptools warnings by replacing dashes in keys with underscores * fix version parsing * version 0.7.2 * Update aioresponses/core.py * adding catch to ignore ValueError when deepcopy is unsuccessful * Remove unused patch. * Update to v0.7.1 * Fix compatibility with aiohttp 3.7 * remove asynctest from compat.py * Python 3.9 compatibility * drop patch merged upstream * fix python version requirement, require asynctest for python36 again * Remove no longer necessary aioresponses replace asynctest patch * Add patch to add compatibility with aiohttp 3.7.0 * Update to v0.7.0 * fixes race condition while removing matchers * drop support for py3.5 and aiohttp2.x * replace asynctest with native Python 3.8 unittest * replace asynctest with native python 3.8 unittest async test class * drop disable-online-test patch and deselect by pytest call * update to 0.6.4 * Load response cookies from headers * BaseException handling(in Pyhton 3.8 asyncio.CancelError, asyncio.TimeoutError are subclass of BaseException) * exception can be as class or as object of exception(Exception or Exception()) * Change method to GET for redirect after POST request. * set request_info on response rather than a mock * Avoid failure in case one of the request arguments cannot be deep copied * update to 0.6.2 * Save every received request. Even when no response is subscribed. * Ensure that a copy of kwargs is stored in request * remove overly verbose Exception * assert the correct ClientConnectionError * Update to 0.6.1: * no upstream changelog * Lower the ddt requirement as it is not really needed * cleanup deps * Remove unnecessary build dependencies * Update to v0.6.0 * Move internal stuff and CallbackResult class to the core module * Add CallbackResult class for returning responses from callbacks * Expose build_response method * Add Python 3.7 for tox * Add callbacks to provide dynamic responses * Use noun phrase / full sentences in summary / description. * Format with spec-cleaner * Initial build * Version 0.5.0 * Include patch to disable online test Changes in python-google-api-core: \- Update to 2.26.0 * Add trove classifier for Python 3.14 (#842) \- from version 2.25.2 * Deprecate credentials_file argument (#841) * Fix async tests and round-off error in test expectations (#837) * Update to 2.25.1 * Allow BackgroundConsumer To Inform Caller of Fatal Exceptions with Optional Callback (3206c01) * Update to 2.25.0 * Add protobuf runtime version to `x-goog-api-client` header (#812) * Support dynamic retry backoff values (#793) * Update to 2.24.2 * **deps:** Allow protobuf 6.x (#804) * Update Requires from pyproject.toml * Update to 2.24.1 * Memory leak in bidi classes (#770) * Resolve the issue where rpc timeout of 0 is used when timeout expires (#776) * Add warnings regarding consuming externally sourced credentials (#783) * Update to 2.24.0 * Add automatic logging config to support debug logging (#754) * Update recognized logging fields (#766) * Update to 2.23.0 * Migrate to pyproject.toml (#736) * from version 2.22.0 * Add support for python 3.13 (#696) * Add type hints to ClientOptions (#735) * Improve `Any` decode error (#712) * Require proto-plus >= 1.25.0 for Python 3.13 (#740) * Switch to unittest.mock from mock (#713) Drop python google api core no mock patch, merged upstream * Update to 2.21.0 * Add support for asynchronous long running operations (#724) Drop python google api core no mock patch, merged upstream * fix requirements * Accepts new protobuf version 5.28 now. * Remove unneeded BuildRequires. * Refreshed patches: * python google api core no mock patch * Update to 2.20.0 * Add async unsupported paramater exception (#694) * Add support for asynchronous rest streaming (#686) * Add support for creating exceptions from an asynchronous response (#688) * Update to 2.19.2 * Fail gracefully if could not import `rpc_status` module (#680) * Adjust upstream source name in spec file * update to 2.19.1: * Add support for protobuf 5.x * Ignore unknown fields in rest streaming. * Update to version 2.19.0 * Add google.api_core.version_header (#638) * from version 2.18.0 * Add common logic for supporting universe domain (#621) * Add _registered_method to grpc ChannelStub (#614) * **deps:** Require proto-plus >= 1.22.3 (#626) * from version 2.17.1 * Resolve issue handling protobuf responses in rest streaming (#604) * from version 2.17.0 * Add attempt_direct_path argument to create_channel (#583) * Retry constructors methods support None (#592) * from version 2.16.2 * Spelling error `a,out` -> `amount` (#596) * from version 2.16.1 * Fix broken import for google.api_core.retry_async.AsyncRetry (#587) * from version 2.16.0 * Retry and retry_async support streaming rpcs (#495) * Refresh patches for new version * Update BuildRequires and Requires from setup.py Changes in python-google-api-python-client: \- Update to version 1.185.0 * **accesscontextmanager:** Update the api * Add support for 3.14 (#2668) * **alloydb:** Update the api * **alloydb:** Update the api * **apigateway:** Update the api * **apigee:** Update the api * **apim:** Update the api * **appengine:** Update the api * **appengine:** Update the api * **apphub:** Update the api * **assuredworkloads:** Update the api * **backupdr:** Update the api * **batch:** Update the api * **beyondcorp:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **certificatemanager:** Update the api * **chromemanagement:** Update the api * **cloudchannel:** Update the api * **clouddeploy:** Update the api * **cloudfunctions:** Update the api * **cloudscheduler:** Update the api * **cloudshell:** Update the api * **composer:** Update the api * **compute:** Update the api * **config:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **datacatalog:** Update the api * **dataform:** Update the api * **datalineage:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **datastore:** Update the api * **developerconnect:** Update the api * **dialogflow:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **docs:** Update the api * **documentai:** Update the api * **documentai:** Update the api * **eventarc:** Update the api * **file:** Update the api * **firebasehosting:** Update the api * **firebaseml:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **gamesConfiguration:** Update the api * **gamesManagement:** Update the api * **games:** Update the api * **gkebackup:** Update the api * **gkehub:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **iam:** Update the api * **iam:** Update the api * **looker:** Update the api * **memcache:** Update the api * **merchantapi:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **netapp:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **networksecurity:** Update the api * **observability:** Update the api * **ondemandscanning:** Update the api * **osconfig:** Update the api * **parallelstore:** Update the api * **paymentsresellersubscription:** Update the api * **policysimulator:** Update the api * **privateca:** Update the api * **pubsublite:** Update the api * **redis:** Update the api * **redis:** Update the api * **retail:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **servicemanagement:** Update the api * **servicenetworking:** Update the api * **spanner:** Update the api * **speech:** Update the api * **sqladmin:** Update the api * **storagebatchoperations:** Update the api * **texttospeech:** Update the api * **tpu:** Update the api * **travelimpactmodel:** Update the api * **vision:** Update the api * **vmmigration:** Update the api * **webrisk:** Update the api * **workloadmanager:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **chat:** Update the api * **secretmanager:** Update the api * **secretmanager:** Update the api * **workspaceevents:** Update the api * Update to version 1.184.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **androidmanagement:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **bigquery:** Update the api * **certificatemanager:** Update the api * **checks:** Update the api * **cloudidentity:** Update the api * **cloudscheduler:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **docs:** Update the api * **documentai:** Update the api * **firebaseappdistribution:** Update the api * **firebaseapphosting:** Update the api * **firestore:** Update the api * **integrations:** Update the api * **migrationcenter:** Update the api * **oracledatabase:** Update the api * **oslogin:** Update the api * **places:** Update the api * **recaptchaenterprise:** Update the api * **saasservicemgmt:** Update the api * **serviceconsumermanagement:** Update the api * **servicemanagement:** Update the api * **serviceusage:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **texttospeech:** Update the api * **tpu:** Update the api * **webfonts:** Update the api * **dataflow:** Update the api * **datastore:** Update the api * **iamcredentials:** Update the api * **logging:** Update the api * **parametermanager:** Update the api * Update to version 1.183.0 * **aiplatform:** Update the api * **androidmanagement:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **chat:** Update the api * **cloudcommerceprocurement:** Update the api * **cloudidentity:** Update the api * **cloudkms:** Update the api * **compute:** Update the api * **connectors:** Update the api * **dataform:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **documentai:** Update the api * **domains:** Update the api * **eventarc:** Update the api * **firebaseappdistribution:** Update the api * **migrationcenter:** Update the api * **netapp:** Update the api * **networkconnectivity:** Update the api * **networksecurity:** Update the api * **oracledatabase:** Update the api * **retail:** Update the api * **sqladmin:** Update the api * **workloadmanager:** Update the api * Update to version 1.182.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticshub:** Update the api * **androidpublisher:** Update the api * **apigee:** Update the api * **apihub:** Update the api * **backupdr:** Update the api * **cloudcommerceprocurement:** Update the api * **compute:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **datamigration:** Update the api * **datastream:** Update the api * **dfareporting:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **drive:** Update the api * **file:** Update the api * **firebaseappcheck:** Update the api * **firebaseappdistribution:** Update the api * **firebaseapphosting:** Update the api * **firebasedataconnect:** Update the api * **firebaseml:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **healthcare:** Update the api * **managedkafka:** Update the api * **merchantapi:** Update the api * **migrationcenter:** Update the api * **netapp:** Update the api * **netapp:** Update the api * **networkmanagement:** Update the api * **networkmanagement:** Update the api * **oracledatabase:** Update the api * **oracledatabase:** Update the api * **privateca:** Update the api * **redis:** Update the api * **redis:** Update the api * **securitycenter:** Update the api * **servicecontrol:** Update the api * **texttospeech:** Update the api * **tpu:** Update the api * **vmmigration:** Update the api * **walletobjects:** Update the api * **datastore:** Update the api * **firestore:** Update the api * **logging:** Update the api * **run:** Update the api * from version 2.181.0 * **aiplatform:** Update the api * **androidmanagement:** Update the api * **backupdr:** Update the api * **bigquery:** Update the api * **contactcenteraiplatform:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **dataplex:** Update the api * **deploymentmanager:** Update the api * **dfareporting:** Update the api * **discoveryengine:** Update the api * **file:** Update the api * **firebaseappdistribution:** Update the api * **logging:** Update the api * **looker:** Update the api * **memcache:** Update the api * **merchantapi:** Update the api * **networkconnectivity:** Update the api * **networksecurity:** Update the api * **observability:** Update the api * **playintegrity:** Update the api * **redis:** Update the api * **sqladmin:** Update the api * **vmmigration:** Update the api * **workloadmanager:** Update the api * **dlp:** Update the api * from version 2.180.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **apigee:** Update the api * **backupdr:** Update the api * **bigquerydatatransfer:** Update the api * **bigtableadmin:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **cloudchannel:** Update the api * **compute:** Update the api * **compute:** Update the api * **config:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **container:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **datastore:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **dlp:** Update the api * **dlp:** Update the api * **documentai:** Update the api * **documentai:** Update the api * **file:** Update the api * **firebaseappdistribution:** Update the api * **firebaseappdistribution:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **healthcare:** Update the api * **iam:** Update the api * **manufacturers:** Update the api * **netapp:** Update the api * **netapp:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **ondemandscanning:** Update the api * **playintegrity:** Update the api * **redis:** Update the api * **redis:** Update the api * **retail:** Update the api * **run:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **versionhistory:** Update the api * **vmwareengine:** Update the api * **workloadmanager:** Update the api * **admin:** Update the api * **admin:** Update the api * **pubsub:** Update the api * Update to version 2.179.0 * **admin:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticshub:** Update the api * **androidpublisher:** Update the api * **apigee:** Update the api * **backupdr:** Update the api * **bigtableadmin:** Update the api * **cloudbuild:** Update the api * **cloudidentity:** Update the api * **cloudkms:** Update the api * **cloudsupport:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **file:** Update the api * **firebaseappdistribution:** Update the api * **firebasedataconnect:** Update the api * **firebaseml:** Update the api * **managedkafka:** Update the api * **merchantapi:** Update the api * **mybusinessverifications:** Update the api * **networkservices:** Update the api * **paymentsresellersubscription:** Update the api * **redis:** Update the api * **run:** Update the api * **texttospeech:** Update the api * **walletobjects:** Update the api * from version 2.178.0 * **aiplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticsadmin:** Update the api * **androidenterprise:** Update the api * **androidpublisher:** Update the api * **apihub:** Update the api * **backupdr:** Update the api * **bigquery:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **chat:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **cloudbuild:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **dfareporting:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **drive:** Update the api * **file:** Update the api * **firebaseml:** Update the api * **firebaseml:** Update the api * **gkebackup:** Update the api * **iam:** Update the api * **integrations:** Update the api * **looker:** Update the api * **merchantapi:** Update the api * **merchantapi:** Update the api * **mybusinessbusinessinformation:** Update the api * **mybusinessverifications:** Update the api * **networkmanagement:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **osconfig:** Update the api * **redis:** Update the api * **redis:** Update the api * **retail:** Update the api * **retail:** Update the api * **searchads360:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **servicenetworking:** Update the api * **serviceusage:** Update the api * **storage:** Update the api * **transcoder:** Update the api * **videointelligence:** Update the api * **workloadmanager:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **iamcredentials:** Update the api * **migrationcenter:** Update the api * Update to version 1.177.0 * **admin:** Update the api * **adsenseplatform:** Update the api * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **androidpublisher:** Update the api * **apphub:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **civicinfo:** Update the api * **cloudasset:** Update the api * **cloudbilling:** Update the api * **compute:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **dataflow:** Update the api * **dataform:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **dlp:** Update the api * **documentai:** Update the api * **firebaseapphosting:** Update the api * **firebasedataconnect:** Update the api * **firebaseml:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **managedkafka:** Update the api * **merchantapi:** Update the api * **merchantapi:** Update the api * **migrationcenter:** Update the api * **netapp:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **notebooks:** Update the api * **oracledatabase:** Update the api * **recaptchaenterprise:** Update the api * **redis:** Update the api * **retail:** Update the api * **run:** Update the api * **searchconsole:** Update the api * **servicenetworking:** Update the api * **transcoder:** Update the api * **videointelligence:** Update the api * **vmmigration:** Update the api * **workloadmanager:** Update the api * **youtube:** Update the api * **artifactregistry:** Update the api * **datalineage:** Update the api * **datalineage:** Update the api * **dataplex:** Update the api * **dataportability:** Update the api * **logging:** Update the api * **parametermanager:** Update the api * **secretmanager:** Update the api * from version 1.176.0 * **adsenseplatform:** Update the api * **aiplatform:** Update the api * **androidpublisher:** Update the api * **apihub:** Update the api * **backupdr:** Update the api * **datamigration:** Update the api * **dataproc:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **drive:** Update the api * **iam:** Update the api * **merchantapi:** Update the api * **policysimulator:** Update the api * **redis:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **spanner:** Update the api * **storage:** Update the api * **workstations:** Update the api * **apigee:** Update the api * **composer:** Update the api * **secretmanager:** Update the api * from version 1.175.0 * **analyticsadmin:** Update the api * **androidmanagement:** Update the api * **apigee:** Update the api * **beyondcorp:** Update the api * **bigqueryreservation:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **datalineage:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **dlp:** Update the api * **eventarc:** Update the api * **firestore:** Update the api * **iam:** Update the api * **integrations:** Update the api * **managedkafka:** Update the api * **metastore:** Update the api * **run:** Update the api * **secretmanager:** Update the api * **securityposture:** Update the api * **testing:** Update the api * **travelimpactmodel:** Update the api * **vmmigration:** Update the api * from version 1.174.0 * **addressvalidation:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **androidmanagement:** Update the api * **appengine:** Update the api * **apphub:** Update the api * **bigtableadmin:** Update the api * **containeranalysis:** Update the api * **content:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **healthcare:** Update the api * **merchantapi:** Update the api * **networkservices:** Update the api * **policysimulator:** Update the api * **redis:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **servicenetworking:** Update the api * **sqladmin:** Update the api * **tpu:** Update the api * **workloadmanager:** Update the api * **admin:** Update the api * **bigqueryreservation:** Update the api * **chat:** Update the api * **workspaceevents:** Update the api * from version 1.173.0 * **adsenseplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticsadmin:** Update the api * **apigee:** Update the api * **appengine:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **cloudresourcemanager:** Update the api * **cloudsupport:** Update the api * **config:** Update the api * **container:** Update the api * **datafusion:** Update the api * **dataproc:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **fcm:** Update the api * **firebaseappdistribution:** Update the api * **firebaseml:** Update the api * **gkeonprem:** Update the api * **integrations:** Update the api * **looker:** Update the api * **netapp:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **readerrevenuesubscriptionlinking:** Update the api * **redis:** Update the api * **retail:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **sheets:** Update the api * **workstations:** Update the api * **bigquerydatatransfer:** Update the api * **compute:** Update the api * Update to version 1.172.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **cloudscheduler:** Update the api * **compute:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **content:** Update the api * **developerconnect:** Update the api * **dfareporting:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **drivelabels:** Update the api * **firebasedataconnect:** Update the api * **firebaseml:** Update the api * **gkebackup:** Update the api * **healthcare:** Update the api * **logging:** Update the api * **managedkafka:** Update the api * **merchantapi:** Update the api * **monitoring:** Update the api * **netapp:** Update the api * **networksecurity:** Update the api * **playintegrity:** Update the api * **policysimulator:** Update the api * **privateca:** Update the api * **servicemanagement:** Update the api * **storage:** Update the api * **travelimpactmodel:** Update the api * **workloadmanager:** Update the api * **dataportability:** Update the api * from version 2.171.0 * **aiplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **androidpublisher:** Update the api * **apim:** Update the api * **bigqueryreservation:** Update the api * **bigtableadmin:** Update the api * **blogger:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **classroom:** Update the api * **cloudkms:** Update the api * **cloudresourcemanager:** Update the api * **composer:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **dataflow:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **dataproc:** Update the api * **datastream:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **dlp:** Update the api * **documentai:** Update the api * **essentialcontacts:** Update the api * **firebaseml:** Update the api * **firebaseml:** Update the api * **gkeonprem:** Update the api * **iap:** Update the api * **integrations:** Update the api * **migrationcenter:** Update the api * **netapp:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **networkservices:** Update the api * **ondemandscanning:** Update the api * **playintegrity:** Update the api * **redis:** Update the api * **retail:** Update the api * **retail:** Update the api * **safebrowsing:** Update the api * **script:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **servicemanagement:** Update the api * **servicenetworking:** Update the api * **serviceusage:** Update the api * **sheets:** Update the api * **spanner:** Update the api * **sqladmin:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **vault:** Update the api * **videointelligence:** Update the api * **vmmigration:** Update the api * **storage:** Update the api * Update to version 1.170.0 * **aiplatform:** Update the api * **aiplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **alloydb:** Update the api * **analyticshub:** Update the api * **analyticshub:** Update the api * **androidmanagement:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **appengine:** Update the api * **artifactregistry:** Update the api * **backupdr:** Update the api * **bigqueryreservation:** Update the api * **bigqueryreservation:** Update the api * **bigquery:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **certificatemanager:** Update the api * **chat:** Update the api * **civicinfo:** Update the api * **cloudbuild:** Update the api * **cloudfunctions:** Update the api * **cloudresourcemanager:** Update the api * **compute:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **contactcenterinsights:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **dataflow:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **documentai:** Update the api * **drive:** Update the api * **drive:** Update the api * **firebaseml:** Update the api * **firebaseml:** Update the api * **gkebackup:** Update the api * **gkeonprem:** Update the api * **iam:** Update the api * **integrations:** Update the api * **integrations:** Update the api * **lifesciences:** Update the api * **managedkafka:** Update the api * **memcache:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **netapp:** Update the api * **networkconnectivity:** Update the api * **networkconnectivity:** Update the api * **networkservices:** Update the api * **networkservices:** Update the api * **notebooks:** Update the api * **ondemandscanning:** Update the api * **oracledatabase:** Update the api * **osconfig:** Update the api * **places:** Update the api * **places:** Update the api * **recaptchaenterprise:** Update the api * **recaptchaenterprise:** Update the api * **retail:** Update the api * **retail:** Update the api * **run:** Update the api * **run:** Update the api * **sheets:** Update the api * **sqladmin:** Update the api * **sqladmin:** Update the api * **storagetransfer:** Update the api * **storagetransfer:** Update the api * **storage:** Update the api * **texttospeech:** Update the api * **trafficdirector:** Update the api * **workloadmanager:** Update the api * **artifactregistry:** Update the api * **cloudkms:** Update the api * **storage:** Update the api * **sts:** Update the api * Update to version 1.169.0 * **aiplatform:** Update the api * **artifactregistry:** Update the api * **blockchainnodeengine:** Update the api * **cloudchannel:** Update the api * **cloudresourcemanager:** Update the api * **connectors:** Update the api * **dataflow:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **documentai:** Update the api * **drive:** Update the api * **file:** Update the api * **firebaseml:** Update the api * **gkehub:** Update the api * **iamcredentials:** Update the api * **integrations:** Update the api * **merchantapi:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **oracledatabase:** Update the api * **orgpolicy:** Update the api * **sheets:** Update the api * **sqladmin:** Update the api * **tpu:** Update the api * **translate:** Update the api * **vpcaccess:** Update the api * **youtube:** Update the api * **admin:** Update the api * **cloudbuild:** Update the api * **storage:** Update the api * Update to version 1.168.0 * **accessapproval:** Update the api * **alertcenter:** Update the api * **alloydb:** Update the api * **analyticshub:** Update the api * **apigateway:** Update the api * **appengine:** Update the api * **apphub:** Update the api * **assuredworkloads:** Update the api * **baremetalsolution:** Update the api * **batch:** Update the api * **beyondcorp:** Update the api * **bigtableadmin:** Update the api * **chromeuxreport:** Update the api * **cloudchannel:** Update the api * **clouddeploy:** Update the api * **cloudfunctions:** Update the api * **cloudkms:** Update the api * **cloudscheduler:** Update the api * **cloudtasks:** Update the api * **compute:** Update the api * **config:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **css:** Update the api * **datacatalog:** Update the api * **datafusion:** Update the api * **datamigration:** Update the api * **deploymentmanager:** Update the api * **dialogflow:** Update the api * **digitalassetlinks:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **dns:** Update the api * **documentai:** Update the api * **eventarc:** Update the api * **file:** Update the api * **firebaseappdistribution:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **gkebackup:** Update the api * **gkehub:** Update the api * **iam:** Update the api * **integrations:** Update the api * **logging:** Update the api * **looker:** Update the api * **managedkafka:** Update the api * **meet:** Update the api * **merchantapi:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **netapp:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **networkservices:** Update the api * **oracledatabase:** Update the api * **places:** Update the api * **privateca:** Update the api * **run:** Update the api * **searchads360:** Update the api * **securitycenter:** Update the api * **tagmanager:** Update the api * **tpu:** Update the api * **vmwareengine:** Update the api * **workflows:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **containeranalysis:** Update the api * **paymentsresellersubscription:** Update the api * Remove setup.cfg configuration for creating universal wheels (#2580) * **storage:** Update the api * **sts:** Update the api * from version 2.167.0 * **admin:** Update the api * **admin:** Update the api * **aiplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticsadmin:** Update the api * **analyticshub:** Update the api * **androidmanagement:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **bigquerydatatransfer:** Update the api * **blockchainnodeengine:** Update the api * **chat:** Update the api * **chromepolicy:** Update the api * **chromepolicy:** Update the api * **classroom:** Update the api * **cloudbuild:** Update the api * **cloudfunctions:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **container:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **deploymentmanager:** Update the api * **deploymentmanager:** Update the api * **developerconnect:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **docs:** Update the api * **file:** Update the api * **firebasedataconnect:** Update the api * **firebaseml:** Update the api * **firebase:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **healthcare:** Update the api * **iam:** Update the api * **ids:** Update the api * **integrations:** Update the api * **managedkafka:** Update the api * **merchantapi:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networkconnectivity:** Update the api * **networkservices:** Update the api * **notebooks:** Update the api * **observability:** Update the api * **oracledatabase:** Update the api * **osconfig:** Update the api * **parallelstore:** Update the api * **paymentsresellersubscription:** Update the api * **policysimulator:** Update the api * **rapidmigrationassessment:** Update the api * **recommender:** Update the api * **redis:** Update the api * **run:** Update the api * **secretmanager:** Update the api * **securitycenter:** Update the api * **servicedirectory:** Update the api * **slides:** Update the api * **testing:** Update the api * **tpu:** Update the api * **vault:** Update the api * **vmmigration:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **youtube:** Update the api * **datalineage:** Update the api * Explicitly declare support for Python 3.13 (#2593) * Update to version 1.166.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticshub:** Update the api * **apigee:** Update the api * **bigqueryreservation:** Update the api * **bigquery:** Update the api * **civicinfo:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **documentai:** Update the api * **gkebackup:** Update the api * **integrations:** Update the api * **managedkafka:** Update the api * **merchantapi:** Update the api * **monitoring:** Update the api * **netapp:** Update the api * **networkconnectivity:** Update the api * **networkservices:** Update the api * **notebooks:** Update the api * **oracledatabase:** Update the api * **pubsub:** Update the api * **securitycenter:** Update the api * **verifiedaccess:** Update the api * **chat:** Update the api * **storage:** Update the api * **sts:** Update the api * from version 2.165.0 * **accesscontextmanager:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticsadmin:** Update the api * **appengine:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **binaryauthorization:** Update the api * **chromemanagement:** Update the api * **cloudasset:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **dataflow:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **eventarc:** Update the api * **firebaseml:** Update the api * **forms:** Update the api * **gkebackup:** Update the api * **healthcare:** Update the api * **integrations:** Update the api * **logging:** Update the api * **looker:** Update the api * **merchantapi:** Update the api * **networksecurity:** Update the api * **networkservices:** Update the api * **places:** Update the api * **playdeveloperreporting:** Update the api * **retail:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **spanner:** Update the api * **sqladmin:** Update the api * **tagmanager:** Update the api * **tpu:** Update the api * **workloadmanager:** Update the api * Resolve issue where pre-release versions of dependencies are installed (#2576) * Update to version 1.164.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticsadmin:** Update the api * **analyticshub:** Update the api * **androidenterprise:** Update the api * **apigee:** Update the api * **authorizedbuyersmarketplace:** Update the api * **bigqueryreservation:** Update the api * **bigtableadmin:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **cloudfunctions:** Update the api * **connectors:** Update the api * **container:** Update the api * **dataportability:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **firebaseappdistribution:** Update the api * **gkebackup:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **ids:** Update the api * **integrations:** Update the api * **metastore:** Update the api * **monitoring:** Update the api * **networkconnectivity:** Update the api * **oslogin:** Update the api * **parallelstore:** Update the api * **paymentsresellersubscription:** Update the api * **places:** Update the api * **redis:** Update the api * **sqladmin:** Update the api * **testing:** Update the api * **verifiedaccess:** Update the api * **workloadmanager:** Update the api * **cloudbuild:** Update the api * **run:** Update the api * **secretmanager:** Update the api * **sts:** Update the api * from version 2.163.0 * **adsense:** Update the api * **alloydb:** Update the api * **androidpublisher:** Update the api * **appengine:** Update the api * **beyondcorp:** Update the api * **bigqueryreservation:** Update the api * **bigtableadmin:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **dataform:** Update the api * **datafusion:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **discoveryengine:** Update the api * **drive:** Update the api * **fcm:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **integrations:** Update the api * **merchantapi:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **networkservices:** Update the api * **privateca:** Update the api * **retail:** Update the api * **run:** Update the api * **spanner:** Update the api * **tpu:** Update the api * from version 1.162.0 * **aiplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticshub:** Update the api * **androidenterprise:** Update the api * **androidmanagement:** Update the api * **apigee:** Update the api * **appengine:** Update the api * **bigqueryreservation:** Update the api * **bigquery:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **cloudbuild:** Update the api * **cloudkms:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **container:** Update the api * **datacatalog:** Update the api * **datamigration:** Update the api * **dataportability:** Update the api * **dataproc:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **digitalassetlinks:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **displayvideo:** Update the api * **dlp:** Update the api * **drive:** Update the api * **drive:** Update the api * **file:** Update the api * **firebaseappdistribution:** Update the api * **firebaseml:** Update the api * **gkebackup:** Update the api * **gkebackup:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **healthcare:** Update the api * **integrations:** Update the api * **logging:** Update the api * **looker:** Update the api * **memcache:** Update the api * **merchantapi:** Update the api * **migrationcenter:** Update the api * **mybusinessbusinessinformation:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **ondemandscanning:** Update the api * **ondemandscanning:** Update the api * **oslogin:** Update the api * **parallelstore:** Update the api * **paymentsresellersubscription:** Update the api * **playintegrity:** Update the api * **realtimebidding:** Update the api * **redis:** Update the api * **redis:** Update the api * **run:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **servicemanagement:** Update the api * **servicenetworking:** Update the api * **serviceusage:** Update the api * **sqladmin:** Update the api * **tagmanager:** Update the api * **vault:** Update the api * **vmwareengine:** Update the api * **workloadmanager:** Update the api * **workloadmanager:** Update the api * **secretmanager:** Update the api * **sts:** Update the api * Update to version 1.161.0 * **aiplatform:** Update the api * **analyticshub:** Update the api * **androidenterprise:** Update the api * **apigee:** Update the api * **appengine:** Update the api * **apphub:** Update the api * **backupdr:** Update the api * **batch:** Update the api * **bigquery:** Update the api * **bigquery:** Update the api * **certificatemanager:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **clouddeploy:** Update the api * **cloudfunctions:** Update the api * **cloudfunctions:** Update the api * **cloudidentity:** Update the api * **compute:** Update the api * **compute:** Update the api * **connectors:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **container:** Update the api * **content:** Update the api * **dataflow:** Update the api * **dataform:** Update the api * **dataform:** Update the api * **datafusion:** Update the api * **datamigration:** Update the api * **dataproc:** Update the api * **datastream:** Update the api * **datastream:** Update the api * **developerconnect:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **displayvideo:** Update the api * **documentai:** Update the api * **drive:** Update the api * **firebaseappdistribution:** Update the api * **firebaseml:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **forms:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **identitytoolkit:** Update the api * **integrations:** Update the api * **logging:** Update the api * **logging:** Update the api * **memcache:** Update the api * **merchantapi:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **monitoring:** Update the api * **netapp:** Update the api * **netapp:** Update the api * **networksecurity:** Update the api * **networksecurity:** Update the api * **pubsub:** Update the api * **recaptchaenterprise:** Update the api * **redis:** Update the api * **run:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **servicecontrol:** Update the api * **servicemanagement:** Update the api * **servicenetworking:** Update the api * **serviceusage:** Update the api * **spanner:** Update the api * **sqladmin:** Update the api * **tagmanager:** Update the api * **toolresults:** Update the api * **vault:** Update the api * **vault:** Update the api * **walletobjects:** Update the api * **webfonts:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **youtube:** Update the api * **youtube:** Update the api * **admin:** Update the api * **calendar:** Update the api * **datalineage:** Update the api * **dataportability:** Update the api * **dlp:** Update the api * **dlp:** Update the api * **meet:** Update the api * **secretmanager:** Update the api * **secretmanager:** Update the api * **sts:** Update the api * Update to version 1.160.0 * **accesscontextmanager:** Update the api * **adsenseplatform:** Update the api * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **analyticshub:** Update the api * **androidenterprise:** Update the api * **classroom:** Update the api * **cloudbuild:** Update the api * **compute:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **file:** Update the api * **gkehub:** Update the api * **integrations:** Update the api * **merchantapi:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **netapp:** Update the api * **networkmanagement:** Update the api * **redis:** Update the api * **spanner:** Update the api * **websecurityscanner:** Update the api * **secretmanager:** Update the api * Update to version 1.159.0 * **adsenseplatform:** Update the api * **alloydb:** Update the api * **authorizedbuyersmarketplace:** Update the api * **cloudasset:** Update the api * **clouddeploy:** Update the api * **cloudfunctions:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **dataflow:** Update the api * **datastream:** Update the api * **deploymentmanager:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dns:** Update the api * **eventarc:** Update the api * **firebasedataconnect:** Update the api * **firebasestorage:** Update the api * **gkehub:** Update the api * **iam:** Update the api * **parallelstore:** Update the api * **pubsub:** Update the api * **redis:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **servicecontrol:** Update the api * **tpu:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **cloudbuild:** Update the api * **cloudkms:** Update the api * Update to version 1.158.0 * **adsenseplatform:** Update the api * **analyticshub:** Update the api * **androidenterprise:** Update the api * **chat:** Update the api * **connectors:** Update the api * **datamigration:** Update the api * **deploymentmanager:** Update the api * **firebaseml:** Update the api * **serviceusage:** Update the api * Update to version 1.157.0 * **aiplatform:** Update the api * **androidpublisher:** Update the api * **apigee:** Update the api * **chromemanagement:** Update the api * **contactcenterinsights:** Update the api * **content:** Update the api * **css:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **firebaseml:** Update the api * **jobs:** Update the api * **merchantapi:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **retail:** Update the api * **run:** Update the api * **translate:** Update the api * **dlp:** Update the api * from version 2.156.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **artifactregistry:** Update the api * **assuredworkloads:** Update the api * **backupdr:** Update the api * **bigqueryreservation:** Update the api * **chat:** Update the api * **cloudbuild:** Update the api * **cloudidentity:** Update the api * **config:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **css:** Update the api * **dataflow:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **file:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **integrations:** Update the api * **migrationcenter:** Update the api * **netapp:** Update the api * **networkmanagement:** Update the api * **notebooks:** Update the api * **oracledatabase:** Update the api * **paymentsresellersubscription:** Update the api * **privateca:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **servicecontrol:** Update the api * **sheets:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **workflows:** Update the api * **workloadmanager:** Update the api * from version 2.155.0 * **admin:** Update the api * **aiplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticsdata:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **apigee:** Update the api * **appengine:** Update the api * **appengine:** Update the api * **bigquery:** Update the api * **checks:** Update the api * **checks:** Update the api * **chromemanagement:** Update the api * **classroom:** Update the api * **cloudidentity:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **contactcenterinsights:** Update the api * **content:** Update the api * **dataform:** Update the api * **datafusion:** Update the api * **datamigration:** Update the api * **deploymentmanager:** Update the api * **digitalassetlinks:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **eventarc:** Update the api * **firebaseappdistribution:** Update the api * **firebasedynamiclinks:** Update the api * **firebaseml:** Update the api * **firebaseml:** Update the api * **forms:** Update the api * **integrations:** Update the api * **merchantapi:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **netapp:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **orgpolicy:** Update the api * **playintegrity:** Update the api * **playintegrity:** Update the api * **policysimulator:** Update the api * **redis:** Update the api * **redis:** Update the api * **retail:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **servicemanagement:** Update the api * **serviceusage:** Update the api * **tagmanager:** Update the api * **toolresults:** Update the api * **walletobjects:** Update the api * **youtube:** Update the api * **youtube:** Update the api * **youtube:** Update the api * Update to version 1.154.0 * **aiplatform:** Update the api * **androidenterprise:** Update the api * **beyondcorp:** Update the api * **cloudsearch:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **datamigration:** Update the api * **deploymentmanager:** Update the api * **digitalassetlinks:** Update the api * **discoveryengine:** Update the api * **drive:** Update the api * **firebaseappdistribution:** Update the api * **firebasestorage:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **netapp:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **networkservices:** Update the api * **securitycenter:** Update the api * **servicemanagement:** Update the api * **servicenetworking:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **sts:** Update the api * **walletobjects:** Update the api * **datalineage:** Update the api * **speech:** Update the api * from version 2.153.0 * **accesscontextmanager:** Update the api * **calendar:** Update the api * **chat:** Update the api * **cloudchannel:** Update the api * **compute:** Update the api * **container:** Update the api * **dataplex:** Update the api * **deploymentmanager:** Update the api * **discoveryengine:** Update the api * **fcm:** Update the api * **firebaseml:** Update the api * **integrations:** Update the api * **networkconnectivity:** Update the api * **paymentsresellersubscription:** Update the api * **places:** Update the api * **searchads360:** Update the api * **servicenetworking:** Update the api * **testing:** Update the api * from version 2.152.0 * **accesscontextmanager:** Update the api * **admin:** Update the api * **aiplatform:** Update the api * **analyticshub:** Update the api * **beyondcorp:** Update the api * **clouddeploy:** Update the api * **compute:** Update the api * **container:** Update the api * **dataflow:** Update the api * **datastream:** Update the api * **developerconnect:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **firebaseappdistribution:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **migrationcenter:** Update the api * **networkmanagement:** Update the api * **serviceusage:** Update the api * **tpu:** Update the api * **youtube:** Update the api * **translate:** Update the api * from version 2.151.0 * **accesscontextmanager:** Update the api * **aiplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **androidenterprise:** Update the api * **androidpublisher:** Update the api * **apigee:** Update the api * **apikeys:** Update the api * **artifactregistry:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **bigqueryreservation:** Update the api * **bigquery:** Update the api * **chat:** Update the api * **checks:** Update the api * **chromemanagement:** Update the api * **cloudbilling:** Update the api * **cloudbuild:** Update the api * **cloudchannel:** Update the api * **cloudcontrolspartner:** Update the api * **clouddeploy:** Update the api * **cloudidentity:** Update the api * **compute:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **container:** Update the api * **content:** Update the api * **datacatalog:** Update the api * **dataform:** Update the api * **datalineage:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **datastore:** Update the api * **developerconnect:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **documentai:** Update the api * **eventarc:** Update the api * **file:** Update the api * **firebaseappdistribution:** Update the api * **firebaseappdistribution:** Update the api * **firebaseml:** Update the api * **gkehub:** Update the api * **iamcredentials:** Update the api * **identitytoolkit:** Update the api * **identitytoolkit:** Update the api * **integrations:** Update the api * **merchantapi:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **networkservices:** Update the api * **oracledatabase:** Update the api * **orgpolicy:** Update the api * **osconfig:** Update the api * **places:** Update the api * **places:** Update the api * **recaptchaenterprise:** Update the api * **recommender:** Update the api * **redis:** Update the api * **retail:** Update the api * **retail:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **securitycenter:** Update the api * **spanner:** Update the api * **spanner:** Update the api * **speech:** Update the api * **texttospeech:** Update the api * **tpu:** Update the api * **vmmigration:** Update the api * **walletobjects:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **youtube:** Update the api * **composer:** Update the api * **workspaceevents:** Update the api * from version 2.150.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **appengine:** Update the api * **apphub:** Update the api * **assuredworkloads:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **compute:** Update the api * **container:** Update the api * **datamigration:** Update the api * **drive:** Update the api * **firebaseml:** Update the api * **gkehub:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **playdeveloperreporting:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **workloadmanager:** Update the api * **youtube:** Update the api * **composer:** Update the api * **spanner:** Update the api * Update to version 2.149.0 * **androidpublisher:** Update the api * **apigee:** Update the api * **artifactregistry:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **bigquery:** Update the api * **chat:** Update the api * **clouddeploy:** Update the api * **container:** Update the api * **datamigration:** Update the api * **dataproc:** Update the api * **discoveryengine:** Update the api * **firebaseappdistribution:** Update the api * **firebaseml:** Update the api * **language:** Update the api * **merchantapi:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **run:** Update the api * **searchads360:** Update the api * **securitycenter:** Update the api * **texttospeech:** Update the api * **developerconnect:** Update the api * **factchecktools:** Update the api * from version 2.148.0 * **accesscontextmanager:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **androidmanagement:** Update the api * **artifactregistry:** Update the api * **assuredworkloads:** Update the api * **backupdr:** Update the api * **bigtableadmin:** Update the api * **clouddeploy:** Update the api * **cloudscheduler:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **developerconnect:** Update the api * **dfareporting:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **firebaseml:** Update the api * **integrations:** Update the api * **memcache:** Update the api * **merchantapi:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **networkservices:** Update the api * **pubsub:** Update the api * **redis:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **servicemanagement:** Update the api * **serviceusage:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **walletobjects:** Update the api * **bigquerydatatransfer:** Update the api * **bigqueryreservation:** Update the api * **places:** Update the api * **spanner:** Update the api * Update to version 2.147.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **androiddeviceprovisioning:** Update the api * **backupdr:** Update the api * **bigquerydatatransfer:** Update the api * **chromeuxreport:** Update the api * **composer:** Update the api * **compute:** Update the api * **connectors:** Update the api * **container:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **eventarc:** Update the api * **firebaseml:** Update the api * **integrations:** Update the api * **merchantapi:** Update the api * **networkmanagement:** Update the api * **networkservices:** Update the api * **places:** Update the api * **redis:** Update the api * **retail:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **servicenetworking:** Update the api * **spanner:** Update the api * **storage:** Update the api * **testing:** Update the api * **tpu:** Update the api * **walletobjects:** Update the api * **youtube:** Update the api * **androidpublisher:** Update the api * **cloudkms:** Update the api * from version 2.146.0 * **accesscontextmanager:** Update the api * **aiplatform:** Update the api * **apigee:** Update the api * **beyondcorp:** Update the api * **bigtableadmin:** Update the api * **civicinfo:** Update the api * **cloudchannel:** Update the api * **cloudfunctions:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **css:** Update the api * **datastream:** Update the api * **discoveryengine:** Update the api * **documentai:** Update the api * **firebaseml:** Update the api * **firebase:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **logging:** Update the api * **looker:** Update the api * **merchantapi:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **serviceconsumermanagement:** Update the api * **serviceusage:** Update the api * **vpcaccess:** Update the api * **walletobjects:** Update the api * **bigquery:** Update the api * **chat:** Update the api * **translate:** Update the api * Update to 2.143.0 * **accessapproval:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **assuredworkloads:** Update the api * **backupdr:** Update the api * **batch:** Update the api * **chat:** Update the api * **cloudasset:** Update the api * **cloudkms:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **customsearch:** Update the api * **dataflow:** Update the api * **dataplex:** Update the api * **dfareporting:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **firebasedynamiclinks:** Update the api * **firebaseml:** Update the api * **gkeonprem:** Update the api * **looker:** Update the api * **merchantapi:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networkmanagement:** Update the api * **networkservices:** Update the api * **notebooks:** Update the api * **redis:** Update the api * **searchads360:** Update the api * **servicenetworking:** Update the api * **solar:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **translate:** Update the api * **workflowexecutions:** Update the api * **workflows:** Update the api * **workstations:** Update the api * from version 2.142.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **androidpublisher:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **compute:** Update the api * **connectors:** Update the api * **container:** Update the api * **dataflow:** Update the api * **datamigration:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **dlp:** Update the api * **documentai:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **integrations:** Update the api * **manufacturers:** Update the api * **migrationcenter:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **recaptchaenterprise:** Update the api * **redis:** Update the api * **run:** Update the api * **searchads360:** Update the api * **securitycenter:** Update the api * **serviceusage:** Update the api * **spanner:** Update the api * **vmmigration:** Update the api * **youtube:** Update the api * from version 2.141.0 * **aiplatform:** Update the api * **androidmanagement:** Update the api * **assuredworkloads:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **bigquerydatapolicy:** Update the api * **bigquerydatatransfer:** Update the api * **bigquery:** Update the api * **certificatemanager:** Update the api * **cloudbuild:** Update the api * **cloudcontrolspartner:** Update the api * **clouddeploy:** Update the api * **compute:** Update the api * **connectors:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **domains:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **notebooks:** Update the api * **realtimebidding:** Update the api * **recaptchaenterprise:** Update the api * **retail:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **servicecontrol:** Update the api * **spanner:** Update the api * **storage:** Update the api * **vault:** Update the api * **walletobjects:** Update the api * **workstations:** Update the api * **cloudkms:** Update the api * **pubsub:** Update the api * **secretmanager:** Update the api * from version 2.140.0 * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **cloudchannel:** Update the api * **cloudfunctions:** Update the api * **compute:** Update the api * **containeranalysis:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **firebaseml:** Update the api * **healthcare:** Update the api * **merchantapi:** Update the api * **networkservices:** Update the api * **recaptchaenterprise:** Update the api * **sqladmin:** Update the api * **cloudkms:** Update the api * Update to 2.139.0 * **appengine:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **cloudbuild:** Update the api * **contactcenterinsights:** Update the api * **contentwarehouse:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dialogflow:** Update the api * **discovery:** Update the api * **dlp:** Update the api * **dns:** Update the api * **file:** Update the api * **firebaseappdistribution:** Update the api * **firebaseml:** Update the api * **merchantapi:** Update the api * **monitoring:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **playintegrity:** Update the api * **recaptchaenterprise:** Update the api * **walletobjects:** Update the api * **workloadmanager:** Update the api * from version 2.138.0 * Add support for reading apiVersion in discovery artifacts (#2380) * **aiplatform:** Update the api * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **analyticsadmin:** Update the api * **androidpublisher:** Update the api * **androidpublisher:** Update the api * **apim:** Update the api * **artifactregistry:** Update the api * **artifactregistry:** Update the api * **artifactregistry:** Update the api * **backupdr:** Update the api * **cloudbuild:** Update the api * **cloudbuild:** Update the api * **cloudcontrolspartner:** Update the api * **cloudsearch:** Update the api * **composer:** Update the api * **compute:** Update the api * **compute:** Update the api * **compute:** Update the api * **connectors:** Update the api * **connectors:** Update the api * **connectors:** Update the api * **container:** Update the api * **content:** Update the api * **dialogflow:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **discovery:** Update the api * **displayvideo:** Update the api * **docs:** Update the api * **documentai:** Update the api * **essentialcontacts:** Update the api * **essentialcontacts:** Update the api * **file:** Update the api * **file:** Update the api * **firebaseappdistribution:** Update the api * **firebaseappdistribution:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **iam:** Update the api * **iam:** Update the api * **integrations:** Update the api * **integrations:** Update the api * **logging:** Update the api * **logging:** Update the api * **manufacturers:** Update the api * **merchantapi:** Update the api * **merchantapi:** Update the api * **merchantapi:** Update the api * **metastore:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **networkservices:** Update the api * **networkservices:** Update the api * **ondemandscanning:** Update the api * **ondemandscanning:** Update the api * **playintegrity:** Update the api * **playintegrity:** Update the api * **recaptchaenterprise:** Update the api * **retail:** Update the api * **retail:** Update the api * **retail:** Update the api * **sheets:** Update the api * **spanner:** Update the api * **spanner:** Update the api * **spanner:** Update the api * **sqladmin:** Update the api * **sqladmin:** Update the api * **sts:** Update the api * **sts:** Update the api * **translate:** Update the api * **vmmigration:** Update the api * **walletobjects:** Update the api * **workflowexecutions:** Update the api * **workloadmanager:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **workstations:** Update the api * **workstations:** Update the api * **dataflow:** Update the api * **dlp:** Update the api * **dlp:** Update the api * Update to 2.137.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticsadmin:** Update the api * **assuredworkloads:** Update the api * **backupdr:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **cloudbuild:** Update the api * **clouderrorreporting:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **dataform:** Update the api * **datafusion:** Update the api * **dataplex:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **firebaseappcheck:** Update the api * **firebaseml:** Update the api * **games:** Update the api * **integrations:** Update the api * **pubsub:** Update the api * **run:** Update the api * **storage:** Update the api * **tagmanager:** Update the api * **vmmigration:** Update the api * **vmwareengine:** Update the api * **workloadmanager:** Update the api * **connectors:** Update the api * Adjust upstream source name in spec file * Update to 2.136.0 * **accesscontextmanager:** Update the api * **analyticshub:** Update the api * **beyondcorp:** Update the api * **bigquery:** Update the api * **chat:** Update the api * **cloudcontrolspartner:** Update the api * **compute:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **dataflow:** Update the api * **dialogflow:** Update the api * **displayvideo:** Update the api * **dlp:** Update the api * **file:** Update the api * **firebaseappdistribution:** Update the api * **gkehub:** Update the api * **logging:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **ondemandscanning:** Update the api * **policysimulator:** Update the api * **pubsub:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **tasks:** Update the api * **vault:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **factchecktools:** Update the api * from version 2.135.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **beyondcorp:** Update the api * **classroom:** Update the api * **containeranalysis:** Update the api * **datafusion:** Update the api * **dataproc:** Update the api * **dlp:** Update the api * **firestore:** Update the api * **games:** Update the api * **healthcare:** Update the api * **iap:** Update the api * **integrations:** Update the api * **jobs:** Update the api * **monitoring:** Update the api * **networkconnectivity:** Update the api * **securitycenter:** Update the api * **vmmigration:** Update the api * **walletobjects:** Update the api * **workloadmanager:** Update the api * **bigquerydatatransfer:** Update the api * **bigqueryreservation:** Update the api * from version 2.134.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **batch:** Update the api * **civicinfo:** Update the api * **cloudbuild:** Update the api * **cloudidentity:** Update the api * **cloudkms:** Update the api * **compute:** Update the api * **connectors:** Update the api * **dataform:** Update the api * **dataplex:** Update the api * **dfareporting:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **dlp:** Update the api * **domains:** Update the api * **file:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **kmsinventory:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **retail:** Update the api * **serviceconsumermanagement:** Update the api * **spanner:** Update the api * update to 2.133.0: * **accessapproval:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **androidmanagement:** Update the api * **bigqueryconnection:** Update the api * **bigquery:** Update the api * **clouddeploy:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dns:** Update the api * **domains:** Update the api * **games:** Update the api * **memcache:** Update the api * **networkconnectivity:** Update the api * **notebooks:** Update the api * **pubsub:** Update the api * **redis:** Update the api * **sqladmin:** Update the api * **vmmigration:** Update the api * update to 2.132.0: * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **androidmanagement:** Update the api * **backupdr:** Update the api * **chromemanagement:** Update the api * **cloudbilling:** Update the api * **cloudfunctions:** Update the api * **cloudsearch:** Update the api * **compute:** Update the api * **connectors:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **documentai:** Update the api * **fcmdata:** Update the api * **firebaseappcheck:** Update the api * **healthcare:** Update the api * **iam:** Update the api * **integrations:** Update the api * **migrationcenter:** Update the api * **networkconnectivity:** Update the api * **policyanalyzer:** Update the api * **resourcesettings:** Update the api * **run:** Update the api * **servicecontrol:** Update the api * **spanner:** Update the api * **versionhistory:** Update the api * **beyondcorp:** Update the api * **composer:** Update the api * **compute:** Update the api * **contactcenteraiplatform:** Update the api * **file:** Update the api * **firebaseml:** Update the api * **gkebackup:** Update the api * **gmail:** Update the api * **ids:** Update the api * **networkmanagement:** Update the api * **networkservices:** Update the api * **recaptchaenterprise:** Update the api * **redis:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **tasks:** Update the api * **workstations:** Update the api * **drive:** Update the api * **prod_tt_sasportal:** Update the api * **sasportal:** Update the api * **secretmanager:** Update the api * Update to 2.130.0 * **admin:** Update the api * **analyticsadmin:** Update the api * **analyticsdata:** Update the api * **androidpublisher:** Update the api * **artifactregistry:** Update the api * **backupdr:** Update the api * **chromemanagement:** Update the api * **cloudbuild:** Update the api * **clouddeploy:** Update the api * **cloudkms:** Update the api * **compute:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **containeranalysis:** Update the api * **content:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **fcmdata:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **integrations:** Update the api * **integrations:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **networkconnectivity:** Update the api * **orgpolicy:** Update the api * **osconfig:** Update the api * **pagespeedonline:** Update the api * **places:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **sqladmin:** Update the api * **walletobjects:** Update the api * **webfonts:** Update the api * **workflows:** Update the api * **youtube:** Update the api * from version 2.129.0 * **admin:** Update the api * **aiplatform:** Update the api * **apigee:** Update the api * **artifactregistry:** Update the api * **authorizedbuyersmarketplace:** Update the api * **cloudidentity:** Update the api * **cloudsearch:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **content:** Update the api * **dataform:** Update the api * **firebaseml:** Update the api * **firestore:** Update the api * **iam:** Update the api * **logging:** Update the api * **monitoring:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **playintegrity:** Update the api * **storagetransfer:** Update the api * **walletobjects:** Update the api * **workloadmanager:** Update the api * from version 2.128.0 * **accessapproval:** Update the api * **accesscontextmanager:** Update the api * **admin:** Update the api * **aiplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **alloydb:** Update the api * **androidmanagement:** Update the api * **artifactregistry:** Update the api * **artifactregistry:** Update the api * **baremetalsolution:** Update the api * **beyondcorp:** Update the api * **beyondcorp:** Update the api * **bigqueryconnection:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **chat:** Update the api * **cloudbuild:** Update the api * **clouddeploy:** Update the api * **cloudkms:** Update the api * **cloudsupport:** Update the api * **cloudsupport:** Update the api * **compute:** Update the api * **compute:** Update the api * **config:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **content:** Update the api * **contentwarehouse:** Update the api * **dataflow:** Update the api * **dataform:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **dns:** Update the api * **documentai:** Update the api * **doubleclickbidmanager:** Update the api * **eventarc:** Update the api * **firebaseappcheck:** Update the api * **firebaseml:** Update the api * **firebaseml:** Update the api * **games:** Update the api * **gkehub:** Update the api * **gmail:** Update the api * **iap:** Update the api * **integrations:** Update the api * **logging:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **ondemandscanning:** Update the api * **orgpolicy:** Update the api * **privateca:** Update the api * **redis:** Update the api * **retail:** Update the api * **run:** Update the api * **serviceconsumermanagement:** Update the api * **servicecontrol:** Update the api * **servicecontrol:** Update the api * **servicemanagement:** Update the api * **servicenetworking:** Update the api * **serviceusage:** Update the api * **sheets:** Update the api * **solar:** Update the api * **spanner:** Update the api * **sts:** Update the api * **youtube:** Update the api * **secretmanager:** Update the api * from version 2.127.0 * **aiplatform:** Update the api * **alertcenter:** Update the api * **alloydb:** Update the api * **analyticshub:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **apigee:** Update the api * **authorizedbuyersmarketplace:** Update the api * **backupdr:** Update the api * **beyondcorp:** Update the api * **chat:** Update the api * **cloudasset:** Update the api * **cloudbuild:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **contactcenterinsights:** Update the api * **content:** Update the api * **customsearch:** Update the api * **dataflow:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **displayvideo:** Update the api * **documentai:** Update the api * **firebaseml:** Update the api * **iam:** Update the api * **integrations:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **networkmanagement:** Update the api * **redis:** Update the api * **retail:** Update the api * **run:** Update the api * **serviceconsumermanagement:** Update the api * **servicecontrol:** Update the api * **tpu:** Update the api * **youtube:** Update the api * **logging:** Update the api * Disable two more tests that require internet connection * test_client_options_universe_configured_with_mtls * test_universe_env_var_configured_with_mtls * Update to 2.126.0 * **advisorynotifications:** Update the api * **aiplatform:** Update the api * **alertcenter:** Update the api * **analyticsadmin:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **cloudsupport:** Update the api * **compute:** Update the api * **compute:** Update the api * **container:** Update the api * **content:** Update the api * **content:** Update the api * **contentwarehouse:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **documentai:** Update the api * **integrations:** Update the api * **integrations:** Update the api * **marketingplatformadmin:** Update the api * **monitoring:** Update the api * **paymentsresellersubscription:** Update the api * **searchads360:** Update the api * **securitycenter:** Update the api * **trafficdirector:** Update the api * **verifiedaccess:** Update the api * **youtube:** Update the api * Added Added syntax highlighting to README (#2384) * **dataportability:** Update the api * **dataportability:** Update the api * from version 2.125.0 * **aiplatform:** Update the api * **alertcenter:** Update the api * **alloydb:** Update the api * **analyticsadmin:** Update the api * **apphub:** Update the api * **beyondcorp:** Update the api * **bigqueryconnection:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **chat:** Update the api * **compute:** Update the api * **content:** Update the api * **contentwarehouse:** Update the api * **customsearch:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discovery:** Update the api * **domains:** Update the api * **factchecktools:** Update the api * **firestore:** Update the api * **gkebackup:** Update the api * **gkehub:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **orgpolicy:** Update the api * **pubsub:** Update the api * **recaptchaenterprise:** Update the api * **redis:** Update the api * **retail:** Update the api * **run:** Update the api * **servicecontrol:** Update the api * **spanner:** Update the api * **sqladmin:** Update the api * **workstations:** Update the api * from version 2.124.0 * Add support to validate credentials for configured universe (#2362) * **adsense:** Update the api * **aiplatform:** Update the api * Allow users to configure client option `universe_domain` (#2368) * Allow users to configure universe environment variable (#2369) * **alloydb:** Update the api * **androidpublisher:** Update the api * **apigee:** Update the api * **bigqueryreservation:** Update the api * **bigtableadmin:** Update the api * **certificatemanager:** Update the api * **cloudsupport:** Update the api * **compute:** Update the api * **connectors:** Update the api * **container:** Update the api * **customsearch:** Update the api * **datacatalog:** Update the api * **dataproc:** Update the api * **datastore:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **iam:** Update the api * **identitytoolkit:** Update the api * **metastore:** Update the api * **redis:** Update the api * **secretmanager:** Update the api * **sqladmin:** Update the api * **testing:** Update the api * Validate credentials for universe before request (#2367) * **workloadmanager:** Update the api * **dataflow:** Update the api * **dataportability:** Update the api * **deps:** Require google-auth-httplib2 >= 0.2.0 (727c073) * **deps:** Require google-auth>=1.32.0 (727c073) * **deps:** Require httplib2>=0.19.0 (727c073) * **storage:** Update the api * from version 2.123.0 * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticsadmin:** Update the api * **analyticshub:** Update the api * **bigtableadmin:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **cloudbilling:** Update the api * **cloudbuild:** Update the api * **cloudidentity:** Update the api * **compute:** Update the api * **content:** Update the api * **datacatalog:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **documentai:** Update the api * **firestore:** Update the api * **iam:** Update the api * **integrations:** Update the api * **logging:** Update the api * **networkmanagement:** Update the api * **osconfig:** Update the api * **redis:** Update the api * **run:** Update the api * **secretmanager:** Update the api * **spanner:** Update the api * **storagetransfer:** Update the api * **storage:** Update the api * **sts:** Update the api * **tasks:** Update the api * **dataproc:** Update the api * **people:** Update the api * from version 2.122.0 * **admin:** Update the api * **adsense:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **artifactregistry:** Update the api * **beyondcorp:** Update the api * **bigquerydatatransfer:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **cloudbilling:** Update the api * **cloudbuild:** Update the api * **compute:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **content:** Update the api * **dataform:** Update the api * **dataplex:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **file:** Update the api * **gkehub:** Update the api * **language:** Update the api * **looker:** Update the api * **networksecurity:** Update the api * **places:** Update the api * **playdeveloperreporting:** Update the api * **run:** Update the api * **secretmanager:** Update the api * **serviceusage:** Update the api * **slides:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **vault:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **youtube:** Update the api * **dataflow:** Update the api * **logging:** Update the api * **workspaceevents:** Update the api * from version 2.121.0 * **alloydb:** Update the api * **apigee:** Update the api * **appengine:** Update the api * **apphub:** Update the api * **authorizedbuyersmarketplace:** Update the api * **chromemanagement:** Update the api * **cloudbuild:** Update the api * **clouddeploy:** Update the api * **cloudresourcemanager:** Update the api * **composer:** Update the api * **container:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **dns:** Update the api * **documentai:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **logging:** Update the api * **metastore:** Update the api * **networkmanagement:** Update the api * **policysimulator:** Update the api * **redis:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **servicecontrol:** Update the api * **storagetransfer:** Update the api * **vmmigration:** Update the api * **youtube:** Update the api * **dataportability:** Update the api * **pubsub:** Update the api * from version 2.12.0 * **admin:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **analyticshub:** Update the api * **apigee:** Update the api * **appengine:** Update the api * **bigtableadmin:** Update the api * **binaryauthorization:** Update the api * **cloudprofiler:** Update the api * **compute:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **datacatalog:** Update the api * **dataflow:** Update the api * **dataplex:** Update the api * **datastore:** Update the api * **dialogflow:** Update the api * **displayvideo:** Update the api * **firestore:** Update the api * **language:** Update the api * **logging:** Update the api * **looker:** Update the api * **metastore:** Update the api * **networkconnectivity:** Update the api * **paymentsresellersubscription:** Update the api * **places:** Update the api * **policysimulator:** Update the api * **privateca:** Update the api * **serviceusage:** Update the api * **storagetransfer:** Update the api * **youtube:** Update the api * **bigqueryreservation:** Update the api * **cloudkms:** Update the api * from version 2.119.0 * **aiplatform:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **appengine:** Update the api * **apphub:** Update the api * **binaryauthorization:** Update the api * **blockchainnodeengine:** Update the api * **books:** Update the api * **certificatemanager:** Update the api * **connectors:** Update the api * **container:** Update the api * **datacatalog:** Update the api * **dataproc:** Update the api * **datastore:** Update the api * **datastream:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **language:** Update the api * **localservices:** Update the api * **networkservices:** Update the api * **securitycenter:** Update the api * **storage:** Update the api * **testing:** Update the api * **transcoder:** Update the api * **walletobjects:** Update the api * **workspaceevents:** Update the api * **youtube:** Update the api * from version 2.118.0 * **aiplatform:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **bigquery:** Update the api * **cloudbuild:** Update the api * **cloudfunctions:** Update the api * **composer:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **dataform:** Update the api * **dataplex:** Update the api * **datastore:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **firestore:** Update the api * **healthcare:** Update the api * **networkmanagement:** Update the api * **recaptchaenterprise:** Update the api * **retail:** Update the api * **searchads360:** Update the api * **spanner:** Update the api * **sqladmin:** Update the api * **storage:** Update the api * **testing:** Update the api * **tpu:** Update the api * **trafficdirector:** Update the api * **workloadmanager:** Update the api * **run:** Update the api * **youtube:** Update the api * from version 2.117.0 * **alertcenter:** Update the api * **androidmanagement:** Update the api * **apphub:** Update the api * **bigquerydatatransfer:** Update the api * **blockchainnodeengine:** Update the api * **cloudbuild:** Update the api * **cloudidentity:** Update the api * **cloudsupport:** Update the api * **composer:** Update the api * **compute:** Update the api * **container:** Update the api * **dfareporting:** Update the api * **discoveryengine:** Update the api * **gkeonprem:** Update the api * **integrations:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **paymentsresellersubscription:** Update the api * **pubsub:** Update the api * **run:** Update the api * **sasportal:** Update the api * **secretmanager:** Update the api * **securitycenter:** Update the api * **spanner:** Update the api * **storagetransfer:** Update the api * **storage:** Update the api * **tpu:** Update the api * **transcoder:** Update the api * **walletobjects:** Update the api * **workstations:** Update the api * **admin:** Update the api * Update BuildRequires and Requires from setup.py * update to 2.116.0: * **aiplatform:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **artifactregistry:** Update the api * **bigqueryconnection:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **blockchainnodeengine:** Update the api * **cloudasset:** Update the api * **clouddeploy:** Update the api * **container:** Update the api * **content:** Update the api * **dataflow:** Update the api * **dataform:** Update the api * **datastore:** Update the api * **displayvideo:** Update the api * **drive:** Update the api * **firebaseappcheck:** Update the api * **firestore:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networkmanagement:** Update the api * **recommender:** Update the api * **retail:** Update the api * **spanner:** Update the api * **sqladmin:** Update the api * **workflowexecutions:** Update the api * **workloadmanager:** Update the api * **youtube:** Update the api * Update to 2.115.0 * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **apigee:** Update the api * **apphub:** Update the api * **cloudsupport:** Update the api * **compute:** Update the api * **connectors:** Update the api * **dataflow:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **documentai:** Update the api * **gkehub:** Update the api * **logging:** Update the api * **monitoring:** Update the api * **notebooks:** Update the api * **policysimulator:** Update the api * **prod_tt_sasportal:** Update the api * **recaptchaenterprise:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **tpu:** Update the api * **vmwareengine:** Update the api * update to 2.114.0: * **aiplatform:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **androidpublisher:** Update the api * **batch:** Update the api * **bigquery:** Update the api * **blockchainnodeengine:** Update the api * **chat:** Update the api * **chromepolicy:** Update the api * **clouddeploy:** Update the api * **cloudfunctions:** Update the api * **composer:** Update the api * **compute:** Update the api * **compute:** Update the api * **contactcenteraiplatform:** Update the api * **dataflow:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **integrations:** Update the api * **logging:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **prod_tt_sasportal:** Update the api * **recommender:** Update the api * **retail:** Update the api * **sasportal:** Update the api * **securitycenter:** Update the api * **speech:** Update the api * **storage:** Update the api * **texttospeech:** Update the api * **toolresults:** Update the api * **vmwareengine:** Update the api * **walletobjects:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * Removed indent from discovery cache json files (#2099) (0a28454), closes #1967 * update to 2.113.0: * **androidmanagement:** Update the api * **batch:** Update the api * **bigtableadmin:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **content:** Update the api * **customsearch:** Update the api * **displayvideo:** Update the api * **firestore:** Update the api * **script:** Update the api * update to 2.112.0: * **accesscontextmanager:** Update the api * **admin:** Update the api * **aiplatform:** Update the api * **alloydb:** Update the api * **apigee:** Update the api * **artifactregistry:** Update the api * **backupdr:** Update the api * **chat:** Update the api * **checks:** Update the api * **chromepolicy:** Update the api * **chromeuxreport:** Update the api * **cloudbuild:** Update the api * **cloudchannel:** Update the api * **cloudfunctions:** Update the api * **cloudprofiler:** Update the api * **cloudsupport:** Update the api * **connectors:** Update the api * **container:** Update the api * **dataflow:** Update the api * **dataform:** Update the api * **dataproc:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **drivelabels:** Update the api * **firebaseappdistribution:** Update the api * **gkehub:** Update the api * **gmail:** Update the api * **healthcare:** Update the api * **integrations:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networkmanagement:** Update the api * **networkservices:** Update the api * **oslogin:** Update the api * **playintegrity:** Update the api * **prod_tt_sasportal:** Update the api * **retail:** Update the api * **run:** Update the api * **sasportal:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **vault:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * update to 2.111.0: * Add support for Python 3.12 (#2288) * **aiplatform:** Update the api * **alloydb:** Update the api * **androidpublisher:** Update the api * **baremetalsolution:** Update the api * **batch:** Update the api * **bigquery:** Update the api * **cloudbilling:** Update the api * **clouddeploy:** Update the api * **connectors:** Update the api * **container:** Update the api * **datacatalog:** Update the api * **dataflow:** Update the api * **dns:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **metastore:** Update the api * **monitoring:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **networkservices:** Update the api * **playdeveloperreporting:** Update the api * **pubsub:** Update the api * **script:** Update the api * **securitycenter:** Update the api * **vpcaccess:** Update the api * Replace deprecated utcnow, utcfromtimestamp (#2286) * Remove pandas from the BuildRequires. It's not really needed. * Update to 2.103.0 * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **analyticshub:** Update the api * **androidmanagement:** Update the api * **batch:** Update the api * **beyondcorp:** Update the api * **bigqueryreservation:** Update the api * **binaryauthorization:** Update the api * **chromepolicy:** Update the api * **cloudtasks:** Update the api * **composer:** Update the api * **compute:** Update the api * **container:** Update the api * **contentwarehouse:** Update the api * **dataflow:** Update the api * **datalabeling:** Update the api * **dataproc:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **docs:** Update the api * **eventarc:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **gmail:** Update the api * **healthcare:** Update the api * **iap:** Update the api * **integrations:** Update the api * **metastore:** Update the api * **ondemandscanning:** Update the api * **oslogin:** Update the api * **recaptchaenterprise:** Update the api * **recommender:** Update the api * **run:** Update the api * **sasportal:** Update the api * **securitycenter:** Update the api * **youtube:** Update the api * **artifactregistry:** Update the api * from version 2.102.0 * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **androidmanagement:** Update the api * **apigeeregistry:** Update the api * **apigee:** Update the api * **baremetalsolution:** Update the api * **blockchainnodeengine:** Update the api * **chat:** Update the api * **chromepolicy:** Update the api * **cloudasset:** Update the api * **cloudbuild:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **contentwarehouse:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **documentai:** Update the api * **gkebackup:** Update the api * **gkeonprem:** Update the api * **gmail:** Update the api * **integrations:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networkservices:** Update the api * **places:** Update the api * **redis:** Update the api * **run:** Update the api * **securitycenter:** Update the api * **storage:** Update the api * **tagmanager:** Update the api * **androidpublisher:** Update the api * **appengine:** Update the api * **healthcare:** Update the api * **translate:** Update the api * from version 2.101.0 * **accessapproval:** Update the api * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **batch:** Update the api * **chat:** Update the api * **clouddeploy:** Update the api * **composer:** Update the api * **compute:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **content:** Update the api * **contentwarehouse:** Update the api * **dataform:** Update the api * **dataproc:** Update the api * **discoveryengine:** Update the api * **documentai:** Update the api * **eventarc:** Update the api * **firebase:** Update the api * **gkehub:** Update the api * **gmail:** Update the api * **healthcare:** Update the api * **iam:** Update the api * **logging:** Update the api * **networksecurity:** Update the api * **paymentsresellersubscription:** Update the api * **policysimulator:** Update the api * **prod_tt_sasportal:** Update the api * **recaptchaenterprise:** Update the api * **run:** Update the api * **vision:** Update the api * **vmmigration:** Update the api * from version 2.100.0 * **accesscontextmanager:** Update the api * **advisorynotifications:** Update the api * **aiplatform:** Update the api * **androidmanagement:** Update the api * **appengine:** Update the api * **artifactregistry:** Update the api * **assuredworkloads:** Update the api * **beyondcorp:** Update the api * **blockchainnodeengine:** Update the api * **checks:** Update the api * **chromemanagement:** Update the api * **cloudasset:** Update the api * **cloudfunctions:** Update the api * **cloudtasks:** Update the api * **composer:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **datamigration:** Update the api * **gkeonprem:** Update the api * **gmail:** Update the api * **integrations:** Update the api * **monitoring:** Update the api * **mybusinessverifications:** Update the api * **networkconnectivity:** Update the api * **networkmanagement:** Update the api * **notebooks:** Update the api * **paymentsresellersubscription:** Update the api * **places:** Update the api * **run:** Update the api * **spanner:** Update the api * **storage:** Update the api * **transcoder:** Update the api * **vision:** Update the api * **smartdevicemanagement:** Update the api * from version 2.99.0 * **artifactregistry:** Update the api * **assuredworkloads:** Update the api * **beyondcorp:** Update the api * **checks:** Update the api * **chromemanagement:** Update the api * **cloudasset:** Update the api * **cloudbuild:** Update the api * **cloudchannel:** Update the api * **clouddeploy:** Update the api * **compute:** Update the api * **contentwarehouse:** Update the api * **dataflow:** Update the api * **datalineage:** Update the api * **dataproc:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **firebasehosting:** Update the api * **firebase:** Update the api * **firestore:** Update the api * **games:** Update the api * **gkehub:** Update the api * **gmailpostmastertools:** Update the api * **iap:** Update the api * **jobs:** Update the api * **memcache:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **networkconnectivity:** Update the api * **osconfig:** Update the api * **oslogin:** Update the api * **places:** Update the api * **playintegrity:** Update the api * **redis:** Update the api * **speech:** Update the api * **storage:** Update the api * **vmmigration:** Update the api * **workflowexecutions:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * from version 2.98.0 * **admin:** Update the api * **admob:** Update the api * **admob:** Update the api * **aiplatform:** Update the api * **alertcenter:** Update the api * **analyticsadmin:** Update the api * **androiddeviceprovisioning:** Update the api * **androidpublisher:** Update the api * **apigee:** Update the api * **assuredworkloads:** Update the api * **baremetalsolution:** Update the api * **baremetalsolution:** Update the api * **bigquery:** Update the api * **billingbudgets:** Update the api * **checks:** Update the api * **checks:** Update the api * **chromemanagement:** Update the api * **chromemanagement:** Update the api * **cloudbilling:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **content:** Update the api * **content:** Update the api * **datacatalog:** Update the api * **datalineage:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **deploymentmanager:** Update the api * **deploymentmanager:** Update the api * **dialogflow:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **documentai:** Update the api * **firebaseappcheck:** Update the api * **firebasehosting:** Update the api * **firebasestorage:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **manufacturers:** Update the api * **monitoring:** Update the api * **networkconnectivity:** Update the api * **networkservices:** Update the api * **paymentsresellersubscription:** Update the api * **places:** Update the api * **policysimulator:** Update the api * **privateca:** Update the api * **prod_tt_sasportal:** Update the api * **pubsub:** Update the api * **retail:** Update the api * **sasportal:** Update the api * **searchads360:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **serviceusage:** Update the api * **sqladmin:** Update the api * **storagetransfer:** Update the api * **testing:** Update the api * **testing:** Update the api * **tpu:** Update the api * **verifiedaccess:** Update the api * **vmmigration:** Update the api * **vmmigration:** Update the api * **youtube:** Update the api * **youtube:** Update the api * Update to 2.97.0 * **adexperiencereport:** Update the api * **aiplatform:** Update the api * **analyticsadmin:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **appengine:** Update the api * **artifactregistry:** Update the api * **assuredworkloads:** Update the api * **baremetalsolution:** Update the api * **beyondcorp:** Update the api * **bigquery:** Update the api * **binaryauthorization:** Update the api * **cloudbuild:** Update the api * **composer:** Update the api * **connectors:** Update the api * **container:** Update the api * **contentwarehouse:** Update the api * **dataform:** Update the api * **dataproc:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **documentai:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **identitytoolkit:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networkmanagement:** Update the api * **paymentsresellersubscription:** Update the api * **redis:** Update the api * **run:** Update the api * **tagmanager:** Update the api * **vmmigration:** Update the api * from version 2.96.0 * **admin:** Update the api * **analyticsadmin:** Update the api * **analyticshub:** Update the api * **androidmanagement:** Update the api * **artifactregistry:** Update the api * **assuredworkloads:** Update the api * **beyondcorp:** Update the api * **bigquerydatatransfer:** Update the api * **chat:** Update the api * **checks:** Update the api * **cloudbuild:** Update the api * **clouddeploy:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **container:** Update the api * **content:** Update the api * **content:** Update the api * **contentwarehouse:** Update the api * **dataflow:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **datastore:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **displayvideo:** Update the api * **documentai:** Update the api * **drivelabels:** Update the api * **firebase:** Update the api * **firestore:** Update the api * **gkebackup:** Update the api * **gkehub:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **healthcare:** Update the api * **integrations:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networkconnectivity:** Update the api * **networkconnectivity:** Update the api * **notebooks:** Update the api * **osconfig:** Update the api * **oslogin:** Update the api * **places:** Update the api * **policysimulator:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **servicecontrol:** Update the api * **servicemanagement:** Update the api * **servicenetworking:** Update the api * **servicenetworking:** Update the api * **serviceusage:** Update the api * **smartdevicemanagement:** Update the api * **toolresults:** Update the api * **tpu:** Update the api * **verifiedaccess:** Update the api * **youtube:** Update the api * **places:** Update the api * from version 2.95.0 * **apigee:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **checks:** Update the api * **cloudbuild:** Update the api * **clouddeploy:** Update the api * **cloudfunctions:** Update the api * **compute:** Update the api * **containeranalysis:** Update the api * **datacatalog:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **documentai:** Update the api * **drive:** Update the api * **firebaseappcheck:** Update the api * **firestore:** Update the api * **gkeonprem:** Update the api * **healthcare:** Update the api * **monitoring:** Update the api * **networksecurity:** Update the api * **ondemandscanning:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **servicedirectory:** Update the api * **servicenetworking:** Update the api * **serviceusage:** Update the api * **sheets:** Update the api * **sqladmin:** Update the api * **tpu:** Update the api * **trafficdirector:** Update the api * **translate:** Update the api * **vault:** Update the api * **verifiedaccess:** Update the api * **videointelligence:** Update the api * **vmmigration:** Update the api * **workloadmanager:** Update the api * from version 2.94.0 * **analyticsdata:** Update the api * **androidenterprise:** Update the api * **androidpublisher:** Update the api * **appengine:** Update the api * **artifactregistry:** Update the api * **assuredworkloads:** Update the api * **baremetalsolution:** Update the api * **batch:** Update the api * **bigquery:** Update the api * **chat:** Update the api * **checks:** Update the api * **classroom:** Update the api * **cloudasset:** Update the api * **cloudbilling:** Update the api * **clouddebugger:** Update the api * **compute:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **content:** Update the api * **contentwarehouse:** Update the api * **datacatalog:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **discovery:** Update the api * **documentai:** Update the api * **doubleclickbidmanager:** Update the api * **drive:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **homegraph:** Update the api * **iam:** Update the api * **identitytoolkit:** Update the api * **integrations:** Update the api * **lifesciences:** Update the api * **logging:** Update the api * **memcache:** Update the api * **networkmanagement:** Update the api * **networksecurity:** Update the api * **notebooks:** Update the api * **ondemandscanning:** Update the api * **pubsublite:** Update the api * **pubsub:** Update the api * **sasportal:** Update the api * **securitycenter:** Update the api * **servicecontrol:** Update the api * **servicemanagement:** Update the api * **serviceusage:** Update the api * **slides:** Update the api * **speech:** Update the api * **sqladmin:** Update the api * **tpu:** Update the api * **verifiedaccess:** Update the api * **vision:** Update the api * **youtube:** Update the api * **smartdevicemanagement:** Update the api * Update to 2.93.0 * **adexchangebuyer2:** Update the api * **analyticshub:** Update the api * **androidmanagement:** Update the api * **apigee:** Update the api * **bigquerydatatransfer:** Update the api * **chat:** Update the api * **cloudchannel:** Update the api * **cloudidentity:** Update the api * **cloudscheduler:** Update the api * **cloudsearch:** Update the api * **cloudsupport:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **content:** Update the api * **dataflow:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **dlp:** Update the api * **dns:** Update the api * **driveactivity:** Update the api * **gkeonprem:** Update the api * **gmail:** Update the api * **healthcare:** Update the api * **identitytoolkit:** Update the api * **jobs:** Update the api * **kmsinventory:** Update the api * **managedidentities:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networkmanagement:** Update the api * **notebooks:** Update the api * **orgpolicy:** Update the api * **pagespeedonline:** Update the api * **prod_tt_sasportal:** Update the api * **realtimebidding:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **serviceusage:** Update the api * **tagmanager:** Update the api * **testing:** Update the api * **websecurityscanner:** Update the api * **workloadmanager:** Update the api * **youtube:** Update the api * from version 2.92.0 * **analyticshub:** Update the api * **androidenterprise:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **apigateway:** Update the api * **apigee:** Update the api * **artifactregistry:** Update the api * **assuredworkloads:** Update the api * **baremetalsolution:** Update the api * **batch:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **civicinfo:** Update the api * **cloudfunctions:** Update the api * **cloudkms:** Update the api * **cloudsupport:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **container:** Update the api * **content:** Update the api * **contentwarehouse:** Update the api * **dataform:** Update the api * **datafusion:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **displayvideo:** Update the api * **eventarc:** Update the api * **fcm:** Update the api * **file:** Update the api * **firebaseappcheck:** Update the api * **firebaseappdistribution:** Update the api * **firebasedynamiclinks:** Update the api * **firebase:** Update the api * **firestore:** Update the api * **fitness:** Update the api * **gkehub:** Update the api * **gmailpostmastertools:** Update the api * **iam:** Update the api * **memcache:** Update the api * **metastore:** Update the api * **mybusinesslodging:** Update the api * **networkconnectivity:** Update the api * **osconfig:** Update the api * **recaptchaenterprise:** Update the api * **run:** Update the api * **sasportal:** Update the api * **searchads360:** Update the api * **searchconsole:** Update the api * **servicenetworking:** Update the api * **sqladmin:** Update the api * **streetviewpublish:** Update the api * **toolresults:** Update the api * **transcoder:** Update the api * **vmmigration:** Update the api * **workloadmanager:** Update the api * **youtubeAnalytics:** Update the api * **youtubereporting:** Update the api * from version 2.91.0 * **analyticsadmin:** Update the api * **artifactregistry:** Update the api * **beyondcorp:** Update the api * **chat:** Update the api * **cloudfunctions:** Update the api * **cloudresourcemanager:** Update the api * **compute:** Update the api * **contactcenteraiplatform:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dfareporting:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **documentai:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **migrationcenter:** Update the api * **networkconnectivity:** Update the api * **networkservices:** Update the api * **notebooks:** Update the api * **people:** Update the api * **privateca:** Update the api * **prod_tt_sasportal:** Update the api * **redis:** Update the api * **securitycenter:** Update the api * **servicedirectory:** Update the api * **tpu:** Update the api * **workflows:** Update the api * **workstations:** Update the api * from version 2.90.0 * **androidpublisher:** Update the api * **baremetalsolution:** Update the api * **batch:** Update the api * **beyondcorp:** Update the api * **calendar:** Update the api * **chat:** Update the api * **civicinfo:** Update the api * **cloudasset:** Update the api * **cloudbilling:** Update the api * **cloudchannel:** Update the api * **clouddebugger:** Update the api * **clouddeploy:** Update the api * **cloudfunctions:** Update the api * **cloudidentity:** Update the api * **cloudsearch:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **container:** Update the api * **content:** Update the api * **contentwarehouse:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **displayvideo:** Update the api * **eventarc:** Update the api * **firebaseappcheck:** Update the api * **gkebackup:** Update the api * **gkehub:** Update the api * **gkeonprem:** Update the api * **gmail:** Update the api * **identitytoolkit:** Update the api * **integrations:** Update the api * **logging:** Update the api * **migrationcenter:** Update the api * **networkmanagement:** Update the api * **prod_tt_sasportal:** Update the api * **pubsub:** Update the api * **recommender:** Update the api * **reseller:** Update the api * **retail:** Update the api * **run:** Update the api * **sasportal:** Update the api * **serviceusage:** Update the api * **spanner:** Update the api * **sqladmin:** Update the api * **tagmanager:** Update the api * **transcoder:** Update the api * **workflowexecutions:** Update the api * **workloadmanager:** Update the api * Add %{?sle15_python_module_pythons} * Update to 2.89.0 * **androidmanagement:** Update the api * **apigee:** Update the api * **appengine:** Update the api * **billingbudgets:** Update the api * **cloudidentity:** Update the api * **cloudsearch:** Update the api * **compute:** Update the api * **connectors:** Update the api * **container:** Update the api * **contentwarehouse:** Update the api * **datacatalog:** Update the api * **dataplex:** Update the api * **dialogflow:** Update the api * **documentai:** Update the api * **firebaseappcheck:** Update the api * **firestore:** Update the api * **healthcare:** Update the api * **iam:** Update the api * **iap:** Update the api * **integrations:** Update the api * **language:** Update the api * **manufacturers:** Update the api * **metastore:** Update the api * **mybusinessbusinessinformation:** Update the api * **networkconnectivity:** Update the api * **paymentsresellersubscription:** Update the api * **securitycenter:** Update the api * **servicemanagement:** Update the api * **sqladmin:** Update the api * **streetviewpublish:** Update the api * **testing:** Update the api * **verifiedaccess:** Update the api * Remove faulty version matcher in setup.py (#2152), closes (#2151) * from version 2.88.0 * **baremetalsolution:** Update the api * **beyondcorp:** Update the api * **beyondcorp:** Update the api * **bigqueryreservation:** Update the api * **cloudidentity:** Update the api * **container:** Update the api * **dataflow:** Update the api * **datastream:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **drive:** Update the api * **firebaseappcheck:** Update the api * **gkeonprem:** Update the api * **integrations:** Update the api * **logging:** Update the api * **ondemandscanning:** Update the api * from version 2.87.0 * **accessapproval:** Update the api * **alertcenter:** Update the api * **analyticsadmin:** Update the api * **analyticshub:** Update the api * **androiddeviceprovisioning:** Update the api * **androidmanagement:** Update the api * **androidpublisher:** Update the api * **apigee:** Update the api * **artifactregistry:** Update the api * **assuredworkloads:** Update the api * **batch:** Update the api * **beyondcorp:** Update the api * **bigquerydatatransfer:** Update the api * **bigqueryreservation:** Update the api * **bigquery:** Update the api * **bigtableadmin:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **cloudasset:** Update the api * **cloudbuild:** Update the api * **cloudchannel:** Update the api * **clouddeploy:** Update the api * **cloudfunctions:** Update the api * **cloudresourcemanager:** Update the api * **cloudsearch:** Update the api * **cloudtasks:** Update the api * **composer:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **content:** Update the api * **contentwarehouse:** Update the api * **datacatalog:** Update the api * **dataflow:** Update the api * **dataform:** Update the api * **datafusion:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **datastream:** Update the api * **dfareporting:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **documentai:** Update the api * **drive:** Update the api * **fcm:** Update the api * **file:** Update the api * **firebaseappcheck:** Update the api * **firebaseappdistribution:** Update the api * **firebasehosting:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **iam:** Update the api * **identitytoolkit:** Update the api * **integrations:** Update the api * **managedidentities:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **networkconnectivity:** Update the api * **networksecurity:** Update the api * **networkservices:** Update the api * **ondemandscanning:** Update the api * **osconfig:** Update the api * **paymentsresellersubscription:** Update the api * **playdeveloperreporting:** Update the api * **playintegrity:** Update the api * **privateca:** Update the api * **pubsub:** Update the api * **recaptchaenterprise:** Update the api * **retail:** Update the api * **run:** Update the api * **script:** Update the api * **searchads360:** Update the api * **securitycenter:** Update the api * **serviceusage:** Update the api * **spanner:** Update the api * **speech:** Update the api * **sqladmin:** Update the api * **storagetransfer:** Update the api * **streetviewpublish:** Update the api * **testing:** Update the api * **tpu:** Update the api * **translate:** Update the api * **verifiedaccess:** Update the api * **vmmigration:** Update the api * **webfonts:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * **youtube:** Update the api * Dead link to WebTest fixed in README. (#2127) (39e19d6) * Update to 2.86.0 * **analyticsadmin:** Update the api * **apigee:** Update the api * **assuredworkloads:** Update the api * **beyondcorp:** Update the api * **bigquery:** Update the api * **certificatemanager:** Update the api * **chromemanagement:** Update the api * **cloudbuild:** Update the api * **cloudfunctions:** Update the api * **cloudkms:** Update the api * **cloudresourcemanager:** Update the api * **compute:** Update the api * **container:** Update the api * **contentwarehouse:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **discoveryengine:** Update the api * **file:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **identitytoolkit:** Update the api * **integrations:** Update the api * **managedidentities:** Update the api * **networksecurity:** Update the api * **retail:** Update the api * **run:** Update the api * **sqladmin:** Update the api * **tpu:** Update the api * **vault:** Update the api * **workloadmanager:** Update the api * **workstations:** Update the api * from version 2.85.0 * **adexperiencereport:** Update the api * **analyticsadmin:** Update the api * **androidpublisher:** Update the api * **assuredworkloads:** Update the api * **batch:** Update the api * **cloudresourcemanager:** Update the api * **cloudsupport:** Update the api * **compute:** Update the api * **connectors:** Update the api * **container:** Update the api * **contentwarehouse:** Update the api * **networkservices:** Update the api * **privateca:** Update the api * **recaptchaenterprise:** Update the api * **retail:** Update the api * **searchads360:** Update the api * **securitycenter:** Update the api * **servicemanagement:** Update the api * **serviceusage:** Update the api * **spanner:** Update the api * **tagmanager:** Update the api * **translate:** Update the api * **vmmigration:** Update the api * **workflowexecutions:** Update the api * **workflows:** Update the api * from version 2.84.0 * **advisorynotifications:** Update the api * **chromepolicy:** Update the api * **civicinfo:** Update the api * **cloudsearch:** Update the api * **cloudsupport:** Update the api * **compute:** Update the api * **contactcenterinsights:** Update the api * **containeranalysis:** Update the api * **container:** Update the api * **content:** Update the api * **datamigration:** Update the api * **dialogflow:** Update the api * **drivelabels:** Update the api * **file:** Update the api * **healthcare:** Update the api * **migrationcenter:** Update the api * **networkservices:** Update the api * **ondemandscanning:** Update the api * **playdeveloperreporting:** Update the api * **policysimulator:** Update the api * **recaptchaenterprise:** Update the api * **searchads360:** Update the api * **securitycenter:** Update the api * **serviceconsumermanagement:** Update the api * **servicenetworking:** Update the api * **serviceusage:** Update the api * **tpu:** Update the api * **transcoder:** Update the api * **translate:** Update the api * **vmmigration:** Update the api * **workflows:** Update the api * from version 2.83.0 * **analyticshub:** Update the api * **appengine:** Update the api * **bigqueryreservation:** Update the api * **bigquery:** Update the api * **cloudchannel:** Update the api * **clouddeploy:** Update the api * **cloudidentity:** Update the api * **composer:** Update the api * **connectors:** Update the api * **contentwarehouse:** Update the api * **datacatalog:** Update the api * **dataflow:** Update the api * **datafusion:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **dfareporting:** Update the api * **discoveryengine:** Update the api * **dlp:** Update the api * **drivelabels:** Update the api * **eventarc:** Update the api * **gkehub:** Update the api * **iam:** Update the api * **identitytoolkit:** Update the api * **metastore:** Update the api * **migrationcenter:** Update the api * **monitoring:** Update the api * **networksecurity:** Update the api * **playdeveloperreporting:** Update the api * **recaptchaenterprise:** Update the api * **retail:** Update the api * **securitycenter:** Update the api * **servicedirectory:** Update the api * **vmmigration:** Update the api * update to 2.82.0: * **analyticsadmin:** Update the api * **androiddeviceprovisioning:** Update the api * **assuredworkloads:** Update the api * **calendar:** Update the api * **chromepolicy:** Update the api * **clouddeploy:** Update the api * **compute:** Update the api * **connectors:** Update the api * **contactcenteraiplatform:** Update the api * **contactcenterinsights:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **discoveryengine:** Update the api * **drivelabels:** Update the api * **firestore:** Update the api * **metastore:** Update the api * **networkservices:** Update the api * **ondemandscanning:** Update the api * **orgpolicy:** Update the api * **playdeveloperreporting:** Update the api * **prod_tt_sasportal:** Update the api * **retail:** Update the api * **storage:** Update the api * **webrisk:** Update the api * Update to version 2.80.0 * **analyticsadmin:** Update the api * **analyticshub:** Update the api * **bigquery:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **chromepolicy:** Update the api * **cloudchannel:** Update the api * **cloudfunctions:** Update the api * **cloudsearch:** Update the api * **compute:** Update the api * **connectors:** Update the api * **containeranalysis:** Update the api * **contentwarehouse:** Update the api * **datamigration:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **dialogflow:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **identitytoolkit:** Update the api * **logging:** Update the api * **monitoring:** Update the api * **policysimulator:** Update the api * **recaptchaenterprise:** Update the api * **sasportal:** Update the api * **servicedirectory:** Update the api * **servicemanagement:** Update the api * **tpu:** Update the api * **transcoder:** Update the api * **vmmigration:** Update the api * **workstations:** Update the api * from version 2.79.0 * **alertcenter:** Update the api * **androidenterprise:** Update the api * **baremetalsolution:** Update the api * **batch:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **cloudsearch:** Update the api * **compute:** Update the api * **content:** Update the api * **drive:** Update the api * **healthcare:** Update the api * **logging:** Update the api * **monitoring:** Update the api * **networksecurity:** Update the api * **ondemandscanning:** Update the api * **paymentsresellersubscription:** Update the api * **privateca:** Update the api * **redis:** Update the api * **safebrowsing:** Update the api * **serviceconsumermanagement:** Update the api * **servicecontrol:** Update the api * **servicenetworking:** Update the api * **serviceusage:** Update the api * from version 2.78.0 * **androidpublisher:** Update the api * **appengine:** Update the api * **artifactregistry:** Update the api * **baremetalsolution:** Update the api * **beyondcorp:** Update the api * **books:** Update the api * **chromemanagement:** Update the api * **chromepolicy:** Update the api * **clouddeploy:** Update the api * **cloudsearch:** Update the api * **compute:** Update the api * **dataproc:** Update the api * **datastream:** Update the api * **dialogflow:** Update the api * **gkehub:** Update the api * **healthcare:** Update the api * **iam:** Update the api * **privateca:** Update the api * **prod_tt_sasportal:** Update the api * **retail:** Update the api * **run:** Update the api * **servicecontrol:** Update the api * from version 2.77.0 * **analyticsadmin:** Update the api * **apigeeregistry:** Update the api * **artifactregistry:** Update the api * **batch:** Update the api * **chromemanagement:** Update the api * **chromeuxreport:** Update the api * **cloudbilling:** Update the api * **cloudsearch:** Update the api * **connectors:** Update the api * **contactcenterinsights:** Update the api * **contentwarehouse:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **documentai:** Update the api * **firebasehosting:** Update the api * **firebase:** Update the api * **gkehub:** Update the api * **manufacturers:** Update the api * **metastore:** Update the api * **notebooks:** Update the api * **safebrowsing:** Update the api * **servicecontrol:** Update the api * **tpu:** Update the api * **workstations:** Update the api * from version 2.76.0 * **analyticsadmin:** Update the api * **container:** Update the api * **datacatalog:** Update the api * **identitytoolkit:** Update the api * **integrations:** Update the api * **monitoring:** Update the api * **recaptchaenterprise:** Update the api * from version 2.75.0 * **apigeeregistry:** Update the api * **batch:** Update the api * **bigqueryreservation:** Update the api * **chromemanagement:** Update the api * **cloudsearch:** Update the api * **compute:** Update the api * **contentwarehouse:** Update the api * **dataflow:** Update the api * **documentai:** Update the api * **file:** Update the api * **gkehub:** Update the api * **integrations:** Update the api * **mybusinessverifications:** Update the api * **retail:** Update the api * **sts:** Update the api * **testing:** Update the api * **workflowexecutions:** Update the api * **workstations:** Update the api * from version 2.74.0 * **analyticshub:** Update the api * **appengine:** Update the api * **baremetalsolution:** Update the api * **bigquery:** Update the api * **cloudbuild:** Update the api * **clouddeploy:** Update the api * **cloudidentity:** Update the api * **compute:** Update the api * **datacatalog:** Update the api * **dataplex:** Update the api * **datastore:** Update the api * **displayvideo:** Update the api * **firebase:** Update the api * **firestore:** Update the api * **gkehub:** Update the api * **identitytoolkit:** Update the api * **integrations:** Update the api * **kmsinventory:** Update the api * **orgpolicy:** Update the api * **pubsub:** Update the api * **retail:** Update the api * **run:** Update the api * **servicenetworking:** Update the api * **androidpublisher:** Update the api * from version 2.73.0 * **admob:** Update the api * **androidenterprise:** Update the api * **appengine:** Update the api * **batch:** Update the api * **cloudtasks:** Update the api * **compute:** Update the api * **content:** Update the api * **dataform:** Update the api * **datamigration:** Update the api * **datastore:** Update the api * **dialogflow:** Update the api * **discoveryengine:** Update the api * **documentai:** Update the api * **firestore:** Update the api * **managedidentities:** Update the api * **metastore:** Update the api * **playdeveloperreporting:** Update the api * **recommender:** Update the api * **streetviewpublish:** Update the api * **translate:** Update the api * **vmmigration:** Update the api * **workstations:** Update the api * from version 2.72.0 * **admin:** Update the api * **baremetalsolution:** Update the api * **blogger:** Update the api * **chat:** Update the api * **chromemanagement:** Update the api * **chromepolicy:** Update the api * **cloudidentity:** Update the api * **container:** Update the api * **contentwarehouse:** Update the api * **datacatalog:** Update the api * **dataflow:** Update the api * **datapipelines:** Update the api * **dataplex:** Update the api * **dialogflow:** Update the api * **displayvideo:** Update the api * **file:** Update the api * **integrations:** Update the api * **playintegrity:** Update the api * **prod_tt_sasportal:** Update the api * **run:** Update the api * **sasportal:** Update the api * **texttospeech:** Update the api * **bigquery:** Update the api * from version 2.71.0 * **accesscontextmanager:** Update the api * **alertcenter:** Update the api * **androidenterprise:** Update the api * **apigee:** Update the api * **batch:** Update the api * **clouddeploy:** Update the api * **compute:** Update the api * **container:** Update the api * **contentwarehouse:** Update the api * **datafusion:** Update the api * **datamigration:** Update the api * **datapipelines:** Update the api * **dataplex:** Update the api * **dataproc:** Update the api * **datastream:** Update the api * **firestore:** Update the api * **gmail:** Update the api * **notebooks:** Update the api * **retail:** Update the api * **speech:** Update the api * **texttospeech:** Update the api * **workloadmanager:** Update the api * Drop patch to disable oauth2client tests, fixed upstream * Update to version 2.70.0 * Features appengine: update the api https://togithub.com/googleapis/google- api-python-client/commit/f3ae3793e74aae883aa8f3bca7d2d75227c99cbd (1506e28) bigquery: update the api https://togithub.com/googleapis/google-api-python- client/commit/9d8a28de9f2709a066cc62765132688f5a4eeba3 (1506e28) chat: update the api https://togithub.com/googleapis/google-api-python- client/commit/4b6ec2a405226f54a846e820be38c4be7e161df3 (1506e28) cloudbilling: update the api https://togithub.com/googleapis/google-api- python-client/commit/6de2af2c211a03d3f9443a89f222c1953d6bec9b (1506e28) cloudchannel: update the api https://togithub.com/googleapis/google-api- python-client/commit/bfbc1b18e9676ab2a7ef322c9ae2ff40bfc0c05e (1506e28) compute: update the api https://togithub.com/googleapis/google-api-python- client/commit/3ad8d540283d6153aeb7e7e5da043515fdd8feae (1506e28) connectors: update the api https://togithub.com/googleapis/google-api-python- client/commit/632cba551d23e3ac8c9044c56f1e3ebbce77ba1c (1506e28) contactcenterinsights: update the api https://togithub.com/googleapis/google-api-python- client/commit/6e512d6e138192e0312e44534b7904e95c36d0fe (1506e28) container: update the api https://togithub.com/googleapis/google-api-python- client/commit/05c853aec288828267afb32571d7f5ad8ac97cdf (1506e28) contentwarehouse: update the api https://togithub.com/googleapis/google-api- python-client/commit/720850e6a8a7cf0cd96170a3b82da993c2967b26 (1506e28) dataflow: update the api https://togithub.com/googleapis/google-api-python- client/commit/1b55a02805496e9431dbf173221958419400f905 (1506e28) dataproc: update the api https://togithub.com/googleapis/google-api-python- client/commit/952d0d1df1ce352ec5d53d9d2eb4fa07629d3c62 (1506e28) documentai: update the api https://togithub.com/googleapis/google-api-python- client/commit/9e0a2601bc52633ff3e3f70800977724fd1f7e0b (1506e28) gkehub: update the api https://togithub.com/googleapis/google-api-python- client/commit/e7a24b27433543dc8afd609bf6340a219456deef (1506e28) ids: update the api https://togithub.com/googleapis/google-api-python- client/commit/d7ca9ebf543d4cb3dbfae00a58862c7300466741 (1506e28) metastore: update the api https://togithub.com/googleapis/google-api-python- client/commit/23800233fe99f56885846fdcd927801b5641b6d3 (1506e28) networksecurity: update the api https://togithub.com/googleapis/google-api- python-client/commit/5cd2d575dc6b58695c3c3f3d32424949f2189f0f (1506e28) pubsublite: update the api https://togithub.com/googleapis/google-api- python-client/commit/ddc2cac9d91b7eb18421695895b41965c2658ac2 (1506e28) recaptchaenterprise: update the api https://togithub.com/googleapis/google- api-python-client/commit/85bf9110ba2ab06d6cc22e8b6c4b7b74309ea0fd (1506e28) servicenetworking: update the api https://togithub.com/googleapis/google- api-python-client/commit/310a96ffbd7672f55acc62a129f54b98b46506d9 (1506e28) sts: update the api https://togithub.com/googleapis/google-api-python- client/commit/e5219026edb8f430f68775cf96e0195a39e1a613 (1506e28) workflowexecutions: update the api https://togithub.com/googleapis/google- api-python-client/commit/3ff77236759bf338f5f295ae0e7453184bfbd745 (1506e28) * Remove python_module macro definition * Update to version 2.69.0 * Features analyticsadmin: update the api https://togithub.com/googleapis/google-api-python- client/commit/1277148ed4bb16c03802a6d11bb15ab138bf6c19 (fa65fca) assuredworkloads: update the api https://togithub.com/googleapis/google-api- python-client/commit/0777a539623f6a0e5c0ee8a0014c49797e14a826 (fa65fca) baremetalsolution: update the api https://togithub.com/googleapis/google- api-python-client/commit/21f9266331d46ae55a4749d485d5937797d75c03 (fa65fca) batch: update the api https://github.com/googleapis/google-api-python- client/commit/5b1f5b056998a149f675ecdf8794563a9e9460fc (f6e9d38) chat: update the api https://togithub.com/googleapis/google-api-python- client/commit/42d7975db499e1298a45b5d7ea086dddbfd3e5ec (fa65fca) cloudbuild: update the api https://github.com/googleapis/google-api-python- client/commit/ef1b5979776140ff203a53e82d0427ebda0112c0 (f6e9d38) cloudfunctions: update the api https://togithub.com/googleapis/google-api- python-client/commit/27456f04a82bd30a897822da45adba98b00d0b73 (fa65fca) cloudsearch: update the api https://togithub.com/googleapis/google-api- python-client/commit/2ebbbba9e1ceac8db6b3a90e56d00bad3c6183c5 (fa65fca) cloudsupport: update the api https://togithub.com/googleapis/google-api- python-client/commit/660300bb6094cdafa87016f16becc956489d723f (fa65fca) composer: update the api https://togithub.com/googleapis/google-api-python- client/commit/b223e46fa38d9cabcf81b66ca78e9b1d4e88c01b (fa65fca) compute: update the api https://github.com/googleapis/google-api-python- client/commit/23ca08a7e9717d0aefff49823f4d594ed118ec25 (f6e9d38) compute: update the api https://togithub.com/googleapis/google-api-python- client/commit/2a5e985835d9e6a6eff7d88c2d8aac08fa4677df (fa65fca) content: update the api https://togithub.com/googleapis/google-api-python- client/commit/93233da7ebde3542aaa004402c77bc19e6c919be (fa65fca) dataplex: update the api https://togithub.com/googleapis/google-api-python- client/commit/714d395fa712c56f1d207e4408ca1a252fd3d162 (fa65fca) dialogflow: update the api https://togithub.com/googleapis/google-api-python- client/commit/1d14a2f69b29855ec25b488babfbceb0609a519c (fa65fca) displayvideo: update the api https://togithub.com/googleapis/google-api- python-client/commit/1a3f64b4fd8e4f1774e1c6e6a70ad91a5a550590 (fa65fca) gamesConfiguration: update the api https://togithub.com/googleapis/google- api-python-client/commit/5e1872ea1691596119064e2d09043a99c15adac3 (fa65fca) metastore: update the api https://togithub.com/googleapis/google-api-python- client/commit/eba8d4f0e129812a600e4e8e6c33f4ab88c95180 (fa65fca) monitoring: update the api https://github.com/googleapis/google-api-python- client/commit/cb568e1f19afa239b1b5dfbc1bc14554c130c15c (f6e9d38) networkmanagement: update the api https://togithub.com/googleapis/google- api-python-client/commit/c65d33b8ca6b2aa014bc39bd4ca32ed1e9ebd96c (fa65fca) paymentsresellersubscription: update the api https://togithub.com/googleapis/google-api-python- client/commit/fd60e1157653d8b018ac093b01a32d3434148df4 (fa65fca) securitycenter: update the api https://togithub.com/googleapis/google-api- python-client/commit/c0c746a361421b6d250817f4d397d2c34dc2c4e9 (fa65fca) servicemanagement: update the api https://togithub.com/googleapis/google- api-python-client/commit/e3f20cd1141dd5ca47b2323eb0fa029e255c78ec (fa65fca) spanner: update the api https://togithub.com/googleapis/google-api-python- client/commit/c2007c17ae0eb31027417903a034dbc98eade638 (fa65fca) storagetransfer: update the api https://github.com/googleapis/google-api- python-client/commit/76c66c741eef394307e290ccad3dde13c950d2cf (f6e9d38) texttospeech: update the api https://togithub.com/googleapis/google-api- python-client/commit/bb64e3c504126472671203b1affec77396db89e7 (fa65fca) vmmigration: update the api https://togithub.com/googleapis/google-api- python-client/commit/3e1a2c94e7c20c7fef3f746bf40f74c06b7c2e29 (fa65fca) * Bug Fixes Fix media upload URI when API endpoint is overridden with client_opions.api_endpoint (#1992) (d0f8a05) * Update to 2.68.0: * Add support for Python 3.11 (#1973) * **androidmanagement:** update the api (9b5767f) * **chat:** update the api (9b5767f) * **chromemanagement:** update the api (03f4753) * **cloudasset:** update the api (9b5767f) * **cloudsearch:** update the api (9b5767f) * **composer:** update the api (9b5767f) * **contactcenterinsights:** update the api (9b5767f) * **container:** update the api (9b5767f) * **datapipelines:** update the api (9b5767f) * **dataplex:** update the api (9b5767f) * **dns:** update the api (9b5767f) * **documentai:** update the api (9b5767f) * **securitycenter:** update the api (9b5767f) * **serviceconsumermanagement:** update the api (9b5767f) * **servicenetworking:** update the api (9b5767f) * **serviceusage:** update the api (9b5767f) * **sqladmin:** update the api (03f4753) * **testing:** update the api (9b5767f) * Update to 2.66.0: * **alertcenter:** update the api * **androiddeviceprovisioning:** update the api * **androidpublisher:** update the api * **appengine:** update the api * **artifactregistry:** update the api * **assuredworkloads:** update the api * **assuredworkloads:** update the api * **baremetalsolution:** update the api * **beyondcorp:** update the api * **bigquery:** update the api * **bigtableadmin:** update the api * **chat:** update the api * **chat:** update the api * **chromepolicy:** update the api * **cloudbuild:** update the api * **cloudfunctions:** update the api * **cloudsearch:** update the api * **cloudtasks:** update the api * **composer:** update the api * **compute:** update the api * **compute:** update the api * **connectors:** update the api * **containeranalysis:** update the api * **content:** update the api * **contentwarehouse:** update the api * **contentwarehouse:** update the api * **datacatalog:** update the api * **dataplex:** update the api * **dataplex:** update the api * **dataproc:** update the api * **dataproc:** update the api * **datastore:** update the api * **dialogflow:** update the api * **displayvideo:** update the api * **documentai:** update the api * **doubleclicksearch:** update the api * **drivelabels:** update the api * **firestore:** update the api * **gkehub:** update the api * **healthcare:** update the api * **integrations:** update the api * **managedidentities:** update the api * **managedidentities:** update the api * **metastore:** update the api * **monitoring:** update the api * **networkconnectivity:** update the api * **playintegrity:** update the api * **redis:** update the api * **retail:** update the api * **retail:** update the api * **run:** update the api * **run:** update the api * **servicecontrol:** update the api * **servicedirectory:** update the api * **speech:** update the api * **sqladmin:** update the api * **tagmanager:** update the api * **translate:** update the api * Fix a typo in UPGRADING.md related to static_discovery (#1956) (bc03ac6) * Update to 2.65.0: Features * alertcenter: update the api https://togithub.com/googleapis/google-api- python-client/commit/99b94eeb1cf0f695d921ac1d9081c0841f6b1693 (5d54a7d) * analyticsadmin: update the api https://togithub.com/googleapis/google-api- python-client/commit/41818c6eb42aa3551fc2a326208f9cc083cb1953 (7110d89) * assuredworkloads: update the api https://togithub.com/googleapis/google-api- python-client/commit/9756c064a5cff42e367677216c48ff6649817dd5 (5d54a7d) * chat: update the api https://togithub.com/googleapis/google-api-python- client/commit/6dce01ba90d86496038bad226a14a9d714fb6e37 (7110d89) * chromepolicy: update the api https://togithub.com/googleapis/google-api- python-client/commit/180883247dcfcd777de04758a7928ca84e2764da (7110d89) * cloudbuild: update the api https://togithub.com/googleapis/google-api- python-client/commit/555317bfb60133f8ff82d4ac28651631404980d4 (5d54a7d) * cloudsearch: update the api https://togithub.com/googleapis/google-api- python-client/commit/2717d97f6ccd16b03f70adbb317fb330f74f3e2d (5d54a7d) * containeranalysis: update the api https://togithub.com/googleapis/google- api-python-client/commit/322df84348b8765bc6dce442c5d03209963a0e6b (5d54a7d) * container: update the api https://togithub.com/googleapis/google-api-python- client/commit/ea99aeeb561642071866b71f54ae84be95ae5bcc (5d54a7d) * dlp: update the api https://togithub.com/googleapis/google-api-python- client/commit/618362554c62d453579ff52933234a93ea5dfae3 (5d54a7d) * doubleclicksearch: update the api https://togithub.com/googleapis/google- api-python-client/commit/1e7db3e4969b55ecf98bbb78d3edc53f4bf08a15 (7110d89) * firebase: update the api https://togithub.com/googleapis/google-api-python- client/commit/569cb7e362206b8a7563b689ccd720ed29259997 (7110d89) * notebooks: update the api https://togithub.com/googleapis/google-api-python- client/commit/9ff1945acf3a74221759c2ceb9eb9a22c22b7c09 (5d54a7d) * retail: update the api https://togithub.com/googleapis/google-api-python- client/commit/32de4a02de0fd9e11755418f13c623f5b5c56674 (7110d89) * securitycenter: update the api https://togithub.com/googleapis/google-api- python-client/commit/b1c67c818d662fe97e82b000931be739766fbe55 (7110d89) * tagmanager: update the api https://togithub.com/googleapis/google-api- python-client/commit/188cd231f843aafb1c49cafe64052ec190e477a8 (5d54a7d) * verifiedaccess: update the api https://togithub.com/googleapis/google-api- python-client/commit/e2dccf7393b2e15986b1ba88ea6aa2b4f621dc17 (7110d89) Bug Fixes * prod_tt_sasportal: update the api https://togithub.com/googleapis/google- api-python-client/commit/9000eddf5e2e22242ebc94cb0af60363ff5c41df (5d54a7d) * sasportal: update the api https://togithub.com/googleapis/google-api-python- client/commit/36e8c8bc1b9cb3bbab1abdb2936d7a9cc9cea87a (7110d89) * smartdevicemanagement: update the api https://togithub.com/googleapis/google-api-python- client/commit/f7cc8d243a3c6b16cdf7aafae285b2efbb65d1fc (7110d89) * Update to 2.64.0: * **analyticsadmin:** update the api * **assuredworkloads:** update the api * **beyondcorp:** update the api * **bigquery:** update the api * **certificatemanager:** update the api * **chromemanagement:** update the api * **chromepolicy:** update the api * **cloudasset:** update the api * **cloudidentity:** update the api * **cloudsearch:** update the api * **cloudtasks:** update the api * **compute:** update the api * **containeranalysis:** update the api * **dataflow:** update the api * **documentai:** update the api * **driveactivity:** update the api * **firebasestorage:** update the api * **monitoring:** update the api * **paymentsresellersubscription:** update the api * **playintegrity:** update the api * **recommender:** update the api * **retail:** update the api * **spanner:** update the api * from version 2.63.0: * **admin:** update the api * **adsense:** update the api * **androidpublisher:** update the api * **assuredworkloads:** update the api * **baremetalsolution:** update the api * **bigquery:** update the api * **chromeuxreport:** update the api * **cloudbuild:** update the api * **clouddeploy:** update the api * **cloudkms:** update the api * **composer:** update the api * **compute:** update the api * **dataplex:** update the api * **dfareporting:** update the api * **dns:** update the api * **documentai:** update the api * **firestore:** update the api * **healthcare:** update the api * **identitytoolkit:** update the api * **language:** update the api * **monitoring:** update the api * **networkconnectivity:** update the api * **networkmanagement:** update the api * **ondemandscanning:** update the api * **recommender:** update the api * **run:** update the api * **securitycenter:** update the api * **youtube:** update the api * Update to 2.62.0: * **analyticshub:** update the api * **artifactregistry:** update the api * **assuredworkloads:** update the api * **bigquery:** update the api * **chromemanagement:** update the api * **chromepolicy:** update the api * **clouddeploy:** update the api * **cloudsearch:** update the api * **container:** update the api * **dataflow:** update the api * **dlp:** update the api * **documentai:** update the api * **gkehub:** update the api * **identitytoolkit:** update the api * **manufacturers:** update the api * **securitycenter:** update the api * **spanner:** update the api * **vmmigration:** update the api * from version 2.61.0: * **androidpublisher:** update the api * **assuredworkloads:** update the api * **bigquery:** update the api * **cloudbuild:** update the api * **clouddeploy:** update the api * **cloudsearch:** update the api * **cloudtasks:** update the api * **compute:** update the api * **containeranalysis:** update the api * **content:** update the api * **dataflow:** update the api * **dataproc:** update the api * **dns:** update the api * **firebase:** update the api * **orgpolicy:** update the api * **paymentsresellersubscription:** update the api * **retail:** update the api * **sqladmin:** update the api * **storagetransfer:** update the api * **tpu:** update the api * **translate:** update the api * **workflowexecutions:** update the api * **tagmanager:** update the api * Update to 2.60.0: * **apigeeregistry:** update the api * **baremetalsolution:** update the api * **bigquery:** update the api * **chat:** update the api * **cloudidentity:** update the api * **compute:** update the api * **datacatalog:** update the api * **dataproc:** update the api * **dialogflow:** update the api * **documentai:** update the api * **gkehub:** update the api * **identitytoolkit:** update the api * **managedidentities:** update the api * **playintegrity:** update the api * **servicemanagement:** update the api * **testing:** update the api * **adsense:** update the api * **policysimulator:** update the api * **samples:** Replace APPENGINE_RUNTIME with GAE_ENV (#1893) * from version 2.59.0: * **analyticsadmin:** update the api * **analyticsdata:** update the api * **assuredworkloads:** update the api * **baremetalsolution:** update the api * **cloudbuild:** update the api * **compute:** update the api * **datamigration:** update the api * **datastream:** update the api * **dialogflow:** update the api * **documentai:** update the api * **iap:** update the api * **monitoring:** update the api * **mybusinessplaceactions:** update the api * **paymentsresellersubscription:** update the api * **serviceconsumermanagement:** update the api * **servicenetworking:** update the api * **serviceusage:** update the api * **speech:** update the api * **firebase:** update the api * from verson 2.58.0: * **adsense:** update the api * **apigee:** update the api * **chromepolicy:** update the api * **cloudsearch:** update the api * **compute:** update the api * **dataflow:** update the api * **dataproc:** update the api * **dlp:** update the api * **documentai:** update the api * **drive:** update the api * **firebase:** update the api * **gkehub:** update the api * **managedidentities:** update the api * **networkmanagement:** update the api * **orgpolicy:** update the api * **playintegrity:** update the api * **retail:** update the api * **secretmanager:** update the api * **serviceconsumermanagement:** update the api * **servicemanagement:** update the api * **servicenetworking:** update the api * **serviceusage:** update the api * **tagmanager:** update the api * **transcoder:** update the api * **dfareporting:** update the api * from version 2.57.0: * **admin:** update the api * **apigee:** update the api * **artifactregistry:** update the api * **bigquery:** update the api * **certificatemanager:** update the api * **cloudidentity:** update the api * **cloudsearch:** update the api * **compute:** update the api * **connectors:** update the api * **containeranalysis:** update the api * **content:** update the api * **dataflow:** update the api * **documentai:** update the api * **gkehub:** update the api * **manufacturers:** update the api * **mybusinessplaceactions:** update the api * **run:** update the api * **securitycenter:** update the api * **sqladmin:** update the api * **toolresults:** update the api * **translate:** update the api * **vision:** update the api * Update to 2.56.0: * * : update the api * deps: require google-auth 1.19.0 (#1824) (7f478ae) * deps: require python 3.7+ * test: Switch to unittest.mock * Refresh patches. * Update to 2.44.0 * * : update the api * deps: require google-api-core>=1.31.5, >=2.3.2 (#1715) (8308e5d) * remove adsense.v1.4.json (#1616) (5d3e588) * expose library version at googleapiclient.version (#1623) (83db1d7) * deps: require uritemplate 3.0.1 (#1629) (1c4cfdb) * Do not test deprecated oauth2client anymore: * Update to 2.31.0: * MediaIoBaseDownload range header off-by-one (#1595) (4b73b2e) * from version 2.28.0: * manage JSONDecodeError exception (#1574) (7d63027) * update thread_safety.md (#1568) (0b400f9) * from version 2.26.1: * disable self signed jwt (#1566) (623a71e) * from version 2.26.0: * add support for python 3.10 (#1557) (bcc507f) * from version 2.25.0: * enable self signed jwt for service account credentials (#1553) (1fb3c8e) * Drop python google api python client no unittest2 patch * Update to 2.20.0: * Adds support for errors.py to also use 'errors' for error_details (#1281) (a5d2081) * add status_code property on http error handling (#1185) (db2a766) * Change default of static_discovery when discoveryServiceUrl set (#1261) (3b4f2e2) * correct api version in oauth-installed.md (#1258) (d1a255f) * fix .close() (#1231) (a9583f7) * Resolve issue where num_retries would have no effect (#1244) (c518472) * Include discovery artifacts in published package (#1221) (ad618d0) * Require Python 3.6+ * Add support for using static discovery documents (#1109) (32d1c59) * Update synth.py to copy discovery files from discovery-artifact-manager (#1104) (af918e8) * Catch ECONNRESET and other errors more reliably (#1147) (ae9cd99) * deps: add upper-bound google-auth dependency (#1180) (c687f42) * handle error on service not enabled (#1117) (c691283) * Improve support for error_details (#1126) (e6a1da3) * MediaFileUpload error if file does not exist (#1127) (2c6d029) * replace deprecated socket.error with OSError (#1161) (b7b9986) * Use logging level info when file_cache is not available (#1125) (0b32e69) * add httplib2 authorization to thread_safety (#1005) (205ae59), closes #808 * Change error parsing to check for 'message' (#1083) (a341c5a), closes #1082 * don't raise when downloading zero byte files (#1074) (86d8788) * Refreshed python google api python client no unittest2 patch * Update to version 1.12.8 * add httplib2 authorization to thread_safety (#1005), closes #808 * from version 1.12.7 * Update Webmasters API sample (#1092) * from version 1.12.6 * Dcoumentation fixes * from version 1.12.5 * don't raise when downloading zero byte files (#1074) * from version 1.12.4 * don't set content-range on empty uploads (#1070) * from version 1.12.3 * deps: update setup.py to install httplib2>=0.15.0 (#1050) * from version 1.12.2 * add method to close httplib2 connections (#1038), closes #618 * from version 1.12.1 * deps: require six>=1.13.0 (#1030) * from version 1.12.0 * convert print statement to function (#988), closes #987 * remove http from batch execute docs (#1003), closes #1002 * Update to version 1.11.0 * add support for mtls env variables (#1008) * from version 1.10.1 * discovery uses V2 when version is None (#975), closes (#971) * fix deprecation warnings due to invalid escape sequences. (#996), closes (#995) * fix link to service accounts documentation (#986) * update generated docs (#981) * from version 1.10.0 * allow to use 'six.moves.collections_abc.Mapping' in 'client_options.from_dict()' (#943) * Build universal wheels (#948) * discovery supports retries (#967), closes (#848) * consolidating and updating the Contribution Guide (#964), closes (#963) * from version 1.9.3 * update GOOGLE_API_USE_MTLS values (#940) * from version 1.9.2 * bump api-core version (#936) * from version 1.9.1 * fix python-api-core dependency issue (#931) * from version 1.9.0 * add mtls feature (#917) * add templates for python samples projects (#506), (#924) * Refresh patches for new version * Update BuildRequires and Requires from setup.py * so remove the dependency on unittest2 from BuildRequires, too * version update to 1.8.4 * don't try to import GAE API in other environments (#903) (09e6447) * the turn down date for global batch uri (#901) (6ddadd7) * downgrade repetitive logging calls to debug (#885) (3bf2781), closes #781 * added patches fix unittest2 seems to be fake dependency * Update to 1.8.2: * Remove apiclient.**version** gh#googleapis/googleapis#870 * Adding ConnectionError to retry mechanism gh#googleapis/googleapis#558 * replace '-' in method names with '_' gh#googleapis/google-api-python- client#863 * Add missing dependency on oauth2client. * Fix filelist (no CHANGELOG anymore, missing README.md) * Update to 1.8.0 * Add api endpoint override. (https://github.com/googleapis/google-api-python- client/pull/829) * Various small bugfixes. * Update to 1.7.11 bsc#1161898: * Various small bugfixes only * Update to 1.7.8: * bunch of small bugfixes * python2 exec prints warning now about deprecation * Remove hide Python dependency patch does not make sense * Add back unittest2 dep, upstream hardcoded it * Remove superfluous devel dependency for noarch package Changes in python-googleapis-common-protos: \- Update to 1.71.0 * add support for Python 3.14 (#14699) * Update to 1.70.0 * Expand QuotaFailure with quota error details (#13745) * Update to 1.69.2 * Allow protobuf 6.x (b4d4551) * Remove setup.cfg configuration for creating universal wheels (#13659) * Resolve issue where pre-release versions of dependencies are installed (b4d4551) * Set `include` in `tool.setuptools.packages.find` (#13662) * Fix changelog entry for previous version * Update GitHub URL in URL field * Update to 1.69.1 * Exclude docs in tool.setuptools.packages.find (#13607) * Restore *.proto files removed in version 1.67.0 (#13614) * from version 1.69.0 * Migrate to pyproject.toml (#13551) * Update Recommends from pyproject.toml * Update to 1.68.0 * Add field `experimental_features` to message `PythonSettings` (#249) * Add FieldInfo.referenced_types for generics (#247) * from version 1.67.0 * A new field `unversioned_package_disabled` is added to message `.google.api.PythonSettings` (eb554e8) * Add support for field generate_omitted_as_internal in selective gapic generation (#13482) * A comment for field `content` in message `.google.api.Page` is changed (eb554e8) * A comment for message `RoutingRule` is changed (eb554e8) * Update to 1.66.0 * Add `MISSING_ORIGIN` and `OVERLOADED_CREDENTIALS` to `ErrorReason` enum (d0478d8) * Add field `protobuf_pythonic_types_enabled` to `ExperimentalFeatures` message (d0478d8) * Add field `selective_gapic_generation` to `CommonLanguageSettings` message (d0478d8) * Add field `time_series_resource_hierarchy_level` to `MetricDescriptorMetadata` message (d0478d8) * Add message `SelectiveGapicGeneration` (d0478d8) * Update to 1.65.0 * Add field `experimental_features` to message `PythonSettings` (#249) * from version 1.64.0 * Add FieldInfo.referenced_types for generics (2ba3577) * Un-deprecate Endpoint.aliases field (2ba3577) * Fix formatting in http.proto comments (2ba3577) * Improve MethodSettings selector examples (2ba3577) * Reformat comments in context proto (2ba3577) * Update ResourceDescriptor.plural docs with AIP-122 nested collections guidance (2ba3577) * Adjust upstream source name in spec file * Remove unnecessary %{modname} and %{pkgname} variables * Update to 1.63.2 * **deps:** Require protobuf >= 3.20.2 (c77c0dc) * Regenerate pb2 files for compatibility with protobuf 5.x (c77c0dc) * Update to 1.63.1 * Increase upper limit for protobuf 5.X versions (#212) * update to 1.63.0: * Add `api_version` field to `ServiceOptions` in `google/api/client.proto` * Add `LOCATION_POLICY_VIOLATED` enum to `ErrorReason` in `google/api/error_reason.proto` * Add `rest_reference_documentation_uri` field to `ServiceOptions` in `google/api/client.proto` Changes in python-google-auth-httplib2: \- update to 0.2.0: * Add support for Python 3.12 (#126) * Remove third-party mock library (#124) drop python google auth httplib2 no mock patch (upstream) * version update to 0.1.1 * remove six, update python versions * modified patches * Add %{?sle15_python_module_pythons} * do not require python-mock for build * added patches fix https://github.com/googleapis/google-auth-library-python- httplib2/issues/68 * Update to version 0.1.0 * chore: release 0.1.0 (#22) * feat: add close method (#14) * build: migrate to flakybot (#21) * chore: use nox and kokoro (#16) * Add renovate.json (#15) * Fix the signature of AuthorizedHttp.request to match the signature of the request in httplib2 (#13) * Expose redirect_codes on AuthorizedHttp. (#12) * from version 0.0.4 * Release 0.0.4 (#11) * feat: expose a few httplib2 properties and a method (#9) * Bug: Catch any underlying exceptions from http.HTTPException (#7) * Update BuildRequires and Requires from setup.py Changes in python-google-auth: \- Update to version 2.41.1 * Suppress deprecation warning for ADC (#1815) \- from version 2.41.0 * Add support for cachetools 6.0 (#1773) * Add trust boundary support for service accounts and impersonation. (#1778) * Deprecating load_credentials_from_dict (58b66ec) * Fix type error in credentials.py for python 3.7 and 3.8 (#1805) * Update user guide to include x509 feature. (#1802) \- Refresh patches for new version * Convert to pip-based build * Update to version 2.40.3 * Auth fetch token from default endpoint (#1779) * Remove unnecessary call to mds service (#1769) * Retry 504 errors (#1767) * Update to version 2.40.2 * Remove sync response logs in AuthorizedSession * Update test to consider new error message from cryptography (#1765) * Update to version 2.40.1 * Disable logging response body for async logs (#1756) * from version 2.40.0 * Add request response logging to auth (#1678) * Correct webauthn JSON parsing to be compliant with standard. (#1658) * from version 2.39.0 * Adds GA support for X.509 workload identity federation (#1695) * Add impersonated SA via local ADC support for fetch_id_token (#1740) * Add missing packaging dependency for feature requiring urllib3 (#1732) * Add request timeout for MDS requests (#1699) * Explicitly declare support for Python 3.13 ([#1741) * Refresh python google auth no mock patch * Skip test broken with new pyOpenSSL * as pyOpenSSL should not be used anymore and continues deprecating functionality, this library should really be migrated to cryptography, otherwise we are facing serious problems in the future * https://github.com/googleapis/google-auth-library-python/issues/1665 * Update to version 2.38.0 * Adding domain-wide delegation flow in impersonated credential (#1624) (34ee3fe) * Add warnings regarding consuming externally sourced credentials (d049370) * Update to version 2.37.0 * Allow users to use jwk keys for verifying ID token (#1641) * from version 2.36.1 * Improve user guide for Impersonation and SA (#1627) * Update BuildRequires and Recommends from setup.py * Update to version 2.36.0 * IAM signblob retries (#1600) * Making IAM endpoint universe-aware (#1604) * Support External Account Authorized User as a Source Credential for impersonated credentials in ADC (#1608) * Adding default parameters to updated interfaces (#1622) * Change universe_domain to universe-domain (#1613) * Remove base class to avoid type conflict (#1619) * Revert templates for iam endpoints (#1614) * Update secret (#1611) * Update secret (#1617) * Update secret (#1621) * Update to version 2.35.0 * Add cred info to ADC creds (#1587) * Add support for asynchronous `AuthorizedSession` api (#1577) * Remove token_info call from token refresh path (#1595) * Refresh patches for new version * Updates BuildRequires from setup.py * Update to version 2.34.0 * **auth:** Update get_client_ssl_credentials to support X.509 workload certs (#1558) * Retry token request on retryable status code (#1563) * from version 2.33.0 * Implement async `StaticCredentials` using access tokens (#1559) * Implement base classes for credentials and request sessions (#1551) * **metadata:** Enhance retry logic for metadata server access in _metadata.py (#1545) * Update argument for Credentials initialization (#1557) * Refresh patches for new version * Update to version 2.32.0 * Adds support for X509 workload credential type (#1541) * Adjust upstream source name in spec file * Update to version 2.31.0 * Adds X509 workload cert logic (#1527) * Added py.typed to MANIFEST.in (#1526) * Pass trust_env kwarg to ClientSession (#1533) * Update to version 2.30.0 * Add WebAuthn plugin component to handle WebAuthn get assertion request (#1464) * ECP Provider drop cryptography requirement (#1524) * Enable webauthn plugin for security keys (#1528) * Fix id_token iam endpoint for non-gdu service credentials (#1506) * Makes default token_url universe aware (#1514) * Refresh patches for new version * Update to version 2.29.0 * Adds support for custom suppliers in AWS and Identity Pool credentials (#1496) * Refactor tech debt in aws and identity pool credentials (#1501) * from version 2.28.2 * Remove gce log for expected 404 (#1491) * from version 2.28.1 * Typo when setting the state for the pickle deserializer. (#1479) * from version 2.28.0 * Adding universe domain support for downscroped credentials (#1463) * Change log level to debug for return_none_for_not_found_error (#1473) * Make requests import conditional for gce universe domain (#1476) * Refresh patches for new version Changes in python-google-cloud-appengine-logging: \- Update to 1.7.0 * Add support for Python 3.14 * Deprecate credentials_file argument \- from version 1.6.2 * Update import statement example in README \- Update BuildRequires and Requires from setup.py * Update to 1.6.1 * [Many APIs] Allow Protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) * from version 1.6.0 * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * from version 1.5.0 * Add support for Python 3.13 (#13200) * from version 1.4.5 * Retry and timeout values do not propagate in requests during pagination * from version 1.4.4 * Allow protobuf 5.x * Adjust upstream source name in spec file * Update BuildRequires and Requires from setup.py * update to 1.4.3: * [Many APIs] Require google-api-core>=1.34.1 * Add google-auth as a direct dependency * Add staticmethod decorator to _get_client_cert_source and _get_api_endpoint * Resolve AttributeError 'Credentials' object has no attribute 'universe_domain' Changes in python-google-cloud-artifact-registry: \- Update to 1.17.0 * Add support for Python 3.14 * Deprecate credentials_file argument \- Update BuildRequires and Requires from setup.py * Add missing BuildRequires on pytest-asyncio. * Update to 1.16.0 * Add the GoModule and KfpArtifact resources * Remove the restriction of the maximum numbers of versions that can be deleted in one BatchDeleteVersions call * from version 1.15.2 * [Many APIs] Allow Protobuf 6.x * Remove setup.cfg configuration for creating universal wheels * from version 1.15.1 * **deps:** Require grpc-google-iam-v1 >= 0.14.0 * from version 1.15.0 * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * from version 1.14.0 * Add support for opt-in debug logging * Fix typing issue with gRPC metadata when key ends in -bin * from version 1.13.1 * Disable universe-domain validation (#13242) * from version 1.13.0 * Add Artifact Registry attachment API * Add Artifact Registry custom remote support * Add Artifact Registry generic repository support * Add Artifact Registry rule APIs * Add Artifact Registry server side resource filtering and sorting * Add Artifact Registry UpdateFile and DeleteFile APIs * Include max page size for all Artifact Registry APIs * from version 1.12.0 * Add support for Python 3.13 (#13206) * from version 1.11.5 * Retry and timeout values do not propagate in requests during pagination * from version 1.11.4 * Allow Protobuf 5.x (#12863) * Adjust upstream source name in spec file * Update BuildRequires and Requires from setup.py * update to 1.11.3: * Add google-auth as a direct dependency (780c5f1) * Add staticmethod decorator to _get_client_cert_source and _get_api_endpoint * Resolve AttributeError 'Credentials' object has no attribute 'universe_domain' * Require google-api-core>=1.34.1 * fix ValueError in test__validate_universe_domain Changes in python-google-cloud-audit-log: \- Update to 0.4.0 * Add support for Python 3.14 (#14699) \- from version 0.3.3 * Add *.proto files to google-cloud- audit-log (#14587) * Update to 0.3.2 * Allow protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) * Resolve issue where pre-release versions of dependencies are installed * from version 0.3.1 * Updates audit_log proto with PermissionType (#13616) * from version 0.3.0 * Add `google/cloud/audit/bigquery_audit_metadata_pb2.py` * Add PolicyViolation. this will only be present when access is denied due to Organization Policy * Add support for Python 3.12 (#113) * Add the principal field to the ServiceAccountDelegationInfo * Introduce compatibility with native namespace packages (#117) * Update AuditLog proto to include all new changes in Audit Logging * **deps:** Require protobuf >= 3.20.2, protobuf >= 6 * Regenerate pb2 files for compatibility with protobuf 5.x * Adjust upstream source name in spec file * Switch upstream tarball to PyPi as tests are now included there * Update BuildRequires and Requires from setup.py Changes in python-google-cloud-build: \- Update to 3.33.0 * Add support for Python 3.14 * Deprecate credentials_file argument \- from version 3.32.0 * Add option to enable nested virtualization if available * Update comments for `machine_type` and `disk_size_gb` \- from version 3.31.3 * [google-cloud-build] Updated Private Service Connect IP ranges when route_all_traffic is false (#14149) \- from version 3.31.2 * Update import statement example in README \- Update BuildRequires and Requires from setup.py * Add missing BuildRequires on pytest-asyncio. * Update to 3.31.1 * [Many APIs] Allow Protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) * from version 3.31.0 * Add option to enable fetching dependencies * Support for git proxy setup * **deps:** Require grpc-google-iam-v1 >= 0.14.0 * Updates to proto message comments * from version 3.30.0 * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * from version 3.29.0 * [google-cloud-build] Add GoModule to Artifact and Results messages and new GO_MODULE_H1 hash type (#13416) * [google-cloud-build] Add option to enable structured logging (#13430) * from version 3.28.0 * Add support for opt-in debug logging * Fix typing issue with gRPC metadata when key ends in -bin * from version 3.27.1 * Disable universe-domain validation (#13242) * from version 3.27.0 * [google-cloud-build] Add PrivateServiceConnect option to WorkerPool (#13221) * from version 3.26.0 * Add support for Python 3.13 (#13206) * from 3.25.0 * Add LEGACY_BUCKET option to DefaultLogsBucketBehavior * Sanitize docs * from version 3.24.2 * Retry and timeout values do not propagate in requests during pagination * from version 3.24.1 * Allow Protobuf 5.x (#12865) * Adjust upstream source name in spec file * Update BuildRequires and Requires from setup.py * update to 3.24.0: * Add Bitbucket Data Center Config and Bitbucket Cloud config for Cloud Build Repositories * Exclude google-auth 2.24.0 and 2.25.0 Changes in python-google-cloud-compute: \- Update to 1.40.0 * Update Compute Engine v1 API to revision 20250916 (#1107) * Add support for Python 3.14 * Deprecate credentials_file argument \- from version 1.39.0 * [google-cloud- compute] Update Compute Engine v1 API to revision 20250909 * [google-cloud- compute] Update Compute Engine v1 API to revision 20250902 \- from version 1.38.0 * [google-cloud-compute] Update Compute Engine v1 API to revision 20250902 (#14434) \- from version 1.37.0 * [google-cloud-compute] Update Compute Engine v1 API to revision 20250810 (#1091) \- from version 1.36.0 * [google- cloud-compute] Update Compute Engine v1 API to revision 20250807 \- from version 1.35.0 * [google-cloud-compute] Update Compute Engine v1 API to revision 20250728 (#1081) * [google-cloud-compute] Update Compute Engine v1 API to revision 20250729 (#1085) \- from version 1.34.0 * [google-cloud-compute] Update Compute Engine v1 API to revision 20250717 (#1074) \- from version 1.33.0 * [google-cloud-compute] Update Compute Engine v1 API to revision 20250708 (#1073) \- from version 1.32.0 * Update Compute Engine v1 API to revision 20250626 (3ad8819) \- from version 1.31.0 * [google-cloud-compute] Update Compute Engine v1 API to revision 20250601 (#13970) * Update Compute Engine v1 API to revision 20250511 (#1047) \- Update BuildRequires and Requires from setup.py * Update to 1.30.0 * Update Compute Engine API to revision 20250415 (#13800) Changes in python-google-cloud-core: \- Update to 2.4.3 * Declare support for Python 3.13 (#326) \- from version 2.4.2 * Client should pass client_options.api_key to auth library (#321) \- Adjust upstream source name in spec file Changes in python-google-cloud-dns: \- Update to 0.35.1 * Remove setup.cfg configuration for creating universal wheels (#316) (942de3a) * Resolve issues where pre-release versions of dependencies are installed (#313) (5e1a6bc) \- Update upstream_name to google_cloud_dns Changes in python-google-cloud-domains: \- Update to 1.11.0 * Add support for Python 3.14 * Deprecate credentials_file argument \- from version 1.10.2 * Update import statement example in README \- Update BuildRequires and Requires from setup.py * Add missing BuildRequires on pytest-asyncio. * Update to 1.10.1 * [Many APIs] Allow Protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) * from version 1.10.1 * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * from version 1.9.0 * Add support for opt-in debug logging * Fix typing issue with gRPC metadata when key ends in -bin * from version 1.8.1 * Disable universe-domain validation (#13242) * from version 1.8.0 * Add support for Python 3.13 (#13204) * from version 1.7.5 * Retry and timeout values do not propagate in requests during pagination * from version 1.7.4 * Allow Protobuf 5.x (#12866) * Adjust upstream source name in spec file * Update BuildRequires and Requires from setup.py * update to 1.7.3: * Exclude google-auth 2.24.0 and 2.25. * fix ValueError in test__validate_universe_domain * deps: [Many APIs] Require google-api-core>=1.34.1 Changes in python-google-cloud-iam: \- Update to 2.20.0 * Add support for Python 3.14 (4763aa7) * Deprecate credentials_file argument (4763aa7) \- Update BuildRequires and Requires from setup.py * Update to 2.19.0 * Add google.cloud.iam_v3 and google.cloud.iam_v3beta * from version 2.18.3 * Update suggested source of IAM samples (#13666) * from version 2.18.2 * [Many APIs] Allow Protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) * from version 2.18.1 * **deps:** Require grpc-google-iam-v1 >= 0.14.0 * from version 2.18.0 * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * from version 2.17.0 * Add support for opt-in debug logging * Fix typing issue with gRPC metadata when key ends in -bin * from version 2.16.1 * Disable universe-domain validation (#13243) * from version 2.16.0 * Add support for Python 3.13 (#13207) * from version 2.15.2 * Retry and timeout values do not propagate in requests during pagination * from version 2.15.1 * Allow Protobuf 5.x (#12867) * Adjust upstream source name in spec file Changes in python-google-cloud-kms-inventory: \- Update to 0.3.0 * Add support for Python 3.14 * Deprecate credentials_file argument \- from version 0.2.15 * Update import statement example in README (821bdb1) \- Update BuildRequires and Requires from setup.py * Update to 0.2.14 * [Many APIs] Allow Protobuf 6.x * from version 0.2.13 * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * from version 0.2.12 * Add support for opt-in debug logging * Fix typing issue with gRPC metadata when key ends in -bin * from version 0.2.11 * Disable universe-domain validation (#13243) * from version 0.2.10 * Add support for Python 3.13 (#13207) * from version 0.2.9 * **deps:** allow google-cloud-kms 3.x * from version 0.2.8 * Retry and timeout values do not propagate in requests during pagination * from version 0.2.7 * Allow Protobuf 5.x (#12867) * Adjust upstream source name in spec file * Update BuildRequires and Requires from setup.py * update to 0.2.6: * Allow users to explicitly configure universe domain * Add google-auth as a direct dependency * Add staticmethod decorator to _get_client_cert_source and _get_api_endpoint (27dceb9) * Resolve AttributeError 'Credentials' object has no attribute 'universe_domain' Changes in python-google-cloud-kms: \- Update to 3.7.0 * Add support for Python 3.14 * Deprecate credentials_file argument \- from version 3.6.0 * Add PublicKeyFormat enums XWING_RAW_BYTES (used for KEM_XWING) and DER (186cef2) * Support KEY_ENCAPSULATION purpose and quantum-safe algorithms ML_KEM_768, ML_KEM_1024 and KEM_XWING (186cef2) \- from version 3.5.1 * [google-cloud-kms] A comment for enum value `DESTROYED` in enum `CryptoKeyVersionState` is changed (#13913) \- from version 3.5.0 * Adding eTag field to AutokeyConfig (5d7b972) * Updating docs for total_size field in KMS List APIs (5d7b972) \- Update BuildRequires and Requires from setup.py * Update to 3.4.1 * [Many APIs] Allow Protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) * from version 3.4.0 * Support PQC asymmetric signing algorithms ML_DSA_65 and SLH_DSA_SHA2_128s (#13538) * Add a PublicKeyFormat enum to allow specifying the format the * from version 3.3.1 * **deps:** Require grpc-google-iam-v1 >= 0.14.0 * from version 3.3.0 * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * from version 3.2.2 * Modify enum comment (#13410) * from version 3.2.1 * Code documentation improvements (#13366) * from version 3.2.0 * Add support for opt-in debug logging * Fix typing issue with gRPC metadata when key ends in -bin * A comment for enum `CryptoKeyVersionAlgorithm` is changed (#13305) * from version 3.1.1 * Disable universe-domain validation (#13243) * from version 3.1.0 * Add support for Python 3.13 (#13207) * from version 3.0.0 * Pagination feature is introduced for method ListKeyHandles in service Autokey * Adding a state field for AutokeyConfig * Pagination feature is introduced for method ListKeyHandles in service Autokey * A comment for field destroy_scheduled_duration in message .google.cloud.kms.v1.CryptoKey is updated for the default duration * Field service_resolvers in message .google.cloud.kms.v1.EkmConnection is Explicitly is marked as to have field behavior of Optional * from version 2.24.2 * Retry and timeout values do not propagate in requests during pagination * from version 2.24.1 * Allow Protobuf 5.x (#12867) * from version 2.24.0 * Support Key Access Justifications policy configuration * from version 2.23.0 * Add client library for KMS Autokey service, which enables automated KMS key provision and management * from version 2.22.0 * Introduce Long-Running Operations (LRO) for KMS * Adjust upstream source name in spec file * Update BuildRequires and Requires from setup.py * update to 2.21.4: * in google.cloud.kms.v1.PublicKey, pem field is always populated * Require google-api-core>=1.34.1 (#12307) (be87bc4) * fix ValueError in test__validate_universe_domain Changes in python-google-cloud-logging: \- Update to 3.12.1 * Make logging handler close conditional to having the transport opened (#990) \- from version 3.12.0 * Add REST Interceptors which support reading metadata * Add support for opt-in debug logging * Added flushes/close functionality to logging handlers (#917) * Allow protobuf 6.x (#977) * **deps:** Require google-cloud-audit-log >= 0.3.1 (#979) * Fix typing issue with gRPC metadata when key ends in -bin * Added documentation on log_level and excluded_loggers params in setup_logging (#971) * Update README to break infinite redirect loop (#972) \- from version 3.11.4 * Made `write_entries` raise `ValueError` on `ParseError`s (#958) * Require proto- plus >= 1.25 for Python 3.13 (#955) \- from version 3.11.3 * 16-bit hexadecimal formatting for XCTC span IDs (#946) \- from version 3.11.2 * **deps:** Require google-cloud-appengine-logging >= 0.1.3 * **deps:** Require google-cloud-audit- log >= 0.2.4 * **deps:** Require opentelemetry-api >= 1.9.0 * Fixed type hinting issue with specifying Transport class (#930) \- from version 3.11.1 * Allow protobuf 5.x (#888) \- from version 3.11.0 * OpenTelemetry trace/spanID integration for Python handlers (#889) * Added environment specific labels to client library when running in Cloud Run Jobs (#877) * Added missing import into logger.py (#896) * Added type hints to CloudLoggingHandler constructor (#903) * Add summary_overview template (#878) * Changed table in web-framework- integration to bulleted list (#875) * Documentation update for OpenTelemetry (#915) * Update `dictConfig` snippet (#885) \- Adjust upstream source name in spec file \- Update BuildRequires and Requires from setup.py * update to 3.10.0: * Allow users to explicitly configure universe domain * Added placeholder kwargs to StructuredLogHandler * Allowed for a partial override of loggers that get excluded from setup_client * Remove usage in including_default_value_fields to prepare for protobuf 5.x * Use value of cluster-location in GKE for tagging location Changes in python-google-cloud-run: \- Update to 0.11.0 * A type of an existing resource_reference option of the field `worker_pool` in message `.google.cloud.run.v2.SubmitBuildRequest` is changed from `cloudbuild.googleapis.com/WorkerPool` to `cloudbuild.googleapis.com/BuildWorkerPool` * A type of an existing resource_reference option of the field `worker_pool` in message `.google.cloud.run.v2.BuildConfig` is changed from `cloudbuild.googleapis.com/WorkerPool` to `cloudbuild.googleapis.com/BuildWorkerPool` * [google-cloud-run] An existing resource_definition `cloudbuild.googleapis.com/WorkerPool` is removed * Adding new resource tpye run.googleapis.com/WorkerPool. (077a8ff) * [google-cloud-run] An existing resource_definition `cloudbuild.googleapis.com/WorkerPool` is removed (077a8ff) * A type of an existing resource_reference option of the field `worker_pool` in message `.google.cloud.run.v2.BuildConfig` is changed from `cloudbuild.googleapis.com/WorkerPool` to `cloudbuild.googleapis.com/BuildWorkerPool` (077a8ff) * A type of an existing resource_reference option of the field `worker_pool` in message `.google.cloud.run.v2.SubmitBuildRequest` is changed from `cloudbuild.googleapis.com/WorkerPool` to `cloudbuild.googleapis.com/BuildWorkerPool` (077a8ff) \- from version 0.10.19 * Add new field `term_signal` to `.google.cloud.run.v2.TaskAttemptResult` (078e0e2) * Support GPU zonal redundancy setting for Cloud Run jobs (078e0e2) \- from version 0.10.18 * Support GPU zonal redundancy setting in Cloud Run services (2f33995) * Support node selector in Cloud Run jobs for GPU setting (2f33995) * Update to 0.10.17 * [Many APIs] Allow Protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) * from version 0.10.16 * **deps:** Require grpc-google-iam-v1 >= 0.14.0 * from version 0.10.15 * Add Base Image URI to Container * Add BuildConfig to Services for configuring Run functions * Add BuildInfo to Revision for displaying BuildConfig used for a specific revision deployment * Add creator field to Execution * Add project_descriptor to BuildspackBuild * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * Some typos were fixed and formatting changed * from version 0.10.14 * Add support for opt-in debug logging * Fix typing issue with gRPC metadata when key ends in -bin * from version 0.10.13 * Support manual instance count in Cloud Run for manual scaling feature * Update BuildRequires and Requires from setup.py * Update to 0.10.12 * Allow users to explicitly configure universe domain * Add google-auth as a direct dependency * Require google-api-core>=1.34.1 * Support mounting NFS and GCS volumes in Cloud Run Jobs and Services * add Job ExecutionReference.completion_status to show status of the most recent execution * add Builds API * Add support for Python 3.13 * support advanced configurations options for cloud storage volumes by setting mount_options in the GCSVolumeSource configuration * add EncryptionKeyRevocationAction and shutdown duration configuration to Services Changes in python-google-cloud-secret-manager: \- Update to 2.25.0 * Add support for Python 3.14 (4763aa7) * Deprecate credentials_file argument (4763aa7) \- from version 2.24.0 * [google-cloud-secret-manager] Update secret manager protos for tags (#13976) \- Update BuildRequires and Requires from setup.py * Update to 2.23.3 * Various documentation clarifications (#13796) * Update to 2.23.2: * Features * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * Add support for opt-in debug logging * Add support for Python 3.13 * Bug Fixes * [Many APIs] Allow Protobuf 6.x * remove setup.cfg configuration for creating universal wheels * deps: Require grpc-google-iam-v1>=0.14.0 * Fix typing issue with gRPC metadata when key ends in -bin * disable universe-domain validation * Retry and timeout values do not propagate in requests during pagination * Allow Protobuf 5.x * update to 2.20.0: * Add Secret Version Delayed Destroy changes for client libraries * Users can now enable secret version delayed destruction * update to 2.19.0: * clients for SecretManager API v1beta2 * Exclude google-auth 2.24.0 and 2.25.0 * Require google-api-core>=1.34.1 * fix ValueError in test__validate_universe_domain * Add google-auth as a direct dependency * Add staticmethod decorator to _get_client_cert_source and _get_api_endpoint * Resolve AttributeError 'Credentials' object has no attribute 'universe_domain' * Allow users to explicitly configure universe domain Changes in python-google-cloud-service-directory: \- Update to 1.14.2 * [Many APIs] Allow Protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) \- from version 1.14.1 * **deps:** Require grpc-google-iam-v1 >= 0.14.0 \- from version 1.14.0 * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML \- from version 1.13.0 * Add support for opt-in debug logging * Fix typing issue with gRPC metadata when key ends in -bin \- from version 1.12.1 * Disable universe-domain validation (#13245) \- from version 1.12.0 * Add support for Python 3.13 (#13209) \- from version 1.11.6 * Retry and timeout values do not propagate in requests during pagination \- from version 1.11.5 * Allow Protobuf 5.x (#12869) \- Adjust upstream source name in spec file \- Update BuildRequires and Requires from setup.py * update to 1.11.4: * add maximum page_size to ListEndpoint API documentation * add maximum page_size to ListNamespace API documentation * add maximum page_size to ListService API documentation * update to 1.11.3: * Exclude google-auth 2.24.0 and 2.25.0 * [Many APIs] Require google-api-core>=1.34.1 * fix ValueError in test__validate_universe_domain Changes in python-google-cloud-spanner: \- Drop python-google-cloud-monitoring from BuildRequires \- Skip tests that require python-google-cloud-monitoring * Replace bash scriptlet to remove mock usage from source code * Update to 3.58.0 * **spanner:** Support setting read lock mode (#1404) * Remove Python 3.7 and 3.8 as supported runtimes (#1395) * from version 3.57.0 * Support configuring logger in dbapi kwargs (#1400) * from version 3.56.0 * Add support for multiplexed sessions - read/write (#1389) * Add support for multiplexed sessions (#1383) * Default enable multiplex session for all operations unless explicitly set to false (#1394) * **spanner:** Add new change_stream.proto (#1382) * Skip gRPC trailers for StreamingRead & ExecuteStreamingSql (#1385) * from version 3.55.0 * Add a `last` field in the `PartialResultSet` (d532d57) * Add support for multiplexed sessions (#1381) * Add throughput_mode to UpdateDatabaseDdlRequest to be used by Spanner Migration Tool. See https://github.com/GoogleCloudPlatform/spanner- migration-tool (d532d57) * Support fine-grained permissions database roles in connect (#1338) * E2E tracing metadata append issue (#1357) * Pass through kwargs in dbapi connect (#1368) * Remove setup.cfg configuration for creating universal wheels (#1324) * A comment for field `chunked_value` in message `.google.spanner.v1.PartialResultSet` is changed (d532d57) * A comment for field `precommit_token` in message `.google.spanner.v1.PartialResultSet` is changed (d532d57) * A comment for field `precommit_token` in message `.google.spanner.v1.ResultSet` is changed (d532d57) * A comment for field `query_plan` in message `.google.spanner.v1.ResultSetStats` is changed (d532d57) * A comment for field `row_count_lower_bound` in message `.google.spanner.v1.ResultSetStats` is changed (d532d57) * A comment for field `row_type` in message `.google.spanner.v1.ResultSetMetadata` is changed (d532d57) * A comment for field `rows` in message `.google.spanner.v1.ResultSet` is changed (d532d57) * A comment for field `stats` in message `.google.spanner.v1.PartialResultSet` is changed (d532d57) * A comment for field `stats` in message `.google.spanner.v1.ResultSet` is changed (d532d57) * A comment for field `values` in message `.google.spanner.v1.PartialResultSet` is changed (d532d57) * A comment for message `ResultSetMetadata` is changed (d532d57) * A comment for message `ResultSetStats` is changed (d532d57) * Fix markdown formatting in transactions page (#1377) * from version 3.54.0 * Add interval type support (#1340) * Add sample for pre-split feature (#1333) * Add SQL statement for begin transaction isolation level (#1331) * Support transaction isolation level in dbapi (#1327) * Improve client-side regex statement parser (#1328) * Add missing test dependencies to BuildRequires * Update to 3.53.0 * Add AddSplitPoints API * Add Attempt, Operation and GFE Metrics (#1302) * Add REST Interceptors which support reading metadata * Add support for opt-in debug logging * Add support for reading selective GAPIC generation methods from service YAML * Add the last statement option to ExecuteSqlRequest and ExecuteBatchDmlRequest * Add UUID in Spanner TypeCode enum * End to end tracing (#1315) * Exposing FreeInstanceAvailability in InstanceConfig * Exposing FreeInstanceMetadata in Instance configuration (to define the metadata related to FREE instance type) * Exposing InstanceType in Instance configuration (to define PROVISIONED or FREE spanner instance) * Exposing QuorumType in InstanceConfig * Exposing storage_limit_per_processing_unit in InstanceConfig * Snapshot isolation (#1318) * **spanner:** A new enum `IsolationLevel` is added (#1224) * Allow Protobuf 6.x (#1320) * Cleanup after metric integration test (#1322) * **deps:** Require grpc-google-iam-v1 >= 0.14.0 * Fix typing issue with gRPC metadata when key ends in -bin * Add option for last_statement (#1313) * A comment for enum `DefaultBackupScheduleType` is changed * A comment for enum value `AUTOMATIC` in enum `DefaultBackupScheduleType` is changed * A comment for enum value `GOOGLE_MANAGED` in enum `Type` is changed * A comment for enum value `NONE` in enum `DefaultBackupScheduleType` is changed * A comment for enum value `USER_MANAGED` in enum `Type` is changed * A comment for field `base_config` in message `.google.spanner.admin.instance.v1.InstanceConfig` is changed * A comment for field `default_backup_schedule_type` in message `.google.spanner.admin.instance.v1.Instance` * A comment for field `filter` in message `.google.spanner.admin.instance.v1.ListInstanceConfigOperationsRequest` is changed * A comment for field `filter` in message `.google.spanner.admin.instance.v1.ListInstancePartitionOperationsRequest` is changed * A comment for field `instance_config` in message `.google.spanner.admin.instance.v1.CreateInstanceConfigRequest` is changed * A comment for field `instance_partition_deadline` in message `.google.spanner.admin.instance.v1.ListInstancePartitionOperationsRequest` is changed * A comment for field `location` in message `.google.spanner.admin.instance.v1.ReplicaInfo` is changed * A comment for field `node_count` in message `.google.spanner.admin.instance.v1.Instance` is changed * A comment for field `node_count` in message `.google.spanner.admin.instance.v1.InstancePartition` is changed * A comment for field `operations` in message `.google.spanner.admin.instance.v1.ListInstanceConfigOperationsResponse` is changed * A comment for field `operations` in message `.google.spanner.admin.instance.v1.ListInstancePartitionOperationsResponse` is changed * A comment for field `optional_replicas` in message `.google.spanner.admin.instance.v1.InstanceConfig` is changed * A comment for field `parent` in message `.google.spanner.admin.instance.v1.ListInstancePartitionsRequest` is changed * A comment for field `processing_units` in message `.google.spanner.admin.instance.v1.Instance` is changed * A comment for field `processing_units` in message `.google.spanner.admin.instance.v1.InstancePartition` is changed * A comment for field `referencing_backups` in message `.google.spanner.admin.instance.v1.InstancePartition` is changed * A comment for field `replicas` in message `.google.spanner.admin.instance.v1.InstanceConfig` is changed * A comment for field `storage_utilization_percent` in message `.google.spanner.admin.instance.v1.AutoscalingConfig` is changed * A comment for field `unreachable` in message `.google.spanner.admin.instance.v1.ListInstancePartitionsResponse` is changed * A comment for message `CreateInstanceConfigRequest` is changed * A comment for message `DeleteInstanceConfigRequest` is changed * A comment for message `UpdateInstanceConfigRequest` is changed * A comment for method `CreateInstance` in service `InstanceAdmin` is changed * A comment for method `CreateInstanceConfig` in service `InstanceAdmin` is changed * A comment for method `CreateInstancePartition` in service `InstanceAdmin` is changed * A comment for method `ListInstanceConfigOperations` in service `InstanceAdmin` is changed * A comment for method `ListInstanceConfigs` in service `InstanceAdmin` is changed * A comment for method `ListInstancePartitionOperations` in service `InstanceAdmin` is changed * A comment for method `MoveInstance` in service `InstanceAdmin` is changed * A comment for method `UpdateInstance` in service `InstanceAdmin` is changed * A comment for method `UpdateInstanceConfig` in service `InstanceAdmin` is changed * A comment for method `UpdateInstancePartition` in service `InstanceAdmin` is changed * Fix typo timzeone -> timezone * from version 3.52.0 * Add additional opentelemetry span events for session pool * Add GCP standard otel attributes for python client (#1308) * Add updated span events + trace more methods (#1259) * MetricsTracer implementation (#1291) * Support GRAPH and pipe syntax in dbapi (#1285) * Support transaction and request tags in dbapi (#1262) * **x-goog-spanner-request-id:** Introduce AtomicCounter (#1275) * Retry UNAVAILABLE errors for streaming RPCs (#1278) * **tracing:** Ensure nesting of Transaction.begin under commit * fix suggestions from feature review (#1287) * **tracing:** Only set span.status=OK if UNSET (#1248) * Update retry strategy for mutation calls to handle aborted transactions (#1279) * from version 3.51.0 * Add connection variable for ignoring transaction warnings (#1249) * **spanner:** Implement custom tracer_provider injection for opentelemetry traces (#1229) * Support float32 parameters in dbapi (#1245) * Allow setting connection.read_only to same value (#1247) * Allow setting staleness to same value in tx (#1253) * Dbapi raised AttributeError with [] as arguments (#1257) * Optimize ResultSet decoding (#1244) * Remove repeated GetSession calls for FixedSizePool (#1252) * **samples:** Add samples for Cloud Spanner Default Backup Schedules (#1238) * Update Suggests from setup.py * Update to 3.50.1 * Add BatchWrite API * spanner: Add autoscaling config to the instance proto * spanner: Add directed_read_option in spanner.proto * Add max_commit_delay API * Exposing Spanner client in dbapi connection * Add support of float32 type * Add support for PG.OID in parameterized queries * spanner: Adding EXPECTED_FULFILLMENT_PERIOD to the indicate instance creation times * Add support for Cloud Spanner Scheduled Backups * spanner: Add support for Cloud Spanner Default Backup Schedules * many more changes, see upstream CHANGELOG.md Changes in python-google-cloud-storage: \- Update to 3.4.1 * Fixes (#1561) by adding an option to specify the entire object checksum for resumable uploads via the `upload_from_string`, `upload_from_file`, and `upload_from_filename` methods. \- from version 3.4.0 * **experimental:** Add async grpc client (#1537) * **experimental:** Add grpc client (#1533) * GAPIC generation failed with 'Directory not empty' (#1542) \- Adjust python folder names in %files section * Update to 3.3.1 * Provide option to user to set entire object checksum at "initiate a resumable upload session" and send the same (#1525) * Send part's checksum for XML MPU part upload (#1529) * from version 3.3.0 * Add support for bucket IP filter (#1516) * Add logs on AssertionError for issue (#1512) * Update the documentation of move_blob function (#1507) * from version 3.2.0 * Adding support of single shot download (#1493) * from version 3.1.1 * Add a check for partial response data (#1487) * Add trove classifier for Python 3.13 (0100916) * **deps:** Require google-crc32c >= 1.1.3 (0100916) * **deps:** Require protobuf >= 3.20.2, < 7.0.0 (0100916) * **deps:** Require requests >= 2.22.0 (0100916) * Remove setup.cfg configuration for creating universal wheels (#1448) * Resolve issue where pre-release versions of dependencies are installed (0100916) * Segmentation fault in tink while writing data (#1490) * Move quickstart to top of readme (#1451) * Update README to break infinite redirect loop (#1450) * Add %{python_sitelib}/google/cloud/storage_v2 in %files section * Update BuildRequires and Requires from setup.py * Update to 3.1.0 * Add api_key argument to Client constructor (#1441) * Add Bucket.move_blob() for HNS-enabled buckets (#1431) * from version 3.0.0 * The default checksum strategy for uploads has changed from None to "auto" (#1383) * The default checksum strategy for downloads has changed from "md5" to "auto" (#1383) * Deprecated positional argument "num_retries" has been removed (#1377) * Deprecated argument "text_mode" has been removed (#1379) * Blob.download_to_filename() now deletes the empty destination file on a 404 (#1394) * Media operations now use the same retry backoff, timeout and custom predicate system as non-media operations, which may slightly impact default retry behavior (#1385) * Retries are now enabled by default for uploads, blob deletes and blob metadata updates (#1400) * Add "auto" checksum option and make default ([1383) * Blob.download_to_filename() deletes the empty destination file on a 404 (#1394) * Enable custom predicates for media operations (#1385) * Integrate google-resumable-media (#1283) * Retry by default for uploads, blob deletes, metadata updates (#1400) * Cancel upload when BlobWriter exits with exception (#1243) * Changed name of methods `Blob.from_string()` and `Bucket.from_string()` to `from_uri()` (#1335) * Correctly calculate starting offset for retries of ranged reads (#1376) * Filter download_kwargs in BlobReader (#1411) * Remove deprecated num_retries argument (#1377) * Remove deprecated text_mode argument (#1379) * Correct formatting and update README.rst (#1427) * Fix issue with exceptions.py documentation (#1328) * Refresh demock patch * Update BuildRequires and Requires from setup.py * Update to 2.19.0: * Features * Add integration test for universe domain * Add restore_bucket and handling for soft-deleted buckets * Add support for restore token * IAM signBlob retry and universe domain support * Bug Fixes * Allow signed post policy v4 with service account and token * Do not spam the log with checksum related INFO messages when downloading using transfer_manager * Update to 2.18.2: * Bug Fixes * Add regression test for range read retry issue and bump dependency to fix * Update to 2.18.1: * Bug Fixes * Properly escape URL construction for XML MPU API * Update to 2.18.0: * Features * Add OpenTelemetry Tracing support as a preview feature * Bug Fixes * Allow Protobuf 5.x * Correct notification error message * Update to 2.17.0: * Features * Support HNS enablement in bucket metadata * Support page_size in bucket.list_blobs * Bug Fixes * Remove deprecated methods in samples and tests * Documentation * Reference Storage Control in readme * Update DEFAULT_RETRY_IF_GENERATION_SPECIFIED docstrings * Update to 2.16.0: * Features * Add support for soft delete * Support includeFoldersAsPrefixes * Update to 2.15.0: * Features * Support custom universe domains/TPC * Bug Fixes * Add "updated" as property for Bucket * Remove utcnow usage Changes in python-google-cloud-vpc-access: \- Update to 1.13.2 * Update import statement example in README * Add missing BuildRequires on pytest-asyncio. * Update to 1.13.1 * [Many APIs] Allow Protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) * from version 1.13.0 * Add REST Interceptors which support reading metadata * Add support for reading selective GAPIC generation methods from service YAML * from version 1.12.0 * Add support for opt-in debug logging * Fix typing issue with gRPC metadata when key ends in -bin * from version 1.11.1 * Disable universe-domain validation (#13247) * from version 1.11.0 * Add support for Python 3.13 (#13210) * from version 1.10.5 * Retry and timeout values do not propagate in requests during pagination * Adjust upstream source name in spec file * Update BuildRequires and Requires from setup.py * update to 1.10.4: * Allow Protobuf 5.x * update to 1.10.3: * deps: [Many APIs] Require google-api-core > =1.34.1 * fix ValueError in test__validate_universe_domain * Add google-auth as a direct dependency * Add staticmethod decorator to _get_client_cert_source and _get_api_endpoint (e16032f) * Resolve AttributeError 'Credentials' object has no attribute 'universe_domain' Changes in python-google-crc32c: \- Update to 1.7.1 * Add Python 3.13 windows wheels \- from version 1.7.0 * Add Python 3.13 trove classifier (#233) * Add support for python 3.13 (#239) * update to 1.6.0: * Add support for python 3.12 * Build using Visual Studio 17 2022 instead of Visual Studio 16 2019 * Drop support for python 3.7 and 3.8 * Drop support for Windows 32bit which is not supported in Visual Studio 17 2022 * Remove manylinux1 which is no longer supported by PyPA Changes in python-google-resumable-media: \- Update to 2.7.2 * Correctly calculate starting offset for retries of ranged reads (#450) \- Adjust upstream source name in spec file * Update to 2.7.1 * Add a check for partial response data (#435) Changes in python-grpc-google-iam-v1: \- Update to 0.14.3 * Add support for Python 3.14 * Regenerate pb2 files with protoc v25.3 * Update to 0.14.2 * Allow protobuf 6.x * Remove setup.cfg configuration for creating universal wheels (#13659) * Resolve issue where pre-release versions of dependencies are installed * Resolve issue where pre-release versions of dependencies are installed (#13653) * Update to 0.14.1 * chore(python): Update the python version in docs presubmit to use 3.10 (#131) * chore: remove pb2 file generation during post processing step (#122) * chore: remove obsolete proto files (#123) * chore: add generation of pb2 files via owlbot/bazel (#124) * chore(python): exclude .github/workflows/unittest.yml in renovate config (#132) * build: update README to indicate that source has moved and delete all files (#135) * Update to 0.14.0 * Add `google.iam.v1.resource_policy_member_pb2` (2e1af7c) * Add support for Python 3.13 (2e1af7c) * Adjust upstream source name in spec file * Update to 0.13.1 * **deps:** Require protobuf >= 3.20.2, protobuf < 6 (ac15e1c) * Regenerate pb2 files for compatibility with protobuf 5.x (ac15e1c) Changes in python-grpc-interceptor: * Use Python 3.11 on SLE-15 by default * Add missing BuildRequires on pytest-asyncio. * Ship README and license in the binary packages. * Initial packaging (v0.15.4), needed by python-google-cloud-spanner Changes in python-mmh3: * Use upstream tarball * Initial packaging for mmh3 (version 4.1.0), needed by the OpenWebUI stack Changes in python-mypy: * Update to 1.5.1: * stubtest: Fix __mypy-replace false positives. * Update typing_extensions stubs. * Update test suite dependencies: * types_psutil_version 5.9.5.15 -> 5.9.5.16 * types_setuptools_version 68.0.0.2 -> 68.0.0.1 * Rename package from mypy to python-mypy. * Rename .spec, .changes and rpmlintrc files, accordingly. * Adjust rpmlintrc. * update to version 1.5.0: * Drop Support for Python 3.7 * Mypy no longer supports running with Python 3.7, which has reached end-of- life. This was contributed by Shantanu (PR 15566). * Optional Check to Require Explicit @override * If you enable the explicit-override error code, mypy will generate an error if a method override doesn?t use the @typing.override decorator (as discussed in PEP 698). This way mypy will detect accidentally introduced overrides. * You can enable the error code via --enable-error-code=explicit-override on the mypy command line or enable_error_code = explicit-override in the mypy config file. * The override decorator will be available in typing in Python 3.12, but you can also use the backport from a recent version of typing_extensions on all supported Python versions. * More Flexible TypedDict Creation and Update * Mypy was previously overly strict when type checking TypedDict creation and update operations. Though these checks were often technically correct, they sometimes triggered for apparently valid code. These checks have now been relaxed by default. You can enable stricter checking by using the new --extra-checks flag. * Deprecated Flag: --strict-concatenate * The behavior of --strict-concatenate is now included in the new --extra- checks flag, and the old flag is deprecated. * Optionally Show Links to Error Code Documentation * If you use --show-error-code-links, mypy will add documentation links to (many) reported errors. The links are not shown for error messages that are sufficiently obvious, and they are shown once per error code only. * Consistently Avoid Type Checking Unreachable Code * If a module top level has unreachable code, mypy won?t type check the unreachable statements. This is consistent with how functions behave. The behavior of --warn-unreachable is also more consistent now. * Experimental Improved Type Inference for Generic Functions * You can use --new-type-inference to opt into an experimental new type inference algorithm. It fixes issues when calling a generic functions with an argument that is also a generic function, in particular. This current implementation is still incomplete, but we encourage trying it out and reporting bugs if you encounter regressions. We are planning to enable the new algorithm by default in a future mypy release. * Partial Support for Python 3.12 * Mypy and mypyc now support running on recent Python 3.12 development versions. Not all new Python 3.12 features are supported, and we don?t ship compiled wheels for Python 3.12 yet. * Improvements to Dataclasses * Improve signature of dataclasses.replace (Ilya Priven, PR 14849) * Fix dataclass/protocol crash on joining types (Ilya Priven, PR 15629) * Fix strict optional handling in dataclasses (Ivan Levkivskyi, PR 15571) * Support optional types for custom dataclass descriptors (Marc Mueller, PR 15628) * Add **slots** attribute to dataclasses (Nikita Sobolev, PR 15649) * Support better **post_init** method signature for dataclasses (Nikita Sobolev, PR 15503) * Mypyc Improvements * Support unsigned 8-bit native integer type: mypy_extensions.u8 (Jukka Lehtosalo, PR 15564) * Support signed 16-bit native integer type: mypy_extensions.i16 (Jukka Lehtosalo, PR 15464) * Define mypy_extensions.i16 in stubs (Jukka Lehtosalo, PR 15562) * Document more unsupported features and update supported features (Richard Si, PR 15524) * Fix final NamedTuple classes (Richard Si, PR 15513) * Use C99 compound literals for undefined tuple values (Jukka Lehtosalo, PR 15453) * Don't explicitly assign NULL values in setup functions (Logan Hunt, PR 15379) * Stubgen Improvements * Teach stubgen to work with complex and unary expressions (Nikita Sobolev, PR 15661) * Support ParamSpec and TypeVarTuple (Ali Hamdan, PR 15626) * Fix crash on non-str docstring (Ali Hamdan, PR 15623) * Documentation Updates * Add documentation for additional error codes (Ivan Levkivskyi, PR 15539) * Improve documentation of type narrowing (Ilya Priven, PR 15652) * Small improvements to protocol documentation (Shantanu, PR 15460) * Remove confusing instance variable example in cheat sheet (Adel Atallah, PR 15441) * Other Notable Fixes and Improvements * Constant fold additional unary and binary expressions (Richard Si, PR 15202) * Exclude the same special attributes from Protocol as CPython (Kyle Benesch, PR 15490) * Change the default value of the slots argument of attrs.define to True, to match runtime behavior (Ilya Priven, PR 15642) * Fix type of class attribute if attribute is defined in both class and metaclass (Alex Waygood, PR 14988) * Handle type the same as typing.Type in the first argument of classmethods (Erik Kemperman, PR 15297) * Fix --find-occurrences flag (Shantanu, PR 15528) * Fix error location for class patterns (Nikita Sobolev, PR 15506) * Fix re-added file with errors in mypy daemon (Ivan Levkivskyi, PR 15440) * Fix dmypy run on Windows (Ivan Levkivskyi, PR 15429) * Fix abstract and non-abstract variant error for property deleter (Shantanu, PR 15395) * Remove special casing for "cannot" in error messages (Ilya Priven, PR 15428) * Add runtime **slots** attribute to attrs classes (Nikita Sobolev, PR 15651) * Add get_expression_type to CheckerPluginInterface (Ilya Priven, PR 15369) * Remove parameters that no longer exist from NamedTuple._make() (Alex Waygood, PR 15578) * Allow using typing.Self in **new** with an explicit @staticmethod decorator (Erik Kemperman, PR 15353) * Fix self types in subclass methods without Self annotation (Ivan Levkivskyi, PR 15541) * Check for abstract class objects in tuples (Nikita Sobolev, PR 15366) * Typeshed Updates * Typeshed is now modular and distributed as separate PyPI packages for everything except the standard library stubs. Please see git log for full list of typeshed changes. * Update to 1.4.1 * disable pep561 tests, as they fail on Python 3.11.4, see https://github.com/python/mypy/issues/15446 * Update to 1.4.0: * The Override Decorator * Propagating Type Narrowing to Nested Functions * Narrowing Enum Values Using ?==? * Performance Improvements * Skip over failing testMathOps (gh#python/mypy#15221). * Update to 1.3.0: * Improve performance of union subtyping * Add negative subtype caches * Stubtest: Check that the stub is abstract if the runtime is, even when the stub is an overloaded method * Stubtest: Verify stub methods or properties are decorated with @final if they are decorated with @final at runtime * Stubtest: Fix stubtest false positives with TypedDicts at runtime * Stubgen: Support @functools.cached_property * Improvements to stubgenc * Add support for converters with TypeVars on generic attrs classes * Fix attrs.evolve on bound TypeVar * Improve async documentation * Improvements to cheat sheet * Add documentation for bytes formatting error code * Convert insecure links to use HTTPS * Also mention overloads in async iterator documentation * stubtest: Improve allowlist documentation * Clarify "Using types... but not at runtime" * Fix alignment of cheat sheet example * Fix error for callback protocol matching against callable type object * Improve bytes formatting error * Fix unions of bools and ints * Fix narrowing union types that include Self with isinstance * Allow objects matching SupportsKeysAndGetItem to be unpacked * Check type guard validity for staticmethods * Fix sys.platform when cross-compiling with emscripten * add sle15_python_module_pythons * update typed_ast to version 1.5.8.6 * update types_psutil to version 5.9.5.12 * update types_setuptools to version 67.7.0.1 * fix "E: wrong-script-end-of-line-encoding" and "E: spurious-executable-perm" for docs/make.bat * fix "W: python-doc-in-package" for %{$python_sitelib}/mypyc/doc in Python 3.9, 3.10 and 3.11 * update mypy to version 1.2.0: * Improvements to Dataclass Transforms * Support implicit default for "init" parameter in field specifiers (Wesley Collin Wright and Jukka Lehtosalo, PR 15010) * Support descriptors in dataclass transform (Jukka Lehtosalo, PR 15006) * Fix frozen_default in incremental mode (Wesley Collin Wright) * Fix frozen behavior for base classes with direct metaclasses (Wesley Collin Wright, PR 14878) * Mypyc: Native Floats * Mypyc now uses a native, unboxed representation for values of type float. Previously these were heap-allocated Python objects. Native floats are faster and use less memory. Code that uses floating-point operations heavily can be several times faster when using native floats. * Various float operations and math functions also now have optimized implementations. Refer to the documentation for a full list. * This can change the behavior of existing code that uses subclasses of float. When assigning an instance of a subclass of float to a variable with the float type, it gets implicitly converted to a float instance when compiled * Previously, implicit conversions were applied to int subclasses but not float subclasses. * Also, int values can no longer be assigned to a variable with type float in compiled code, since these types now have incompatible representations. An explicit conversion is required. * This restriction only applies to assignments, since they could otherwise narrow down the type of a variable from float to int. int values can still be implicitly converted to float when passed as arguments to functions that expect float values. * Note that mypyc still doesn?t support arrays of unboxed float values. Using list[float] involves heap-allocated float objects, since list can only store boxed values. Support for efficient floating point arrays is one of the next major planned mypyc features. * Related changes: * Use a native unboxed representation for floats (Jukka Lehtosalo, PR 14880) * Document native floats and integers (Jukka Lehtosalo, PR 14927) * Fixes to float to int conversion (Jukka Lehtosalo, PR 14936) * Mypyc: Native Integers * Mypyc now supports signed 32-bit and 64-bit integer types in addition to the arbitrary-precision int type. You can use the types mypy_extensions.i32 and mypy_extensions.i64 to speed up code that uses integer operations heavily. * Refer to the documentation for more information. This feature was contributed by Jukka Lehtosalo. * Other Mypyc Fixes and Improvements * Support iterating over a TypedDict (Richard Si, PR 14747) * Faster coercions between different tuple types (Jukka Lehtosalo, PR 14899) * Faster calls via type aliases (Jukka Lehtosalo, PR 14784) * Faster classmethod calls via cls (Jukka Lehtosalo, PR 14789) * Fixes to Crashes * Fix crash on class-level import in protocol definition (Ivan Levkivskyi, PR 14926) * Fix crash on single item union of alias (Ivan Levkivskyi, PR 14876) * Fix crash on ParamSpec in incremental mode (Ivan Levkivskyi, PR 14885) * Documentation Updates * Update adopting --strict documentation for 1.0 (Shantanu, PR 14865) * Some minor documentation tweaks (Jukka Lehtosalo, PR 14847) * Improve documentation of top level mypy: disable-error-code comment (Nikita Sobolev, PR 14810) * Error Reporting Improvements * Add error code to typing_extensions suggestion (Shantanu, PR 14881) * Add a separate error code for top-level await (Nikita Sobolev, PR 14801) * Don?t suggest two obsolete stub packages (Jelle Zijlstra, PR 14842) * Add suggestions for pandas-stubs and lxml-stubs (Shantanu, PR 14737) * Other Fixes and Improvements * Multiple inheritance considers callable objects as subtypes of functions (Christoph Tyralla, PR 14855) * stubtest: Respect @final runtime decorator and enforce it in stubs (Nikita Sobolev, PR 14922) * Fix false positives related to type[] (sterliakov, PR 14756) * Fix duplication of ParamSpec prefixes and properly substitute ParamSpecs (EXPLOSION, PR 14677) * Fix line number if **iter** is incorrectly reported as missing (Jukka Lehtosalo, PR 14893) * Fix incompatible overrides of overloaded generics with self types (Shantanu, PR 14882) * Allow SupportsIndex in slice expressions (Shantanu, PR 14738) * Support if statements in bodies of dataclasses and classes that use dataclass_transform (Jacek Cha?upka, PR 14854) * Allow iterable class objects to be unpacked (including enums) (Alex Waygood, PR 14827) * Fix narrowing for walrus expressions used in match statements (Shantanu, PR 14844) * Add signature for attr.evolve (Ilya Konstantinov, PR 14526) * Fix Any inference when unpacking iterators that don't directly inherit from typing.Iterator (Alex Waygood, PR 14821) * Fix unpack with overloaded **iter** method (Nikita Sobolev, PR 14817) * Reduce size of JSON data in mypy cache (dosisod, PR 14808) * Improve ?used before definition? checks when a local definition has the same name as a global definition (Stas Ilinskiy, PR 14517) * Honor NoReturn as **setitem** return type to mark unreachable code (sterliakov, PR 12572) * Update to 1.1.1: * Support for dataclass_transform (as defined in PEP-681). * Dedicated Error Code for Method Assignments * Stubgen improvements * Stubtest improvements * Typeshed updates * Plenty of fixes * Removed upstreamed patch I64Cast fix patch * Sadly, six is still required for tests, re-add to BuildRequires. * add test I64 Cast fix test patch to make it working (gh#python/mypy#14691). * Skip failing test testI64Cast (gh#python/mypy#14633). * Update to 1.0.0 (YAY!): * Mypy 1.0 is up to 40% faster than mypy 0.991 when type checking the Dropbox internal codebase. We also set up a daily job to measure the performance of the most recent development version of mypy to make it easier to track changes in performance. * Warn About Variables Used Before Definition * Detect Possibly Undefined Variables (Experimental) * Support the ?Self? Type * Support ParamSpec in Type Aliases * ParamSpec and Generic Self Types No Longer Experimental * Miscellaneous New Features * plenty of bug fixes * Update to 0.991 * Basic Python 3.11 Support * Breaking Change: No Implicit Optional Types for Arguments * Breaking Change: Namespace Packages Enabled by Default * Recursive Types Enabled By Default * Error Codes Shown by Default * Safe Handling of Empty Function Bodies * Enabling Experimental Features Individually * Configuring Packages/Modules in the Config File * Warn about Variable Annotations in Unchecked Functions * Error Code for Using an Abstract Class as type[T] * Performance Improvements * Changes to Error Reporting and Messages * Remove walrus patch. * Update to 0.981 * Drop support for Python3.6 and python2 * Generate Error on Unbound TypeVar Return Type * Methods with Empty Bodies in Protocols Are Abstract * Implicit Optional Types Will Be Disabled by Default * Precise Types for **kwds Using TypedDict * Experimental Support for General Recursive Types * Generic NamedTuples and TypedDicts * Better Support for Callable Attributes * Per-Module Error Code Configuration * Experimental Support for Interactive Inspection of Expressions * Mypyc Improvements * Support async for as a statement and in comprehensions (Michael J. Sullivan, PR 13444) * Support async with (Michael J. Sullivan, PR 13442) * Fix clang warning on different signs integer (Paul m. p. Peny, PR 13239) * Fix AttributeError message (Jukka Lehtosalo, PR 13382) * Fix **call** subclasses (Ken Jin, PR 13152) * Fix setup conflict with attributes named up (davfsa, PR 13012) * Fix bad C generated for multiple assignment (Jukka Lehtosalo, PR 13147) * Update, simplify check version test (Shantanu, PR 13125) The full release notes can be found here: https://mypy-lang.blogspot.com/2022/09/mypy-0981-released.html * Update Requirements * Add walrus patch * fix test failures with Python >= 3.10.6 * Update to 0.971: * Last Release Officially Supporting Python 2 and 3.6: * Support for Python 2 will be completely removed in the next mypy feature release after this one, mypy 0.980. * Support for Python 3.6 will also be dropped in mypy 0.980, since Python 3.6 has reached its end of life. It will be still possible to target Python 3.6 using --python-version in future mypy versions, but no bugs will be fixed that affect only Python 3.6 (unless they are regressions). Also note that typeshed just recently dropped Python 3.6 support, so standard library features only available in Python 3.6 will not be supported. on https://mypy-lang.blogspot.com/2022/07/mypy-0971-released.html * Mypyc Improvements and Fixes * Speed up accessing always defined native attributes (Jukka Lehtosalo, PR 12600) * Reduce the overhead of reference counting (Jukka Lehtosalo, PR 12805, PR 12810, PR 12817) * Fix Python 3.11 C API errors (97littleleaf11, PR 12850) * Generate smaller code for casts and some implicit type coercions (Jukka Lehtosalo, PR 12839) * Optimize calling Python objects with zero or one arguments (97littleleaf11, PR 12862) * Replace integer floor division by a power of two with a shift (Jukka Lehtosalo, PR 12870) * Add primitives for faster access of float and tuple type objects (Richard Si, PR 13078) * Fix compile error related to operator assignment in a generator function (Zsolt Dollenstein, PR 13144) * Stubtest Improvements * Allow ellipsis as default argument (Shantanu, PR 12838) * Support --version (Shantanu, PR 12852) * Check type variables and ParamSpecs (Shantanu, PR 12851) * Add error summary and other output tweaks (KotlinIsland, PR 12855) * Other Notable Fixes and Improvements * Disallow assignments to awaited coroutines that do not return (Shantanu, PR 12853) * Search sys.path for PEP 561 compliant packages (Ashley Whetter, PR 11143) * Treat generators with await as async (Jared Hance, PR 12925) * Fix bug in constraints solver regarding ParamSpec upper bounds (Alex Waygood, PR 12938) * Fix crash on redefined class variable annotated with Final[] (Alex Waygood, PR 12951) * Improve handling of overloads with ParamSpec (Alex Waygood, PR 12953) * Don?t suggest installing types packages for some third-party packages that now include types or are obsolete (Shantanu, PR 12959) * Add a short note when an error may be fixed by adding an await (Ivan Levkivskyi, PR 12958) * Support unannotated converters for attr.ib (t4lz, PR 12815) * Disallow undesirable implicit reexport with a from import (Shantanu, PR 12704) * Fix crash when subclass method has the same name as a type alias (Wesley Collin Wright, PR 13015) * Include end column offset in the mypy AST (bruno messias, PR 12972) * Fix "attribute 'arguments' of 'FuncDef' undefined" incremental crash (Fr?d?ric Perrin, PR 12324) * Fix false positive error on multiple enum base classes (Alex Waygood, PR 12963) * Don't add **match_args** for dataclasses and named tuples on Python versions lower than 3.10 (Stanislav K, PR 12503) * Fix crash when overriding partial-type attribute with method (Jake Lishman, PR 12943) * Fix editable installs to current working directory (Shantanu, PR 13161) * Typeshed is now modular and distributed as separate PyPI packages for everything except the standard library stubs. Please see git log for full list of typeshed changes. * remove obsolete patch stringent err msg patch * update to version 0.960: * Recognise typing.LiteralString and typing_extensions.LiteralString as aliases to str. * This does not add proper support for LiteralString, but this allows it to be used in type annotations and stubs. LiteralString will be included in Python 3.11 (PEP 675), and it can be used to require that a value is an arbitrary literal string (once fully supported). * Per-file Timing Stats * When mypy is run with the (currently hidden) --timing-stats FILE option, mypy will record detailed information about time spent type checking each file (microseconds). When profiling mypy runs over a large codebase, it can be useful to know which files are the slowest to type check. We are happy to receive bug reports about unexpectedly slow type checking. * Performance Improvements * Cache type of container literals when possible (Hugues, PR 12707) * Speed up type checking of nested if expressions (Hugues, PR 12700) * Speed up type checking of container literals with tuple entries (Hugues, PR 12706) * Speed up argument count check (Hugues, PR 12703) * Speed up processing large error counts and improve error filtering (Hugues, PR 12631) * Experimental Fast Module Lookup * Use the new --fast-module-lookup to switch to an alternative import resolution implementation that is faster when a large number of folders share a top-level namespace. We?d like to hear if you notice an improvement when using this flag, so that we can potentially prioritize work to enable this by default. * Documentation Updates * Add information about classes and types to ?Getting started? (Michael Lee, PR 6557) * Mention no_type_check decorator in documentation (Shantanu, PR 12713) * Remove most mentions of type comments from docs (Shantanu, PR 12683) * Use PEP 585 syntax in "The type of class objects" (Alex Waygood, PR 12516) * Improvements to Plugin System * Add a class attribute hook to the plugin system (Danny Weinberg, PR 9881) * Add an alternative class decorator hook that is less error-prone than the old one (Jukka Lehtosalo, PR 12762) * ParamSpec Improvements * Friendlier errors for ParamSpec (PEP 612) (Shantanu, PR 12832) * Fix ParamSpec crash related to Any types (EXPLOSION, PR 12548) * Use tuple[object, ...] and dict[str, object] as upper bounds for ParamSpec.args and ParamSpec.kwargs (Alex Waygood, PR 12668) * Fixes to Crashes * Fix crash on invalid Python executable (Pranav Rajpal, PR 12812) * Fix crash on type alias definition inside dataclass declaration (Alex Waygood, PR 12792) * Fix crash related to namedtuple in unannotated function (Jukka Lehtosalo, PR 12804) * Fix nested namedtuple crash in incremental mode (Jukka Lehtosalo, PR 12803) * Fix forward references and generic inheritance in attrs classes (Jukka Lehtosalo, PR 12772) * mypyc: Fix TypeError in lambda argument to overloaded function (Jukka Lehtosalo, PR 12780) * Fix crashes related to functools.total_ordering and forward references (Jukka Lehtosalo, PR 12767) * Fix crashes related to dataclasses and forward references (Jukka Lehtosalo, PR 12762) * Fix crash on invalid TypedDict definition (Alex Waygood, PR 12741) * Fix crash when using decorator in class scope (dzcode, PR 12724) * Other Notable Fixes and Improvements * Fix type annotation support of dunder methods in stubgen (Fabian Keller, PR 12828) * Fix some value patterns in match statements to be non-exhaustive (?t?p?n Hor??ek, PR 12751) * Generate error when using both abstractmethod and final (Tomoki Nakagawa, PR 12743) * Add more precise error message for Callable annotation (frerikandriessen, PR 12518) * Fix generic inference in functions with TypeGuard (Nikita Sobolev, PR 11797) * Add check if python_version was parsed as float in pyproject.toml (Marcel Otoboni, PR 12558) * Fix nested overload merging (Marc Mueller, PR 12607) * stubtest: Generate error if type alias doesn't exist at runtime (Alex Waygood, PR 12608) * Support typing_extensions.overload (Jelle Zijlstra, PR 12602) * update to version 0.950: * Recent third-party library stubs available via types-* packages (e.g. types- requests) are actively using recent typing features that may not be supported by older mypy releases. We recommend that if you pin mypy to a specific version, you should also pin any stub packages to a version no more recent than the mypy release. Otherwise the mypy version you use may silently fall back to Any types if it encounters annotation syntax that it can?t process. It?s fine to continue using older versions of stubs when you upgrade mypy. * Note also that recent versions of many third-party stub packages don?t support Python 2 any more. If you are using mypy to type check Python 2 code, it?s important to pin all stub packages to versions that still support Python 2. Generally stub package versions: in Feb 2022 or earlier still support Python 2 (assuming that they supported Python 2 at all). * New Features: Concatenate and Literals with ParamSpec * It?s now possible to precisely annotate decorators that add/remove arguments, using ParamSpec together with typing.Concatenate (Python 3.10 or later) or typing_extensions.Concatenate. The decorator in this example provides an implicit Request argument to the decorated function. * New Feature: Detect Unused Coroutines and Awaitables * Now mypy will give an error if you forget to await a coroutine: * If you enable the unused-awaitable error code, mypy will also complain about any unused value that supports **await**. This is not enabled by default, since this can cause false positives. * New Feature: assert_type * You can now use typing_extensions.assert_type to ask mypy to validate that an expression has a specific static type. Mypy will report an error if the inferred type is not as expected: * from typing_extensions import assert_type * assert_type([1], list[int]) # OK * # Error: Expression is of type "List[int]", not "List[str]" * assert_type([1], list[str]) * This can be used to validate that the expected type is inferred by mypy when calling a complex overloaded function, for example. At runtime assert_type just returns the first argument and doesn?t perform a runtime type check. * Mypyc Fixes and Improvements * Fix overflow in id built-in (Ekin Dursun, PR 12332) * Simplify generated code for native attribute get (Jukka Lehtosalo, PR 11978) * Implement close method for generators (Max Shvets, PR 12042) * Use more accurate flags with msvc (KotlinIsland, PR 12468) * Fix potential memory leak with setdefault() (Jukka Lehtosalo, PR 12514) * Make boxed integer constants/literals faster (Jukka Lehtosalo, PR 12507) * Performance Improvements * Mypy now type checks somewhat faster, in particular when dealing with enums and unions with many items. * Speed up union types (Jukka Lehtosalo, PR 12541, PR 12519) * Speed up subtype checks (Jukka Lehtosalo, PR 12540, PR 12538, PR 12536, PR 12539) * Speed up type checking enums (Hugues, PR 12032) * Speed up union types further (Hugues, PR 12630) * Documentation Improvements * Use Furo theme for documentation (97littleleaf11, PR 12348) * Add missing enable_error_code to config documentation (Mathieu Kniewallner, PR 12346) * Correct example in ?Annotation issues at runtime? (Alex Waygood, PR 12356) * Fix inaccuracy: NoneType is exposed in the types module on Python 3.10+ (Alex Waygood, PR 12515) * Stubgen Improvements * Fix handling of Protocol (citruz, PR 12129) * Use _typeshed.Incomplete instead of typing.Any (Sebastian Rittau, PR 12449) * Do not consider nested generators (?t?p?n Hor??ek, PR 12463) * Fix behavior for instance variables in C extensions (Shubham SInghal, PR 12524) * Stubtest Improvements * Generate error for read-only property at runtime, but not in stub (Alex Waygood, PR 12291) * Enable verification of **match_args** attributes (Alex Waygood, PR 12465) * Other Notable Fixes and Improvements * Use tomllib on Python 3.11 (Shantanu, PR 12305) * Print compilation status with --version (Shantanu, PR 12318) * Fix **annotations** being undefined (Niklas Gustafsson, PR 10969) * Add success message for notes-only output (97littleleaf11, PR 12306) * dmypy: Warn instead of failing if report generation is configured (Nate McMaster, PR 10181) * Fix caching of PEP 561 namespace packages with missing submodules (Shantanu, PR 12250) * Fix empty reveal_locals output (Cibin Mathew, PR 12400) * Check that async for/with is inside an async function (?t?p?n Hor??ek, PR 12418) * Recognize Hashable as a real protocol (Nikita Sobolev, PR 11802) * Remove the * for inferred types from reveal_type output (Stanislav K, PR 12459) * Unify a codepath in typevarlike semanal (Jared Hance, PR 12480) * Recognise both attrs and attr package names (Spencer Brown, PR 12469) * Fix Callable attributes in frozen dataclasses (Jordan Speicher, PR 12383) * Improve checking of **slots** (Jukka Lehtosalo, PR 12531) * Avoid conflicts between type variables defined in different classes (Jukka Lehtosalo, PR 12590) * Fix **slots** and **deletable** in incremental mode (Jukka Lehtosalo, PR 12645) * Fix issue with ParamSpec serialization (Jukka Lehtosalo, PR 12654) * Fix types of inherited attributes in generic dataclasses (Jukka Lehtosalo, PR 12656) * Add stringent-err-msg patch to make mypy work with more stringent error messages in Python >= 3.10.3 (gh#python/mypy#12451). * Update to version 0.942: * Fixes to Regressions: * Let overload item have a more general return type than the implementation (Jukka Lehtosalo, PR 12435) * Fix inheritance false positives with dataclasses/attrs (Jukka Lehtosalo, PR 12411) * Support overriding dunder attributes in Enum subclass (Petter Friberg, PR 12138) * Fix small conditional overload regression (Marc Mueller, PR 12336) * Other Fixes: * Fix issues related to the order of processing in the builtins import cycle (Jukka Lehtosalo, PR 12431) * Fix crash in match statement if class name is undefined (Jukka Lehtosalo, PR 12417) * Allow non-final **match_args** and overriding (Jukka Lehtosalo, PR 12415) * Update to version 0.941: * No changelog available. * Update to version 0.940: * Match Statement Mypy now has experimental support for type checking match statements introduced in Python 3.10. * Python 2 End-of-Life Schedule After this release, Python 2 support is in feature freeze. Mypy won?t add new features or fixes specific to type checking Python 2 code, expect for fixes of significant regressions. Mypy will drop Python 2 support in the second half of 2022. Important note: Since typeshed is in the process of removing Python 2 specific stubs, you should pin all installed typeshed stub packages for third-party libraries to a version from Feb 2022 or earlier if you want to type check Python 2 code. * Miscellaneous New Features * Add support for conditionally defined overloads (Marc Mueller, PR 10712) * Give "as" variables in with statements separate scopes when it is safe to do so (Jukka Lehtosalo, PR 12254) * Add an optional error code ignore-without-code to require ignore comments to have error codes (Peter Law, PR 11633) * Add support for typing.Never and typing_extensions.Never as alternative spellings of NoReturn (Jelle Zijlstra, PR 12153) * Add support for typing.reveal_type (Jelle Zijlstra, PR 12117) * Support universal2 macOS wheels (97littleleaf11, PR 10651) * Add match_args support to attr.s() (Nikita Sobolev, PR 12111) * Enum Improvements * Check Enum definition for invalid base classes (Nikita Sobolev, PR 12026) * Understand the self-destructing nature of Enum._ignore_ (Kenny Stauffer, PR 12128) * Add StrEnum support for Python 3.11 (Nikita Sobolev, PR 12035) * Make enum values final (joey-laminar, PR 11962) * Improve final detection for Enum (Nikita Sobolev, PR 11984) * Fix Enum final properties and writable special members (Nikita Sobolev, PR 11945) * Enum now accepts String literals and final values as 2nd argument (Vincent Perez, PR 8664) * Fix false positive about member name reuse in enum (Max Rossmannek, PR 11972) * Fix enum inheritance regression (Nikita Sobolev, PR 12260) * Mypyc Fixes and Improvements * Use Py_TYPE and Py_IsNone (97littleleaf11, PR 12233) * Implement additional internal consistency checks (Jared Hance, PR 12191) * Raise AttributeError also for non-refcounted types (Jukka Lehtosalo, PR 11940) * Fix invalid unlikely() in certain rare branches (Jukka Lehtosalo, PR 11939) * Skip no-op super calls to object.**init**() (Jukka Lehtosalo, PR 11938) * Use latest pythoncapi_compat (97littleleaf11, PR 12188) * Add helpful message to assert (Joshua Cannon, PR 12119) * Documentation Updates * Add documentations about Enum types (Nikita Sobolev, PR 11805) * Update Enum documentation (Nikita Sobolev, PR 12238) * Improve documentation of allow_redefinition (KotlinIsland, PR 11951) * Fix intelligent indexing example (Chris Keefe, PR 11973) * Explain generic Protocol[T1, T2, ...] shorthand (Matt Bogosian, PR 12047) * Clarify that stub-only packages need to be installed (Gustav Gr?nsbo, PR 9958) * Small documentation improvements for conditional overloads (Marc Mueller, PR 12283) * Improved Error Messages * Improve the "Argument must be a mapping" error message (Purna Chandra Mansingh, PR 12222) * Coalesce Literals when printing unions (Marti Raudsepp, PR 12205) * Suggest typing.Callable when using callable as type (Tuomas Siipola, PR 12204) * Suggest typing.Any when using any as type (Tuomas Siipola, PR 12185) * Add note about wrong error code in type: ignore (Jukka Lehtosalo, PR 12067) * Add no-overload-impl error code (Brian Phillips, PR 11944) * Display ellipsis when formatting variadic tuple[T, ...] (Marti Raudsepp, PR 11857) * Deduplicate error codes for ignore-without-code (Marc Mueller, PR 12194) * Tweak ignore-without-code error message (Marc Mueller, PR 12216) * Mention common resolutions for build errors (Shantanu, PR 12154) * Stubtest Improvements * Ignore more dunder positional-only errors (Shantanu, PR 12294) * Fix wrong assumption about relative path (Stanislav Levin, PR 12282) * Catch more getattr errors (Shantanu, PR 12219) * Error if module level dunder is missing, housekeeping (Shantanu, PR 12217) * Ignore **main** module (Shantanu, PR 12218) * Error if a dunder method is missing from a stub (Alex Waygood, PR 12203) * Error if a function is async at runtime but not in the stub (and vice versa) (Alex Waygood, PR 12212) * Do not error if a stub is async, but runtime is not (Alex Waygood, PR 12234) * Error if a class should be decorated with @final (Akuli, PR 12091) * Use VERSIONS for submodules (Shantanu, PR 12083) * Treat dicts as a subtype of typeddict (Shantanu, PR 12040) * Ignore more exceptions in stubtest (Jelle Zijlstra, PR 11946) * Other Notable Fixes and Improvements * Fix non-default keyword-only argument positioning in stubgen (?t?p?n Hor??ek, PR 12303) * Remove orjson stubs from default list (Shantanu, PR 12264) * Use **truediv** for Python 2 with **future** import (Nikita Sobolev, PR 11787) * Fix Python 2 compatibility issue (Shantanu, PR 12244) * Use type variable bound to infer constraints (Jukka Lehtosalo, PR 12230) * Handle raise Exception(), None on Python 2.7 (Nikita Sobolev, PR 11786) * Fix inference of protocol against overloaded function (Jukka Lehtosalo, PR 12227) * Fix an issubclass failure for protocols with overloaded methods (Bas van Beek, PR 9904) * Fix crashes in class scoped imports (PR 12199, PR 12023) (Shantanu) * Fix use of TypeAlias from aliased imports (Shantanu, PR 12180) * Delete open plugin (Shantanu, PR 9275) * Read pyproject.toml with correct encoding on Windows (Dominic Davis-Foster, PR 12105) * Fix issue with implicit type aliases in import cycles (but only for stubs) (Alex Waygood, PR 11915) * Forbid extra ParamSpec arguments (Nikita Sobolev, PR 12024) * Fix crash involving explicit any flag and Required (Mehdi Drissi, PR 12039) * Fix join of Any against a union type (Jukka Lehtosalo, PR 12068) * Simplify unions when erasing last known values (Jukka Lehtosalo, PR 12064) * Fix crash with yield in comprehension (Alexandre Bouayad, PR 12048) * Fix handling of NoReturn in union return types (Jannic Warken, PR 11996) * Fix **init** in dataclasses inheriting from Any (joey-laminar, PR 11966) * Narrow NamedTuple to bool correctly when **bool** is defined (Nikita Sobolev, PR 11822) * Improve type of **attrs_attrs** in attrs classes (Tin Tvrtkovi?, PR 11794) * Install dependencies needed for reports via pip install mypy[reports] (James Braza, PR 11777) * Consider import * to be an explicit re-export (Shantanu, PR 11867) * Fix --no-implicit-reexport inconsistency (Shantanu, PR 11707) * Fix crash if "_" is in builtins (StefanM-TT, PR 11811) * Fixes crash on subclassing Annotated without args (Nikita Sobolev, PR 11814) * Typeshed Updates * Typeshed is now modular and distributed as separate PyPI packages for everything except the standard library stubs. Please see git log for full list of typeshed changes. * Skip teststubtest because we use a pytest-xdist version which is not allowed by upstream -- gh#python/mypy#11019 * Update to version 0.931: * Fixes to Regressions * Fix mypyc binary wheel (Michael R. Crusoe, PR 11862) * Revert to treating multi-line strings as a single value for exclude in TOML files (Matt Bogosian, PR 11828) * Revert to treating exclude in .ini as a single value (Matt Bogosian, PR 11881) * Fix **slots** regression (Nikita Sobolev, PR 11824) * Fix regression with **module** and similar non-final Enum attributes (Nikita Sobolev, PR 11823) * Fix regression when a contextmanager yields a generic function (Anthony Sottile, PR 11870) * Fix **reduce** regression (Shantanu, PR 11866) * Fix NoReturn type aliases (Nikita Sobolev, PR 11912) * Fix regression in None handling with --no-strict-optional (Nikita Sobolev, PR 11717) * Fix crash related to generics (Nikita Sobolev, PR 11924) * Restore removed builtin_type() plugin API method (Jukka Lehtosalo, PR 11932) * Other Fixes * Always allow the use of type[T] in stubs (Nikita Sobolev, PR 11863) * Fix PEP 585 type aliases in stubs (Shantanu, PR 11918) * Fix bug with literal types in stubtest (Nikita Sobolev, PR 11931) * Need typed_ast for all flavors in testing * Skip failing tests on 32-bit: gh#python/mypy#11148 * add missing g++ compiler for tests * add python-psutil as optional dependency. * Update requirements * Reenable testsuite by including the typed_ast stubs manually * Update to version 0.930: * New Feature: Explicit Type Aliases (PEP 613) * You can now explicitly mark an assignment as a type alias, by using typing.TypeAlias * For more context, see the docs or PEP 613. * New Feature: NotRequired in TypedDicts * You can now define individual TypedDict items as non-required by using typing_extensions.NotRequired. Previously this could only be configured at TypedDict level (by using total=). * You can also use typing_extensions.Required to mark an item as required in a non-total TypedDict. * New Feature: ParamSpec (Experimental) * Mypy now partially support ParamSpec, which was introduced in Python 3.10. This makes it possible to define type variables that range over the parameter specification of a callable type. In particular, it allows giving precise types for some decorators that change the return type of the decorated function. * Miscellaneous New Features * Define a GitHub Action that makes it easier to run mypy in GitHub CI workflows (Elvis Pranskevichus, PR 11320) * Allow mypy to run self check on PyPy 3.8 beta (Ethan Smith, PR 11350) * Check that enum values are unique (Nikita Sobolev, PR 11267) * Make enum classess with values implicitly final (Nikita Sobolev, PR 11247) * Make enum members implicitly final (Nikita Sobolev, PR 10852) * Allow NamedTuple to be used as a type that accepts all named tuples, as an experimental extension (Nikita Sobolev, PR 11162) * Allow booleans to be narrowed to literal types (Ethan Leba, PR 10389) * Add slots=True support for @dataclass (Nikita Sobolev, PR 11483) * Add slots=True support for @attr.s (Nikita Sobolev, PR 11489) * Support the typing_extensions.OrderedDict alias (Nikita Sobolev, PR 11533) * Usability and Documentation Improvements * Add better NamedTuple error messages (Nikita Sobolev, PR 11127) * Show all overloads in error message (Akuli, PR 9177) * Fix error message for dataclasses.field with positional argument (Hiroshi Ogawa, PR 11180) * Fix error message for f-string and str-bytes-safe (Nikita Sobolev, PR 11139) * Add documentation for type: ignore (Tushar Sadhwani, PR 11358) * Support --exclude more than once on command line (Nipunn Koorapati, PR 11329) * Use list[int] instead of List[int] in documentation (PR 11377, PR 11450) (Nick Crews) * Remove builtins. from error messages (97littleleaf11, PR 11522) * Document explicit type aliases (Nikita Sobolev, PR 11800) * Improve documentation of annotating generator functions (Alex Waygood, PR 11623) * Improve error message for nested TypedDict (97littleleaf11, PR 11658) * Exit gracefully on KeyboardInterrupt (Marc Mueller, PR 10725) * Optimizations: This release includes some optimizations that make mypy a bit faster (in addition to mypyc performance improvements discussed below): * Enable --fast-exit by default to speed up mypy (Jukka Lehtosalo, PR 11541) * Only read the stdlib versions dictionary once per run (Jukka Lehtosalo, PR 11542) * Optimize commonly used function (Jukka Lehtosalo, PR 11543) * Minor optimization/cleanup (Jukka Lehtosalo, PR 11544) * Reduce the number of executed local imports (Jukka Lehtosalo, PR 11545) * Mypyc Fixes and Improvements * Add missing type coercions (Jared Hance, PR 11176) * Support --allow-redefinition (Jared Hance, PR 11175) * Constant fold integer operations and string concatenation (Jukka Lehtosalo, PR 11194) * Use optimized implementation for builtins.sum (Sara Sinback and 97littleleaf11, PR 10268) * Move mypyc to console_scripts to fix running on Windows 10 (???, PR 11494) * Make min(x, y) faster(Chetan Khanna and 97littleleaf11, PR 10265) * Make max(x, y) faster (97littleleaf11, PR 11530) * Speed up reference counting operations by inlining them in commonly executed blocks (Jukka Lehtosalo, PR 11540) * Add support for attrs classes (Chad Dombrova, PR 11328) * Port mypyc to Python 3.11 (Victor Stinner, PR 11652) * Reduce the amount of debug information included in compiled extension modules (Nehal J Wani, PR 11526) * Other Notable Fixes and Improvements * Fix semantic analysis of assignment expressions (Shantanu, PR 11153) * Fixes mypy crash on protocol with contravariant variable (Nikita Sobolev, PR 11135) * Warn about unused ignores when not all specified error codes are used (Hiroshi Ogawa, PR 11178) * Improve type narrowing for walrus operator in conditional statements (Shantanu, PR 11202) * Fix literal type compatibility checking special case (Nikita Sobolev, PR 11236) * Rename API method builtin_type to named_type (97littleleaf11, PR 11224) * Fix narrowing information not propagated in assignment and boolean expressions (Ran Benita, PR 11207) * Fix narrowing of a nested union of TypedDicts (Ran Benita, PR 11204) * Fix case mismatching modules during namespace package search (Nipunn Koorapati, PR 11261) * Disallow invalid identifiers from getting implicit bazel **init**.py (Nipunn Koorapati, PR 11268) * Don?t type check lambdas nested in unchecked functions (Nikita Sobolev, PR 11213) * Update None.**bool** to return Literal[False] (Nikita Sobolev, PR 11290) * Relax type checking of % formatting when the right operand is an iterable (97littleleaf11, PR 11319) * Fix crash with namespace packages when generating html reports (Nikita Sobolev, PR 11338) * Allow slice syntax in Annotated types (Zac Hatfield-Dodds, PR 11345) * Show warning if self / cls argument is missing (Nikita Sobolev, PR 11317) * Improve subtype checking of TypeGuard types (Nikita Sobolev, PR 11314) * Fix type narrowing for overlaping runtime types (Nikita Sobolev, PR 11273) * Do not use TypeGuard context for lambda (Nikita Sobolev, PR 11417) * Check reachability in module bodies (Nikita Sobolev, PR 11361) * Check that **new** in a metaclass returns a subtype of type (Nikita Sobolev, PR 11420) * Improve support of contextlib.asynccontextmanager (Barnaby Shearer, PR 11352) * Discard deprecated builtin_type (97littleleaf11, PR 11343) * Don't look in user site packages when using a virtual env (Dimitri Merejkowsky, PR 11444) * Update stubgen to preserve string literals in annotations (Imad Eddine Rezgui, PR 11292) * Fix issue with exporting names in the presence of **getattr** (Shantanu, PR 11411) * Reject duplicate bases when defining TypedDict (97littleleaf11, PR 11485) * Fix type inference for index expression with a bounded TypeVar (Ilya Labun, PR 11434) * Fix get_dynamic_class_hook in some scenarios (Jade Lin, PR 10904) * Check print >> properly (Nikita Sobolev, PR 11576) * Correctly handle cls in protocol classmethod (Ilia Novoselov, PR 11119) * Use current Python version, rather than hardcoding 3.6, in stubgen (Shantanu, PR 10907) * Don't use ModuleType.**getattr** if we know module symbols (Jukka Lehtosalo, PR 11597) * Fix strict equality when using the latest typeshed (Jukka Lehtosalo, PR 11599) * Make sure ClassVar does not contain type variables (Nikita Sobolev, PR 11585) * Allow overriding attributes with methods (Nikita Sobolev, PR 11561) * Don?t generate an error for PEP 593 Annotated with a string literal second argument (Seth Yastrov, PR 10777) * Install types to the correct environment (Konstantin Weddige, PR 11457) * Support decorators in additional contexts (Nikita Sobolev, PR 11150) * Fix crash involving unreachable binary operations (Shantanu, PR 11680) * Fix None assignments with mypy daemon cache (Christian Bundy, PR 11574) * Handle OSError when accessing the mtime of a mypy cache file (Zac Hatfield- Dodds, PR 11718) * Special case some special Enum properties to be non-final (Nikita Sobolev, PR 11713) * Fix crash involving undefined cyclic import * (Shantanu, PR 11681) * Remove incorrect assumption about file system case sensitivity (Shantanu, PR 11708) * Fix compatibility of bool and Literal[True, False] (Nikita Sobolev, PR 11709) * Allow subclassing enums with annotations and no values (Nikita Sobolev, PR 11579) * Update to version 0.921: * Bug Fixes Included in This Release: * Fix regression in PathLike (Shantanu, PR 11785) * Allow calling a function with name _ (Jukka Lehtosalo, PR 11810) * Fix signature in curses and corresponding dmypy bug (Shantanu, PR 11785) * Update to version 0.920: * Making a Variable Optional in an Else Block * Now mypy alllows more general conditionally defined variables with optional types. Previously mypy allowed this only if a None assignment happened first. Now this is also supported. Implemented by Michael J. Sullivan in PR 11002. * Type Checking **slots** Assignment * For classes that define the special **slots** attribute, mypy will now report an error on assigning to attributes that are not found in the slots definitions (this matches runtime semantics). * Note that this feature does not work for dynamically computed slots. Implemented by Nikita Sobolev in PR 10864. * Partial Python 3.10 Support * We now ship binary wheels for Python 3.10 and mypy supports the new Python 3.10 union type syntax. * Some new features, including the match statement, ParamSpec and TypeAlias are not supported yet. * Python 3.5 Is No Longer Supported * Python 3.5 reached its end of life more than a year ago. Its support was deprecated in mypy 0.910 and it is no longer supported in mypy 0.920. * Efficient String and Bytes Formatting in Mypyc * Most string and bytes formatting methods now use fast C-level logic when compiled with mypyc. This includes % formatting, the format() method, and f-strings. This was implemented by 97littleleaf11 as part of a Google Summer of Code project. * Work Towards singledispatch Support * The signature of the initial function variant handles the generic case and describes the external signature of the singledispatch function. * This was implemented Pranav Rajpal as part of a Google Summer of Code project. * Stubgen Improvements * Add support for yield statements in stubgen (Sebastian Rittau, PR 10745) * Handle commas in namedtuple field definition in stubgen (Vanessa Ung, PR 10828) * Other Notable Fixes and Improvements * Allow plugin signature hooks to return FunctionLike (to support overloads) (pranavrajpal, PR 10717) * Narrow type with type variable when the upper bound is a subtype of current type (ethframe, PR 10658) * Make --cache-fine-grained imply --local-partial-types (Michael J. Sullivan, PR 10737) * Support new union syntax in stubs independent of target Python version and in runtime context (PR 10770, PR 10771) (Jukka Lehtosalo) * Support new union type syntax with isinstance() (Jukka Lehtosalo, PR 10775) * Better message if method is incompatible with base class (Anmol Takiar, PR 10572) * Allow redefinition of underscore functions (named '_') (pranavrajpal, PR 10811) * Properly track positional-only arguments for unannotated functions (Michael J. Sullivan, PR 10802) * Fixes to type checking %c string and bytes interpolation (97littleleaf11, PR 10869) * Use better error message for %c interpolation (97littleleaf11, PR 10875) * Skip overlapping overload checks in ignored files (Shantanu, PR 10922) * Fix ad hoc instance intersection logic (Christoph Tyralla, PR 9909) * Support tuple multiplication with literal integers (hatal175, PR 10361) * Fix recursion issue with nested instances and unions (Peilonrayz, PR 9663) * Fix caching behavior of PEP561-installed namespace packages (Michael J. Sullivan, PR 10937) * Add **dataclass_fields** and **attrs_attrs** to dataclasses (Timofey Kukushkin, PR 8578) * Fix argument checking on empty dict with double stars (Momoko Hattori, PR 9629) * Fix some type-guard-related crashes (Shantanu, PR 11061) * Reject raise Err if Err can?t be called without arguments (Nikita Sobolev, PR 11125) * Fix TypedDict crash with function definition (Nikita Sobolev, PR 11126) * Report attribute access errors for type variable bound to a union (Christoph Tyralla, PR 11140) * Fix crash on dataclasses.field(unpack) (Nikita Sobolev, PR 11137) * Fix crash related to ParamSpec in mypy daemon (Jukka Lehtosalo, PR 11567) * Properly type check *CustomType and CustomType function arguments (Nikita Sobolev, PR 11151) * Fix crash with overload and callable object decorators (Shantanu, PR 11630) * Fix crash involving explicit reexport, import cycle, and a wildcard (Shantanu, PR 11632) * Mypyc Features, Fixes, and Performace Improvements * Fix class-based named tuples (Jukka Lehtosalo, PR 10746) * Add a special case for len() of a string value (97littleleaf11, PR 10710) * Reject instance attribute access through class object (Jukka Lehtosalo, PR 10798) * Speed up the construction of list objects (97littleleaf11, PR 10807) * Add bytes primitive type (97littleleaf11, PR 10881) * Add bytearray support (97littleleaf11, PR 10891) * Optimize construction via list() and dict() (Richard Si, PR 10918) * Speed up bytes join() method (jhance, PR 10929) * Speed up len(bytes) (97littleleaf11, PR 10936) * Speed up bytes indexing and slicing (PR 10966, PR 10950) (97littleleaf11) * Speed up bytes.decode() and str.encode() (PR 10974, PR 10951) (97littleleaf11) * Speed up bytes equality checks (jhance, PR 10928) * Documentation Improvements * Add docs about exhaustive literal and enum checks (Nikita Sobolev, PR 10860) * Add ?or? regular expression example to --exclude documentation (Niklas Gustafsson, PR 10903) * Document per-module follow_imports more explicitly (Shantanu, PR 10845) * Add docs for the TypeGuard type (Nikita Sobolev, PR 10758) * Update type narrowing section in common issues (Nikita Sobolev, PR 11014) * Document how --no-implicit-reexport handles from X import Y as Z (Max Marrone, PR 11083) * Document strict config file option (Anders Kaseorg, PR 11132) * Add better type narrowing documentation (Nikita Sobolev, PR 11088) * Add documentation about := and type guards (Nikita Sobolev, PR 11161) * disable the tests to fix the build temporarily * Remove obsolete build (prep) instructions: typeshed has been removed from the archive. * update to version 0.910: * Mypy 0.900 added --install-types to install missing stub packages. We received feedback that this wasn?t a good fit for all use cases, since it asks for interactive confirmation from the user, and it requires another mypy invocation to actually perform type checking. * This release adds the new option --non-interactive that can be used with --install-types to install suggested stub packages without asking for confirmation. This can be useful in Continuous Integration jobs. The option causes mypy to both install stub packages and perform type checking within a single invocation. When not using --non-interactive, you?d have to run mypy again to get up-to-date results with the installed stubs. * This option provides a new way to migrate existing mypy runner scripts after updating to mypy 0.9xx: just add the --install-types --non-interactive options to your mypy command line. * Note that --install-types currently always installs the latest stubs for all supported packages. If you want reproducible results from your builds, we recommend explicitly pinning stub package versions in your requirements.txt file, for example. * Python 3.5 Deprecation * Running mypy on Python 3.5 is now deprecated. A future mypy release will drop Python 3.5 support. We haven?t decided when this will happen, but this might happen in the next feature release after 0.910. * Stubgen Improvements * Don't annotate unknown argument and return types (Sebastian Rittau, PR 10626) * Never generate a variable initializer (Sebastian Rittau, PR 10623) * Use NamedTuple class syntax (Sebastian Rittau, PR 10625) * Use T | None (PEP 604) instead of Optional[T] (Sebastian Rittau, PR 10624) * Other Fixes and Improvements * Fix some crashes from faulty casts (Shantanu, PR 10560) * Update docs for deferral of PEP 563 to 3.11 (Smart, PR 10655) * Don't suggest to install stubs for packages with py.typed files (Sebastian Rittau, PR 10652) * Correct the type package name of pyopenssl ( Sebastian Rittau, PR 10656) * Improve error reporting when --install-types has no cache (PR 10667) * Suggest types-setuptools for pkg_resources (Sebastian Rittau, PR 10681) * Fix crash with assignment to variable guarded with TypeGuard (PR 10683) * Don't ask to install a stub package if stubs are installed (PR 10670) * Fix crash when inferring multiple assignment with overloaded function (PR 10689) * update to version 0.900: * Third-party Library Stubs in Stub Packages (Breaking Change) * Mypy now only ships with type stubs for stdlib modules (plus typing_extensions and mypy_extensions). If you use third-party libraries that don?t include stubs or inline type annotations, you can explicitly install stub packages, usually called types-. * You can also now run mypy --install-types to install all missing stub packages in the mypy run (or the previous run, if you don?t pass any files to check). * Using cached types_requests-0.1.8-py2.py3-none-any.whl (22 kB) * For more information, read the blog post about this change and why we did this. There is more detail in the docs. * Python 2 Support is Opt-in (Breaking Change) * If you want to type check Python 2 code, you now have to install mypy[python2] using pip (on Python 3.8 and later): * python3 -m pip install -U mypy[python2] * This will install the additional typed-ast pip dependency that is required for Python 2 support. Type checking Python 2 code is still fully supported by mypy. * TypeGuard * Mypy now supports defining user-defined functions that perform type narrowing, similar to isinstance. Read PEP 647 for the details. * Since TypeGuard will be included in Python 3.10, which hasn?t been released yet, you will have to import it from a recent version of typing_extensions for now. * Support for pyproject.toml * Binary Wheels for Apple Silicon * We now include binary wheels for Apple Silicon. This can make mypy runs over 4x faster on supported hardware. This requires a native Apple Silicon build of Python 3.9 to work. * Type Narrowing with type(x) * Hosted Documentation for Mypyc * We now have hosted user documentation for mypyc, the compiler we use to speed up mypy. Mypyc is still experimental, but we are looking for early adopters. * New Mypyc Features * Support **setitem** , **delitem** , **len** and **contains** in native classes (PR 10451) * Basic support for class-based named tuples (PR 10252) * Support class-based TypedDict definitions (PR 10226) * Mypyc Performance Improvements * Pre-allocate space in list comprehensions (97littleleaf11, PR 10295) * Faster dict true test (97littleleaf11, PR 10333) * Implement dict.setdefault primitive (97littleleaf11, PR 10286) * Optimize truth value testing for strings (pranavrajpal, PR 10269) * Faster set creation with generator expression (97littleleaf11, PR 10261) * Add a primitive for loading the bool type (97littleleaf11, PR 10257) * Faster creation of a tuple from list/tuple (97littleleaf11, PR 10217) * Use vectorcalls to speed up calls to Python objects (PR 10153) * Add primitive for str.replace (97littleleaf11, PR 10088) * Add primitives for list.index() and list.remove() (PR 9961) * Intern string literals (PR 9960) * Add fast path for simple calls in wrapper functions (PR 9948) * Use METH_FASTCALL with **call** (PR 9946) * Use faster METH_FASTCALL wrapper functions on Python 3.7+ (PR 9894) * Add primitives for list.sort() and list.reverse() (PR 9897) * Recognize six.moves.xrange as an alias of range (PR 9896) * Some tagged integer micro-optimizations (PR 9801) * Add primitive for dict.copy (vsakkas, PR 9721) * Other Mypyc Fixes and Improvements * Fix reference counting in dict.setdefault (97littleleaf11, PR 10334) * Don't coerce types checked with isinstance (Sara Sinback, PR 10245) * Simplify argument parsing in legacy wrapper functions (PR 10234) * Simplify generated C by omitting gotos to the next block (PR 10230) * Box initializers of final variables when required (PR 10229) * Fix compilation of unreachable expressions (PR 10228) * Foundational support for tuple literals (and None and bool literals, PR 10148) * Use tables to construct and store literals (PR 10147) * Fix overflow error handling in list.insert (PR 9895) * Always add implicit None return type to **init** method (Thomas Johnson, PR 9866) * Small documentation updates (Thomas Johnson, PR 10184) * Updates to introduction in the documentation (PR 10179) * Various small doc updates (PR 10177) * Make mypyc docs use the same theme as mypy docs (PR 10176) * Fix mypyc failing to compile on CPython 3.10.0a6 (Adrian Freund, PR 10202) * Avoid declaring variable in C for loop initialization (Thomas Johnson, PR 10091) * Stubgen Improvements * Properly convert overloaded functions (Chad Dombrova, PR 9613) * Fix invoking mro() (Gen Xu, PR 10138) * Render a bit better stubs (Sergei Izmailov, PR 9903) * Fixed Any and Dict missing from stubgen imports list (Ashley Whetter, PR 9900) * Fix type error (Shantanu, PR 10523) * Fixes and typos (Sergei Izmailov, PR 9877) * Stubtest Improvements * Improve build error messages (Shantanu, PR 10365) * Check overloads are functions, don't early return (Shantanu, PR 10258) * Fix signature construction for overload + implicit classmethod (Shantanu, PR 9921) * Documentation Updates * Add security documentation for --install-types (Adam Weeden, PR 10555) * Improve documentation of extending mypy (Nikita Sobolev, PR 10222) * Update documentation links (Shantanu, PR 10159) * Fix incomplete error codes documentation (Iulian Onofrei, PR 9799) * Document explicit_package_bases config file option (Sam Bull, PR 10020) * Clarify that mypy_path is relative to current working directory (Gustav Gr?nsbo, PR 9959) * Emphasise that users probably want --follow-imports=normal (Shantanu, PR 9955) * Other Notable Fixes and Improvements * Make ignore_missing_imports work for third-party libraries which previously had bundled stubs (PR 10582) * Restrict the number of errors shown when there are missing stubs (PR 10579) * Mention fullname of PlaceholderNode in assertion to simplify debugging (Adam Weeden, PR 10565) * Use double quotes in error messages instead of single quotes (Dixith) * Use double quotes in various error messages (Prasanth Chettri, PR 10053) * Fix crash on TypeGuard plus "and" (Jelle Zijlstra, PR 10496) * Fix spurious name undefined error in class body within import cycle (PR 10498) * Remove assertion from TypeGuard serialization (Jelle Zijlstra, PR 10486) * Do not allow to use Final and ClassVar at same time (Yurii Karabas, PR 10478) * Allow running mypy if Python 2 typeshed stubs aren't installed (PR 10494) * Allow inline comments in VERSIONS (Sebastian Rittau, PR 10472) * Infer unreachability for await no_return() (Shantanu, PR 10458) * Fix unresolved reference + tuples crashing (EXPLOSION, PR 10401) * Fix crash with type alias inside **init** in incremental mode (PR 10432) * Fix crash with nested NamedTuple in incremental mode (PR 10431) * Fix crash related to module-level **getattr** in incremental mode (PR 10430) * Add support for functools.cached_property (Marc Mueller, PR 10408) * Don't narrow Type[X] with a metaclass (PR 10424) * Remove note: setup.cfg does need [mypy] section (James Cooke, PR 10364) * Fix inference of IntEnum value attribute type (Python 2, PR 10417) * Don't report error when using total_ordering in Python 2 mode (PR 10416) * Fix narrowing down TypedDict unions with enum literal types (PR 10415) * Fix inference of IntEnum value attribute type (PR 10412) * Use typeddict-item error code for more errors (PR 10410) * Fix a bunch of tests broken by python 3.10 (Adrian Freund, PR 10404) * Support maximum version marker of stdlib typeshed modules (Sebastian Rittau, PR 10402) * First look into @python2 subdirectory of search path items in Python 2 mode (PR 10392) * Make enum type compatible with union of all enum item literals (PR 10388) * Fix an issue with union types containing literals (Adrian Freund, PR 10373) * Fix re-exporting **all** in a stub file (PR 10382) * Extend the dataclass plugin to deal with callable properties (Aaron Ecay, PR 10292) * Make TypedDict incompatible type message more understandable (Akshay K, PR 10326) * Make --explicit-package-bases invertible (Gustav Gr?nsbo, PR 9969) * Fix crash for protocol classes and Hashable false negative (Christoph Tyralla, PR 10308) * Fix strict equality false positive when strict optional disabled (Kamil Turek, PR 10174) * Issue an error when overriding typeguard with non-typeguard in subclass (Kamil Turek, PR 10300) * Support functools.total_ordering (Ashley Whetter, PR 7831) * Support reversed operand order when comparing against sys.version_info (Kamil Turek, PR 10288) * Only import distutils if it is needed (Adrian Freund, PR 10203) * Recombine complete union of enum literals into original type (PR 9097, PR 9063) (Ethan Leba) * Support union type arguments when showing protocol member conflicts (97littleleaf11, PR 10154) * Fix recently added enum value type prediction (Paddy, PR 10057) * Support subclassing of NodeVisitor and TraverserVisitor in plugins (Nikita Sobolev, PR 10125) * Speed up processing of new files in daemon by caching ASTs (PR 10128) * Add narrowing and closures to common issues (Shantanu, PR 9956) * Add Python script to build wheels using cibuildwheel (PR 10096) * Don't try to follow imports to encodings.* (PR 10094) * Speed up case sensitive is-file check in file system cache (PR 10093) * Use fast path for finding modules in mypy daemon (PR 10095) * Fix following stub imports in daemon when using --follow-imports=skip (PR 10092) * Use sys.executable instead of python3 for --install-types (Anthony Sottile, PR 10086) * Add build-requirements.txt to MANIFEST.in (PR 10071) * Add separate requirements file for mypy self-compile (PR 10069) * Expand user home for cache_dir (Marco Zatta, PR 10051) * Fix daemon crash when deleting packages (PR 10036) * Keep track of fine-grained dependencies for modules in typeshed (PR 10034) * Fix import following issue in daemon (PR 10032) * Fix mypy daemon crash when following from a new module (PR 10030) * Detect invalid value for --custom-typeshed-dir (PR 9985) * Fix pip install for new typeshed (Ivan Levkivskyi, PR 9976) * Report incompatible assignments for descriptors with overloaded **set** methods (Christoph Tyralla, PR 9893) * Fix TypedDict.get("missing_key") with string literal (Adrian Freund, PR 9906) * update to version0.812L * Improved Source File Finding * Mypy 0.800 changed how mypy finds modules if you run mypy as mypy directory/ or mypy -p package. Mypy started looking for source files in directories without a **init**.py file. This is often the expected behavior, and it avoids excluding some files that should be type checked. * However, this caused issues for some users, such as when using mypy . to type check all files under the current directory. Mypy could now try to type check files inside nested virtual environments and node_modules directories, which is usually not desirable. This could result in mypy needlessly complaining about duplicate module names, in particular. * Now mypy will skip directories named site-packages or node_modules, and any directory beginning with a dot (such as .git) when recursively looking for files to check. * This doesn?t affect how mypy resolves imports ? it only affects when mypy is given a directory or a package to type check. You can override the exclusions by explicitly passing the files on the command line. * Excluding Paths * Mypy now supports the --exclude regex command line option to exclude paths matching a regular expression when searching for files to type check. For example, mypy --exclude '/setup.py$' skips all setup.py files. This lets you exclude additional paths that mypy started finding after mypy 0.800 changed module finding behavior, as discussed above. * You can also specify this in the config file (exclude=regex). The option expects forward slashes as directory separators on all platforms, including Windows, for consistency. * Update to version 0.812 * Improved Source File Finding * Mypy 0.800 changed how mypy finds modules if you run mypy as mypy directory/ or mypy -p package. Mypy started looking for source files in directories without a **init**.py file. This is often the expected behavior, and it avoids excluding some files that should be type checked. However, this caused issues for some users, such as when using mypy . to type check all files under the current directory. Mypy could now try to type check files inside nested virtual environments and node_modules directories, which is usually not desirable. This could result in mypy needlessly complaining about duplicate module names, in particular. Now mypy will skip directories named site-packages or node_modules, and any directory beginning with a dot (such as .git) when recursively looking for files to check. This doesn?t affect how mypy resolves imports ? it only affects when mypy is given a directory or a package to type check. You can override the exclusions by explicitly passing the files on the command line. * Excluding Paths * Mypy now supports the --exclude regex command line option to exclude paths matching a regular expression when searching for files to type check. For example, mypy --exclude '/setup.py$' skips all setup.py files. This lets you exclude additional paths that mypy started finding after mypy 0.800 changed module finding behavior, as discussed above. * You can also specify this in the config file (exclude=regex). The option expects forward slashes as directory separators on all platforms, including Windows, for consistency. * Provide the toolname only for the primary python3 flavor in order to avoid choice conflicts. * python3-mypy and python3Y-mypy are provided automatically. * Update to version 0.800: * Python 3.9 Support * Typing Usability Improvements (PEP 585 and PEP 604) The necessity to repeatedly import various types and special forms from typing has been a long-term nuisance for users of static type checking and Python. Two new Python features improve this situation and are now supported by mypy: PEP 585 lets you use list[int] instead of List[int] (no need to import List and other generic collections from typing). PEP 604 lets you write X | Y instead of Union[X, Y], and X | None instead of Optional[X] (no need to import Union or Optional from typing). Note: Using list[int] requires Python 3.9 and X | Y requires Python 3.10 (alpha) in order to work at runtime. To use them on older versions of Python, use from **future** import annotations. This allows them to be used in type annotations, but the older variants (or string literal escaping) may be required in non-annotation contexts, such as in type aliases. See the docs for more details. Here is an example that uses the new features: from **future** import annotations def fields(s: str | None) -> list[str]: if not s: return [] else: return s.split(',') These were implemented by Allan Daemon in PR 9564 and by Marc Mueller in PR 9647. * Improvements to Finding Modules This release adds several improvements to how mypy finds Python source files to type check. You can now pass paths to files within namespace packages on the command line, and mypy can better infer their module names. As before, use --namespace-packages to enable namespace packages. When you use --explicit-package-bases together with --namespace-packages, mypy assumes that only the current directory and directories explicitly specified in MYPYPATH (or mypy_path in the config file) are valid package roots. This can help with situations where the module name of a file is ambiguous. For example, it may not be clear whether src/pkg/mod.py should be treated as src.pkg.mod or pkg.mod, and you can use this option to disambiguate between the two (more information in the docs). The above improvements were implemented in PR 9742 by Shantanu. Other related improvements (also implemented by Shantanu): * When you run mypy as mypy , look for source files recursively also inside directories without a **init**.py (PR 9614) * Support namespace packages with -p (PR 9683) * Log encountered source files when running mypy with -v (PR 9672) * Document the new module finding behavior (PR 9923) * Other Notable Improvements and Bug Fixes * Only treat import X as X as a re-export in stubs (Shantanu, PR 9515) * Fix package imports with aliases in stubgen (Chad Dombrova, PR 9534) * Require first argument of namedtuple() to match the variable name (Momoko Hattori, PR 9577) * Add error code for name mismatches in named tuples and TypedDicts to make it easy to disable these error messages (Jukka Lehtosalo, PR 9811) * Document local_partial_types config option (Momoko Hattori, PR 9551) * Improve ambiguous kwargs checking (Erik Soma, PR 9573) * Disable unreachable warnings in boolean operators for type variables with value restrictions (Vincent Barbaresi, PR 9572) * Allow assignment to an empty tuple (Tobin Yehle, PR 5617) * Use absolute path when checking source duplication error (Yuki Igarashi, PR 9059) * Add get_function_signature_hook() to the plugin API (Nikita Sobolev, PR 9102) * Speed up type checking of dictionary, set, and list expressions (Hugues, PR 9477) * Allow non-types as arguments in Annotated (Patrick Arminio, PR 9625) * Add support for next generation attrs API (David Euresti, PR 9396) * Fix case folding of missing keys error message for TypedDicts (Marti Raudsepp, PR 9757) * Fix generic inheritance of **init**() methods in dataclasses and attrs classes (Nate McMaster, PR 9383, PR 9380) * Add more information to error message on too few arguments (Abhinay Pandey, PR 9796) * Document PEP 585, 563, 604, and related functionality (Shantanu, PR 9763) * Mypyc Improvements We use mypyc to compile mypy into fast C extension modules. This release includes many mypyc improvements. Xuanda Yang finished the migration to use a new, lower-level compiler intermediate representation in his Google Summer of Code project. * New supported Python features: * Support the walrus operator (:=) (Michael J. Sullivan, PR 9624) * Performance improvements: * Add primitives for list sort and list reverse (Jukka Lehtosalo, PR 9897) * Recognize six.moves.xrange again as an alias of range (Jukka Lehtosalo, PR 9896) * Speed up some integer primitives (Jukka Lehtosalo, PR 9801) * Speed up if x for int values (Jukka Lehtosalo, PR 9854) * Implement dict clear primitive (Vasileios Sakkas, PR 9724) * Implement list insert primitive (Vasileios Sakkas, PR 9741) * Implement float abs primitive (Xuanda Yang, PR 9695) * Implement str-to-float primitive (Xuanda Yang, PR 9685) * Specialize some calls to frozenset (Michael J. Sullivan, PR 9623) * Speed up multiple assignment from tuple (Xuanda Yang, PR 9575) * Speed up multiple assignment from sequence (Jukka Lehtosalo, PR 9800) * Optimize startswith and endswith (Tomer Chachamu, PR 9557) * Add primitives for bitwise ops (Jukka Lehtosalo, PR 9529) * Speed up in operations for list/tuple (Johan Dahlin, PR 9004) * Add primitives for list, str and tuple slicing (Jukka Lehtosalo, PR 9283) * Speed up tuple equality checks (Xuanda Yang, PR 9343) * Bug fixes: * Always add implicit None return type to **init** method (Thomas Johnson, PR 9866) * Fix deallocation of deeply nested data structures (Michael J. Sullivan, PR 9839) * Fix using package imported inside a function (Jukka Lehtosalo, PR 9782) * Fix type of for loop index register in for over range (Jukka Lehtosalo, PR 9634) * Convert to single-spec * Use update-alternatives to handle binaries * Do not expect python3.5 during tests * update to version 0.790: * Enabling and Disabling Error Codes * You can now globally disable and enable the generation of error messages with specific error codes by using --enable-error-code and --disable-error- code command line options (and config file options). This lets you disallow certain checks that don?t provide value or are too noisy, and in the future these can be used to enable optional, stricter checks. For more information, read the documentation. * Bug Fixes * Fix disable_error_code config file option (Aristotelis Mikropoulos, PR 9538) * Fix partial type crash during protocol checking (Shantanu, PR 9495) * Store the type for assignment expression (walrus) targets (Lawrence Chan, PR 9479) * Always type check arguments when using --disallow-untyped-calls (PR 9510) * Make None compatible with Hashable (PR 9371) * Don't infinite loop on self dependencies in --follow-imports=normal (Michael J. Sullivan, PR 9302) * Don't simplify away Any when joining union types (PR 9301) * Check for deleted vars in raise from (Alexandre Viau, PR 9272) * Fix corner case for comparing nested overloads (Nikita Sobolev, PR 9259) * Fix issues with async for and with statements (Guido van Rossum, PR 9268) * Fix internal error on list/dict comprehension with walrus operator in global scope (dhood, PR 9062) * Fix propagation of module-specific options to the parser (Guido van Rossum, PR 9247) * Fix crash when super is called outside a method (Weiss, PR 9173) * Fix untyped decorator overload error on class decorator with **call** overloads (Ran Benita, PR 9232) * Clean up terminal width handling (Florian Bruhin, PR 9143) * Add keyword arguments for functional Enum API (LiuYuhui, PR 9123) * Validate follow_imports values in mypy.ini (Michael J. Sullivan, PR 9165) * Fix *expr in an assigned expression (LiuYuhui, PR 8827) * Don't consider comparing True and False as a dangerous comparison (PR 9021) * Make reveal_type work with call expressions returning None (Jakub Stasiak, PR 8924) * Error Reporting Improvements * Improve missing module error for subdirectories (Ethan Leba, PR 8927) * Clarify bytes formatting error messages (Shantanu, PR 9243) * Fix misleading follow_imports error message in dmypy (Michael J. Sullivan, PR 9167) * Use [arg-type] error code for additional argument type error messages (PR 9090) * Report some additional serious errors in junit.xml (PR 8950) * Report note about binary operation on the same location as error message (PR 8936) * Documentation Updates * Document disable_error_code config file option (Aristotelis Mikropoulos, PR 9539) * Add cross references to config file values (Oleg H?fling, PR 7859) * Add cross references to additional config values, and missing plugins config value, and document --help option for stubgen (Oleg H?fling, PR 9241) * Remove note that Final is experimental and suggest importing it from typing (Ran Benita, PR 9138) * Discuss unreachable code as a common issue (Chetan Khanna, PR 8899) * Stubgen Improvements * Improve property type detection in extension modules (Antoine Prouvost, PR 8999) * Fix type stubgen crash caused by invalid type annotation (Henry Schreiner, PR 8888) * Import Iterable and Iterator from typing in generated stubs (Ashley Whetter, PR 9088) * Other Improvements * Speed up type checking of unions containing many literal string types (Akuli, PR 9192) * Add scripts to misc/ (in the mypy GitHub repository) for computing and applying diffs of mypy caches to enable incremental cache downloads (Michael J. Sullivan, PR 8906) * Internal Changes * This release includes several improvements to mypyc, the compiler we use to speed up mypy. Most notably, Xuanda Yang has been migrating mypyc to use a new, lower-level intermediate representation in his Google Summer of Code project. This provides a solid foundation for a variety of future mypyc improvements. * Additional mypyc improvements: * Dynamically disallow instantiating traits/interpreted subclasses (Michael J. Sullivan, PR 9248) * Basic support for protocols (PR 8914) Michael J. Sullivan) * Various optimizations (PR 8903, PR 8870) (Michael J. Sullivan and Xuanda Yang, PR 9245) * Make it easier to write mypyc test cases (PR 9094) * Typeshed Updates * Many improvements were made to typeshed ? too many to list. * update to version 0.780: * Following Imports in Mypy Daemon * You can now leave out the --follow-imports option when running dmypy, and mypy daemon will follow imports, similar to a non-daemon mypy run. Previously mypy daemon did not support this, and it was necessary to use --follow-imports and explicitly mention all files to check on the command line. (Following imports in mypy daemon is an experimental feature.) See the docs about following import in mypy. * Miscellaneous New Features: * Support environment variable interpolation for junit_xml configuration key (Mattwmaster58, PR 8479) * Add no_site_packages config file setting (davidzwa, PR 8524) * Allow .mypy.ini (with a dot prefix) as an alternative name to mypy.ini (dosisod, PR 8515) * Disallow unpacking of strings in multiple assignment, as this is usually a bug (Abtin, PR 8589) * Allow type aliases in a runtime (non-type) context (PR 8779) * Add narrowing unions with bool literals via identity check (Steve Dignam, PR 8821) * Always allow to cast to Any without warnings (oda, PR 8544) * Suggest solutions for a typo in a key of a TypedDict (Felici?n N?meth, PR 8483) * Provide more context about why incompatible with supertype is an error (Chetan Khanna, PR 8866) * Other Notable Improvements and Bug Fixes: * Fix handling dependencies to **call** in mypy daemon (PR 8494) * Various improvements to stubtest (PR 8502, PR 8886) (Shantanu) * Fix invalid type causing named tuple errors reported in wrong files (PR 8549) * Clarify documentation of Liskov substitution principle (PR 8563) * Fix type inference with lambda that returns None (PR 8562) * Fix incremental crash bug caused by NewType in functions (PR 8607) * Fix indexed assignment check when TypedDict is used as upper bound (Xuanda Yang, PR 8621) * Improve error message for bad indexed assignment (pando, PR 8641) * Fix crash when the same file is processed under multiple names (PR 8644) * Fix parser when using Python 3.9 (PR 8716) * Accept dict() as an empty dictionary in a TypedDict context (PR 8749) * Fix incorrect coroutine return type for nested function (Jens Widell, PR 8741) * Reject bytes literal as a TypedDict key (PR 8782) * Allow attrs keyword-only arguments at any position (Markus Schmaus, PR 8803) * Detect duplicate keys in call-based TypedDict definitions (PR 8849) * Look at arguments when generating constraints for an overload (PR 8845) * Fix potential wrong-file error message for unsupported types (PR 8854) * Typeshed Updates * Many small improvements were made to typeshed ? too many to list. Browse the typeshed commit log here. * update to version 0.770: * Tagged Unions * Previously, the only way to distinguish between two types in a union was to use an isinstance check. Now, mypy supports distinguishing between two or more types based on the value of some common shared "tag" field. This feature is most useful when you want to narrow down a union of TypedDicts: since TypedDicts are really just regular dicts at runtime, using isinstance checks won't work. Instead, you can now label or tag each TypedDict with a distinct Literal type and discriminate by checking that tag. Note that you can import Literal from typing_extensions on Python 3.7 and earlier. You can also use this technique to discriminate between unions of objects, tuples, or named tuples, so long as: 1. Every item in your union is tagged with a unique value 2. Mypy understands how to narrow the union of the tag values. For more details and examples, see the documentation on tagged unions. * Type Inference Improvements Type inference is now more powerful. Mypy can infer types in some cases where you previously needed an explicit type annotation. Mypy can infer a built-in collection type from augmented assignment statements. Some dictionary construction idioms are better supported. Mypy is better at inferring defaultdict types. * Multiple Inheritance and isinstance() Checks Previously, mypy assumed a variable cannot have two unrelated types when analyzing isinstance checks. For example, in the following example B is not a subclass of A, so mypy would incorrectly conclude the isinstance check is always false, and that the if-branch is unreachable ? even though var could actually be a subtype of both types. This meant that mypy skipped type checking anything inside the if statement, since it (by design) skips analyzing unreachable branches. Now, mypy will instead decide that the narrowed type of x is test., instead of marking the branch as unreachable. If it?s impossible for two types to be a subtype of one another, mypy will continue to not attempt to infer this "ad-hoc intersection". * Other Notable Improvements and Bug Fixes: * Fix some crash bugs involving import * and import cycles (PR 8450) * Fix interaction of descriptor methods with plugins (Jan Verbeek, PR 8365) * Allow strict in config file (Ville Skytt?, PR 8192) * Don?t crash when a module shadows builtin libraries (such as typing or types, PR 8405) * Fix type join between subclasses of unicode and str (PR 8402) * Fix type join of fixed-length tuples with mismatching lengths (Marti Raudsepp, PR 8333) * Fix type join of Sequence (e.g. variadic tuple) and fixed-length tuple (Marti Raudsepp, PR 8335) * Make mypy.api.run_dmypy actually capture the output (PR 8375) * Support determining whether a literal is truthy (Jan Verbeek, PR 8368) * Fix covariant overriding of decorated methods (Xuanda Yang, PR 8350) * Support typing.Annotated in addition to typing_extensions.Annotated (Jakub Stasiak, PR 8371) * Add add_method_to_class function to plugins.common (useful when writing mypy plugins) (Maksim Kurnikov, PR 8245) * Fix module alias as instance attribute (Uwe L. Korn, PR 8259) * Automatically write a file .gitignore file to cache directory, ignoring everything (Ville Skytt? , PR 8193) * Don't make dunder attributes enum members (Xuanda Yang, PR 8302) * Allow redefining TypedDict keys (while still generating an error) (Cohen Karnell, PR 8109) * Fix some crashes in dataclasses (PR 8271) * Use TypedDict union as type context when unambiguous (PattenR, PR 8212) * Fix false positive for subclasses of bytes overriding **str** (Shantanu, PR 8222) * Fix deeply nested InitVar definitions in dataclasses with init=False (Jacob Beck, PR 8208) * Narrow types for walrus assignment in if statements in some cases (Shantanu, PR 8258) * Narrow types for walrus assignment in if statements in most of the rest of cases (PR 8458) * Fix incorrect error code indexing (Xuanda Yang, PR 8248) * Fix regression in container check logic (Michael Lee, PR 8232) * Make reachability code understand chained comparisons (Michael Lee, PR 8148) * Fix incorrect name lookup for decorated methods (Xuanda Yang, PR 8175) * Fix simplifying unions with type aliases (Xuanda Yang, PR 8146) * Fix crash when overriding **init** in a dataclass subclass (Jacob Beck, PR 8159) * Fix some daemon crashes involving classes becoming generic (PR 8157) * Documentation and Error Reporting Improvements * Use fully qualified names in error messages for class names resembling builtins(Mukuntha N S, PR 8425) * Improve diagnostics involving missing stubs for a library that is installed in site-packages (Michael Lee, PR 8238) * Add a section to the documentation about incompatible overrides (RAHUL RAJA, PR 8377) * Add variable-sized tuples to the cheat sheet (Marcio Mazza, PR 8364) * Improve documentation of decorators (add decorator factories) (Marti Raudsepp, PR 8336) * Update documentation of variables and aliases (Xuanda Yang, PR 8200) * Report an error if a final class has abstract attributes (Denys Halenok, PR 8332) * Update common issues to include **init** without arguments (Tan Yuanhong, PR 8303) * Add a new error code for errors about unreachability (Denys Halenok, PR 8312) * Fix error indicator position in code with tabs (dosisod, PR 8307) * Document --local-partial-types (Xuanda Yang, PR 8201) * Update documentation for Literal types (Michael Lee, PR 8152) * Stubtest rewrite stubtest is a tool that compares stub definitions to what it finds at runtime with introspection and reports back inconsistencies. It got a complete rewrite. Some features of the new stubtest are: * Find missing, extraneous or mistyped classes, methods, functions and attributes in the stubs * Check presence, names and kinds of function arguments, accounting for overloads, decorators, *args and kwargs. Checks argument types against their default values, accounting for type vars. * Checks @property, @classmethod, @staticmethod declarations * Check types of module level and class level attributes and enums * Some results of this: * We now run stubtest in typeshed CI (for stdlib) * We?ve fixed about 1900 issues in typeshed definitions * We?ve greatly improved Python 3.8 support in typeshed and it?ll be easier to make the changes needed for future Python versions * We?ve uncovered a handful of issues in Python itself * Typeshed Updates: * Many small improvements were made to typeshed ? too many to list. Browse the typeshed commit log here. * Update to 0.770: too many changes to list here, but all information is on https://mypy-lang.blogspot.com/2019/12/mypy-0760-released.html Remove 0003 Pass executable path into main when running install patch it got already broken by upstream in e491b5d4aa anyway. * update to version 0.761 * Type Signature Suggestions for Tools * Type Inference Improvements * Fixes to Regressions * Fix regression introduced in 0.750: union (non-)simplification should not affect type inference (PR 8095) * Breaking Changes * Make the error code of a binary operation involving overload operator, for consistency (PR 8124) * Other Notable Improvements and Bug Fixes * Generate error when assigning an Enum or TypedDict type to an attribute (Xuanda Yang, PR 8107) * Fix relative path calculation if path is on a different drive on Windows (Netzeband, PR 8094) * Don?t infer an abstract type object type from concrete type object values (Xuanda Yang, PR 8096) * Fix an inconsistency with type checking lambda expressions (PR 8080) * Fix crash involving generic callable types (PR 8075) * Improve error message with long tuple initializer (Xuanda Yang, PR 7995) * Improve mypy daemon documentation (PR 8041) * Recommend typing_extensions instead of mypy_extensions for TypedDict (PR 8023) * Fix an inconsistency with self types (PR 8030, PR 8021) * Support type alias within Literal[...] (Xuanda Yang, PR 8014) * Fix --warn-return-any false positive when returning Any from a function declared to return object (Xuanda Yang, PR 8011) * Stubgen: Split @abstractproperty into @abstractmethod and @property (Xuanda Yang, PR 8066) * Stubgen: Give a better error message when using a .pyd file as target (Xuanda Yang, PR 8063) * Update stubgen documentation (PR 8031) * Typeshed Updates * Many small improvements were made to typeshed ? too many to list. Browse the typeshed commit log here. * update to 0.750 * More Precise Error Locations * Colors in Output * Pretty Output Mode * Old Semantic Analyzer Removed * Type Checking for str.format Calls * Improved check_untyped_defs * Stricter Treatment of Context Manager Objects * More Powerful Self-types * Mypy Daemon is No Longer Experimental * Pull in full interpreter as we can't have this package working with just base interpreter * Update to version 0.720: * New Semantic Analyzer Used by Default * New Feature: Warn about Unreachable Code * Plugin API Changes * Notable Improvements and Bug Fixes * Have --package usage respect mypy_path (Aaron Batilo, PR 6926) * Support flexible option specification in config files. Now all the flags support invertible forms so that one can specify either strict_optional = False or no_strict_optional = True. This matches how flags work on the command line (PR 7054) * Fix reachability inference with isinstance(Any, Any) (Michael Lee, PR 7048) * Fix mypyc crash with plugins using get_customize_class_mro_hook() (PR 7075) * Fix slicing tuples with non-literal expressions (Ethan Smith, PR 7066) * Fixes to column numbers in error messages (PR 7078, PR 7081) * Make Need type annotation for variable error more consistent (PR 7079, PR 7113) * Fix error reporting context for missing generic type arguments (PR 7100) * Use only directories containing no **init**.py as namespace packages (Arne Welzel, PR 7108) * Support method plugin hooks on union types (PR 6560) * Fix some corner cases in --strict-equality (PR 7156, PR 7164) * Fix binding of self-types on unions (PR 7152) * Add more details for Invalid type errors (PR 7166) * Fix custom **init**() in dataclasses (Ryan Gonzalez, PR 7168) * Better support for indexing with unions of literal types (Michael Lee, PR 6558) * update to version 0.711: * Revert typeshed PR 2878 (?Define functools.partial as overloaded function instead of its own class?). This caused too many false positive errors in real-world code. (PR 3077) * Fix MYPYC_BLACKLIST on Windows. This broke running dmypy on Windows. (PR 7032) * Update to 0.710: too many changes to list here (and there is no perfect changelog), but all information is on http://www.mypy-lang.org/ * update Pass executable path into main when running installe patch * Update to 0.700: too many changes to list here (and there is no perfect changelog), but all information is on http://www.mypy-lang.org/ * Update to 0.670: too many changes to list here (and there is no perfect changelog), but all information is on http://www.mypy-lang.org/ * Remove already included patches * desinglespec - is app and only for python3 * add RH patchset * update to 0.620 * fix install deps * support for dataclasses * better support for PEP 561 * adds support for dmypy run and a host of other small * many other imporvents * Drop dependency over devel python package, not needed * Do not skip build on < 3.4 python, we do not ship that anywhere (last seen on 13.1) * update to version 0.590: * New Features * experimental support for PEP 561 * Incremental mode is on by default * Flags for always true/false * Add a per-module follow_imports_for_stubs options * Notable Bugs Fixed * Fix error message when assigning to read-only property (PR 4863 by Michael Lee, fixes issue 4756) * Respect --follow-imports=silent in --warn-unused-ignores (PR 4857, fixes issue 3949) * Don't produce spurious ?unused type ignore? messages in incremental mode (PR 4841, fixes issue 2960) * Fix operator access on Type[...] (PR 4823, fixes issue 4789) * Remove incorrect override check on overloaded methods (PR 4810 by Michael Lee, fixes issue 4565) * Handle NotImplemented returned from **ne** (PR 4770 by Peter Ludemann, fixes issue 4767) * Options in mypy.ini should be spelled with underscores, not hyphens (PR 4754 by Emil Hessman, fixes issue 4753) * Documentation Improvements * Add coroutines to cheat sheet (PR 4677 by Rob Day) * Add None return/strict-optional to common issues (PR 4594 by Viet Hung Nguyen) * Mention that SupportsInt and friends don't support arithmetic (PR 4781, fixes issue 4758) * Stubgen Improvements * Emit Any type annotations for unannotated arguments (PR 4774 by Matt Gilson, fixes issue 4766) * Fix stubgen --recursive to only generate stubs for requested submodules. (PR 4845 by Matt Gilson, fixes issue 4844) * Properly format Callables (PR 4650 by Evan Hubinger, fixes issue 4640) * update to version 0.580: * Type check class decorators * Plugin for typechecking classes generated by attrs (Documentation) * Hooks into the semantic analyzer for plugins (PR 4328, PR 4397) * bugfixes and improved error messages * update to version 0.570: * Add support for attrs_package * update to version 0.560: * Iterable and Friends Are Now Protocols * Improved Error Messages * include compiled docs in package * fix build for distributions with python 3.4 * update to 0.550: * Running mypy now requires Python 3.4 or higher. However Python 3.3 is still valid for the target of the analysis (i.e. the `--python-version` flag). * Split `--disallow-any` flag into `separate boolean flags <disallow- any>`. * The `--old-html-report` flag was removed. * update to 0.540 * Switch to More Rapid Releases new mypy version roughly every 2-4 weeks * New Features * Allow assignments to multiple targets from union types (Ivan Levkivskyi, PR 4067) * Allow definitions of subscripted type aliases such as Item = Tuple[int, str] within functions (Ivan Levkivskyi, PR 4000) * Narrow type of optional left operand of in operator if the collection items aren?t optional (Ivan Levkivskyi, PR 4072) * Generate an error if type would be inferred for a variable (PR 4112) * Notable Bugs Fixed * Fix errors not being reported for some modules with incremental mode by deleting cache file for a module if errors are found (Ivan Levkivskyi, PR 4045) * Fix incremental mode crash related to Type[...] types (Ivan Levkivskyi, PR 4038) * Fix crash related to tuple types (Ivan Levkivskyi, PR 4051) * Fix incorrect errors about **getattr** methods (Ivan Levkivskyi, PR 4073) * Fixes to non-method attributes with callable types (Elazar Gershuni, PR 4016) * Fix function overloading based on Type[...] types (Ivan Levkivskyi, PR 4037) * Fix processing invalid overloaded function definitions (Elazar Gershuni, PR 4064) * Fix handling of disallow_any/disallow_untyped_defs combination in mypy config file (Jelle Zijlstra, PR 4076) * fix shebang removal * update to 0.521 * Mypy Bugs Fixed * Fix crash on name collision for self attributes (Ivan Levkivskyi, PRs 3700 and 3719) * Fix bug in cache updates and improve cache logging (PR 3708) * Fix per-file strict Optional interaction with default-None args (PR 3686) * Fix crash in --quick mode when aliases are re-exported (Ivan Levkivskyi, PR 3740) * Fix crash on incompatible redefinition in named tuple (Ivan Levkivskyi, PR 3760) * Typeshed Bugs Fixed * Fix regressions in csv.DictReader (Thomas Grainger, PRs 1475 and 1478) * upgrade to 0.520 * Add :ref:`fine-grained control of Any types <disallow-any>`. * Add :ref:`typeddict`. * Other updates to :ref:`command-line`: * Add --no-implicit-optional. * Add --shadow-file. * Add --no-incremental. * correct shebangs of typeshed libs * fix build for older versions * Enhance description by some more text from the webpage. * use python singlespec approach marking as uncompatible with python2 * first package Changes in python-opentelemetry-resourcedetector-gcp: * Initial build * Version 1.9.0a0 Changes in python-poetry-core: \- Update to 2.1.3 * Improve performance of marker operations * Fix various issues with markers * Update list of supported licenses * Fix an issue where optional dependencies defined in the project section were treated as non-optional when a source was defined for them in the tool.poetry section * Fix an issue where local versions with upper case letters caused an error * Fix an issue where inheriting from WheelBuilder was unnecessarily difficult * Update to 2.1.1 * Fix an issue where simplifying a python_version marker resulted in an invalid marker (#838). * Changes from 2.1.0 * Fix an issue where inclusive ordering with post releases was inconsistent with PEP 440 (#379). * Fix an issue where invalid URI tokens in PEP 508 requirement strings were silently discarded (#817). * Fix an issue where wrong markers were calculated when removing parts covered by the project's python constraint (#824). * Fix an issue where optional dependencies that are not part of an extra were included in the wheel metadata (#830). * Fix an issue where the **pycache** directory and *.pyc files were included in sdists and wheels (#835). * Changes from 2.0.1 * Replace the deprecated core metadata field Home-page with Project-URL: Homepage (#807). * Fix an issue where includes from tool.poetry.packages without a specified format were not initialized with the default value resulting in a KeyError (#805). * Fix an issue where some project.urls entries were not processed correctly resulting in a KeyError (#807). * Fix an issue where dynamic project.dependencies via tool.poetry.dependencies were ignored if project.optional-dependencies were defined (#811). * Unset source date epoch for tests * Change test skipping, the skipped one works, and another is broken. * update to 2.0.0: * **Add support for the`project` section in the `pyproject.toml` file according to PEP 621** (#708, #792). * Add support for non PEP440 compliant version in the `platform_release` marker (#722). * Add support for string comparisons with `in` / `not in` in generic constraints (#722). * Add support for script files that are generated by a build script (#710). * Add support for `SOURCE_DATE_EPOCH` when building packages (#766, #781). * Drop support for Python 3.8 (#798). * Create `METADATA` files with version 2.3 instead of 2.2 * Normalize source vcs URLs (#701). * Make `allow-prereleases` a tri-state setting (#783). * Rename exceptions to have an `Error` suffix (#767). * Remove support for `x` in version constraints (#770). * Remove support for scripts with extras (#708). * Remove deprecated features and interfaces (#702, * # 769). * Deprecate `tool.poetry.dev-dependencies` in favor of `tool.poetry.group.dev.dependencies` (#754). * Deprecate `Package.python_marker` (#446). * Improve Cygwin git support under Windows (#704). * Improve error message when the `pyproject.toml` file cannot be parsed (#734). * Improve handling of `readme` files (#752). * Improve error handling when the Python constraint is empty (#761). * Improve performance for creating a PEP 508 requirement from a dependency (#779). * Fix an issue where the `platlib` directory of the wrong Python was used (#726). * Fix handling of generic constraints (#732). * Fix an issue where building a wheel in a nested output directory results in an error (#762). * Fix an issue where `+` was not allowed in git URL paths (#765). * Fix an issue where the temporary directory was not cleaned up on error (#775). * Fix an issue where the regular expression for author names was too restrictive (#517). * Fix an issue where basic auth http(s) credentials could not be parsed (#791). * update to 1.9.1: * Add `3.13` to the list of available Python versions (#747). * drop upstream patch * Add patch support newer pythons patch: * Remove failing test with Python 3.12.6 and 3.13. * Switch to autosetup macro. * Skip test failing with Python 3.12.6 gh#python-poetry/poetry#9678 * Update to 1.9.0 (bsc#1221705): * Added * Add a to key in tool.poetry.packages to allow custom subpackage names * Add support for path dependencies that do not define a build system * Add a tool.poetry.package-mode key to support non-package mode * Changed * Update list of supported licenses * Improve support for PEP 691 JSON-based Simple API * Establish zipapp compatibility * Rework list of files included in build artifacts * Improve performance by treating collections in packages as immutable * Deprecate poetry.core.masonry.builder * Deprecate scripts that depend on extras * Fixed * Fix an issue where insignificant errors were printed if the working directory is not inside a git repository * Fix an issue where the project's directory was not recognized as git repository on Windows due to an encoding issue * Vendoring fastjsonschema==2.19.1 lark==1.1.8 * update to 1.8.1: * Fix an issue where git URLs starting with `git+` could not be parsed anymore (#657). * Add `3.12` to the list of available Python versions (#631). * Add support for creating packages dynamically in the build script * Improve marker logic for `extra` markers (#636). * Update list of supported licenses (#635, * # 646). * Deprecate `Dependency.transitive_python_versions` (#648). * Deprecate `Dependency.transitive_python_constraint` (#649). * Fix an issue where projects with extension modules were not installed in editable mode (#633). * Fix an issue where the wrong or no `lib` folder was added to the wheel (#634). * Replace `jsonschema` with `fastjsonschema`. * `lark==1.1.8` * `packaging==23.2` * Update to 1.7.0 ## Added * Optionally use resolved references when converting a VCS dependency to a PEP 508 dependency specification (#603). * Improve performance of marker handling (#609). ## Changed * Drop support for Python 3.7 (#566). * Remove deprecated poetry.core.constraints.generic and poetry.core.semver (#601). * Allow | as a value separator in markers with the operators in and not in (#608). * Put pretty name (instead of normalized name) in metadata (#620). * Update list of supported licenses (#623). ## Fixed * Fix an issue where the encoding was not handled correctly when calling a subprocess (#602). * Fix an issue where caret constraints with additional whitespace could not be parsed (#606). * Fix an issue where PEP 508 dependency specifications with names starting with a digit could not be parsed (#607). * Fix an issue where Poetry considered an unrelated .gitignore file resulting in an empty wheel (#611). * Update description * Update to version 1.4.0 version constraints (#128). * unbundle vendored packages Changes in python-proto-plus: \- Update to 1.26.1 * **deps:** Allow protobuf 6.x (#536) * update to 1.26.0: * Migrate to pyproject.toml * Construct messages with nested duration in protobuf 5.28+ * Fix enums initialization in PyPy * Incorrect return type annotation for Message.to_dict * Use include rather than exclude to find_namespace_packages in setup.py * Update to 1.25.0 * Add support for Python 3.13 * Construct messages with nested struct * Fix 'Couldn't build proto file' when using Python 3.13 * Fix conda compatibility issue * Fix issue with equality comparison of repeated field with None * Remove check for Protobuf version * Drop merged pytest static method patch * Explicitly BuildRequires on pytz, the testsuite uses it. * update to 1.24.0: * Add `always_print_fields_with_no_presence` fields to `to_json` and `to_dict` * Add compatibility with protobuf==5.x * AttributeError module 'google._upb._message' has no attribute 'MessageMapContainer' * Deprecate field `including_default_value_fields` in `to_json` and `to_dict` Changes in python-pytest-asyncio: \- Add patch to allow use of older setuptools * Add upstream patch for compatibility with pytest 8.4.0 * update to 1.0.0: https://github.com/pytest-dev/pytest- asyncio/releases/tag/v1.0.0 * Removed * The deprecated event_loop fixture. (#1106) * Added * Prelimiary support for Python 3.14 (#1025) * Changed * Scoped event loops (e.g. module-scoped loops) are created once rather than per scope (e.g. per module). This reduces the number of fixtures and speeds up collection time, especially for large test suites. (#1107) * The loop_scope argument to pytest.mark.asyncio no longer forces that a pytest Collector exists at the level of the specified scope. For example, a test function marked with pytest.mark.asyncio(loop_scope="class") no longer requires a class surrounding the test. This is consistent with the behavior of the scope argument to pytest_asyncio.fixture. (#1112) * Fixed * An error caused when using pytest's [--setup-plan]{.title-ref} option. (#630) * Unsuppressed import errors with pytest option \--doctest-ignore-import-errors (#797) * A "fixture not found" error in connection with package-scoped loops (#1052) * Notes for Downstream Packagers * Removed a test that had an ordering dependency on other tests. (#1114) * update to 0.26.0: * Adds configuration option that sets default event loop scope for all tests #793 * Improved type annotations for pytest_asyncio.fixture #1045 * Added typing-extensions as additional dependency for Python <3.10 #1045 * update to 0.25.3: * Avoid errors in cleanup of async generators when event loop is already closed #1040 * update to 0.25.2: * Call loop.shutdown_asyncgens() before closing the event loop to ensure async generators are closed in the same manner as asyncio.run does #1034 * update to 0.25.1: * Fixes an issue that caused a broken event loop when a function-scoped test was executed in between two tests with wider loop scope #950 * Improves test collection speed in auto mode #1020 * Corrects the warning that is emitted upon redefining the event_loop fixture * Update to 0.25.0: * Deprecated: Added warning when asyncio test requests async @pytest.fixture in strict mode. This will become an error in a future version of flake8-asyncio. #979 * Updates the error message about pytest.mark.asyncio's scope keyword argument to say loop_scope instead. #1004 * Verbose log displays correct parameter name: asyncio_default_fixture_loop_scope #990 * Propagates contextvars set in async fixtures to other fixtures and tests on Python 3.11 and above. #1008 * Update to 0.24.0 * BREAKING: Updated minimum supported pytest version to v8.2.0 * Adds an optional loop_scope keyword argument to pytest.mark.asyncio. * Deprecates the optional scope keyword argument to pytest.mark.asyncio for API consistency with pytest_asyncio.fixture. * Fixes a bug that caused module-scoped async fixtures to fail when reused in other modules * Fixes a bug that caused duplicate markers in async tests * Declare support for Python 3.13 * Drop merged duplicated markers patch * Add patch to fix some testsuites broken by duplicate markers; * update to 0.23.7: * Silence deprecation warnings about unclosed event loops that occurred with certain CPython patch releases * update to 0.23.6: * compatibiltiy with pytest 8.2 * update to 0.23.5.post1: * Declare compatibility with pytest 8 * Fix typing errors with recent versions of mypy #769 * Prevent DeprecationWarning about internal use of `asyncio.get_event_loop()` from affecting test cases #757 * Update to 0.23.5 * Declare compatibility with pytest 8 #737 * Fix typing errors with recent versions of mypy #769 * Prevent DeprecationWarning about internal use of asyncio.get_event_loop() from affecting test cases #757 ## Known issues * As of v0.23, pytest-asyncio attaches an asyncio event loop to each item of the test suite (i.e. session, packages, modules, classes, functions) and allows tests to be run in those loops when marked accordingly. Pytest- asyncio currently assumes that async fixture scope is correlated with the new event loop scope. This prevents fixtures from being evaluated independently from the event loop scope and breaks some existing test suites (see #706). For example, a test suite may require all fixtures and tests to run in the same event loop, but have async fixtures that are set up and torn down for each module. If you're affected by this issue, please continue using the v0.21 release, until it is resolved. * Release 0.23.4 * pytest-asyncio no longer imports additional, unrelated packages during test collection #729 * Addresses further issues that caused an internal pytest error during test collection * Declares incompatibility with pytest 8 #737 * update to 0.23.3: * Fixes a bug that caused event loops to be closed prematurely when using async generator fixtures with class scope or wider in a function-scoped test #706 * Fixes various bugs that caused an internal pytest error during test collection #711 #713 #719 * Fixes a bug that caused an internal pytest error when collecting .txt files * Fixes a bug that caused an internal pytest error when using module-level skips #701 This release is backwards-compatible with v0.21. Changes are non- breaking, unless you upgrade from v0.22. * BREAKING: The asyncio_event_loop mark has been removed. Event loops with class, module, package, and session scopes can be requested via the scope keyword argument to the _asyncio_ mark. - Introduces the event_loop_policy fixture which allows testing with non-default or multiple event loops * Introduces pytest_asyncio.is_async_test which returns whether a test item is managed by pytest-asyncio * Removes and pytest trio, mypy, and flaky from the test dependencies * Deprecate redefinition of the event_loop fixture. #587 Users requiring a class-scoped or module-scoped asyncio event loop for their tests should mark the corresponding class or module with asyncio_event_loop. * Test items based on asynchronous generators always exit with xfail status and emit a warning during the collection phase. This behavior is consistent with synchronous yield tests. #642 * Remove support for Python 3.7 * Declare support for Python 3.12 * drop hypothesis health check patch (upstream) * remove unnecessary dependency on async_generator * Add hypothesis-health-check patch to fix tests * Prevent DeprecationWarning to bubble up on CPython 3.10.9 and 3.11.1. #460 * Inject multibuild to defeat a build loop * Initial release of python-pytest-asyncio 0.8.0 Changes in python-syrupy: * Update to 4.9.1 * **serializer:** preserve trailing newlines in ambr serialization (#950) * from version 4.9.0 * **serializer:** raise TypeError when serializing non-byte like object in binary mode (#951) * Add --snapshot-ignore-file-extensions argument to support DVC (#943) * Add compose_matchers utility for composing 1 or more matchers (#952) * Add SingleFileAmberSnapshotExtension as a single-file variant of the default amber extension (#959) * Include details about created/updated snapshots in detailed report (#942) * from version 4.8.3 * Snapshots of deselected parametrized tests wrongly marked as unused (#965) * from version 4.8.2 * Avoid unnecessary env updates to reduce chances of segfault (#956) * from version 4.8.1 * Check current session's pending-write queue when recalling snapshots (e.g. diffing) (#927) * from version 4.8.0 * Add option to disable diffing (#924) * update to 4.7.2: * allow snapshot dir to be different * pytest-rerunfailures compatibility * Added a new CLI flag: --snapshot-patch-pycharm-diff * relax python version constraint, remove upperbound * ignore unused snapshots for skipped test * update classifiers, metadata * Add %{?sle15_python_module_pythons} * update to 4.6.1: * support pytest 8 * update to 4.6.0: * **serializer:** add support for FunctionType serialization * support setting defaults * **filter:** add paths_include filter * add include option to snapshots, similar to exclude * remove colored dependency * support python 3.12 * **serializer:** add snapshot regex value matcher and bypass custom repr helper * preserve Falsy values in assertion diff function * **amber:** expose serialize_custom_iterable method of AmberDataSerializer * drop no colored patch: obsolete * update to 4.0.8: * diffing excessively large snapshot lines (#778) (64b4265) * large snapshot diff recursion error (#776) (24260b1) * improve reporting around xfailed snapshots * hide empty snapshot report (#768) (8f581d5) * Initial packaging (v4.0.4), needed by translate-toolkit Changes in python-typed-ast: \- update to 1.5.5: * update project to be end of life * set dev status to inactive * add sle15_python_module_pythons * Release version 1.5.4 (#189) * Do not include now private code.h (#188) As of https://github.com/python/cpython/pull/32385 the header code.h is private but directly included into Python.h * Fix Python 3.11 support (#187) The compilation error on master is: `ast3/Parser/tokenizer.c:1991:10: error: implicit declaration of function '_Py_dup' is invalid in C99 [-Werror,-Wimplicit-function- declaration] fd = _Py_dup(fd); ^ 1 error generated.` Probably as a result of https://github.com/python/cpython/pull/30484 Just declaring it seems to fix things. Add a (slightly) hacky way of testing Python 3.11 in CI prior to manylinux / cibuildwheel support. * Bump version to 1.5.4.dev0 (#186) * Release version 1.5.3 (#185) * FIX: Account form stdbool.h being included in Python.h (#184) As of CPython 3.11 (via https://github.com/python/cpython/pull/29883) stdbool.h is now included in Python.h so do attempt to redefine bool/true/false. * Bump version to 1.5.3.dev0 * Release version 1.5.2 * Add support for building aarch64 wheels (#182) Co-authored-by: Shantanu <12621235+hauntsaninja at users.noreply.github.com> * Remove update process document (#177) typed_ast will not be updated to support syntax past Python 3.8 as Python 3.8's ast module now incorporates the features of typed_ast. * Bump version to 1.5.2.dev0 * Release version 1.5.1 (#181) * Fix #167: Port ast27 to Python 3.11 (#176) Copy _PyLong_DigitValue table from Python 3.10 as "digitvalue" in ast27/Python/mystrtoul.c. The symbol has been removed from the public Python 3.11 C API. * Bump version to 1.5.1.dev0 * Add patch to use PyUnicode_DecodeUnicodeEscape directly, rather than wrapping it. * update to 1.5.0: * Drop python 3.5 support * Define _PyUnicode_DecodeUnicodeEscape even on Python 3.6+ * Recommend ast on Python 3.8+ * update to version 1.4.3: * Download wheels for 3.9 as well * Download aarch64 wheels (#154) * Allow compilation on python 3.10.0a6 (#155) Closes #156. (Except for Apple Silicon.) * Fix compilation on python 3.10.0a7 (#158) * PyArena was removed from the public api in python/cpython#25007 * This commit adds two new files (a copy of each for ast27 and ast3): * pycore_pyarena.h: Taken from the cpython source code with minimal changes * pyarena.h: Maps the new, underscored function names to the old function names, allowing the code to work on both python 3.10 and older versions * Add Python 3.10 classifier (#160) * remove obsolete ppc64 and s390x patch, included upstream * update to version 1.4.2: * Fix linker error in debug build (#131) * Fix cross compile by adjusting includes (#135) * Add note in incompatabilities that PyPy is broken and unsupported (#144) * Remove reference to PyNode_ListTree for Python 3.10 (#153) * ast27: prefix exported symbols (#152) * Add 3.9 to supported versions * Add patch from upstream PR#152 to fix ppc64 and s390x builds/tests and run all tests again. * Use (fixed in the meantime) pytest_arch macro in order to ignore the _build directories from multiple python3 flavors gh#openSUSE/python-rpm-macros#66 * Add a kind field to Bytes as well (#83) * Fix await in functions with type comments (#86) * Put _ast3 and _ast27 in the typed_ast package (#85) Changes in python-uritemplate: \- Switch to pyproject macros. * Use sle15_python_module_pythons * Remove completely unnecessary dependency on python-simplejson. * update to 4.1.1: * Add type annotations to uritemplate and distribute them for others to use * Update to a modern documentation theme as well * Drop support for Python 2.7, 3.4, and 3.5 * Better support number-like types as values for variables in a template * update to 3.0.1 * Update to Python 3.6, 3.7, and 3.8 * Drop support for Python 2.6, 3.2, and 3.3 * Ignore None in list argument expansion * Handle a list with an empty string appropriately * Remove superfluous devel dependency for noarch package Changes in python-dnspython: \- Drop patch for CVE-2023-29483, fixed upstream. * Update to version 2.6.1 * The Tudoor fix ate legitimate Truncated exceptions, preventing the resolver from failing over to TCP and causing the query to timeout. * Update to version 2.6.0 * As mentioned in the ?TuDoor? paper and the associated CVE-2023-29483, the dnspython stub resolver is vulnerable to a potential DoS if a bad-in-some- way response from the right address and port forged by an attacker arrives before a legitimate one on the UDP port dnspython is using for that query. This release addresses the issue by adopting the recommended mitigation, which is ignoring the bad packets and continuing to listen for a legitimate response until the timeout for the query has expired. * Added support for the NSID EDNS option. * Dnspython now looks for version metadata for optional packages and will not use them if they are too old. This prevents possible exceptions when a feature like DoH is not desired in dnspython, but an old httpx is installed along with dnspython for some other purpose. * The DoHNameserver class now allows GET to be used instead of the default POST, and also passes source and source_port correctly to the underlying query methods. * Update to version 2.5.0 * Dnspython now uses hatchling for builds. * Cython is no longer supported due to various typing issues. * Dnspython now explicitly canonicalizes IPv4 and IPv6 addresses. Previously it was possible for non-canonical IPv6 forms to be stored in a AAAA address, which would work correctly but possibly cause problmes if the address were used as a key in a dictionary. * The number of messages in a section can be retrieved with section_count(). * Truncation preferences for messages can be specified. * The length of a message can be automatically prepended when rendering. * dns.message.create_response() automatically adds padding when required by RFC 8467. * The TLS verify parameter is now supported by dns.query.tls(), and the DoH and DoT Nameserver subclasses. * The MutableMapping used to store content in a zone may now be specified by a factory when subclassing. Factories may also be provided for writable verisons and immutable versions. * dns.name.Name now has predecessor() and successor() methods implementing RFC 4471. * QUIC has had a number of bug fixes and also now supports session tickets for faster session resumption. * The NSEC3 class now has a next_name() method for retrieving the next name as a dns.name.Name. * Don't use curio. * update to version 2.4.2: * Async queries could wait forever instead of respecting the timeout if the timeout was 0 and a packet was lost. The timeout is now respected. * Restore HTTP/2 support which was accidentally broken during the https refactoring done as part of 2.4.0. * When an inception time and lifetime are specified, the signer now sets the expiration to the inception time plus lifetime, instead of the current time plus the lifetime. * update to version 2.4.1: * Importing dns.dnssecalgs without the cryptography module installed no longer causes an ImportError. * A number of timeout bugs with the asyncio backend have been fixed. * DNS-over-QUIC for the asyncio backend now works for IPv6. * Dnspython now enforces that the candidate DNSKEYs for DNSSEC signatures have protocol 3 and have the ZONE flag set. This is a standards compliance issue more than a security issue as the legitimate authority would have to have published the non-compliant keys as well as updated their DS record in order for the records to validate (the DS digest includes both flags and protocol). Dnspython will not make invalid keys by default, but does allow them to be created and used for testing purposes. * Dependency specifications for optional features in the package metadata have been improved. * update to version 2.4.0: * Python 3.8 or newer is required. * The stub resolver now uses instances of `dns.nameserver.Nameserver` to represent remote recursive resolvers, and can communicate using DNS over UDP/TCP, HTTPS, TLS, and QUIC. In additional to being able to specify an IPv4, IPv6, or HTTPS URL as a nameserver, instances of `dns.nameserver.Nameserver` are now permitted. * The DNS-over-HTTPS bootstrap address no longer causes URL rewriting. * DNS-over-HTTPS now only uses httpx; support for requests has been dropped. A source port may now be supplied when using httpx. * DNSSEC zone signing with NSEC records is now supported. Thank you very much (again!) Jakob Schlyter! * The resolver and async resolver now have the `try_ddr()` method, which will try to use Discovery of Designated Resolvers (DDR) to upgrade the connection from the stub resolver to the recursive server so that it uses DNS-over- HTTPS, DNS-over-TLS, or DNS-over-QUIC. This feature is currently experimental as the standard is still in draft stage. * The resolver and async resolver now have the `make_resolver_at()` and `resolve_at()` functions, as a convenience for making queries to specific recursive servers. * Curio support has been removed. Changes in python-trio: \- Remove version restriction for python-setuptools in BuildRequires * Update to 0.30.0 * Add @trio.as_safe_channel, a wrapper that can be used to make async generators safe. This will be the suggested fix for the flake8-async lint rule ASYNC900. (#3197) * Allow trio to be a types.ModuleType and still have deprecated attributes. (#2135) * Fixed socket module for some older systems which lack socket.AI_NUMERICSERV. * Now trio works on legacy (pre-Lion) macOS. (#3133) * Update type hints for trio.run_process and trio.lowlevel.open_process. (#3183) * Don't mutate the global runner when MockClock is created. (#3205) * Fix incorrect return type hint for Nursery.start(). (#3224) * Update wording in documentation to more accurately reflect Trio's maturity. (#3216) * Update BuildRequires from pyproject.toml * Update to 0.29.0 * Add trio.lowlevel.in_trio_run() and trio.lowlevel.in_trio_task() and document the semantics (and differences) thereof. See the documentation. (#2757) * If trio.testing.RaisesGroup does not get the expected exceptions it now raises an AssertionError with a helpful message, instead of letting the raised exception/ group fall through. The raised exception is available in the **context** of the AssertionError and can be seen in the traceback. (#3145) * Clear Trio?s cache of worker threads upon os.fork. (#2764) * Stop using ctypes to mutate tracebacks for strict_exception_groups=False?s exception collapsing. (#405) * Fixed spelling error in Windows error code enum for ERROR_INVALID_PARAMETER. (#3166) * Publicly re-export **version** for type checking purposes. (#3186) * The typing of trio.abc.HostnameResolver.getaddrinfo() has been corrected to match that of the stdlib socket.getaddrinfo, which was updated in mypy 1.15 (via a typeshed update) to include the possibility of tuple[int, bytes] for the sockaddr field of the result. This happens in situations where Python was compiled with --disable-ipv6. * Additionally, the static typing of trio.to_thread.run_sync(), trio.from_thread.run() and trio.from_thread.run_sync() has been improved and should reflect the underlying function being run. (#3201) * Add sed command to remove shebangs from check_type_completeness.py and gen_exports.py * Update to 0.28.0 * :func:inspect.iscoroutinefunction and the like now give correct answers when called on KI-protected functions. * Rework KeyboardInterrupt protection to track code objects, rather than frames, as protected or not. The new implementation no longer needs to access frame.f_locals dictionaries, so it won't artificially extend the lifetime of local variables. Since KeyboardInterrupt protection is now imposed statically (when a protected function is defined) rather than each time the function runs, its previously-noticeable performance overhead should now be near zero. The lack of a call-time wrapper has some other benefits as well: * :func:inspect.iscoroutinefunction and the like now give correct answers when called on KI-protected functions. * Calling a synchronous KI-protected function no longer pushes an additional stack frame, so tracebacks are clearer. * A synchronous KI-protected function invoked from C code (such as a weakref finalizer) is now guaranteed to start executing; previously there would be a brief window in which KeyboardInterrupt could be raised before the protection was established. * One minor drawback of the new approach is that multiple instances of the same closure share a single KeyboardInterrupt protection state (because they share a single code object). That means that if you apply trio.lowlevel.enable_ki_protection to some of them and not others, you won't get the protection semantics you asked for. See the documentation of trio.lowlevel.enable_ki_protection for more details and a workaround. * Rework foreign async generator finalization to track async generator ids rather than mutating ag_frame.f_locals. This fixes an issue with the previous implementation: locals' lifetimes will no longer be extended by materialization in the ag_frame.f_locals dictionary that the previous finalization dispatcher logic needed to access to do its work. * Ensure that Pyright recognizes our underscore prefixed attributes for attrs classes. * Fix trio.testing.RaisesGroup's typing. * Improve error message when run after gevent's monkey patching. * Document that trio.sleep_forever is guaranteed to raise an exception now. * Remove workaround for OpenSSL 1.1.1 DTLS ClientHello bug. * Drop support for Python 3.8. * Switch to using PEP570 for positional-only arguments for trio.socket.SocketType's methods. * Improve type annotations in several places by removing Any usage. * Get and enforce 100% coverage. * update to 0.27.0: * :func:`trio.move_on_after` and :func:`trio.fail_after` previously set the deadline relative to initialization time, instead of more intuitively upon entering the context manager. This might change timeouts if a program relied on this behavior. If you want to restore previous behavior you should instead use trio.move_on_at(trio.current_time() + ...). flake8-async has a new rule to catch this, in case you're supporting older trio versions. See :ref:`ASYNC122`. * :meth:`CancelScope.relative_deadline` and :meth:`CancelScope.is_relative` added, as well as a relative_deadline parameter to **init**. This allows initializing scopes ahead of time, but where the specified relative deadline doesn't count down until the scope is entered. * :class:`trio.Lock` and :class:`trio.StrictFIFOLock` will now raise :exc:`trio.BrokenResourceError` when :meth:`trio.Lock.acquire` would previously stall due to the owner of the lock exiting without releasing the lock. * trio.move_on_at, trio.move_on_after, trio.fail_at and trio.fail_after now accept shield as a keyword argument. If specified, it provides an initial value for the ~trio.CancelScope.shield attribute of the trio.CancelScope object created by the context manager. * Added :func:`trio.lowlevel.add_parking_lot_breaker` and :func:`trio.lowlevel.remove_parking_lot_breaker` to allow creating custom lock/semaphore implementations that will break their underlying parking lot if a task exits unexpectedly. :meth:`trio.lowlevel.ParkingLot.break_lot` is also added, to allow breaking a parking lot intentionally. * Allow sockets to bind any os.PathLike object. * Update trio.lowlevel.open_process's documentation to allow bytes. * Update :func:`trio.sleep_forever` to be NoReturn. * Add docstrings for memory channels' statistics() and aclose methods. * update to 0.26.2: * Remove remaining hash usage and fix test configuration issue that prevented it from being caught. * Switched attrs usage off of hash, which is now deprecated. * Use PyPI's Trusted Publishers to make releases. * Added an interactive interpreter python -m trio. This makes it easier to try things and experiment with trio in the a Python repl. Use the await keyword without needing to call trio.run() $ python -m trio Trio 0.21.0+dev, Python 3.10.6 Use "await" directly instead of "trio.run()". Type "help", "copyright", "credits" or "license" for more information. >>> import trio >>> await trio.sleep(1); print("hi") # prints after one second hi See :ref:`interactive debugging` for further detail. (#2972) * :class:`trio.testing.RaisesGroup` can now catch an unwrapped exception with unwrapped=True. This means that the behaviour of :ref:`except* <except_star>` can be fully replicated in combination with flatten_subgroups=True (formerly strict=False). (#2989) * Fixed a bug where :class:`trio.testing.RaisesGroup(..., strict=False) <trio.testing.RaisesGroup>` would check the number of exceptions in the raised ExceptionGroup before flattening subgroups, leading to incorrectly failed matches. It now properly supports end ($) regex markers in the match message, by no longer including " (x sub-exceptions)" in the string it matches against. * Deprecated strict parameter from :class:`trio.testing.RaisesGroup`, previous functionality of strict=False is now in flatten_subgroups=True. * update to 0.25.1: * Fix crash when importing trio in embedded Python on Windows, and other installs that remove docstrings. * Update to 0.25.0 * New helper classes: RaisesGroup and Matcher. * MultiError has been fully removed, and all relevant trio functions now raise ExceptionGroups instead. * The strict_exception_groups parameter now defaults to True in trio.run and trio.lowlevel.start_guest_run. * Add trio.testing.wait_all_threads_completed, which blocks until no threads are running tasks. * Path is now a subclass of pathlib.PurePath, allowing it to interoperate with other standard pathlib types. * We don't need isort for the tests: Avoid it for Ring1 * Clean dependencies * update to 0.23.2: * TypeVarTuple is now used to fully type :meth:`nursery.start_soon() <trio.Nursery.start_soon>`, :func:`trio.run()`, :func:`trio.to_thread.run_sync()`, and other similar functions accepting (func, *args). This means type checkers will be able to verify types are used correctly. :meth:`nursery.start() <trio.Nursery.start>` is not fully typed yet however. (#2881) * Make pyright recognize :func:`open_memory_channel` as generic. (#2873) backlink Unknown interpreted text role "func". * Make pyright recognize :func:`open_memory_channel` as generic. * Unknown interpreted text role "func". * Moved the metadata into PEP 621-compliant :file:`pyproject.toml`. (#2860) * update to 0.23.1: * Don't crash on import in Anaconda interpreters. * Add type hints. * When exiting a nursery block, the parent task always waits for child tasks to exit. This wait cannot be cancelled. However, previously, if you tried to cancel it, it _would_ inject a `Cancelled` exception, even though it wasn't cancelled. Most users probably never noticed either way, but injecting a `Cancelled` here is not really useful, and in some rare cases caused confusion or problems, so Trio no longer does that. * If called from a thread spawned by `trio.to_thread.run_sync`, `trio.from_thread.run` and `trio.from_thread.run_sync` now reuse the task and cancellation status of the host task; * this means that context variables and cancel scopes naturally propagate 'through' threads spawned by Trio. You can also use `trio.from_thread.check_cancelled` to efficiently check for cancellation without reentering the Trio thread. * :func:`trio.lowlevel.start_guest_run` now does a bit more setup of the guest run before it returns to its caller, so that the caller can immediately make calls to :func:`trio.current_time`, :func:`trio.lowlevel.spawn_system_task`, :func:`trio.lowlevel.current_trio_token`, etc. * When a starting function raises before calling :func:`trio.TaskStatus.started`, :func:`trio.Nursery.start` will no longer wrap the exception in an undocumented :exc:`ExceptionGroup`. * To better reflect the underlying thread handling semantics, the keyword argument for `trio.to_thread.run_sync` that was previously called `cancellable` is now named `abandon_on_cancel`. * The old `cancellable` name is now deprecated. * Update to 0.22.2: * Fix PermissionError when importing trio due to trying to access pthread. * Breaking change: Timeout functions now raise ValueError if passed math.nan. This includes trio.sleep, trio.sleep_until, trio.move_on_at, trio.move_on_after, trio.fail_at and trio.fail_after. * Added support for naming threads created with trio.to_thread.run_sync, requires pthreads so is only available on POSIX platforms with glibc installed. * trio.socket.socket now prints the address it tried to connect to upon failure. * Fixed a crash that can occur when running Trio within an embedded Python interpreter, by handling the TypeError that is raised when trying to (re-)install a C signal handler. * Fix sniffio.current_async_library() when Trio tasks are spawned from a non- Trio context (such as when using trio-asyncio). Previously, a regular Trio task would inherit the non-Trio library name, and spawning a system task would cause the non-Trio caller to start thinking it was Trio. * Documented that Nursery.start_soon does not guarantee task ordering. Changes in python-websocket-client: \- Adjust License tag on spec file after transition to Apache-2.0 * Update to 1.9.0 * Remove Python 3.8 support (EOL), add Python 3.13 (5f25030) * Remove localhost and 127.0.0.1 from default NO_PROXY list (#994) * Support IPv6 CIDRs in the no_proxy option (#1033) * Fix thread safety condition in `teardown()` to improve `run_forever()` (#1015) * Fix #1024 by chunking data, recursion in on_error callback, thread leak in `_stop_ping_thread()`, avoid implicit None in `recv()` (#1036) * Avoid bare except clauses for better error handling (#1036) * Fix async (#983) * Resolve mypy type errors (#996, #1006, 813d570) * Test coverage improvements (#1035, #1036) * flake8 linting improvements (#1034) * Update to 1.8.0: * Added `on_reconnect` parameter to WebSocketApp to handle callback ambiguity * Improve handling of SSLEOFError and use reconnect bool * Switch to pyproject macros. * update to 1.7.0: * Renamed `mask` variable in ABNF to prevent name collision with `mask()` function (9b51f73) * Fixed old http import of HTTPStatus in _handshake.py * Add `send_text()` and `send_bytes()` to _app.py * Improved typehint support * General readability improvements, made all string concatenations use f-strings * Applied black formatting style to code (da7f286) * update to 1.6.4: * Fix #952, add support for HTTP 307 and 308 redirect codes * Fix type hints issues * Add support for Python beta release 3.12 in CI * Add maintainer email in setup.py * Add support for SSLKEYLOGFILE environment variable * Add support for callable header arguments * Change handling of proxy environment variables, is_secure set to true now prevents http_proxy from getting used * Fix Dispatcher keyboard interrupt. Should solve reconnect loop with rel * Fix teardown issue when ping thread is not properly ended * Fix double ping wait time on first ping * Minor type hints improvements (eda6724, 54b3013) * Add logic to avoid error in the case where content-length header does not exist, bug introduced in 1.5.2 * Fix wsdump.py script typing, bug introduced in 1.5.2 * Add type hints * Fix pytype errors * Fix args passed to logging function * Standardize PEP 3101 formatting (c6a445f) * Add more verbose exception for unsuccessful handshake ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-2816=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2816=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2816=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2816=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-2816=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2816=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2816=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-grpc-interceptor-0.15.4-150400.9.4.1 * python311-pytest-asyncio-1.0.0-150400.10.6.2 * python311-google-auth-2.47.0-150400.6.12.2 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-grpcio-1.60.1-150600.16.10.1 * Public Cloud Module 15-SP6 (noarch) * python311-grpc-interceptor-0.15.4-150400.9.4.1 * python311-google-cloud-compute-1.42.0-150400.9.11.2 * python311-google-cloud-run-0.14.0-150400.9.8.2 * python311-google-api-core-2.28.0-150400.5.9.2 * python311-google-cloud-service-directory-1.16.0-150400.9.8.2 * python311-google-cloud-appengine-logging-1.8.0-150400.9.8.2 * python311-grpc-google-iam-v1-0.14.3-150400.9.6.2 * python311-google-cloud-kms-inventory-0.4.0-150400.9.8.2 * python311-google-cloud-dns-0.36.0-150400.9.8.2 * python311-google-cloud-build-3.35.0-150400.9.8.2 * python311-proto-plus-1.26.1-150400.9.6.2 * python311-google-cloud-audit-log-0.4.0-150400.9.8.1 * python311-google-cloud-domains-1.12.0-150400.9.8.2 * python311-google-cloud-spanner-3.58.0-150400.9.8.1 * python311-google-cloud-vpc-access-1.15.0-150400.9.8.2 * python311-google-cloud-secret-manager-2.26.0-150400.9.8.2 * python311-google-auth-2.47.0-150400.6.12.2 * python311-google-cloud-storage-3.8.0-150400.10.9.2 * python311-google-cloud-logging-3.13.0-150400.9.8.2 * python311-google-resumable-media-2.8.0-150400.10.9.2 * python311-google-cloud-artifact-registry-1.19.0-150400.9.8.2 * python311-google-cloud-core-2.5.0-150400.5.9.2 * python311-google-cloud-kms-3.9.0-150400.9.8.2 * python311-googleapis-common-protos-1.72.0-150400.10.9.2 * python311-google-cloud-iam-2.21.0-150400.9.11.2 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python-google-crc32c-debugsource-1.8.0-150400.9.8.2 * python311-grpcio-debuginfo-1.60.1-150600.16.10.1 * python311-google-crc32c-1.8.0-150400.9.8.2 * python311-google-crc32c-debuginfo-1.8.0-150400.9.8.2 * python311-grpcio-1.60.1-150600.16.10.1 * python-grpcio-debugsource-1.60.1-150600.16.10.1 * Public Cloud Module 15-SP5 (noarch) * python311-grpc-interceptor-0.15.4-150400.9.4.1 * python311-google-cloud-compute-1.42.0-150400.9.11.2 * python311-google-cloud-run-0.14.0-150400.9.8.2 * python311-google-api-core-2.28.0-150400.5.9.2 * python311-google-cloud-service-directory-1.16.0-150400.9.8.2 * python311-grpc-google-iam-v1-0.14.3-150400.9.6.2 * python311-google-cloud-appengine-logging-1.8.0-150400.9.8.2 * python311-google-cloud-kms-inventory-0.4.0-150400.9.8.2 * python311-google-cloud-dns-0.36.0-150400.9.8.2 * python311-google-cloud-build-3.35.0-150400.9.8.2 * python311-proto-plus-1.26.1-150400.9.6.2 * python311-google-cloud-audit-log-0.4.0-150400.9.8.1 * python311-google-cloud-domains-1.12.0-150400.9.8.2 * python311-google-cloud-spanner-3.58.0-150400.9.8.1 * python311-google-cloud-vpc-access-1.15.0-150400.9.8.2 * python311-google-cloud-secret-manager-2.26.0-150400.9.8.2 * python311-google-auth-2.47.0-150400.6.12.2 * python311-google-cloud-storage-3.8.0-150400.10.9.2 * python311-google-cloud-logging-3.13.0-150400.9.8.2 * python311-google-resumable-media-2.8.0-150400.10.9.2 * python311-google-cloud-artifact-registry-1.19.0-150400.9.8.2 * python311-google-cloud-core-2.5.0-150400.5.9.2 * python311-google-cloud-kms-3.9.0-150400.9.8.2 * python311-googleapis-common-protos-1.72.0-150400.10.9.2 * python311-google-cloud-iam-2.21.0-150400.9.11.2 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python311-google-crc32c-1.8.0-150400.9.8.2 * python-google-crc32c-debugsource-1.8.0-150400.9.8.2 * python311-google-crc32c-debuginfo-1.8.0-150400.9.8.2 * Public Cloud Module 15-SP4 (noarch) * python311-grpc-interceptor-0.15.4-150400.9.4.1 * python311-google-cloud-compute-1.42.0-150400.9.11.2 * python311-google-cloud-run-0.14.0-150400.9.8.2 * python311-google-api-core-2.28.0-150400.5.9.2 * python311-google-cloud-service-directory-1.16.0-150400.9.8.2 * python311-grpc-google-iam-v1-0.14.3-150400.9.6.2 * python311-google-cloud-appengine-logging-1.8.0-150400.9.8.2 * python311-google-cloud-kms-inventory-0.4.0-150400.9.8.2 * python311-google-cloud-dns-0.36.0-150400.9.8.2 * python311-google-cloud-build-3.35.0-150400.9.8.2 * python311-proto-plus-1.26.1-150400.9.6.2 * python311-google-cloud-audit-log-0.4.0-150400.9.8.1 * python311-google-cloud-domains-1.12.0-150400.9.8.2 * python311-google-cloud-spanner-3.58.0-150400.9.8.1 * python311-google-cloud-vpc-access-1.15.0-150400.9.8.2 * python311-google-cloud-secret-manager-2.26.0-150400.9.8.2 * python311-google-auth-2.47.0-150400.6.12.2 * python311-google-cloud-storage-3.8.0-150400.10.9.2 * python311-google-cloud-logging-3.13.0-150400.9.8.2 * python311-google-resumable-media-2.8.0-150400.10.9.2 * python311-google-cloud-artifact-registry-1.19.0-150400.9.8.2 * python311-google-cloud-core-2.5.0-150400.5.9.2 * python311-google-cloud-kms-3.9.0-150400.9.8.2 * python311-googleapis-common-protos-1.72.0-150400.10.9.2 * python311-google-cloud-iam-2.21.0-150400.9.11.2 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python-google-crc32c-debugsource-1.8.0-150400.9.8.2 * python311-google-crc32c-1.8.0-150400.9.8.2 * python311-google-crc32c-debuginfo-1.8.0-150400.9.8.2 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python-google-crc32c-debugsource-1.8.0-150400.9.8.2 * python311-google-crc32c-1.8.0-150400.9.8.2 * python311-typed-ast-debuginfo-1.5.5-150400.5.3.2 * python311-mmh3-debuginfo-4.1.0-150400.9.3.3 * python311-google-crc32c-debuginfo-1.8.0-150400.9.8.2 * python-mmh3-debugsource-4.1.0-150400.9.3.3 * python-typed-ast-debugsource-1.5.5-150400.5.3.2 * python311-typed-ast-1.5.5-150400.5.3.2 * python311-mmh3-4.1.0-150400.9.3.3 * openSUSE Leap 15.4 (noarch) * python311-grpc-interceptor-0.15.4-150400.9.4.1 * python311-google-cloud-compute-1.42.0-150400.9.11.2 * python311-google-api-core-2.28.0-150400.5.9.2 * python311-google-cloud-run-0.14.0-150400.9.8.2 * python311-google-cloud-service-directory-1.16.0-150400.9.8.2 * python311-google-cloud-appengine-logging-1.8.0-150400.9.8.2 * python311-grpc-google-iam-v1-0.14.3-150400.9.6.2 * python311-google-cloud-kms-inventory-0.4.0-150400.9.8.2 * python311-google-cloud-dns-0.36.0-150400.9.8.2 * python311-google-cloud-build-3.35.0-150400.9.8.2 * python311-proto-plus-1.26.1-150400.9.6.2 * python311-google-auth-httplib2-0.2.0-150400.10.3.2 * python311-google-cloud-audit-log-0.4.0-150400.9.8.1 * python311-google-api-python-client-2.185.0-150400.10.3.2 * python311-pytest-asyncio-1.0.0-150400.10.6.2 * python311-google-cloud-domains-1.12.0-150400.9.8.2 * python311-syrupy-4.9.1-150400.9.3.2 * python311-opentelemetry-resourcedetector-gcp-1.9.0a0-150400.9.3.2 * python311-google-cloud-spanner-3.58.0-150400.9.8.1 * python311-google-cloud-vpc-access-1.15.0-150400.9.8.2 * python311-poetry-core-2.1.3-150400.9.6.2 * python311-google-cloud-secret-manager-2.26.0-150400.9.8.2 * python311-google-auth-2.47.0-150400.6.12.2 * python311-google-cloud-storage-3.8.0-150400.10.9.2 * python311-google-cloud-logging-3.13.0-150400.9.8.2 * python311-google-resumable-media-2.8.0-150400.10.9.2 * python311-google-cloud-artifact-registry-1.19.0-150400.9.8.2 * python311-mypy-1.5.1-150400.9.3.2 * python311-google-cloud-core-2.5.0-150400.5.9.2 * python311-google-cloud-kms-3.9.0-150400.9.8.2 * python311-googleapis-common-protos-1.72.0-150400.10.9.2 * python311-google-cloud-iam-2.21.0-150400.9.11.2 * python311-uritemplate-4.1.1-150400.9.3.2 * python311-aioresponses-0.7.8-150400.9.3.2 * Public Cloud Module 15-SP7 (noarch) * python311-google-cloud-compute-1.42.0-150400.9.11.2 * python311-google-api-core-2.28.0-150400.5.9.2 * python311-google-cloud-run-0.14.0-150400.9.8.2 * python311-google-cloud-service-directory-1.16.0-150400.9.8.2 * python311-grpc-google-iam-v1-0.14.3-150400.9.6.2 * python311-google-cloud-appengine-logging-1.8.0-150400.9.8.2 * python311-google-cloud-kms-inventory-0.4.0-150400.9.8.2 * python311-google-cloud-dns-0.36.0-150400.9.8.2 * python311-google-cloud-build-3.35.0-150400.9.8.2 * python311-proto-plus-1.26.1-150400.9.6.2 * python311-google-cloud-audit-log-0.4.0-150400.9.8.1 * python311-google-cloud-domains-1.12.0-150400.9.8.2 * python311-google-cloud-spanner-3.58.0-150400.9.8.1 * python311-google-cloud-vpc-access-1.15.0-150400.9.8.2 * python311-google-cloud-secret-manager-2.26.0-150400.9.8.2 * python311-google-cloud-storage-3.8.0-150400.10.9.2 * python311-google-cloud-logging-3.13.0-150400.9.8.2 * python311-google-resumable-media-2.8.0-150400.10.9.2 * python311-google-cloud-artifact-registry-1.19.0-150400.9.8.2 * python311-google-cloud-core-2.5.0-150400.5.9.2 * python311-google-cloud-kms-3.9.0-150400.9.8.2 * python311-googleapis-common-protos-1.72.0-150400.10.9.2 * python311-google-cloud-iam-2.21.0-150400.9.11.2 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-google-crc32c-debugsource-1.8.0-150400.9.8.2 * python311-grpcio-debuginfo-1.60.1-150600.16.10.1 * python311-google-crc32c-1.8.0-150400.9.8.2 * python311-google-crc32c-debuginfo-1.8.0-150400.9.8.2 * python311-grpcio-1.60.1-150600.16.10.1 * python-grpcio-debugsource-1.60.1-150600.16.10.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * python311-grpcio-debuginfo-1.60.1-150600.16.10.1 * python311-grpcio-1.60.1-150600.16.10.1 * python-grpcio-debugsource-1.60.1-150600.16.10.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1161898 * https://bugzilla.suse.com/show_bug.cgi?id=1221705 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 20:30:55 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 20:30:55 -0000 Subject: SUSE-RU-2026:2815-1: important: Recommended update for apptainer Message-ID: <178362905593.765.16081192152050050257@5ed4f61072e9> # Recommended update for apptainer Announcement ID: SUSE-RU-2026:2815-1 Release Date: 2026-07-09T13:12:52Z Rating: important References: * bsc#1270529 * jsc#PED-16347 Cross-References: * CVE-2026-2303 CVSS scores: * CVE-2026-2303 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-2303 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-2303 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for apptainer contains the following fixes: Security fixes included on this update: * CVE-2026-2303: go.mongodb.org/mongo-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling (bsc#1270529). Other fixes: * Enable building of SUID starter for SLES 15 (jsc#PED-16347). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2815=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-2815=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2815=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * squashfuse-0.5.0-150600.3.4.1 * squashfuse-devel-0.5.0-150600.3.4.1 * squashfuse-tools-0.5.0-150600.3.4.1 * libsquashfuse0-debuginfo-0.5.0-150600.3.4.1 * squashfuse-debugsource-0.5.0-150600.3.4.1 * squashfuse-tools-debuginfo-0.5.0-150600.3.4.1 * squashfuse-debuginfo-0.5.0-150600.3.4.1 * libsquashfuse0-0.5.0-150600.3.4.1 * openSUSE Leap 15.6 (aarch64 x86_64) * apptainer-debuginfo-1.5.1-150600.4.29.1 * apptainer-1.5.1-150600.4.29.1 * apptainer-suid-1.5.1-150600.4.29.1 * apptainer-suid-debuginfo-1.5.1-150600.4.29.1 * openSUSE Leap 15.6 (noarch) * apptainer-sle16-1.5.1-150600.4.29.1 * apptainer-sle15_7-1.5.1-150600.4.29.1 * apptainer-sle15_6-1.5.1-150600.4.29.1 * apptainer-leap-1.5.1-150600.4.29.1 * HPC Module 15-SP7 (aarch64 x86_64) * squashfuse-0.5.0-150600.3.4.1 * squashfuse-tools-0.5.0-150600.3.4.1 * libsquashfuse0-debuginfo-0.5.0-150600.3.4.1 * apptainer-1.5.1-150600.4.29.1 * apptainer-debuginfo-1.5.1-150600.4.29.1 * squashfuse-debugsource-0.5.0-150600.3.4.1 * squashfuse-tools-debuginfo-0.5.0-150600.3.4.1 * squashfuse-debuginfo-0.5.0-150600.3.4.1 * libsquashfuse0-0.5.0-150600.3.4.1 * HPC Module 15-SP7 (noarch) * apptainer-sle15_7-1.5.1-150600.4.29.1 * SUSE Package Hub 15 15-SP7 (aarch64 x86_64) * apptainer-1.5.1-150600.4.29.1 * apptainer-suid-1.5.1-150600.4.29.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * squashfuse-0.5.0-150600.3.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2303.html * https://bugzilla.suse.com/show_bug.cgi?id=1270529 * https://jira.suse.com/browse/PED-16347 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 20:31:09 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 09 Jul 2026 20:31:09 -0000 Subject: SUSE-SU-2026:2814-1: important: Security update for MozillaFirefox Message-ID: <178362906924.765.9429095043294268740@5ed4f61072e9> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:2814-1 Release Date: 2026-07-09T12:26:39Z Rating: important References: * bsc#1268071 * bsc#1269226 Cross-References: * CVE-2026-12289 * CVE-2026-12290 * CVE-2026-12291 * CVE-2026-12292 * CVE-2026-12294 * CVE-2026-12295 * CVE-2026-12296 * CVE-2026-12297 * CVE-2026-12298 * CVE-2026-12299 * CVE-2026-12302 * CVE-2026-12304 * CVE-2026-12305 * CVE-2026-12306 * CVE-2026-12307 * CVE-2026-12308 * CVE-2026-12309 * CVE-2026-12310 * CVE-2026-12311 * CVE-2026-12312 * CVE-2026-12313 * CVE-2026-12314 * CVE-2026-12315 * CVE-2026-12324 * CVE-2026-12325 * CVE-2026-12327 * CVE-2026-12328 * CVE-2026-12329 * CVE-2026-12330 CVSS scores: * CVE-2026-12289 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12289 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-12292 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12294 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12298 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12302 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12302 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12304 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12304 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12305 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12305 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12306 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12306 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12309 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12309 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12310 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12310 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12311 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12311 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12312 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12313 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12313 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12314 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12314 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12315 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12315 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12324 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12324 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12325 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12325 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12327 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12327 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12329 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12330 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12330 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 29 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: * Removed obsolete mozilla-nss-certs and recommends p11-kit-nss-trust (bsc#1269226) Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): * CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. * CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12291: Use-after-free in the Networking: HTTP component. * CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. * CVE-2026-12294: Sandbox escape in the DOM: Workers component. * CVE-2026-12295: Sandbox escape in the DOM: Navigation component. * CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. * CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. * CVE-2026-12302: Mitigation bypass in the DOM: Security component. * CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. * CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12315: Mitigation bypass in the DOM: Security component. * CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. * CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2814=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2814=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2814=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2814=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2814=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2814=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * Desktop Applications Module 15-SP7 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12289.html * https://www.suse.com/security/cve/CVE-2026-12290.html * https://www.suse.com/security/cve/CVE-2026-12291.html * https://www.suse.com/security/cve/CVE-2026-12292.html * https://www.suse.com/security/cve/CVE-2026-12294.html * https://www.suse.com/security/cve/CVE-2026-12295.html * https://www.suse.com/security/cve/CVE-2026-12296.html * https://www.suse.com/security/cve/CVE-2026-12297.html * https://www.suse.com/security/cve/CVE-2026-12298.html * https://www.suse.com/security/cve/CVE-2026-12299.html * https://www.suse.com/security/cve/CVE-2026-12302.html * https://www.suse.com/security/cve/CVE-2026-12304.html * https://www.suse.com/security/cve/CVE-2026-12305.html * https://www.suse.com/security/cve/CVE-2026-12306.html * https://www.suse.com/security/cve/CVE-2026-12307.html * https://www.suse.com/security/cve/CVE-2026-12308.html * https://www.suse.com/security/cve/CVE-2026-12309.html * https://www.suse.com/security/cve/CVE-2026-12310.html * https://www.suse.com/security/cve/CVE-2026-12311.html * https://www.suse.com/security/cve/CVE-2026-12312.html * https://www.suse.com/security/cve/CVE-2026-12313.html * https://www.suse.com/security/cve/CVE-2026-12314.html * https://www.suse.com/security/cve/CVE-2026-12315.html * https://www.suse.com/security/cve/CVE-2026-12324.html * https://www.suse.com/security/cve/CVE-2026-12325.html * https://www.suse.com/security/cve/CVE-2026-12327.html * https://www.suse.com/security/cve/CVE-2026-12328.html * https://www.suse.com/security/cve/CVE-2026-12329.html * https://www.suse.com/security/cve/CVE-2026-12330.html * https://bugzilla.suse.com/show_bug.cgi?id=1268071 * https://bugzilla.suse.com/show_bug.cgi?id=1269226 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:30:27 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:30:27 -0000 Subject: SUSE-SU-2026:2835-1: important: Security update for clamav Message-ID: <178367222704.944.12099331299802622358@530c474df1e7> # Security update for clamav Announcement ID: SUSE-SU-2026:2835-1 Release Date: 2026-07-09T19:13:18Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2835=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2835=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2835=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2835=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * Basesystem Module 15-SP7 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:30:46 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:30:46 -0000 Subject: SUSE-SU-2026:2834-1: important: Security update for clamav Message-ID: <178367224601.944.14100701637645059703@530c474df1e7> # Security update for clamav Announcement ID: SUSE-SU-2026:2834-1 Release Date: 2026-07-09T19:12:56Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2834=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2834=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2834=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:31:02 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:31:02 -0000 Subject: SUSE-SU-2026:2833-1: important: Security update for clamav Message-ID: <178367226218.944.4117609256811540494@530c474df1e7> # Security update for clamav Announcement ID: SUSE-SU-2026:2833-1 Release Date: 2026-07-09T19:11:01Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2833=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2833=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-debuginfo-1.5.3-3.56.1 * libfreshclam4-debuginfo-1.5.3-3.56.1 * clamav-devel-1.5.3-3.56.1 * clamav-debuginfo-1.5.3-3.56.1 * libclamav12-1.5.3-3.56.1 * libclamav12-debuginfo-1.5.3-3.56.1 * clamav-milter-1.5.3-3.56.1 * clamav-1.5.3-3.56.1 * clamav-milter-debuginfo-1.5.3-3.56.1 * clamav-debugsource-1.5.3-3.56.1 * libfreshclam4-1.5.3-3.56.1 * libclammspack0-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libclammspack0-debuginfo-1.5.3-3.56.1 * libfreshclam4-debuginfo-1.5.3-3.56.1 * clamav-devel-1.5.3-3.56.1 * clamav-debuginfo-1.5.3-3.56.1 * libclamav12-1.5.3-3.56.1 * clamav-milter-1.5.3-3.56.1 * libclamav12-debuginfo-1.5.3-3.56.1 * clamav-1.5.3-3.56.1 * clamav-debugsource-1.5.3-3.56.1 * clamav-milter-debuginfo-1.5.3-3.56.1 * libfreshclam4-1.5.3-3.56.1 * libclammspack0-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * clamav-docs-html-1.5.3-3.56.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:31:23 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:31:23 -0000 Subject: SUSE-SU-2026:2832-1: important: Security update for rustup Message-ID: <178367228369.944.14560663203492674878@530c474df1e7> # Security update for rustup Announcement ID: SUSE-SU-2026:2832-1 Release Date: 2026-07-09T19:02:15Z Rating: important References: * bsc#1203257 * bsc#1230032 * bsc#1243862 * bsc#1249008 * bsc#1270186 * bsc#1270521 * bsc#1270619 * bsc#1270644 * bsc#1270795 * bsc#1270870 * bsc#1270874 * bsc#1270989 Cross-References: * CVE-2024-12224 * CVE-2025-58160 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 10 vulnerabilities and has two security fixes can now be installed. ## Description: This update for rustup fixes the following issues Security issues: * CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243862). * CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249008). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270186). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270619). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270644). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270795). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270870). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270521). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270874). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270989). * rust-shlex: Multiple issues involving quote API ( RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032). Non security issue: * devel:languages:rust/rustup: Missing symlink for rust-analyzer (bsc#1203257). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2832=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2832=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2832=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2832=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * rustup-1.28.2~0-150600.10.13.1 * rustup-debuginfo-1.28.2~0-150600.10.13.1 * Development Tools Module 15-SP7 (aarch64 x86_64) * rustup-1.28.2~0-150600.10.13.1 * rustup-debuginfo-1.28.2~0-150600.10.13.1 * openSUSE Leap 15.6 (aarch64 x86_64) * rustup-1.28.2~0-150600.10.13.1 * rustup-debugsource-1.28.2~0-150600.10.13.1 * rustup-debuginfo-1.28.2~0-150600.10.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * rustup-1.28.2~0-150600.10.13.1 * rustup-debuginfo-1.28.2~0-150600.10.13.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-58160.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1203257 * https://bugzilla.suse.com/show_bug.cgi?id=1230032 * https://bugzilla.suse.com/show_bug.cgi?id=1243862 * https://bugzilla.suse.com/show_bug.cgi?id=1249008 * https://bugzilla.suse.com/show_bug.cgi?id=1270186 * https://bugzilla.suse.com/show_bug.cgi?id=1270521 * https://bugzilla.suse.com/show_bug.cgi?id=1270619 * https://bugzilla.suse.com/show_bug.cgi?id=1270644 * https://bugzilla.suse.com/show_bug.cgi?id=1270795 * https://bugzilla.suse.com/show_bug.cgi?id=1270870 * https://bugzilla.suse.com/show_bug.cgi?id=1270874 * https://bugzilla.suse.com/show_bug.cgi?id=1270989 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:31:48 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:31:48 -0000 Subject: SUSE-SU-2026:2831-1: important: Security update for rustup Message-ID: <178367230837.944.6986164668284512376@530c474df1e7> # Security update for rustup Announcement ID: SUSE-SU-2026:2831-1 Release Date: 2026-07-09T18:55:58Z Rating: important References: * bsc#1203257 * bsc#1230032 * bsc#1243862 * bsc#1249008 * bsc#1257902 * bsc#1270186 * bsc#1270521 * bsc#1270619 * bsc#1270644 * bsc#1270795 * bsc#1270870 * bsc#1270874 * bsc#1270989 Cross-References: * CVE-2024-12224 * CVE-2025-58160 * CVE-2026-25727 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 11 vulnerabilities and has two security fixes can now be installed. ## Description: This update for rustup fixes the following issues Security issues: * CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243862). * CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249008). * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257902). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270186). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270619). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270644). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270795). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270870). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270521). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270874). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270989). * rust-shlex: Multiple issues involving quote API ( RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032). Non security issue: * devel:languages:rust/rustup: Missing symlink for rust-analyzer (bsc#1203257). Changes for rustup: * Completely drop openssl to prevent future security issues Update to version 1.28.2~0: * Deprecate native-tls as well * Enable HTTP/2 support for reqwest download backend * Emit tracing events from log facade calls * download: show Debug representation for errors * Avoid repeated globals in tracing events * Log original download errors immediately * feat(cli/rustup-mode): add aliases to `rustup component remove` * Switch flate2 to use the zlib-rs backend * Hardlink proxies if symlinks aren't reachable * Add powerpc64le-unknown-linux-musl support * Add toolchain_name to not installed bail msg * Warn about using curl * Drop workspace indirection * Fold download crate back into rustup * download: merge integration test files * chore(deps): lock file maintenance * Test CARGO environment replacement * Update CARGO env var if it is a rustup proxy * Tweak toolchain subcommand help text * Move toolchain and default commands first * show toolchain paths in rustup show -v output * refactor(cli/self-update): save allocations in `Nu::rcfiles()` * fix(cli/self-update)!: stop appending to `env.nu` due to deprecation * fix(cli/self-update): consider Windows paths in Nushell suggestions * refactor(cli/self-update): use `path add` in `env.nu` template * fix(cli/self-update): use interpolated string in `env.nu` template * Upgrade dependencies * docs(user-guide/environment-variables): document `RUSTUP_VERSION` * feat(rustup-init/sh): allow setting `RUSTUP_VERSION` during installation * feat(cli/self-update): allow setting `RUSTUP_VERSION` for arbitrary downgrades * feat(test/clitools): add `Config::expect_ok_ex_env()` * fix(errors)!: improve error messages for `RustupError::ToolchainNotInstalled` * Add set auto-install disable * Use `cursor: pointer` for copy button on website * fix(dist): refine suggestions about missing targets * Append Windows bin directory to PATH by default * Remove validation for custom toolchains when reading rust-toolchain.toml * document RUSTUP_AUTO_INSTALL * Fix build script `cargo` instructions Update to version 1.28.1~0: * dist(rustup-init/sh): update commit shasum * Update changelog for 1.28.1 * fix!(config): re-enable implicit toolchain installation in `Cfg::local_toolchain()` with optional opt-out * refactor(test/clitools): extract `Config::expect_err_env()` * Use relative symlinks when possible * docs: update CHANGELOG for v1.28.1 release * fix!(config): re-enable active toolchain installation in `Cfg::find_active_toolchain()` with optional opt-out * config: make Config::find_active_toolchain() async * Use terse output for rustup show active-toolchain * Use read_timeout for reqwest instead of timeout * test: turn set_current_dist_date() into a Config method * test: privatize clitools module * test: remove function wrappers for cmd() and env() * test: privatize mock module * test: move create_mock_dist_server() to Scenario::write_to() * test: move Release into dist * test: turn channel builders into constructors * test: move mock channel builders into dist * test: move arch consts into top-level module * test: turn build_*_installer() functions into constructors * test: move installer builders into mock module * test: privatize items in clitools * test: keep Config impl close to type definition * test: privatize dist module * test: privatize items in test::dist * test: inline short module topical_doc_data * Remove level of nesting in test module * Tweak SanitizedOutput style * docs: update `CHANGELOG` for v1.28.0 release * Have mocked cargo better adhere to cargo conventions * Do not append `EXE_SUFFIX` in `Config::cmd` * Add `TryFrom<Output>` for `SanitizedOutput` * refactor(test): replace `(before|after)_test_async()` with `TestProcess::_telemetry_guard` * style(rustup-init): reorganize imports * refactor(log): introduce `GlobalTelemetryGuard` * refactor(process): rename `TestProcess::_guard` to `_tracing_guard` * chore(deps): update opentelemetry * fix(deps): update rust crate windows-registry to 0.5.0 * refactor: improve binary suffix stripping * build: bump the codebase Language Edition to 2024 * style(cli/job): fix `unsafe-op-in-unsafe-fn` * style(cli/log): use precise capturing when necessary * chore: use unsafe versions of `(add|remove)_var()` * style: remove redundant `ref` keywords * style: partially migrate away from `if-let` * style: format sources with the 2024 Style Edition * chore: fix new `clippy` warnings * fix(deps): update rust crate pulldown-cmark to 0.13 * feat(rustup-init/sh): add env var to print arch detection result * refactor(component): reduce allocations in `ComponentPart::encode()` * refactor(component)!: extract `ComponentPartKind` * style(component): reduce right drift in `ComponentPart::decode()` * refactor(component)!: turn `ComponentPart`'s fields into named ones * fix(dist/prefix): normalize path separators in `REL_MANIFEST_DIR` * fix(component): normalize path separators during `ComponentPart::(en|de)code()` * Upgrade to rand 0.9 * fix(ci/doc): fix typo in renovate `datasource` * ci(doc): make `renovatebot` bump locked `mdbook` * ci(doc): pin `mdbook` to `0.4.43` * ci(schedule): run cron tasks more times per week * ci(schedule): promote to use the `stable` job list * ci(doc): fix stable build of `user-guide` * ci(linux): enable the full test suite for `aarch64-unknown-linux-gnu` * ci(linux): use public ARM64 Linux runners * ci(deploy-docs): merge with `test-docs` * ci(deploy-docs): enable on PR without uploads * ci(deploy-docs): build one book per workflow step * ci(deploy-docs): install `mdbook` with `install-action` * Change installation of dependencies for Aarch64 Dockerfile * Run Aarch64 jobs on PRs * Use ARM based runners for ARM CI targets * style: fix `clippy` warnings * docs(user-guide/components): add deprecation notice for `wasm32-wasi` * Update Windows dependencies * feat(cli/rustup-mode)!: simplify error message for `rustup show active- toolchain` * fix(cli/rustup-mode): make `rustup show active-toolchain` exit with `1` when none is active * fix(cli/rustup-mode): make `rustup default` exit with `1` when there's no default * fix(cli/rustup-mode)!: change `rustup doc --error_codes` to `--error-codes` * fix(deps): update rust crate itertools to 0.14 * fix(cli): align `rustup show`'s `--verbose` behavior with `rustup show active-toolchain` * feat(cli): show the toolchain path with `rustup show active-toolchain --verbose` * feat(test): accept more than one args in `for_host*!()` * fix(ci): fix installation of `cargo-all-features` * docs(user-guide/installation): update "General tips" * move deps around * fix(deps): update rust crate rustls-platform-verifier to 0.5 * fix(rustup-init/sh): don't emit "unknown macOS major version" for macOS v11+ * refactor(rustup-init/sh): extract `$_os_major` * refactor(rustup-init/sh): extract `$_os_version` * ci(linux): move `bindgen-cli` installation into `run.bash` * ci(stable): enable `loongarch64-unknown-linux-musl` builds * ci(linux): disable `reqwest-rustls-tls` for unsupported platforms * ci(linux): configure `gcc-multilib` and `libclang` for some *nix builds * chore(deps): bump `aws-lc-rs` and `aws-lc-sys` * download: clean up TLS feature guards * download: simplify feature guards * download: attach download functions to Backend type * download: remove intermediate reqwest-backend feature * Implement more complete backend selection * Simplify logic for download backend notification * docs(dev-guide/tracing): make "Adding instrumentation" a level-2 title * ci(windows): don't install `awscli` via `choco` * test(mock/topical-doc-data): add test cases with both a flag and a topic * refactor(test/mock): use tuples for `topical_doc_data::TEST_CASES` * feat(cli/rustup-mode): allow `rustup doc` with both a flag and a topic * refactor(toolchain): allow passing a fragment in `Toolchain::doc_path()` * refactor(toolchain): allow absolute paths in `Toolchain::doc_path()` * refactor(toolchain): simplify `Toolchain::doc_path()` * refactor(cli/rustup-mode): rename `doc_url` to `doc_path` * refactor(cli/rustup-mode): make `DocPage::path()` return `Option<&Path>` * refactor(cli/rustup-mode): move `DocPage::name()` to a separate `impl` block * refactor(cli/topical-doc): clean up some funtions * refactor(cli/rustup-mode): use early return in `doc()` * Update semver-compatible dependencies * fix: make sure no overflow on small screens * feat: make the box white * feat: use the color form the rust website for tags, hr and copy button * Add the main element and header to setup new layout * chore: remove the old pitch first * Apply clippy suggestions * Append to 1.28.0 changelog * Bump version, commit and date in rustup-init.sh * Clean up trailing whitespace in rustup-init.sh * Add changelog for 1.28.0 * Bump version to 1.28.0 * chore(deps): update remove-dir-all to 1.0 * Add aliases for remove/uninstall/unset commands * feat: add nushell support * Upgrade to opentelemetry 0.27 * fix: add missing close body tag * Upgrade thiserror to 2 * Upgrade to rustls-platform-verifier 0.4 * fix(cli/rustup-mode): remove `.num_args()` when `.value_delimiter(',')` is present * refactor(cli/rustup-mode): remove deprecated `.use_value_delimiter()` * chore(config): migrate config .github/renovate.json * docs: update channel toolchain syntax * feat(cli/rustup-mode): support more books in `rustup doc` * style(cli/rustup-mode): reorder items in `docs_data![]` * fix: add powerpc64 and s390x to known target_arch values for tests * style(utils): put the `mod` declarations below the imports * style: regroup some imports * refactor(utils): hoist `utils::utils` into `utils` * feat(rustup-init): detect and warn about existing `settings.toml` * fix: fix typo in `check_existence_of_rustc_or_cargo_in_path()` * style: allow using `dbg!()` across `rustup::test` * refactor(diskio): replace `eprintln!()` with `debug!()` * style: enable `clippy::(dbg_macro|todo)` across the workspace * style: enable `clippy::print_std(err|out)` when applicable * style: introduce workspace-wide lint tables * build: use `workspace.package` properties in `Cargo.toml` * fix(config): improve error when overridden active custom toolchain isn't installed * fix(config): print special error for invalid toolchain name in override file * Update semver-compatible dependencies, except openssl-src * style(rustup-init/sh): ignore `shellcheck` SC2086 false positives * fix(rustup-init/sh): fix incorrect TLS warning with curl v8.10 * tests: rust-toolchain + profile in settings * Remove unnecessary methods * replace `winreg` dependency * Update remove_dir_all * refactor(cli/common)!: deny installing a host-incompatible toolchain w/o `--force-non-host` * refactor(cli/common)!: take in `toolchain: String` in `warn_if_host_is_incompatible()` * feat(cli/rustup-mode): add `--force-non-host` to `rustup default` * refactor(config)!: pass the `force_non_host` flag to `Cfg::ensure_installed()` * refactor(cli/rustup-mode): rename `forced` to `force_non_host` * docs(README): Point out where to find nightly/master docs. * Note that selecting VS lang packs is optional * Make symlink_or_hardlink_file remove dest * Try symlinking proxies first * Apply clippy suggestions from 1.81 * feat(cli/rustup-mode)!: set log level to `INFO`/`DEBUG` on `--quiet`/`--verbose` if `RUSTUP_LOG` is unset * refactor(cli/setup-mode): extract `update_console_logger()` * fix(cli/setup-mode): simplify description for `--quiet` * feat(cli/setup-mode)!: set log level to `DEBUG` on `--verbose` if `RUSTUP_LOG` is unset * refactor(common)!: remove `verbose` flag in several places * refactor(config): simplify `find_or_install_active_toolchain()` * refactor(config)!: return `LocalToolchainName` from `find_or_install_active_toolchain()` * refactor(config): simplify `resolve_toolchain()` * refactor(config): simplify `toolchain_from_partial()` * chore(triage): allow transferring issues to other org repos * Allow `rustup doc` to search for unions * docs(user-guide): add a link to the latest "Previous components" section * test(cli_v2): introduce `update_removed_component_toolchain()` * feat(dist): add notes for `stable` and `beta` in `components_missing_msg()` * refactor(dist): inline some const strings in `components_missing_msg()` * refactor(dist): extract "nightly tips" out of the match block in `components_missing_msg()` * fix: fix typo in several places * Upgrade pulldown-cmark to 0.12 * fix(manifest): consider possible renames in `Component::try_new()` * ci(macos): install `awscli` from `brew` * refactor(config)!: make `toolchain_from_partial()` sync * feat(config)!: remove implicit installation from `toolchain_from_partial()` * refactor(config)!: make `resolve_toolchain()` sync * feat(config)!: remove implicit installation from `resolve_toolchain()` * test(cli-rustup): remove `heal_damaged_toolchain()` * refactor(config): extract `local_toolchain()` from `resolve_local_toolchain()` * refactor(config): extract `toolchain` variable from `resolve_local_toolchain()` * refactor(config)!: make `resolve_local_toolchain()` sync * feat(config)!: remove implicit installation from `resolve_local_toolchain()` * refactor(config)!: rename `local_toolchain()` to `resolve_local_toolchain()` * feat(rustup-mode): install the active toolchain by default on `rustup toolchain install` * fix(rustup-mode): adjust descriptions for `rustup toolchain uninstall` * feat(rustup-mode)!: add `ensure_active_toolchain` flag to `update()` * feat(config)!: add `verbose` flag to `find_or_install_active_toolchain()` * style(config): replace `dist::Profile` with `Profile` * style(config): replace `dist::TargetTriple` with `TargetTriple` * fix(config): call `warn_if_host_is_incompatible()` in `ensure_installed()` * refactor(common): use early return in `warn_if_host_is_incompatible()` * refactor(rustup-mode): extract `warn_if_host_is_incompatible()` * style(common): merge imports * refactor(distributable)!: avoid unnecessary clones * refactor(distributable)!: replace `install_if_not_installed()` with `ensure_installed()` * feat(config)!: add `verbose` flag to `ensure_installed()` * feat(config)!: return `UpdateStatus` from `ensure_installed()` * feat(config)!: use `Cfg::get_profile()` for unspecified profile in `ensure_installed()` * chore(config): add `#[tracing::instrument]` to `ensure_installed()` * ci(freebsd): fix build failure related to `aws-lc` * ci(windows): don't install OpenSSL via `choco` * ci(run): remove redundant `if` predicate * ci(run): use the detected number of test threads * feat(download/rustls): use `aws-lc` instead of `ring` * style(taplo): enable `reorder_keys` for `*dependencies` in `Cargo.toml` * Upgrade windows-sys to 0.59 * fix: fix unreachable code lints on Android * docs(dev-guide): remove descriptions of `rustup_macros` * docs(dev-guide): update description of `rustup::process` * Remove `once_cell` dependency * docs(dev-guide): add guideline for atomic commits to the developer guide * fix: fix `clippy` lints * docs(user-guide): use `brew install rustup` instead of `rustup-init` * Bump fs_at to 0.2.1 * chore(deps/renovate): disable `automerge` * Upgrade to opentelemetry 0.24 * build(windows): don't link against `powrprof` * build(windows): fix typo in `build.rs` * fix(utils): make `ExitCode` `#[must_use]` * refactor(rustup-mode): introduce `ExitCode::bitand*()` * fix(rustup-mode): return `ExitCode(1)` when `update()` fails * refactor(rustup-mode)!: remove redundant `ExitCode` in `self_update()`'s callback * test(cli-misc): simplify `version_mentions_rustc_version_confusion()` * fix(rustup-mode): refine output for `rustup --version` * fix(rustup-mode)!: don't install toolchain on `rustup --version` * chore(deps/renovate): update `automerge` schedule for `lockFileMaintenance` * ci(check): add `taplo fmt` test for TOMLs * style: reformat all TOMLs with `taplo` * ci(gen-workflows): remove `--quiet` from `git diff` * refactor: use `#[cfg()]` instead of `cfg!()` when possible * refactor(self-update): remove outdated `do_pre_install_sanity_checks` * Add help message for missing toolchain * Rename OSProcess to OsProcess * Rename currentprocess to process * Forward to Process::var_os() directly * Fix home_dir() and current_dir() regression * feat(log): set level of `#[tracing::instrument(err)]` to `TRACE` * feat(log): unhide `tracing::instrument` from behind `feature = "otel"` * ci(windows): increase stack size to 16MiB * Upload Windows artifacts into correct subdirectory * Fix uploading of Windows build artifacts * Prepare deployment on master branch * Grant GitHub Actions workflows access to OIDC token * chore(deps): update aws-actions/configure-aws-credentials action to v4 * Authenticate CI uploads with OIDC * Upload release artifacts to new S3 bucket * chore(deps/renovate): set `prCreation` to `immediate` * feat(dist): refine suggestions regarding manifest checksum mismatches * refactor(config): extract `dist_root_server()` * refactor(dist): use `let-else` in `dl_v2_manifest()` * refactor(dist/notifications)!: inline usages of `Notification::ManifestChecksumFailedHack` * refactor(install): avoid extra clone in `InstallMethod::install` * Reorder operations in order to simplify * Deduplicate handling of environnment variables * Move if_not_empty() to calling module * feat(cli): warn when removing the default/active toolchain * feat(cli): improve warning when removing the last/host target for a toolchain * docs(ci): simplify the target policy in the README * Add loongarch64-unknown-linux-musl support * fix(download): fix build error with `--no-default-features --features=curl- backend` * feat(rustup-init): set log level to `WARN` on `-q` if `RUSTUP_LOG` is unset * implements quiet flag in `rustup-init.sh` * test(manifestation): introduce and migrate tests to `TestContext` * chore(manifestation): organize imports * add regression tests for smart guess * apply smart guess to `rustup update/uninstall self` * Disable automatic self updates in CI environments * feat(download/rustls): use `rustls-platform-verifier` * ci(windows): run `cargo all-features` * fix(self-update/windows): address some `unused_imports` warnings * fix(rustup-mode): improve `clap` error format * Add period in warning while checking existing rust installations * Move Windows-only test code into windows module * Asyncify CLI tests * Use guard type to replace with_saved_path() * Refactor test registry state to be more type safe * Inline single-use with_saved_global_state() function * Privatize with_saved_global_state() * Move change_dir() into CliTestContext * Move with_update_server() into CliTestContext * Remove Config::with_scenario() * Port cli_v2 to CliTestContext * Port cli_v1 to CliTestContext * Port cli_self_upd to CliTestContext * Port cli_rustup to CliTestContext * Port cli_paths to CliTestContext * Port cli_misc to CliTestContext * Port cli_inst_interactive to CliTestContext * Port cli_exact to CliTestContext * Use CliTestContext directly in self_update_setup() * Start CliTestContext type wrapper * docs(dev-guide/tracing): mention `RUSTUP_LOG` and console-based tracing * docs(dev-guide/linting): improve wording * test(dist): add simple tests for `PartialVersion` * chore(dist): add some doc comments * fix(dist): throw an error when a `PartialVersion` string doesn't start with an ASCII digit * ci(all-features): add `-D warnings` to `cargo check-all-features` * fix(currentprocess/filesource): address some `unused_imports` warnings * fix(currentprocess): address some `unused_imports` warnings * fix(regex): replace `\d` to `[0-9]` to avoid matching non-ASCII digits * refactor(toolchain/names): replace `toolchain_sort` with `ToolchainName`'s `Ord` instance * refactor(dist)!: make `ToolchainDesc.channel` more strongly typed * Remove unnecessary lint suppressions * Use local suppression for clippy::too_many_arguments * Rename desc fields to toolchain * Remove intermediate state from error handling * Remove indirection in update error handling * Inline wrapper function * Reduce rightward drift * Propagate use of DistOptions * Avoid unnecessary unwrapping * Extract struct from InstallMethods::Dist variant * refactor(log): replace the `TELEMETRY_DEFAULT_TARCER` singleton with a function * test(clitools): revive `run_inprocess()` * fix(dist/arm): don't assume `armv7` if `/proc/cpuinfo` is unavailable * fix(dist): add fallbacks to `/proc/self/exe` in `rustup-init.sh` * Rename default-tls to native-tls * Inline small errors module * Inline addition/removal to programs * Move windows-only self_update code into windows module * Reorganize platform-dependent imports in self_update * refactor(log): replace `[Ww]arning:` log line prefix with `warn:` * refactor(log): rename `NotificationLevel::Debug` to `Trace` and `Verbose` to `Debug` * Remove unused code * Hoist Toolchain up into top-level toolchain module * Remove unused derived sorting implementations * Privatize internal organization of toolchain module * Inline argument * Inline trivial wrapper * Move toolchain resolution into Cfg method * Check settings version on Cfg construction * Move proxy toolchain resolution logic into Cfg method * Move rustc_version() function into Cfg * Expose higher-level interface in Toolchain * Move DistributableToolchain::installed_paths() into Cfg * No need to store cfg in DistributableToolchain * Reduce indirection in Cfg::from_partial() * Move Toolchain::from_partial() to Cfg * Take owned LocalToolchainName in Toolchain::from_local() * Simplify Toolchain::from_local() * refactor(dist): hoist `dist::dist` into `dist` * refactor(dist): privatize imports from `dist::dist` * Fix the `TODO` in `src\toolchain\toolchain.rs` * Use tracing macros directly * Inline single-caller maybe_trace_rustup() * Remove rustup test wrapper macros * Use tokio::main attribute * Attach Process-dependent utils to Process * Remove with_runtime() * fix(config): fix typo in `ActiveReason` * fix(log): use `RUSTUP_LOG` for internal `tracing` instead of `RUST_LOG` * refactor(currentprocess): make use of `Arc::default()` * refactor(currentprocess): rename `TestProcess.guard` to `_guard` * Remove currentprocess::with() * Privatize most TestProcess fields * Remove unused TestProcess::id * Pass Process around explicitly * Let argument parser handle SelfUpdateMode conversion * Let argument parser handle Profile conversion * Use simpler form for string concatenation * Reduce rightward drift by duplicating some Ok-wrapping * Rename _install_selection() to IInstallOpts::install() * Inline async closure * Move error mapping out of validation function * Rename do_pre_install_options_sanity_checks() to InstallOpts::validate() * Rename customize_install() to InstallOpts::customize() * Pass InstallOpts around directly * refactor(terminalsource): use `.eq_ignore_ascii_case()` in `ColorableTerminal::new` * chore(notify): sort logging macros and `NotificationLevel` on verbosity * chore(env): retire `RUSTUP_DEBUG` in favor of `RUST_LOG` * feat(log): make `console_logger()` accept `RUSTUP_TERM_COLOR` and `NO_COLOR` * refactor(log): reimplement `log` using `tracing` * refactor(test): clean up `before_test_async()` * chore(deps): make `tracing-subscriber` a hard requirement * refactor(test): setup `tracing` subscriber in `before_test_async()` * test(clitools): disable `run_inprocess()` * refactor(test): execute all `#[rustup_macros::unit_test]`s within a `tokio` context * refactor(log): extract `telemetry()` * Remove noop functions in favor of conditional compilation * Avoid trivial wrapper functions * Store process name in error variant directly * Inline trivial wrapper function * Fix misleading "uninstalled toolchain" notification * refactor(ci/run): use more `target_cargo()` in `run.bash` * Remove trivial new() implementation * Use serde to encode/decode mock manifests * Use serde to encode/decode rustup manifests * Use serde to encode/decode config * Represent config version as an enum * Use serde to encode/decode manifests * Represent manifest version as enum * Use serde to encode/decode settings * Add tests for settings encoding * Derive Default for Settings * Represent metadata version as an enum * Use Default impl for Settings::profile default * Derive Default for Profile * Discard unnecessary layer of Arc * Externalize wrapping of DownloadTracker * Inline NotifyOnConsole * Internalize interior mutability for Notifier * Decouple Cfg from Notifier initialization * fix(dist/triple): ensure `dist::triple::known` is up to date with `platforms` * refactor(toolchain): reuse `dist::triple::known` in `toolchain::names` * refactor(dist/triple): move known triples to `dist::triple::known` * refactor(build): use `platforms` to verify `RUSTUP_OVERRIDE_BUILD_TRIPLE` * refactor(build): simplify the code obtaining the current triple * feat(cli): add `--quiet` to `rustup (target|component) list` * feat(cli): add `--quiet` to `rustup toolchain list` * Inline trivial single-use function utils::to_absolute() * Inline trivial single-use function Cfg::which_binary() * Inline short single-use function direct_proxy() * Rename new_toolchain_with_reason() to Toolchain::with_reason() * Move Cfg::maybe_do_cargo_fallback() to Toolchain * Move Cfg::create_command_for_toolchain() to Toolchain::command() * Extract common usage of Cfg::create_command_for_toolchain() * Inline trivial single-use function Cfg::create_command_for_dir() * Inline simple function Cfg::create_command_for_toolchain() * Move toolchain construction out of Cfg::create_command_for_toolchain() * Inline single-use function * Improve error message for failing .rustup creation * Inline trivial single-use function * Inline utils::current_dir() * Take explicit current_dir argument in to_absolute() * Pass current_dir down from main() * Update rustup.rs website to offer Rustup on Windows on Arm * Use Cfg::current_dir in override_remove() * Use Cfg::current_dir in override_add() * Use Cfg::current_dir in find_or_install_active_toolchain() * Use Cfg::current_dir for create_command_for_dir() * Use Cfg::current_dir for find_or_install_active_toolchain() * Store current_dir in Cfg for use in find_active_toolchain() * Enable building Rustup win-aarch64 on PR * Add aarch64-apple-darwin and aarch64-pc-windows-msvc to cloudfront- invalidation.txt * Update Other installation methods page to include aarch64-pc-windows-msvc * Remove unnecessary trait abstraction * Simplify process access to current_dir * Simplify process access to environment variables * Remove unnecessary trait bound for home::Env * Simplify process access to pid * Simplify process access to stdin * Simplify process access to stderr * Simplify process access to stdout * Simplify process access to argument iterator * fix(download): work around `hyper` hang issue by adjusting `reqwest` config * test(download): fix clippy warnings regarding `Mutex` in `async` * test(dist): add regression tests for parsing beta versions with tags * test(dist): introduce scenario `BetaTag` with mock test data * feat(dist): add support for parsing beta versions with tags in the toolchain * refactor(utils): move `run_future()` under `manifestation` * feat(config): make `create_command_for_toolchain()` async * refactor(config): make `update_all_channels()` async * refactor(self_update): make `maybe_install_rust()` async * refactor(config): make `ensure_installed` async * fix expected path-separators on windows * add a regression test * consistently add context with file path when parsing fails * ci(windows/gnu): install `mingw` via `bwoodsend/setup-winlibs-action` * ci(windows): enable CI on `x86_64-pc-windows-gnu` * Make manifestation test update_from_dist async * Make update async * Make default_ async * Make check_updates async * Make target_add async * Make target_remove async * Make component_add async * Make component_remove async * Make update_all_channels async * Make toolchain_link async * Make override_add async * Make DistributableToolchain::remove_component async * Make DistributableToolchain::add_component async * Make DistributableTool::install_if_not_installed async * Make DistributableToolChain::install async * Make toolchain.update async * Make update_extra async * Make show_dist_version async * Make InstallMethod::install async * Make InstallMethod::run async * Make update_from_dist async * Make update_from_dist_ async * Make try_update_from_dist_ async * Make update_v1 async * Make dist::dl_*_manifest async * Make common::self_update async * Make manifestation::update async * Make download retries async * Make DownloadCfg::download_and_check async * Make DownloadCfg::download_hash async * Make self_update::update async * Make check_rustup_update async * Make prepare_update async * Make get_available_rustup_version async * Make setup_mode::main async * Make self_update::install async * Make try_install_msvc async * Make download_file async * Make DownloadCfg::download async * Make download_file_with_resume async * Make download_file_ async * Make download_to_path_with_backend async * Make download_with_backend async * Make rustup_mode::main async * Convert run_rustup_inner to async * Make run_rustup async * Remove maybe_trace_rustup runtime setup * Make maybe_trace_rustup async * Convert main to using a tokio runtime always * Ring 0.17.x support Windows on ARM * ci(macos): use `macos-latest` instead of `macos-14` * fix(deps): update rust crate itertools to 0.13 * fix(deps): update rust crate pulldown-cmark to 0.11 * Avoid unnecessary allocations * Attempt to reduce duplication by adding a little abstraction * Move explicit_desc_or_dir_toolchain() to Toolchain::from_partial() * Propagate ExitStatus instead of custom ExitCode * Use precise internal imports * Use idiomatic way to proxy str data * Inline RustupSubcmd::dispatch() * refactor(filesource): replace repetitive `#[cfg()]` usages with a new `mod` * Fix ETA display after regression * Stop showing ETA after download is complete * refactor(cli): hoist the `handle_epipe()` call out of the `match` * refactor(cli): rewrite `rustup` itself with `clap-derive` * refactor(cli): rewrite `rustup (self|set)` with `clap-derive` * refactor(cli): rewrite `rustup (man|completions)` with `clap-derive` * refactor(cli): rewrite `rustup doc` with `clap-derive` * refactor(cli): rewrite `rustup (run|which|dump-testament)` with `clap- derive` * refactor(cli): rewrite `rustup override` with `clap-derive` * refactor(cli): rewrite `rustup component` with `clap-derive` * refactor(cli): rewrite `rustup target` with `clap-derive` * refactor(cli): rewrite `rustup (check|default)` with `clap-derive` * refactor(cli): rewrite `rustup (toolchain|update|(un)?install)` with `clap- derive` * refactor(cli): remove `deprecated()` * refactor(cli): rewrite `rustup show` with `clap_derive` * fix(rustup-init): fix typo in `rustup-init[.sh]` args * feat(download): reflect the download/TLS backends in the user agent * Make find_override_from_dir_walk return OverrideCfg * Make settings file allow multiple borrows * Fix doc error with `rust-toolchain.toml` custom TC * Make `rustup default` not error if no default * Update format of `toolchain list` * Update format of `show` and `show active-toolchain` * Redesign OverrideCfg to be more type-driven * Pull match statement out in OverrideCfg::from_file() * Change find_override to find_active_toolchain * Pull out `new_toolchain_with_reason()` * Pull out `ensure_installed()` * refactor(cli): reorder `if` statement in `cli::setup_mode::main()` * refactor(cli): rewrite `rustup-init` with `clap_derive` * Avoid code duplication for printing target/component items * Deduplicate code to get components from distributable * Merge list_{,installed_}targets * Merge list_{,installed_}components functions * fix(filesource): make some constructs only available via the `test` feature * fix(ci/freebsd): install ca certs to prevent `invalid peer certificate: UnknownIssuer` * feat(download-backend)!: make `reqwest/rustls` the new default * feat(download-backend)!: refine selection logic * Update MSVC requirements to VS 2017 to match Rust repo * refactor(download): use `DownloadCallBack` in `download_with_backend()` * ci: don't build for `i686-linux-android` due to OpenSSL v3 atomic issues * ci(android): update NDK version * fix(deps): update rust crate openssl-src to v300 * ci(linux-gnu): install `perl-IPC-Cmd` to make OpenSSL v3 happy * chore(deps): update ubuntu docker tag to v24 * docs(dev-guide): remove "pushing to master" in the release process * Replace remaining winapi usage with windows-sys Update to version 1.27.1~0: * chore(dist): update commit shasum in `rustup-init.sh`, take 2 * fix(ci/linux): don't use `pip3` to install `awscli` * fix(ci/macos): don't use `pip3` to install `awscli` * chore(dist): update commit shasum in `rustup-init.sh` * docs: update CHANGELOG for v1.27.1 * feat(dist): improve `changelog_helper` script * dist: bump `rustup` version to `1.27.1` * chore: fix some typos in comments * Remove TryFrom for TargetTriple * Add tests for add/remove components by name with target triple * Replace Component::new_with_target by Component::try_new * refactor(self-update)!: remove confusing `get_path()` impl on Unix * test(self-update): ensure the resolution of #3739 * feat(self-update): add `with_saved_reg_value()` * refactor(self-update): extract `(get|restore)_reg_value()` * refactor(self-update): extract `with_saved_global_state()` * refactor(self-update): use `std::io` * fix(self-update): replace some `#[cfg(not(unix))]` usages with `#[cfg(windows)]` * feat(self-update): improve error messages on Windows * fix(self-update): run `do_update_programs_display_version()` on `run_update()` * refactor(self-update): extract `get_and_parse_new_rustup_version()` * refactor(self-update): extract `do_update_programs_display_version()` * ci: don't test for FreeBSD on PRs * docs(user-guide): update `environment-variables` * refactor(self-update): eliminate needless clone * feat(self-update): log `RUSTUP_DIST_*` if it's set * feat(self-update): log `RUSTUP_UPDATE_ROOT` if it's set * refactor(self-update): rename `UPDATE_ROOT` to `DEFAULT_UPDATE_ROOT` * refactor(self-update): extract `update_root()` * once_cell only used with reqwest in download crate, so gate it * tracing unsed only from otel feature, so move it to optional * Add loongarch64-unknown-linux-gnu to installation docs * Add loongarch64-unknown-linux-gnu to cloudfront invalidations * Use pattern matching to make Debug impl for Cfg more robust * Use std IsTerminal interface * Rename temp::Cfg to Context * temp: keep definitions and impls together * Remove derivative dependency in favor of manual implementation * docs(dev-guide): move all mentions of `cargo clippy` to `linting.md` * docs(dev-guide): mention that we need to keep mdBook links stable * refactor(utils)!: rename `delete_dir_contents()` to `delete_dir_contents_following_links()` * fix(utils): resolve input path in `delete_dir_contents()` if it's a link * test(cli): ensure the resolution of #3344 * Revert "fix(utils): unlink input path in `delete_dir_contents()` if it's a link" * Revert "refactor(utils)!: rename `delete_dir_contents()` to `delete_dir_contents_or_unlink()`" * Revert "test(cli): ensure the resolution of #3344" * refactor(utils)!: rename `delete_dir_contents()` to `delete_dir_contents_or_unlink()` * fix(utils): unlink input path in `delete_dir_contents()` if it's a link * test(cli): ensure the resolution of #3737 * refactor(util)!: rename `open_dir()` to `open_dir_following_links()` * fix(utils): don't use `O_NOFOLLOW` in `open_dir()` * chore: fix typo in `CHANGELOG` * chore(meta): update `bug_report` issue template * Add hr to Windows instructions * fix(doc): don't show the opening message when --path is used * chore: remove repetitive words * fix(deps): update rust crate opener to 0.7.0 * fix(config): remove unnecessary debug print * fix(ci): fix file paths in CI-generated `*.sha256` files on *nix * fix(ci): correct error message after bumping reqwest * fix(deps): update rust crate reqwest to 0.12 * doc(dev-guide): Fix test Lint and add explanation * Fix "component add" error message * ci: use `stable` Rust for all clippy lints * style: apply clippy suggestions from Rust 1.78.0 * fix(ci/windows): disable `cargo clippy` on `*-windows-gnu` * fix(shell): create parent dir before appending to rcfiles * fix(fish): fix definition of `Fish::update_rcs` * docs(dev-guide): update `release-process.md` to match the new workflow based on GitHub Merge Queue * ci(macos): add `MACOSX_DEPLOYMENT_TARGET` and friends * Replaced `.` with `source` in fish shell's `source_string` * Deny clippy warnings in CI * Rely on implicit conversion to OperationResult * Extract closure from match scrutinee * fix(cli): fix incorrect color state after `ColorableTerminal::reset` * docs: Add note about stability of llvm-tools. * Change default for RUSTUP_WINDOWS_PATH_ADD_BIN * ci: remove direct `renovate/*` tests * Fix dead_code and unused_imports warnings Update to version 1.27.0~0: * docs: update `CHANGELOG` for v1.27.0 * hack(deps): pin `openssl-sys` to 0.9.92 * fix #3663. Feedback in terminal when opening browser for docs * Fix copy icon position in Safari * Upgrade to opentelemetry 0.22 * fix ambiguous prompt after setting up custom installation * docs: rephrase and split sentence about Visual Studio license * Add comment on why we prefer symlinks to junctions * Windows: Try using symlinks if they're allowed * chore(ci): unify the matrix format to (mode, target) * ci: update runners for macOS-related workflows * docs: mention `apt` in installation methods * docs: fix missing links in `CHANGELOG.md` * chore(deps): update rust crate trycmd to 0.15.0 * fix(deps): downgrade `openssl-sys` to 0.9.92 * ci: remove the now-tier3 `mips*-unknown-linux-gnu*` targets from the build * Update mdbook and fix some source issues. * Rename `.cargo/config` to `.cargo/config.toml` * chore: update `CHANGELOG.md` * dist: bump `rustup-init.sh` version to `1.27.0` * dist: bump `rustup` version to `1.27.0` * feat: introduce `changelog_helper` script * Upgrade to pulldown-cmark 0.10 * Fix some typos * fix(deps): update rust crate libc to 0.2.153 * Download rust CI Docker images from a registry * Component is now named 'llvm-tools' * chore: add docstring to `is_32bit_userspace()` * chore: disable some unix-only helper functions on Windows * chore(deps): update actions/cache action to v4 * refactor(cli): simplify case splitting on `clap::error::ErrorKind` * refactor(names): replace `maybe_official_toolchainame_parser` with `impl FromStr` * refactor: simplify `is_proxyable_tools` * refactor(distributable): import `ComponentStatus` * refactor(cli): avoid nested combinators in `has_at_most_one_target` * feat(cli): warn when removing the last/host target for a toolchain * refactor(toolchain): extract `DistributableToolchain::components()` * www: detect RISC-V 64 platform * fix(deps): update rust crate strsim to 0.11 * chore(deps): update `renovate.json` to remove version bumps covered by lockfile maintenance PRs, take 3 * feat(ci): configure `merge_queue` to be a PR-like event * feat(ci): enable the `merge_group` trigger * fix(ci): use `github.event_name == 'schedule'` instead of `github.event.schedule` * chore(deps): update `renovate.json` to remove version bumps covered by lockfile maintenance PRs, take 2 * fix(deps): update rust crate clap to v4.4.13 * fix(deps): update rust crate syn to v2.0.48 * chore(deps): update rust crate opentelemetry_sdk to v0.21.2 * fix(ci): use `github.event_name == 'push'` instead of `github.event.push` * feat(ci): add CI workflow generation checks * refactor(ci): disassemble and reorganize `ci/cirrus-templates` * feat(ci): add `conclusion` job * refactor(ci): move `freebsd-builds` to GitHub Actions * refactor(ci): merge all current GitHub Actions workflows into `ci.yaml` * chore(ci): clean up current CI files * chore(deps): update `renovate.json` to remove version bumps covered by lockfile maintenance PRs * fix(deps): update rust crate syn to v2.0.47 * fix(deps): update rust crate proc-macro2 to v1.0.75 * fix(deps): update rust crate clap_complete to v4.4.6 * fix(deps): update rust crate serde to v1.0.194 * fix(deps): update rust crate semver to v1.0.21 * chore(deps): update rust crate thiserror to v1.0.56 * chore(deps): update rust crate anyhow to v1.0.79 * fix(deps): update rust crate syn to v2.0.45 * fix(deps): update rust crate proc-macro2 to v1.0.73 * fix(deps): update rust crate syn to v2.0.44 * fix(deps): update rust crate quote to v1.0.34 * fix(deps): update rust crate proc-macro2 to v1.0.72 * chore(deps): update rust crate anyhow to v1.0.78 * chore(deps): update rust crate thiserror to v1.0.53 * fix(deps): update rust crate clap to v4.4.12 * chore(deps): update rust crate tempfile to v3.9.0 * fix(deps): update rust crate clap_complete to v4.4.5 * chore(deps): update rust crate anyhow to v1.0.77 * chore(deps): update rust crate thiserror to v1.0.52 * fix(deps): update rust crate syn to v2.0.43 * fix(deps): update rust crate openssl to v0.10.62 * fix(deps): update rust crate proc-macro2 to v1.0.71 * fix(deps): update rust crate syn to v2.0.42 * chore(deps): update rust crate anyhow to v1.0.76 * chore(deps): update rust crate hyper-util to v0.1.2 * chore(deps): update rust crate tokio to v1.35.1 * fix(deps): update rust crate reqwest to v0.11.23 * chore(deps): update rust crate hyper to v1.1.0 * docs: move "rls" and "rust-analysis" to separate section "previous..." (#3591) * chore(deps): update actions/upload-artifact action to v4 * Fix rustup-init failure to read ZDOTDIR from zsh when SHELL is not zsh (#3584) * CI: Enable rustls on loongarch64 * CI: Revert "Disable openssl for loongarch64-unknown-linux-gnu" * fix(deps): update rust crate openssl-src to v300.2.1+3.2.0 * fix(deps): update rust crate syn to v2.0.41 * fix(deps): update rust crate syn to v2.0.40 * fix(deps): update rust crate libc to v0.2.151 * chore(deps): update rust crate once_cell to v1.19.0 * fix(deps): update rust crate clap to v4.4.11 * fix(deps): update rust crate openssl to v0.10.61 * Fix test permanently adding to PATH * chore(deps): revert `Cargo.toml` bump in #3540 * chore(deps): revert `Cargo.toml` bump in #3532 * chore(renovate): prevent unnecessary `Cargo.toml` bumps * Lock file maintenance * Fix panic in `component list --toolchain stable` * Upgrade hyper to 1.0 (#3543) * Clarify several docs and help messages * Remove rel paths from rust-toolchain.toml docs * CI: Disable openssl for loongarch64-unknown-linux-gnu * Update Rust crate url to 2.5 * Update Rust crate winreg to 0.52 * Update Rust crate windows-sys to 0.52.0 * Update Rust crate termcolor to 1.4 * Streamline dependencies in `Cargo.toml` * Update opentelemetry * [doc] windows.md: fix link * Inline channel pattern list * Remove unused import * Explicitly import symbols * Remove unused dependencies from macros crate * Replace usage of lazy_static with once_cell * Use more conventional field order in package table * Remove authors from Cargo manifest (per RFC 3052) * Use uniform dependency specification style * Inline `semver::Version` in `toolchain_sort` * Add docs specifying `toolchain_sort`'s expected behavior * Change key used in `toolchain_sort` * Inline `special_version` in `toolchain_sort` * Inline `toolchain_sort_key` in `toolchain_sort` * Replace `sort_by` with `sort_by_key` in `toolchain_sort` * Refine `test_toolchain_sort` * Suggest installing MSYS2 for `windows-gnu` * Fix the test toolchain_broken_symlink on Windows * Move `TOOLSTATE_MSG` to `dist` to serve toolchain-wide operations * Add test to ensure resolution of #3418 * Add `Panics` sections to docstrings * Refactor `components_*_msg` * Delete suggestions of removing the relevant component from `component_unavailable_msg` * Clean up some `manifestation` logic * Warn when running under Rosetta emulation * Typo fixed in tips-and-tricks.md file * Adjust suggestions about sourcing `env` files * Restrict zsh `shwordsplit` to `downloader()` * Update Rust crate zstd to 0.13 * Apply `clippy` suggestions * Extract `post_install_msg_unix_source_env!()` * Add suggestions to mention sourcing `env.fish` * Fix zsh word splitting for curl "\--retry 3" * Add ksh compatibility for latest illumos and others * Remove redundant message if an error occurs during package extraction * Update Rust crate regex to 1.10.0 * Write a custom env script for fish * Fix fish config dir paths * Update all rc fish scripts * Try to add support for fish shell * Clarify the origin of `rust-$TARGET` CI Docker images * Apply more `clippy` suggestions * Capturing IO error in download_file_with_resume (#3421) * Adjust instructions for manual installation (#3502) * Windows: Load DLLs from system32 * When running a 32-bit rustup on an aarch64 CPU, select a 32-bit toolchain * Do not fallback to "arm" in rustup-init.sh on aarch64 with 32-bit userland * Update Rust crate toml to 0.8 * Mention `brew install rustup-init` in the user guide * Adjust section titles in the user guide * Update actions/checkout action to v4 * Avoid warning for unused variant * fix invalid link for 1.25.2 * 1.26.0 should not be unreleased in the changelog * Refactor test case `install_uninstall_affect_path` * Update Rust crate winreg to 0.51 * Apply clippy suggestions from Rust 1.74 (#3497) * Fix rustup_only_options_stdout * Bring additional help section style in line with clap 4 * Upgrade to clap 4 * Avoid deprecated clap API * Isolate trycmd tests from environment * Update Rust crate tracing-opentelemetry to 0.21.0 * buf writes to components * Update Rust crate tempfile to 3.8 * Return the right lifetime from DistributableToolchain::install * Fix handling of async tests * Improve CI debugability * Refactor: Use download_cfg.notify_handler in update() * Authenticate when installing protoc * Avoid installing protoc for most CI workflows * Refine suggestions of sourcing `$HOME/.cargo/env` * Avoid `sysctl: unknown oid` stderr output and/or non-zero exit code * Configure automerge in Renovate * Fix renovate.json * Make `RUSTUP_TERM_COLOR`'s value case insensitive * Add unit tests for `RUSTUP_TERM_COLOR` * Support `RUSTUP_TERM_COLOR` as an override environment variable * macOS `uname -m` can lie due to Rosetta shenanigans * Migrate CONTRIBUTING.md to an mdbook * Build docs during CI * Move the user guide from doc to doc/user-guide * Update Rust crate tempfile to 3.7 * Use available_parallelism replace the `num_cpus`crate * rustup-init.sh: Check for kernel UAPI compatibility on LoongArch * Enable loongarch64-linux-gnu builds on stable * allow `clippy::arc_with_non_send_sync` * Address `#[warn(clippy::useless_vec)]` * Address `#[warn(clippy::needless_borrow)]` * Address `#[warn(clippy::useless_conversion)]` * Address `#[warn(clippy::redundant_pattern_matching)]` * Address `#[warn(clippy::redundant_field_names)]` * Bump proc-macro2 v1.0.51 -> v1.0.63 * Bump the openssl v0.10.52 -> v0.10.55 * Fix typo: prerequistes -> prerequisites * update installation methods to use TLS v1.2 * Disable the "oldtime" feature of chrono * Update Rust crate tempfile to 3.6 * Update Rust crate url to 2.4 * Update Rust crate once_cell to 1.18.0 * Make download_tracker thread safe. * Enable broken color in MSYS2 shells * Add suggest_message helper for errors * replace term with termcolor * Tweak docs * Improve error message for removing uninstalled target * Improve error message for adding unknown target * CI support for loongarch64-unknown-linux-gnu * Fix compile on rust nightly * Group updates to opentelemetry together * Improve CurrentProcess * Update dependencies * TestProcess and friends should be test only * Update Rust crate windows-sys to 0.48.0 * Rework Toolchain model and drop relative file path overrides * Add in opentelemetry tracing as a feature * Remove repeated definite article * Make clippy happy * Update Rust crate toml to 0.7.3 * Suggest right toolchain when running clippy * Fix small typo * Update Rust crate winreg to 0.50 * Update Rust crate tempfile to 3.5 * Compile static Mutex where possible * Upgrade CI image to FreeBSD 13.2 * Update Rust crate opener to 0.6.0 * Update Rust crate enum-map to 2.5.0 * Bumped retry ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2831=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2831=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2831=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2831=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2831=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2831=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2831=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2831=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2831=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * openSUSE Leap 15.4 (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64) * rustup-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * rustup-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-58160.html * https://www.suse.com/security/cve/CVE-2026-25727.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1203257 * https://bugzilla.suse.com/show_bug.cgi?id=1230032 * https://bugzilla.suse.com/show_bug.cgi?id=1243862 * https://bugzilla.suse.com/show_bug.cgi?id=1249008 * https://bugzilla.suse.com/show_bug.cgi?id=1257902 * https://bugzilla.suse.com/show_bug.cgi?id=1270186 * https://bugzilla.suse.com/show_bug.cgi?id=1270521 * https://bugzilla.suse.com/show_bug.cgi?id=1270619 * https://bugzilla.suse.com/show_bug.cgi?id=1270644 * https://bugzilla.suse.com/show_bug.cgi?id=1270795 * https://bugzilla.suse.com/show_bug.cgi?id=1270870 * https://bugzilla.suse.com/show_bug.cgi?id=1270874 * https://bugzilla.suse.com/show_bug.cgi?id=1270989 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:03 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:32:03 -0000 Subject: SUSE-SU-2026:2830-1: important: Security update for warewulf4 Message-ID: <178367232373.944.16849122163100013757@530c474df1e7> # Security update for warewulf4 Announcement ID: SUSE-SU-2026:2830-1 Release Date: 2026-07-09T18:42:10Z Rating: important References: * bsc#1254470 * bsc#1258511 * bsc#1262810 * bsc#1265653 * bsc#1266483 * bsc#1268790 Cross-References: * CVE-2025-69725 * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 CVSS scores: * CVE-2025-69725 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N * CVE-2025-69725 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-69725 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 An update that solves four vulnerabilities and has two security fixes can now be installed. ## Description: This update for warewulf4 fixes the following issues: Update to v4.7.0. Security issues fixed: * CVE-2025-69725: incorrect input validation in the `RedirectSlashes` function can lead to an open redirect (bsc#1258511). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` can lead to a denial of service (bsc#1265653). * CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262810). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266483). Other updates and bugfixes: * Add correct flag `--update-overlays` fix (bsc#1268790). * v4.7.0: * New `wwctl` unset command * Refactored server routes (URLs) * New `/files/` route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions * v4.6.5: * New wwctl overlay info command * Fixed `wwctl` image import `--update` option * Cross-arch support for `wwclient` * Improved IPv6 support * Improved support for bonded interfaces * Renamed `debian.interfaces` overlay to `ifupdown` * New `systemd-networkd` overlay * `warewulf-dracut` fixes, including `provision-to-disk` fixes * Remove `slurm-overlay` package. * Fix `wwctl` image import `--update` option (bsc#1254470). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2830=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2830=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2830=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2830=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-2830=1 ## Package List: * openSUSE Leap 15.5 (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 * warewulf4-overlay-rke2-4.7.0-150500.6.42.1 * openSUSE Leap 15.5 (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * HPC Module 15-SP7 (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * HPC Module 15-SP7 (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 ## References: * https://www.suse.com/security/cve/CVE-2025-69725.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1254470 * https://bugzilla.suse.com/show_bug.cgi?id=1258511 * https://bugzilla.suse.com/show_bug.cgi?id=1262810 * https://bugzilla.suse.com/show_bug.cgi?id=1265653 * https://bugzilla.suse.com/show_bug.cgi?id=1266483 * https://bugzilla.suse.com/show_bug.cgi?id=1268790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:15 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:32:15 -0000 Subject: SUSE-SU-2026:2829-1: important: Security update for libaom Message-ID: <178367233536.944.11599255591144782004@530c474df1e7> # Security update for libaom Announcement ID: SUSE-SU-2026:2829-1 Release Date: 2026-07-09T18:40:25Z Rating: important References: * bsc#1268650 * bsc#1268651 * bsc#1268653 * bsc#1268655 Cross-References: * CVE-2026-56208 * CVE-2026-56209 * CVE-2026-56210 * CVE-2026-56211 CVSS scores: * CVE-2026-56208 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56208 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56209 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56209 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56210 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56210 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56211 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56211 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for libaom fixes the following issues: * CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap- based buffer overflow and a process crash (bsc#1268650). * CVE-2026-56209: crafted video frames with specific Y-plane pixel values can lead to an arbitrary memory write (bsc#1268651). * CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out- of-bounds heap read (bsc#1268653). * CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to remote code execution (bsc#1268655). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2829=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2829=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2829=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2829=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2829=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2829=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2829=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2829=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2829=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libaom3-64bit-debuginfo-3.7.1-150400.3.12.1 * libaom3-64bit-3.7.1-150400.3.12.1 * openSUSE Leap 15.4 (x86_64) * libaom3-32bit-3.7.1-150400.3.12.1 * libaom3-32bit-debuginfo-3.7.1-150400.3.12.1 * openSUSE Leap 15.4 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56208.html * https://www.suse.com/security/cve/CVE-2026-56209.html * https://www.suse.com/security/cve/CVE-2026-56210.html * https://www.suse.com/security/cve/CVE-2026-56211.html * https://bugzilla.suse.com/show_bug.cgi?id=1268650 * https://bugzilla.suse.com/show_bug.cgi?id=1268651 * https://bugzilla.suse.com/show_bug.cgi?id=1268653 * https://bugzilla.suse.com/show_bug.cgi?id=1268655 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:21 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:32:21 -0000 Subject: SUSE-SU-2026:2828-1: moderate: Security update for python-idna Message-ID: <178367234134.944.11011634051847652764@530c474df1e7> # Security update for python-idna Announcement ID: SUSE-SU-2026:2828-1 Release Date: 2026-07-09T18:30:14Z Rating: moderate References: * bsc#1265413 Cross-References: * CVE-2026-45409 CVSS scores: * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-idna fixes the following issue * CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2828=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2828=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2828=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-idna-3.4-150400.11.13.1 * Public Cloud Module 15-SP4 (noarch) * python311-idna-3.4-150400.11.13.1 * openSUSE Leap 15.4 (noarch) * python311-idna-3.4-150400.11.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45409.html * https://bugzilla.suse.com/show_bug.cgi?id=1265413 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:30 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:32:30 -0000 Subject: SUSE-SU-2026:2827-1: important: Security update for cosign Message-ID: <178367235016.944.3511416651721534026@530c474df1e7> # Security update for cosign Announcement ID: SUSE-SU-2026:2827-1 Release Date: 2026-07-09T18:28:33Z Rating: important References: * bsc#1261811 * bsc#1266049 * bsc#1267044 Cross-References: * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33815 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33815 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-33815 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-33815 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for cosign fixes the following issues * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: multiple issues when parsing HTML files (bsc#1267044). * CVE-2026-33815: memory-safety vulnerability (bsc#1261811). * CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: Fixed multiple issues in golang.org/x/crypto/ssh (bsc#1266049). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2827=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2827=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2827=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2827=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2827=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2827=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2827=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2827=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2827=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2827=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2827=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2827=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * cosign-bash-completion-3.1.1-150400.3.45.1 * cosign-zsh-completion-3.1.1-150400.3.45.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * cosign-debuginfo-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * cosign-debuginfo-3.1.1-150400.3.45.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cosign-3.1.1-150400.3.45.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * cosign-debuginfo-3.1.1-150400.3.45.1 * openSUSE Leap 15.4 (noarch) * cosign-bash-completion-3.1.1-150400.3.45.1 * cosign-fish-completion-3.1.1-150400.3.45.1 * cosign-zsh-completion-3.1.1-150400.3.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * cosign-3.1.1-150400.3.45.1 * cosign-debuginfo-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * cosign-3.1.1-150400.3.45.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33815.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1261811 * https://bugzilla.suse.com/show_bug.cgi?id=1266049 * https://bugzilla.suse.com/show_bug.cgi?id=1267044 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:47 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:32:47 -0000 Subject: SUSE-SU-2026:2826-1: important: Security update for rust-keylime Message-ID: <178367236754.944.18242654731267932973@530c474df1e7> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:2826-1 Release Date: 2026-07-09T18:21:49Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves eight vulnerabilities and has one security fix can now be installed. ## Description: This update for rust-keylime fixes the following issues * Update to version 0.2.9+49. * Update openssl to 0.10.81. * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-openssl crate (bsc#1270614). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270699). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270842). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-openssl crate (bsc#1270999). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2826=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2826=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * rust-keylime-debuginfo-0.2.9+49-150400.3.19.1 * rust-keylime-0.2.9+49-150400.3.19.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * rust-keylime-debuginfo-0.2.9+49-150400.3.19.1 * rust-keylime-0.2.9+49-150400.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:33:04 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:33:04 -0000 Subject: SUSE-SU-2026:2825-1: important: Security update for rust-keylime Message-ID: <178367238443.944.7109166836547812567@530c474df1e7> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:2825-1 Release Date: 2026-07-09T18:18:08Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that solves eight vulnerabilities and has one security fix can now be installed. ## Description: This update for rust-keylime fixes the following issues * Update to version 0.2.9+49. * Update openssl to 0.10.81. * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-openssl crate (bsc#1270614). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270699). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270842). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-openssl crate (bsc#1270999). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2825=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2825=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * rust-keylime-0.2.9+49-150400.3.21.1 * rust-keylime-debuginfo-0.2.9+49-150400.3.21.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * rust-keylime-0.2.9+49-150400.3.21.1 * rust-keylime-debuginfo-0.2.9+49-150400.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:33:25 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:33:25 -0000 Subject: SUSE-SU-2026:2824-1: important: Security update for alloy Message-ID: <178367240557.944.16130273184650586011@530c474df1e7> # Security update for alloy Announcement ID: SUSE-SU-2026:2824-1 Release Date: 2026-07-09T18:18:01Z Rating: important References: * bsc#1260981 * bsc#1265440 * bsc#1266196 * bsc#1266654 * bsc#1267185 * bsc#1267333 * bsc#1267481 * bsc#1267485 * bsc#1267488 * bsc#1267489 * bsc#1267811 Cross-References: * CVE-2026-10722 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33532 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41889 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-44740 * CVE-2026-45678 * CVE-2026-45682 * CVE-2026-45685 * CVE-2026-45686 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-10722 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10722 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10722 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10722 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-10722 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33532 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33532 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33532 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41889 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41889 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41889 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41889 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44740 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45678 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45678 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45678 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45682 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45685 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45685 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45685 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45686 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45686 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45686 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 27 vulnerabilities can now be installed. ## Description: This update for alloy fixes the following issues * CVE-2026-10722: github.com/cilium/ebpf: BTF string offset boundary check can lead to crash when parsing malformed ELF/BTF input (bsc#1267811). * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267185). * CVE-2026-33532: denial of service via deeply nested YAML document parsing (bsc#1260981). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266654). * CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues (bsc#1266196). * CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: SQL injection when placeholders in dollar-quoted string literals are used in the SQL query (bsc#1265440). * CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267333). * CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are processed (bsc#1267481). * CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by `CappedConcurrentHashMap` after removals allows repeated connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485). * CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS (bsc#1267488). * CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process and cause denial of service (bsc#1267489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2824=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * alloy-1.17.1-150700.15.23.1 * alloy-debuginfo-1.17.1-150700.15.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10722.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33532.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41889.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-44740.html * https://www.suse.com/security/cve/CVE-2026-45678.html * https://www.suse.com/security/cve/CVE-2026-45682.html * https://www.suse.com/security/cve/CVE-2026-45685.html * https://www.suse.com/security/cve/CVE-2026-45686.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1260981 * https://bugzilla.suse.com/show_bug.cgi?id=1265440 * https://bugzilla.suse.com/show_bug.cgi?id=1266196 * https://bugzilla.suse.com/show_bug.cgi?id=1266654 * https://bugzilla.suse.com/show_bug.cgi?id=1267185 * https://bugzilla.suse.com/show_bug.cgi?id=1267333 * https://bugzilla.suse.com/show_bug.cgi?id=1267481 * https://bugzilla.suse.com/show_bug.cgi?id=1267485 * https://bugzilla.suse.com/show_bug.cgi?id=1267488 * https://bugzilla.suse.com/show_bug.cgi?id=1267489 * https://bugzilla.suse.com/show_bug.cgi?id=1267811 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:33:33 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:33:33 -0000 Subject: SUSE-SU-2026:2823-1: important: Security update for helm Message-ID: <178367241301.944.3996521987195772968@530c474df1e7> # Security update for helm Announcement ID: SUSE-SU-2026:2823-1 Release Date: 2026-07-09T18:14:15Z Rating: important References: * bsc#1266598 * bsc#1270127 Cross-References: * CVE-2026-39821 * CVE-2026-48978 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for helm fixes the following issues * Update to version 3.21.2. * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2823=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2823=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2823=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2823=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2823=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2823=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2823=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2823=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2823=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2823=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2823=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2823=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2823=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * Containers Module 15-SP7 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.21.2-150000.1.80.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-48978.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 * https://bugzilla.suse.com/show_bug.cgi?id=1270127 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:33:56 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:33:56 -0000 Subject: SUSE-SU-2026:2822-1: important: Security update for gnutls Message-ID: <178367243624.944.12083799397612029594@530c474df1e7> # Security update for gnutls Announcement ID: SUSE-SU-2026:2822-1 Release Date: 2026-07-09T18:07:13Z Rating: important References: * bsc#1257960 * bsc#1263704 * bsc#1263705 * bsc#1263707 * bsc#1263708 * bsc#1263709 * bsc#1263710 * bsc#1263711 * bsc#1263712 * bsc#1263713 * bsc#1263714 * bsc#1263715 Cross-References: * CVE-2025-14831 * CVE-2026-33845 * CVE-2026-33846 * CVE-2026-3833 * CVE-2026-42009 * CVE-2026-42010 * CVE-2026-42011 * CVE-2026-42012 * CVE-2026-42013 * CVE-2026-42014 * CVE-2026-42015 * CVE-2026-5260 CVSS scores: * CVE-2025-14831 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-14831 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-14831 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33845 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33845 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-33845 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33845 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-33845 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3833 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3833 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3833 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3833 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42009 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42009 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42009 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42009 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42010 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42010 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42010 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42010 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42010 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42011 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42011 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42012 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42012 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2026-42012 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2026-42013 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42013 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42014 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42014 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42014 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-42015 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42015 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-42015 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5260 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-5260 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5260 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that solves 12 vulnerabilities can now be installed. ## Description: This update for gnutls fixes the following issues * CVE-2025-14831: excessive resource consumption when verifying specially crafted malicious certificates containing a large number of name constraints and SANs (bsc#1257960). * CVE-2026-3833: incorrectly accepted domain names due to comparison during name constraints processing being case-sensitive (bsc#1263707). * CVE-2026-5260: heap overread when processing extremely short premaster secret as part of an RSA key exchange (bsc#1263715). * CVE-2026-33845: integer overflow and heap overrun when parsing fragments with zero length and non-zero offset during DTLS handshake (bsc#1263704). * CVE-2026-33846: heap overwrite during DTLS handshake fragment reassembly due to missing validations and checks (bsc#1263705). * CVE-2026-42009: undefined behavior resulting in a DoS when handling DTLS packets with duplicate sequence numbers (bsc#1263708). * CVE-2026-42010: authentication bypass when processing a PSK username with a NUL-character (bsc#1263709). * CVE-2026-42011: name constraint bypass leading to acceptance of invalid certificates during certificate validation (bsc#1263710). * CVE-2026-42012: spoofing of legitimate services and sensitive information interception via specially crafted certificates containing URIs or SRV SANs. (bsc#1263711). * CVE-2026-42013: certificate validation bypass when validating certificates with an oversized SAN (bsc#1263712). * CVE-2026-42014: use-after-free when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path (bsc#1263713). * CVE-2026-42015: memory corruption when appending to a PKCS#12 bag that already contains 32 elements (bsc#1263714). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2822=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2822=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libgnutls30-3.7.3-150400.24.2 * gnutls-3.7.3-150400.24.2 * libgnutls30-hmac-3.7.3-150400.24.2 * libgnutls30-debuginfo-3.7.3-150400.24.2 * gnutls-debuginfo-3.7.3-150400.24.2 * gnutls-debugsource-3.7.3-150400.24.2 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libgnutls30-3.7.3-150400.24.2 * gnutls-3.7.3-150400.24.2 * libgnutls30-hmac-3.7.3-150400.24.2 * libgnutls30-debuginfo-3.7.3-150400.24.2 * gnutls-debuginfo-3.7.3-150400.24.2 * gnutls-debugsource-3.7.3-150400.24.2 ## References: * https://www.suse.com/security/cve/CVE-2025-14831.html * https://www.suse.com/security/cve/CVE-2026-33845.html * https://www.suse.com/security/cve/CVE-2026-33846.html * https://www.suse.com/security/cve/CVE-2026-3833.html * https://www.suse.com/security/cve/CVE-2026-42009.html * https://www.suse.com/security/cve/CVE-2026-42010.html * https://www.suse.com/security/cve/CVE-2026-42011.html * https://www.suse.com/security/cve/CVE-2026-42012.html * https://www.suse.com/security/cve/CVE-2026-42013.html * https://www.suse.com/security/cve/CVE-2026-42014.html * https://www.suse.com/security/cve/CVE-2026-42015.html * https://www.suse.com/security/cve/CVE-2026-5260.html * https://bugzilla.suse.com/show_bug.cgi?id=1257960 * https://bugzilla.suse.com/show_bug.cgi?id=1263704 * https://bugzilla.suse.com/show_bug.cgi?id=1263705 * https://bugzilla.suse.com/show_bug.cgi?id=1263707 * https://bugzilla.suse.com/show_bug.cgi?id=1263708 * https://bugzilla.suse.com/show_bug.cgi?id=1263709 * https://bugzilla.suse.com/show_bug.cgi?id=1263710 * https://bugzilla.suse.com/show_bug.cgi?id=1263711 * https://bugzilla.suse.com/show_bug.cgi?id=1263712 * https://bugzilla.suse.com/show_bug.cgi?id=1263713 * https://bugzilla.suse.com/show_bug.cgi?id=1263714 * https://bugzilla.suse.com/show_bug.cgi?id=1263715 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:02 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:34:02 -0000 Subject: SUSE-SU-2026:2821-1: moderate: Security update for python-sqlparse Message-ID: <178367244210.944.11481043675486473220@530c474df1e7> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:2821-1 Release Date: 2026-07-09T18:05:57Z Rating: moderate References: * bsc#1268597 Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that has one security fix can now be installed. ## Description: This update for python-sqlparse fixes the following issue * Fixed an issue where formatting list of tuples leads to denial of service (bsc#1268597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2821=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * python2-sqlparse-0.2.4-150100.6.8.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:34:07 -0000 Subject: SUSE-SU-2026:2820-1: important: Security update for GraphicsMagick Message-ID: <178367244760.944.12490989740913724196@530c474df1e7> # Security update for GraphicsMagick Announcement ID: SUSE-SU-2026:2820-1 Release Date: 2026-07-09T18:01:15Z Rating: important References: * bsc#1269891 Cross-References: * CVE-2026-13606 CVSS scores: * CVE-2026-13606 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for GraphicsMagick fixes the following issue * CVE-2026-13606: crafted Photo CD (PCD) file can cause memory corruption (bsc#1269891). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2820=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2820=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * GraphicsMagick-debuginfo-1.3.42-150600.3.33.1 * GraphicsMagick-devel-1.3.42-150600.3.33.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.33.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.33.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.33.1 * GraphicsMagick-1.3.42-150600.3.33.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagick++-devel-1.3.42-150600.3.33.1 * perl-GraphicsMagick-1.3.42-150600.3.33.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagick3-config-1.3.42-150600.3.33.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.33.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.33.1 * GraphicsMagick-debugsource-1.3.42-150600.3.33.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * GraphicsMagick-debuginfo-1.3.42-150600.3.33.1 * GraphicsMagick-devel-1.3.42-150600.3.33.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.33.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.33.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.33.1 * GraphicsMagick-1.3.42-150600.3.33.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagick++-devel-1.3.42-150600.3.33.1 * perl-GraphicsMagick-1.3.42-150600.3.33.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.33.1 * libGraphicsMagick3-config-1.3.42-150600.3.33.1 * GraphicsMagick-debugsource-1.3.42-150600.3.33.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13606.html * https://bugzilla.suse.com/show_bug.cgi?id=1269891 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:15 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:34:15 -0000 Subject: SUSE-SU-2026:2819-1: moderate: Security update for python-Django Message-ID: <178367245566.944.14678766855547474863@530c474df1e7> # Security update for python-Django Announcement ID: SUSE-SU-2026:2819-1 Release Date: 2026-07-09T17:12:22Z Rating: moderate References: * bsc#1271029 * bsc#1271030 Cross-References: * CVE-2026-48588 * CVE-2026-53877 CVSS scores: * CVE-2026-48588 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48588 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48588 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48588 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-53877 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53877 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-53877 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-Django fixes the following issues: * CVE-2026-48588: potential exposure of private data via cached `Set-Cookie` response (bsc#1271029). * CVE-2026-53877: information disclosure via 32-byte heap buffer overread in `GDALRaster` (bsc#1271030). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2819=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2819=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * python311-Django-4.2.11-150600.3.62.1 * openSUSE Leap 15.6 (noarch) * python311-Django-4.2.11-150600.3.62.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48588.html * https://www.suse.com/security/cve/CVE-2026-53877.html * https://bugzilla.suse.com/show_bug.cgi?id=1271029 * https://bugzilla.suse.com/show_bug.cgi?id=1271030 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:27 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:34:27 -0000 Subject: SUSE-SU-2026:2818-1: important: Security update for go1.26 Message-ID: <178367246743.944.2017251776427507103@530c474df1e7> # Security update for go1.26 Announcement ID: SUSE-SU-2026:2818-1 Release Date: 2026-07-09T17:09:48Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 Cross-References: * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities, contains one feature and has three security fixes can now be installed. ## Description: This update for go1.26 fixes the following issues * Update to version go1.26.5 (bsc#1255111) * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2818=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2818=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2818=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2818=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2818=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2818=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2818=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2818=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2818=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2818=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2818=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:48 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 08:34:48 -0000 Subject: SUSE-SU-2026:2817-1: important: Security update for go1.25 Message-ID: <178367248820.944.15623343123754512003@530c474df1e7> # Security update for go1.25 Announcement ID: SUSE-SU-2026:2817-1 Release Date: 2026-07-09T17:08:22Z Rating: important References: * bsc#1244485 * bsc#1245878 * bsc#1259264 * bsc#1259265 * bsc#1259268 * bsc#1264394 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 Cross-References: * CVE-2026-25679 * CVE-2026-27139 * CVE-2026-27142 * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-25679 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27139 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27142 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities, contains one feature and has three security fixes can now be installed. ## Description: This update for go1.25 fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2817=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2817=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2817=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2817=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2817=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2817=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2817=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2817=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2817=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2817=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2817=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25679.html * https://www.suse.com/security/cve/CVE-2026-27139.html * https://www.suse.com/security/cve/CVE-2026-27142.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1259264 * https://bugzilla.suse.com/show_bug.cgi?id=1259265 * https://bugzilla.suse.com/show_bug.cgi?id=1259268 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:30:37 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:30:37 -0000 Subject: SUSE-SU-2026:22536-1: important: Security update for update 5.1.3 for SUSE_Multi-Linux_Manager Client Tools and Salt Bundle Message-ID: <178368663793.1052.14528788618775779046@5ed4f61072e9> # Security update for update 5.1.3 for SUSE_Multi-Linux_Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22536-1 Release Date: 2026-06-15T07:20:25Z Rating: important References: * bsc#1250367 * bsc#1252548 * bsc#1252964 * bsc#1254154 * bsc#1254619 * bsc#1254629 * bsc#1257447 * bsc#1257660 * bsc#1257831 * bsc#1257941 * bsc#1258015 * bsc#1258418 * bsc#1258927 * bsc#1258957 * bsc#1259208 * bsc#1259553 * bsc#1259554 Cross-References: * CVE-2026-31958 CVSS scores: * CVE-2026-31958 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31958 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves one vulnerability and has 16 fixes can now be installed. ## Description: This update fixes the following issues: golang-github-lusitaniae-apache_exporter: * Internal changes to fix build issues with no impact for customers uyuni-tools: * version 5.1.26-0 * Fixed applying PTF with images from RPMs (bsc#1252548) * Fixed Ssl Key file that can miss if CA password is blank (bsc#1254154) * mgrpxy ssh tuning should happens before crypto policies (bsc#1254619) * Fixed default value for helm registry (bsc#1258927). * Removed hub register command * Optimized postgres migration disk space usage (bsc#1257447) * Added continuous database backup support (bsc#1250367) * Explicitly start proxy pods after operations (bsc#1258015) * Use static supportconfig name to avoid dynamic search (bsc#1257941) * Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) * Show where final tarball was generated (bsc#1259208) * Set proxy config file permissions (bsc#1257660) * version 5.1.25-0 * If PTF image doesn't exists, use the current service image (bsc#1258418) venv-salt-minion: * Security issues fixed: * CVE-2026-31958: Security patch for Salt vendored tornado: Added limits on multipart form data parsing (bsc#1259554) * Added x86_64_v2 as a possible rpm package architecture * Make users with backslash working for salt-ssh (bsc#1254629) * Fixed ansible.playbooks extra-vars quoting (bsc#1257831) * Fixed virtualenv call in test helper to use proper python version * Fixed the issue preventing SELinux profile to be loaded on SLES 16 deployed using cloud images (bsc#1258957) * Fixed the typo causing buiding EL9 bundle without binary dependencies ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-64=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-5.1.26-1.1 * mgrctl-lang-5.1.26-1.1 * mgrctl-bash-completion-5.1.26-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-5.1.26-1.1 * mgrctl-debuginfo-5.1.26-1.1 * venv-salt-minion-3006.0-11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31958.html * https://bugzilla.suse.com/show_bug.cgi?id=1250367 * https://bugzilla.suse.com/show_bug.cgi?id=1252548 * https://bugzilla.suse.com/show_bug.cgi?id=1252964 * https://bugzilla.suse.com/show_bug.cgi?id=1254154 * https://bugzilla.suse.com/show_bug.cgi?id=1254619 * https://bugzilla.suse.com/show_bug.cgi?id=1254629 * https://bugzilla.suse.com/show_bug.cgi?id=1257447 * https://bugzilla.suse.com/show_bug.cgi?id=1257660 * https://bugzilla.suse.com/show_bug.cgi?id=1257831 * https://bugzilla.suse.com/show_bug.cgi?id=1257941 * https://bugzilla.suse.com/show_bug.cgi?id=1258015 * https://bugzilla.suse.com/show_bug.cgi?id=1258418 * https://bugzilla.suse.com/show_bug.cgi?id=1258927 * https://bugzilla.suse.com/show_bug.cgi?id=1258957 * https://bugzilla.suse.com/show_bug.cgi?id=1259208 * https://bugzilla.suse.com/show_bug.cgi?id=1259553 * https://bugzilla.suse.com/show_bug.cgi?id=1259554 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:31:23 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:31:23 -0000 Subject: SUSE-SU-2026:22535-1: important: Security update 5.1.2 for Multi-Linux Manager Client Tools and Salt Bundle Message-ID: <178368668351.1052.17905683202633443375@5ed4f61072e9> # Security update 5.1.2 for Multi-Linux Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22535-1 Release Date: 2026-06-15T07:20:17Z Rating: important References: * bsc#1175946 * bsc#1227207 * bsc#1240532 * bsc#1246130 * bsc#1247644 * bsc#1247721 * bsc#1248848 * bsc#1249400 * bsc#1249434 * bsc#1250520 * bsc#1250940 * bsc#1250976 * bsc#1250981 * bsc#1251044 * bsc#1251138 * bsc#1251776 * bsc#1252244 * bsc#1252285 * bsc#1253282 * bsc#1253347 * bsc#1253738 * bsc#1253966 * bsc#1254325 * bsc#1254478 * bsc#1254903 * bsc#1254904 * bsc#1254905 * bsc#1255781 * jsc#MSQA-1040 Cross-References: * CVE-2025-13836 * CVE-2025-62348 * CVE-2025-62349 CVSS scores: * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-62348 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-62348 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62348 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62349 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-62349 ( SUSE ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2025-62349 ( NVD ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62349 ( NVD ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves three vulnerabilities, contains one feature and has 25 fixes can now be installed. ## Description: This update fixes the following issues: uyuni-tools: * Version 5.1.24-0 * Actually use the --dbupgrade-tag parameter when computing the image URL (bsc#1249400) * Handle CA files with symlinks during migration (bsc#1251044) * Adjust traefik exposed configuration for chart v27+ (bsc#1247721) * Fix systemd object initialization in server rename. (bsc#1250981) * Add SSL secrets to the db setup container during migration. (bsc#1250976) * Fix images handling in mgrpxy support ptf (bsc#1250940) * Fix helm upgrade parameters (bsc#1253966) * Detect custom apache and squid config in the /etc/uyuni/proxy folder * Add ssh tuning to configure sshd (bsc#1253738) * Move the SSL checks at the begining of the migration * Remove cgroup mount for podman containers (bsc#1253347) * Convert the traefik install time to local time (bsc#1251138) * During migration, krb5.conf.d should be copied in /etc/rhn (bsc#1254478) * Read env var from http conf file (bsc#1253282) * Add --registry-host, --registry-user and --registry-password to pull images from an authenticate registry * Deprecate --registry * Unify backup create and restore dryrun option case * Fix calling of squid -z in mgrpxy cache clear (bsc#1247644) * Always start database container even if enabled * Remove extra ipv6 mapping and nftables workaround (bsc#1248848) * Remove old PostgreSQL exporter environment file before migration * Support config command parse correctly supportconfig output (bsc#1255781) * Version 5.1.23-0 * Update the default tag * Version 5.1.22-0 * Fix cobbler config migration to standalone files * Fix generated DB certificate subject alternate names * Version 5.1.21-0 * Remove extraneous quotes when getting the running image (bsc#1249434) venv-salt-minion: * Security issues fixed: * CVE-2025-67724: Fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: Fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: Fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * Fixed TLS and x509 modules for OSes with older cryptography module * Fixed Salt for Python > 3.11 (bsc#1252285) (bsc#1252244) * Use external tornado on Python > 3.11 * Make tls and x509 to use python-cryptography * Remove usage of spwd * Fixed payload signature verification on Tumbleweed (bsc#1251776) * Fixed known_hosts error on gitfs (bsc#1250520) (bsc#1227207) * Made syntax in httputil_test compatible with Python 3.6 * Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) * Use internal deb classes instead of external aptsource lib * Speed up wheel key.finger call (bsc#1240532) * Improved utils.find_json function (bsc#1246130) * Extended warn_until period to 2027 golang-github-QubitProducts-exporter_exporter: * New package at version 0.4.0 golang-github-lusitaniae-apache_exporter: * Build without apparmor for openSUSE Leap 16, SLES 16 or newer * Require Go 1.23 for building * Update to version 1.0.10 * Update github.com/prometheus/client_golang to 1.21.1 * Update github.com/prometheus/common to 0.63.0 * Update github.com/prometheus/exporter-toolkit to 0.14.0 * Update to version 1.0.9 * Update github.com/prometheus/client_golang to 1.20.4 * Update github.com/prometheus/common to 0.59.1 * Update github.com/prometheus/exporter-toolkit to 0.13.0 * Migrate logging to log/slog * Fix signal handler logging golang-github-prometheus-node_exporter: * Non-customer-facing optimization around source building ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-63=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-lang-5.1.24-1.1 * mgrctl-zsh-completion-5.1.24-1.1 * mgrctl-bash-completion-5.1.24-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-node_exporter-1.9.1-2.1 * mgrctl-debuginfo-5.1.24-1.1 * venv-salt-minion-3006.0-10.1 * mgrctl-5.1.24-1.1 * golang-github-prometheus-node_exporter-debuginfo-1.9.1-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-62348.html * https://www.suse.com/security/cve/CVE-2025-62349.html * https://bugzilla.suse.com/show_bug.cgi?id=1175946 * https://bugzilla.suse.com/show_bug.cgi?id=1227207 * https://bugzilla.suse.com/show_bug.cgi?id=1240532 * https://bugzilla.suse.com/show_bug.cgi?id=1246130 * https://bugzilla.suse.com/show_bug.cgi?id=1247644 * https://bugzilla.suse.com/show_bug.cgi?id=1247721 * https://bugzilla.suse.com/show_bug.cgi?id=1248848 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249434 * https://bugzilla.suse.com/show_bug.cgi?id=1250520 * https://bugzilla.suse.com/show_bug.cgi?id=1250940 * https://bugzilla.suse.com/show_bug.cgi?id=1250976 * https://bugzilla.suse.com/show_bug.cgi?id=1250981 * https://bugzilla.suse.com/show_bug.cgi?id=1251044 * https://bugzilla.suse.com/show_bug.cgi?id=1251138 * https://bugzilla.suse.com/show_bug.cgi?id=1251776 * https://bugzilla.suse.com/show_bug.cgi?id=1252244 * https://bugzilla.suse.com/show_bug.cgi?id=1252285 * https://bugzilla.suse.com/show_bug.cgi?id=1253282 * https://bugzilla.suse.com/show_bug.cgi?id=1253347 * https://bugzilla.suse.com/show_bug.cgi?id=1253738 * https://bugzilla.suse.com/show_bug.cgi?id=1253966 * https://bugzilla.suse.com/show_bug.cgi?id=1254325 * https://bugzilla.suse.com/show_bug.cgi?id=1254478 * https://bugzilla.suse.com/show_bug.cgi?id=1254903 * https://bugzilla.suse.com/show_bug.cgi?id=1254904 * https://bugzilla.suse.com/show_bug.cgi?id=1254905 * https://bugzilla.suse.com/show_bug.cgi?id=1255781 * https://jira.suse.com/browse/MSQA-1040 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:31:52 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:31:52 -0000 Subject: SUSE-SU-2026:22534-1: important: Security update 5.0.8 for Multi-Linux Manager Client Tools, Salt Bundle and Salt Message-ID: <178368671297.1052.11560841898184301014@5ed4f61072e9> # Security update 5.0.8 for Multi-Linux Manager Client Tools, Salt Bundle and Salt Announcement ID: SUSE-SU-2026:22534-1 Release Date: 2026-06-03T12:47:13Z Rating: important References: * bsc#1252964 * bsc#1254619 * bsc#1254629 * bsc#1254900 * bsc#1257583 * bsc#1257831 * bsc#1257941 * bsc#1258927 * bsc#1258957 * bsc#1259208 * bsc#1259554 * bsc#1259700 * bsc#1259804 * bsc#1259808 * bsc#1261810 Cross-References: * CVE-2026-27448 * CVE-2026-27459 * CVE-2026-31958 CVSS scores: * CVE-2026-27448 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27448 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-27448 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27448 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31958 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31958 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves three vulnerabilities and has 12 fixes can now be installed. ## Description: This update fixes the following issues: golang-github-prometheus-node_exporter: * Version 1.10.2: * meminfo: Fix typo in Zswap metric name * Version 1.10.1: * filesystem: Fix mount points being collected multiple times * filesystem: Refactor mountinfo parsing (bsc#1261810) * meminfo: Add Zswap/Zswapped metrics * Version 1.10.0: * Changes: * mdadm: Use sysfs for RAID metrics * filesystem: Add erofs in default excluded fs * tcpstat: Use std lib binary.NativeEndian * New Features: * pcidevice: Add new collector for PCIe devices * AIX: Add more metrics * systemd: Add Virtualization metrics * swaps: Add new collector * Enhancements: * wifi: Add packet received and transmitted metrics * filesystem: Take super options into account for read-only * pcidevice: Add additional metrics * perf: Add tlb_data metrics * Bugs fixed: * interrupts: Fix OpenBSD interrupt device parsing * diskstats: Simplify condition * thermal: Sanitize darwin thermal strings * filesystem: Fix Darwin collector cgo memory leak * cpufreq: Fix: collector enable * ethtool: Fix returning 0 for sanitized metrics * netdev: Fix Darwin netdev i/o bytes metric * systemd: Fix logging race * filesystem: Fix duplicate Darwin CGO import salt: * Security issues fixed: * CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554) * Other updates and bugfixes: * Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) * Fixed testsuite failures * Make users with backslash working for salt-ssh (bsc#1254629) * Fixed ansible.playbooks extra-vars quoting (bsc#1257831) * Fixed virtualenv call in test helper to use proper python version uyuni-tools: * Version 0.1.39-0: * mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) * Fixed default value for helm registry (bsc#1258927). * Use static supportconfig name to avoid dynamic search (bsc#1257941) * Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) * Show where final tarball was generated (bsc#1259208) venv-salt-minion: * Security issues fixed: * CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554) * CVE-2026-27459: pyOpenSSL: Fixed issue with large cookie value that can lead to a buffer overflow (bsc#1259808) * CVE-2026-27448: pyOpenSSL: Fixed unhandled exception can result in connection not being cancelled (bsc#1259804) * Other updates and bugfixes: * Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) * Make users with backslash work for `salt-ssh` (bsc#1254629). * Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831), * Fixed `virtualenv` call in test helper to use proper Python version. * Fixed the issue preventing SELinux profile to be loaded on SLES 16 deployed using cloud images (bsc#1258957) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6740=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.39-1.1 * mgrctl-lang-0.1.39-1.1 * mgrctl-bash-completion-0.1.39-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-0.1.39-1.1 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-1.1 * venv-salt-minion-3006.0-11.1 * mgrctl-0.1.39-1.1 * golang-github-prometheus-node_exporter-1.10.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27448.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-31958.html * https://bugzilla.suse.com/show_bug.cgi?id=1252964 * https://bugzilla.suse.com/show_bug.cgi?id=1254619 * https://bugzilla.suse.com/show_bug.cgi?id=1254629 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1257831 * https://bugzilla.suse.com/show_bug.cgi?id=1257941 * https://bugzilla.suse.com/show_bug.cgi?id=1258927 * https://bugzilla.suse.com/show_bug.cgi?id=1258957 * https://bugzilla.suse.com/show_bug.cgi?id=1259208 * https://bugzilla.suse.com/show_bug.cgi?id=1259554 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259804 * https://bugzilla.suse.com/show_bug.cgi?id=1259808 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:32:18 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:32:18 -0000 Subject: SUSE-SU-2026:22533-1: important: Security update 5.0.7 for Multi-Linux Manager for Client Tools, Salt Bundle, Salt Message-ID: <178368673852.1052.7757606197686336898@5ed4f61072e9> # Security update 5.0.7 for Multi-Linux Manager for Client Tools, Salt Bundle, Salt Announcement ID: SUSE-SU-2026:22533-1 Release Date: 2026-03-24T06:26:01Z Rating: important References: * bsc#1240532 * bsc#1246130 * bsc#1253347 * bsc#1253738 * bsc#1254256 * bsc#1254257 * bsc#1254325 * bsc#1254589 * bsc#1254903 * bsc#1254904 * bsc#1254905 * bsc#1255781 * bsc#1256803 * bsc#1257941 Cross-References: * CVE-2025-62348 * CVE-2025-62349 * CVE-2025-67724 * CVE-2025-67725 * CVE-2025-67726 CVSS scores: * CVE-2025-62348 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-62348 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62348 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62349 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-62349 ( SUSE ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2025-62349 ( NVD ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62349 ( NVD ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2025-67724 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-67724 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-67725 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67725 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67726 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves five vulnerabilities and has nine fixes can now be installed. ## Description: This update for fixes the following issues: golang-github-prometheus-node_exporter: * Require gcc11-c++ for building with SLE 12 uyuni-tools: * Version 0.1.38-0: * Fixed cobbler config migration to standalone files (bsc#1256803) * Detect custom apache and squid config in the /etc/uyuni/proxy folder * Added ssh tuning to configure sshd (bsc#1253738) * Ignore supportconfig errors (bsc#1255781) * Bumped the default image tag to 5.0.7 * Remove cgroup mount for podman containers (bsc#1253347) * Registry flag can be a string (bsc#1254589) * Use static supportconfig name to avoid dynamic search (bsc#1257941) venv-salt-minion: * Security issues fixed: * CVE-2025-67724: missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fix DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fix HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-62349: Add minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Junos module yaml loader fix (bsc#1254256) * Fixed the typo causing buiding EL9 bundle without binary dependencies * Make syntax in httputil_test compatible with Python 3.6 * Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) * Use internal deb classes instead of external aptsource lib * Speed up wheel key.finger call (bsc#1240532) * Simplify and speed up utils.find_json function (bsc#1246130) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6635=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.38-1.1 * mgrctl-lang-0.1.38-1.1 * mgrctl-bash-completion-0.1.38-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-node_exporter-1.9.1-2.1 * venv-salt-minion-3006.0-10.1 * mgrctl-debuginfo-0.1.38-1.1 * golang-github-prometheus-node_exporter-debuginfo-1.9.1-2.1 * mgrctl-0.1.38-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-62348.html * https://www.suse.com/security/cve/CVE-2025-62349.html * https://www.suse.com/security/cve/CVE-2025-67724.html * https://www.suse.com/security/cve/CVE-2025-67725.html * https://www.suse.com/security/cve/CVE-2025-67726.html * https://bugzilla.suse.com/show_bug.cgi?id=1240532 * https://bugzilla.suse.com/show_bug.cgi?id=1246130 * https://bugzilla.suse.com/show_bug.cgi?id=1253347 * https://bugzilla.suse.com/show_bug.cgi?id=1253738 * https://bugzilla.suse.com/show_bug.cgi?id=1254256 * https://bugzilla.suse.com/show_bug.cgi?id=1254257 * https://bugzilla.suse.com/show_bug.cgi?id=1254325 * https://bugzilla.suse.com/show_bug.cgi?id=1254589 * https://bugzilla.suse.com/show_bug.cgi?id=1254903 * https://bugzilla.suse.com/show_bug.cgi?id=1254904 * https://bugzilla.suse.com/show_bug.cgi?id=1254905 * https://bugzilla.suse.com/show_bug.cgi?id=1255781 * https://bugzilla.suse.com/show_bug.cgi?id=1256803 * https://bugzilla.suse.com/show_bug.cgi?id=1257941 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:33:03 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:33:03 -0000 Subject: SUSE-SU-2026:22532-1: important: Security update 5.0.6 for Multi-Linux Manager Client Tools, Salt and Salt Bundle Message-ID: <178368678367.1052.4146861532444217668@5ed4f61072e9> # Security update 5.0.6 for Multi-Linux Manager Client Tools, Salt and Salt Bundle Announcement ID: SUSE-SU-2026:22532-1 Release Date: 2025-12-16T07:28:05Z Rating: important References: * bsc#1227207 * bsc#1243611 * bsc#1243704 * bsc#1244027 * bsc#1244127 * bsc#1244534 * bsc#1245099 * bsc#1245740 * bsc#1246068 * bsc#1246320 * bsc#1246553 * bsc#1246662 * bsc#1246738 * bsc#1246789 * bsc#1246882 * bsc#1246906 * bsc#1246925 * bsc#1247688 * bsc#1247721 * bsc#1250520 * bsc#1250755 * bsc#1251044 * bsc#1251138 * bsc#1251776 * bsc#1252244 * bsc#1252285 * bsc#1254256 * bsc#1254257 Cross-References: * CVE-2025-62348 * CVE-2025-62349 CVSS scores: * CVE-2025-62348 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-62348 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62348 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62349 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-62349 ( SUSE ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2025-62349 ( NVD ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62349 ( NVD ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves two vulnerabilities and has 26 fixes can now be installed. ## Description: This update fixes the following issues: salt: * Security issues fixed: * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * Backport security fixes for vendored tornado * BDSA-2024-3438 * BDSA-2024-3439 * BDSA-2024-9026 * Other changes and bugs fixed: * Fixed TLS and x509 modules for OSes with older cryptography module * Fixed Salt for Python > 3.11 (bsc#1252285) (bsc#1252244) * Use external tornado on Python > 3.11 * Make tls and x509 to use python-cryptography * Remove usage of spwd * Fixed payload signature verification on Tumbleweed (bsc#1251776) * Fixed broken symlink on migration to Leap 16.0 (bsc#1250755) * Fixed known_hosts error on gitfs (bsc#1250520) (bsc#1227207) * Fixed functional.states.test_user for SLES 16 and Micro systems * Fixed the tests failing on AlmaLinux 10 and other clones * Improved SL Micro 6.2 detection with grains * Require Python dependencies only for used Python version * Reverted requirement of M2Crypto >= 0.44.0 for SUSE Family distros * Set python-CherryPy as required for python-salt-testsuite uyuni-tools: * Version 0.1.37-0 * Added --registry-host, --registry-user and --registry-password to pull images from an authenticate registry * Added a lowercase version of --logLevel (bsc#1243611) * Added migration for server monitoring configuration (bsc#1247688) * Added SLE15SP7 to buildin productmap * Adjusted traefik exposed configuration for chart v27+ (bsc#1247721) * Automatically get up-to-date systemid file on salt based proxy hosts (bsc#1246789) * Check for restorecon presence before calling (bsc#1246925) * Convert the traefik install time to local time (bsc#1251138) * Deprecated --registry * Do not require backups to be at the same location for restoring (bsc#1246906) * Do not use sudo when running as a root user (bsc#1246882) * Fixed channel override for distro copy * Fixed loading product map from mgradm configuration file (bsc#1246068) * Fixed recomputing proxy images when installing a ptf or test (bsc#1246553) * Handle CA files with symlinks during migration (bsc#1251044) * Migrate custom auto installation snippets (bsc#1246320) * Run smdba and reindex only during migration (bsc#1244534) * Stop executing scripts in temporary folder (bsc#1243704) * Support config: collect podman inspect for hub container(bsc#1245099) * Use new dedicated path for Cobbler settings (bsc#1244027) * Version 0.1.36-0 * Bump the default image tag to 5.0.5.1 * Version 0.1.35-0 * Restore SELinux contexts for restored backup volumes (bsc#1244127) * Version 0.1.34-0 * Fixed mgradm backup create handling of images and systemd files (bsc#1246738) * Version 0.1.33-0 * Restore volumes using tar instead of podman import (bsc#1244127) * Version 0.1.32-0 * Fixed version compare by backport from main (bsc#1246662) venv-salt-minion: * Security issues fixed: * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * Backport security fixes for vendored tornado * BDSA-2024-3438 * BDSA-2024-3439 * BDSA-2024-9026 * Other changes and bugs fixed: * Added `minion_legacy_req_warnings` option to avoid noisy warnings * Fixed TLS and x509 modules for OSes with older cryptography module * Fixed Salt for Python > 3.11 (bsc#1252285) (bsc#1252244) * Use external tornado on Python > 3.11 * Make tls and x509 to use python-cryptography * Remove usage of spwd * Filter out zero-length check as the empty files are expected there * Filter out env-script-interpreter for ssh-id-wrapper as not used with the Salt Bundle, but present inside the salt module * Fixed functional.states.test_user for SLES 16 and Micro systems * Fixed known_hosts error on gitfs (bsc#1250520) (bsc#1227207) * Fixed payload signature verification on Tumbleweed (bsc#1251776) * Fixed the tests failing on AlmaLinux 10 and other clones * Improve SL Micro 6.2 detection with grains * Removed unused activate script (bsc#1245740) * Use more strict way to Fixed shebang in the bundle scripts * Use versioned python interpreter for salt-ssh ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6535=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-0.1.37-1.1 * mgrctl-debuginfo-0.1.37-1.1 * venv-salt-minion-3006.0-9.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.37-1.1 * mgrctl-lang-0.1.37-1.1 * mgrctl-bash-completion-0.1.37-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-62348.html * https://www.suse.com/security/cve/CVE-2025-62349.html * https://bugzilla.suse.com/show_bug.cgi?id=1227207 * https://bugzilla.suse.com/show_bug.cgi?id=1243611 * https://bugzilla.suse.com/show_bug.cgi?id=1243704 * https://bugzilla.suse.com/show_bug.cgi?id=1244027 * https://bugzilla.suse.com/show_bug.cgi?id=1244127 * https://bugzilla.suse.com/show_bug.cgi?id=1244534 * https://bugzilla.suse.com/show_bug.cgi?id=1245099 * https://bugzilla.suse.com/show_bug.cgi?id=1245740 * https://bugzilla.suse.com/show_bug.cgi?id=1246068 * https://bugzilla.suse.com/show_bug.cgi?id=1246320 * https://bugzilla.suse.com/show_bug.cgi?id=1246553 * https://bugzilla.suse.com/show_bug.cgi?id=1246662 * https://bugzilla.suse.com/show_bug.cgi?id=1246738 * https://bugzilla.suse.com/show_bug.cgi?id=1246789 * https://bugzilla.suse.com/show_bug.cgi?id=1246882 * https://bugzilla.suse.com/show_bug.cgi?id=1246906 * https://bugzilla.suse.com/show_bug.cgi?id=1246925 * https://bugzilla.suse.com/show_bug.cgi?id=1247688 * https://bugzilla.suse.com/show_bug.cgi?id=1247721 * https://bugzilla.suse.com/show_bug.cgi?id=1250520 * https://bugzilla.suse.com/show_bug.cgi?id=1250755 * https://bugzilla.suse.com/show_bug.cgi?id=1251044 * https://bugzilla.suse.com/show_bug.cgi?id=1251138 * https://bugzilla.suse.com/show_bug.cgi?id=1251776 * https://bugzilla.suse.com/show_bug.cgi?id=1252244 * https://bugzilla.suse.com/show_bug.cgi?id=1252285 * https://bugzilla.suse.com/show_bug.cgi?id=1254256 * https://bugzilla.suse.com/show_bug.cgi?id=1254257 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:33:35 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:33:35 -0000 Subject: SUSE-SU-2026:22531-1: important: Security update 5.1.1 for Multi-Linux Manager Client Tools and Salt Bundle Message-ID: <178368681516.1052.10000190841282010968@5ed4f61072e9> # Security update 5.1.1 for Multi-Linux Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22531-1 Release Date: 2025-10-23T15:29:04Z Rating: important References: * bsc#1229825 * bsc#1243331 * bsc#1243611 * bsc#1243704 * bsc#1244027 * bsc#1244127 * bsc#1245099 * bsc#1245120 * bsc#1245740 * bsc#1246068 * bsc#1246320 * bsc#1246553 * bsc#1246628 * bsc#1246789 * bsc#1246864 * bsc#1246882 * bsc#1246906 * bsc#1247688 * bsc#1247836 * jsc#MSQA-1023 Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that contains one feature and has 19 fixes can now be installed. ## Description: This update fixes the following issues: uyuni-tools: * Version 5.1.20-0 * Add migration for server monitoring configuration (bsc#1247688) * Version 5.1.19-0 * Add a lowercase version of --logLevel (bsc#1243611) * Stop executing scripts in temporary folder (bsc#1243704) * support config: collect podman inspect for hub container (bsc#1245099) * Use new dedicated path for Cobbler settings (bsc#1244027) * Migrate custom auto installation snippets (bsc#1246320) * Add SUSE Linux Enterprise 15 SP7 to buildin productmap * Fix loading product map from mgradm configuration file (bsc#1246068) * Fix channel override for distro copy * Do not use sudo when running as a root user (bsc#1246882) * Do not require backups to be at the same location for restoring (bsc#1246906) * Fix recomputing proxy images when installing a PTF or TEST (bsc#1246553) * Add mgradm server rename to change the server FQDN (bsc#1229825) * If no DB SSL CA parameter is given, use the other one (bsc#1245120) * More fault tolerant mgradm stop (bsc#1243331) * Backup systemd dropin directory too and create if missing * Add 3rd party SSL options for upgrade and migration scenarios * Do not consider stderr output of podman as an error (bsc#1247836) * Restore SELinux contexts for restored backup volumes (bsc#1244127) * Automatically get up-to-date systemid file on salt based proxy hosts (bsc#1246789) * Bump the default image tag to 5.1.1 * Version 5.1.18-0 * Update translation strings * Version 5.1.17-0 * upgrade saline should use scale function (bsc#1246864) * Version 5.1.16-0 * Use database backup volume as temporary backup location (bsc#1246628) venv-salt-minion: * Improve SL Micro 6.2 detection with grains * Fix functional.states.test_user for SLES 16 and Micro systems * Fix the tests failing on AlmaLinux 10 and other clones * Add `minion_legacy_req_warnings` option to avoid noisy warnings * Use more strict way to fix shebang in the bundle scripts * Remove unused activate script (bsc#1245740) * Filter out zero-length check as the empty files are expected there * Filter out env-script-interpreter for ssh-id-wrapper as not used with the Salt Bundle, but present inside the salt module * venv-salt-minion-rpmlintrc ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-62=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-bash-completion-5.1.20-1.4 * mgrctl-lang-5.1.20-1.4 * mgrctl-zsh-completion-5.1.20-1.4 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-5.1.20-1.4 * mgrctl-5.1.20-1.4 * venv-salt-minion-3006.0-9.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1229825 * https://bugzilla.suse.com/show_bug.cgi?id=1243331 * https://bugzilla.suse.com/show_bug.cgi?id=1243611 * https://bugzilla.suse.com/show_bug.cgi?id=1243704 * https://bugzilla.suse.com/show_bug.cgi?id=1244027 * https://bugzilla.suse.com/show_bug.cgi?id=1244127 * https://bugzilla.suse.com/show_bug.cgi?id=1245099 * https://bugzilla.suse.com/show_bug.cgi?id=1245120 * https://bugzilla.suse.com/show_bug.cgi?id=1245740 * https://bugzilla.suse.com/show_bug.cgi?id=1246068 * https://bugzilla.suse.com/show_bug.cgi?id=1246320 * https://bugzilla.suse.com/show_bug.cgi?id=1246553 * https://bugzilla.suse.com/show_bug.cgi?id=1246628 * https://bugzilla.suse.com/show_bug.cgi?id=1246789 * https://bugzilla.suse.com/show_bug.cgi?id=1246864 * https://bugzilla.suse.com/show_bug.cgi?id=1246882 * https://bugzilla.suse.com/show_bug.cgi?id=1246906 * https://bugzilla.suse.com/show_bug.cgi?id=1247688 * https://bugzilla.suse.com/show_bug.cgi?id=1247836 * https://jira.suse.com/browse/MSQA-1023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:34:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:34:13 -0000 Subject: SUSE-SU-2026:22530-1: important: Security update 5.0.5 for Multi-Linux Manager Client Tools, Salt and Salt Bundle Message-ID: <178368685304.1052.5265731271955842391@5ed4f61072e9> # Security update 5.0.5 for Multi-Linux Manager Client Tools, Salt and Salt Bundle Announcement ID: SUSE-SU-2026:22530-1 Release Date: 2025-07-23T13:31:05Z Rating: important References: * bsc#1236621 * bsc#1236877 * bsc#1238686 * bsc#1238849 * bsc#1238929 * bsc#1240626 * bsc#1240698 * bsc#1242174 * bsc#1243105 * bsc#1243268 * bsc#1243274 * bsc#1243297 * bsc#1243802 * bsc#1244561 * bsc#1244564 * bsc#1244565 * bsc#1244566 * bsc#1244567 * bsc#1244568 * bsc#1244570 * bsc#1244571 * bsc#1244572 * bsc#1244574 * bsc#1244575 * jsc#MSQA-993 Cross-References: * CVE-2024-38822 * CVE-2024-38823 * CVE-2024-38824 * CVE-2024-38825 * CVE-2025-22236 * CVE-2025-22237 * CVE-2025-22238 * CVE-2025-22239 * CVE-2025-22240 * CVE-2025-22241 * CVE-2025-22242 * CVE-2025-22870 * CVE-2025-47287 CVSS scores: * CVE-2024-38822 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-38822 ( SUSE ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2024-38822 ( NVD ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2024-38823 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2024-38823 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-38823 ( NVD ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2024-38824 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2024-38824 ( SUSE ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2024-38824 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2024-38824 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-38825 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-38825 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N * CVE-2024-38825 ( NVD ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N * CVE-2025-22236 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L * CVE-2025-22236 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2025-22236 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2025-22237 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-22237 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-22237 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-22238 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22238 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2025-22238 ( NVD ): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2025-22239 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L * CVE-2025-22239 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2025-22239 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2025-22240 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-22240 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2025-22240 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2025-22241 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22241 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2025-22241 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2025-22242 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22242 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22242 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:H * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-47287 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47287 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47287 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves 13 vulnerabilities, contains one feature and has 11 fixes can now be installed. ## Description: This update fixes the following issues: golang-github-prometheus-node_exporter: * Security issues fixed: * CVE-2025-22870: Prevent a matching of hosts against proxy patterns to improperly treat an IPv6 zone ID as a hostname component (bsc#1238686) * Other bugs fixed: * Fixed Darwin memory leak * pressure: Fix missing IRQ on older kernels salt, venv-salt-minion: * Security issues fixed: * CVE-2024-38822: Fixed Minion token validation (bsc#1244561) * CVE-2024-38823: Fixed server vulnerability to replay attacks when not using a TLS encrypted transport (bsc#1244564) * CVE-2024-38824: Fixed directory traversal vulnerability in recv_file method (bsc#1244565) * CVE-2024-38825: Fixed salt.auth.pki module authentication issue (bsc#1244566) * CVE-2025-22240: Fixed arbitrary directory creation or file deletion with GitFS (bsc#1244567) * CVE-2025-22236: Fixed Minion event bus authorization bypass (bsc#1244568) * CVE-2025-22241: Fixed the use of un-validated input in the VirtKey class (bsc#1244570) * CVE-2025-22237: Fixed exploitation of the 'on demand' pillar functionality (bsc#1244571) * CVE-2025-22238: Fixed the master's default cache vulnerability to a directory traversal attack (bsc#1244572) * CVE-2025-22239: Fixed the arbitrary event injection on the Salt Master (bsc#1244574) * CVE-2025-22242: Fixed a Denial of Service vulnerability through file read operation (bsc#1244575) * CVE-2025-47287: Fixed a Denial of Service vulnerability in Tornado logging behavior (bsc#1243268) * Other bugs fixed: * Added subsystem filter to udev.exportdb (bsc#1236621) * Added `minion_legacy_req_warnings` option to avoid noisy warnings * Fixed Ubuntu 24.04 edge-case test failures * Fixed refresh of osrelease and related grains on Python 3.10+ * Fixed issue requiring proper Python flavor for dependencies * Require M2Crypto version 0.44.0 or higher * venv-salt-minion: Fixed bundle path in pyvenv.cfg uyuni-tools: * Version 0.1.31-0: * Added the info message about End User License Agreement * Don't migrate py2*-compat-salt.conf files (bsc#1240626) * Check for restorecon before using it (bsc#1240698) * Adjust the distro path in cobbler files after migration (bsc#1238929) * Added mgradm support ptf podman --pullPolicy flag (bsc#1236877) * Support: don't dump files in bound folders (bsc#1243297) * Cleanup host supportconfig files (bsc#1242174) * During migration, check if backup already exists (bsc#1243105) * Removed SHM size limits from all containers (bsc#1243274) * Don't migrate /etc/apache2/vhosts.d/cobbler.conf * Fixed migration --prepare for autoinstallable distributions (bsc#1243802) * Skip instalation if the server is already set up (bsc#1238849) * Bumped the default image tag to 5.0.5 ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6392=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-bash-completion-0.1.31-1.1 * mgrctl-zsh-completion-0.1.31-1.1 * mgrctl-lang-0.1.31-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * venv-salt-minion-3006.0-8.1 * mgrctl-0.1.31-1.1 * golang-github-prometheus-node_exporter-1.9.1-1.1 * golang-github-prometheus-node_exporter-debuginfo-1.9.1-1.1 * mgrctl-debuginfo-0.1.31-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-38822.html * https://www.suse.com/security/cve/CVE-2024-38823.html * https://www.suse.com/security/cve/CVE-2024-38824.html * https://www.suse.com/security/cve/CVE-2024-38825.html * https://www.suse.com/security/cve/CVE-2025-22236.html * https://www.suse.com/security/cve/CVE-2025-22237.html * https://www.suse.com/security/cve/CVE-2025-22238.html * https://www.suse.com/security/cve/CVE-2025-22239.html * https://www.suse.com/security/cve/CVE-2025-22240.html * https://www.suse.com/security/cve/CVE-2025-22241.html * https://www.suse.com/security/cve/CVE-2025-22242.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://www.suse.com/security/cve/CVE-2025-47287.html * https://bugzilla.suse.com/show_bug.cgi?id=1236621 * https://bugzilla.suse.com/show_bug.cgi?id=1236877 * https://bugzilla.suse.com/show_bug.cgi?id=1238686 * https://bugzilla.suse.com/show_bug.cgi?id=1238849 * https://bugzilla.suse.com/show_bug.cgi?id=1238929 * https://bugzilla.suse.com/show_bug.cgi?id=1240626 * https://bugzilla.suse.com/show_bug.cgi?id=1240698 * https://bugzilla.suse.com/show_bug.cgi?id=1242174 * https://bugzilla.suse.com/show_bug.cgi?id=1243105 * https://bugzilla.suse.com/show_bug.cgi?id=1243268 * https://bugzilla.suse.com/show_bug.cgi?id=1243274 * https://bugzilla.suse.com/show_bug.cgi?id=1243297 * https://bugzilla.suse.com/show_bug.cgi?id=1243802 * https://bugzilla.suse.com/show_bug.cgi?id=1244561 * https://bugzilla.suse.com/show_bug.cgi?id=1244564 * https://bugzilla.suse.com/show_bug.cgi?id=1244565 * https://bugzilla.suse.com/show_bug.cgi?id=1244566 * https://bugzilla.suse.com/show_bug.cgi?id=1244567 * https://bugzilla.suse.com/show_bug.cgi?id=1244568 * https://bugzilla.suse.com/show_bug.cgi?id=1244570 * https://bugzilla.suse.com/show_bug.cgi?id=1244571 * https://bugzilla.suse.com/show_bug.cgi?id=1244572 * https://bugzilla.suse.com/show_bug.cgi?id=1244574 * https://bugzilla.suse.com/show_bug.cgi?id=1244575 * https://jira.suse.com/browse/MSQA-993 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:34:31 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:34:31 -0000 Subject: SUSE-RU-2026:22529-1: moderate: Recommended update 5.0.4 for Multi-Linux Manager Client Tools and Salt Bundle Message-ID: <178368687197.1052.13924987902848850274@5ed4f61072e9> # Recommended update 5.0.4 for Multi-Linux Manager Client Tools and Salt Bundle Announcement ID: SUSE-RU-2026:22529-1 Release Date: 2025-04-14T09:56:59Z Rating: moderate References: * bsc#1215484 * bsc#1220905 * bsc#1226964 * bsc#1230642 * bsc#1230944 * bsc#1231605 * bsc#1234022 * bsc#1234881 * bsc#1235658 * bsc#1235861 * jsc#MSQA-934 * jsc#PED-12480 * jsc#PED-12485 Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that contains three features and has 10 fixes can now be installed. ## Description: This update for fixes the following issues: uyuni-tools: * Version 0.1.29-0 * Fixed label of proxy configuration files on SELinux (bsc#1235658) * Reverted use of :z flag on Server volumes (bsc#1235861) venv-salt-minion: * Fixed aptpkg 'NoneType object has no attribute split' error * Detect openEuler as RedHat family OS * Ensure the correct crypt module is loaded * Implement multiple inventory for ansible.targets * Made x509 module compatible with M2Crypto 0.44.0 * Removed deprecated code from x509.certificate_managed test mode * Move logrotate config to /usr/etc/logrotate.d where possible * Added DEB822 apt repository format support * Made Salt-SSH work with all SSH passwords (bsc#1215484) * Removed strict binary dependency for libcrypt.so for EL9 bundle to make it compatible with openEuler and make using passlib instead. * Fixed virt_query outputter and added support for block devices * Made _auth calls visible with master stats * Repaired mount.fstab_present always returning pending changes * Set virtual grain in Podman systemd container * Fixed crash due wrong client reference on `SaltMakoTemplateLookup` * Enhanced batch async and fixed some detected issues * Fixed tests failures after "repo.saltproject.io" deprecation * Fixed error to stat '/root/.gitconfig' on gitfs (bsc#1230944) (bsc#1234881) (bsc#1220905) * Adapt to removal of hex attribute in pygit2 v1.15.0 (bsc#1230642) * Enhanced smart JSON parsing when garbage is present (bsc#1231605) * Fixed virtual grains for VMs running on Nutanix AHV (bsc#1234022) * Fixed issues running on Python 3.12 and 3.13 (bsc#1226964) golang-github-prometheus-node_exporter: * Implementation of `golang-github-prometheus-node_exporter` at version 1.9.0 (jsc#PED-12480, jsc#PED-12485) system-user-prometheus: * Implementation of `system-user-prometheus` at version 1.0.0 (jsc#PED-12480, jsc#PED-12485) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6285=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-lang-0.1.29-1.1 * mgrctl-bash-completion-0.1.29-1.1 * mgrctl-zsh-completion-0.1.29-1.1 * system-user-prometheus-1.0.0-2.4 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-0.1.29-1.1 * venv-salt-minion-3006.0-5.1 * golang-github-prometheus-node_exporter-debuginfo-1.9.0-1.1 * golang-github-prometheus-node_exporter-1.9.0-1.1 * mgrctl-debuginfo-0.1.29-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1215484 * https://bugzilla.suse.com/show_bug.cgi?id=1220905 * https://bugzilla.suse.com/show_bug.cgi?id=1226964 * https://bugzilla.suse.com/show_bug.cgi?id=1230642 * https://bugzilla.suse.com/show_bug.cgi?id=1230944 * https://bugzilla.suse.com/show_bug.cgi?id=1231605 * https://bugzilla.suse.com/show_bug.cgi?id=1234022 * https://bugzilla.suse.com/show_bug.cgi?id=1234881 * https://bugzilla.suse.com/show_bug.cgi?id=1235658 * https://bugzilla.suse.com/show_bug.cgi?id=1235861 * https://jira.suse.com/browse/MSQA-934 * https://jira.suse.com/browse/PED-12480 * https://jira.suse.com/browse/PED-12485 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:35:01 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:35:01 -0000 Subject: SUSE-SU-2026:22528-1: moderate: Security update for SUSE Manager Client Tools Message-ID: <178368690132.1052.6201191640806141242@5ed4f61072e9> # Security update for SUSE Manager Client Tools Announcement ID: SUSE-SU-2026:22528-1 Release Date: 2025-02-13T08:42:02Z Rating: moderate References: * bsc#1228182 * bsc#1228690 * bsc#1229079 * bsc#1229104 * bsc#1231497 * bsc#1231568 * bsc#1231618 * bsc#1231759 * bsc#1232575 * bsc#1232769 * bsc#1232817 * bsc#1233202 * bsc#1233279 * bsc#1233630 * bsc#1233660 * bsc#1233667 * bsc#1234123 * jsc#MSQA-914 Cross-References: * CVE-2024-22037 CVSS scores: * CVE-2024-22037 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L * CVE-2024-22037 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-22037 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-22037 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves one vulnerability, contains one feature and has 16 fixes can now be installed. ## Description: This update fixes the following issues: salt: * Revert setting SELinux context for minion service (bsc#1233667) * Removed System V init support * Fix the condition of alternatives for Tumbleweed and Leap 16 * Build all python bindings for all flavors * Make minion reconnecting on changing master IP (bsc#1228182) * Handle logger exception when flushing already closed file * Include passlib as a recommended dependency * Make Salt Bundle more tolerant to long running jobs (bsc#1228690) uyuni-tools was updated from version 0.1.23-0 to 0.1.27-0: * Security issues fixed: * CVE-2024-22037: Use podman secret to store the database credentials (bsc#1231497) * Other changes and bugs fixed: * Version 0.1.27-0 * Bump the default image tag to 5.0.3 * IsInstalled function fix * Run systemctl daemon-reload after changing the container image config (bsc#1233279) * Coco-replicas-upgrade * Persist search server indexes (bsc#1231759) * Sync deletes files during migration (bsc#1233660) * Ignore coco and hub images when applying PTF if they are not ailable (bsc#1229079) * Add --registry back to mgrpxy (bsc#1233202) * Only add java.hostname on migrated server if not present * Consider the configuration file to detect the coco or hub api images should be pulled (bsc#1229104) * Only raise an error if cloudguestregistryauth fails for PAYG (bsc#1233630) * Add registry.suse.com login to mgradm upgrade podman list (bsc#1234123) * Version 0.1.26-0 * Ignore all zypper caches during migration (bsc#1232769) * Use the uyuni network for all podman containers (bsc#1232817) * Version 0.1.25-0 * Don't migrate enabled systemd services, recreate them (bsc#1232575) * Version 0.1.24-0 * Redact JSESSIONID and pxt-session-cookie values from logs and console output (bsc#1231568) venv-salt-minion: * Included D-Bus python module for SUSE distros (bsc#1231618) * Reverted setting SELinux context for minion service (bsc#1233667) * Make minion reconnecting on changing master IP (bsc#1228182) * Fixed post_start_cleanup.sh shebang to work on all systems * Handle logger exception when flushing already closed file * Made Salt Bundle more tolerant to long running jobs (bsc#1228690) * Modified: * include-rpm * filter-requires.sh ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6211=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-0.1.28-1.1 * venv-salt-minion-3006.0-4.1 * mgrctl-0.1.28-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.28-1.1 * mgrctl-bash-completion-0.1.28-1.1 * mgrctl-lang-0.1.28-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22037.html * https://bugzilla.suse.com/show_bug.cgi?id=1228182 * https://bugzilla.suse.com/show_bug.cgi?id=1228690 * https://bugzilla.suse.com/show_bug.cgi?id=1229079 * https://bugzilla.suse.com/show_bug.cgi?id=1229104 * https://bugzilla.suse.com/show_bug.cgi?id=1231497 * https://bugzilla.suse.com/show_bug.cgi?id=1231568 * https://bugzilla.suse.com/show_bug.cgi?id=1231618 * https://bugzilla.suse.com/show_bug.cgi?id=1231759 * https://bugzilla.suse.com/show_bug.cgi?id=1232575 * https://bugzilla.suse.com/show_bug.cgi?id=1232769 * https://bugzilla.suse.com/show_bug.cgi?id=1232817 * https://bugzilla.suse.com/show_bug.cgi?id=1233202 * https://bugzilla.suse.com/show_bug.cgi?id=1233279 * https://bugzilla.suse.com/show_bug.cgi?id=1233630 * https://bugzilla.suse.com/show_bug.cgi?id=1233660 * https://bugzilla.suse.com/show_bug.cgi?id=1233667 * https://bugzilla.suse.com/show_bug.cgi?id=1234123 * https://jira.suse.com/browse/MSQA-914 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:35:36 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:35:36 -0000 Subject: SUSE-SU-2026:22527-1: important: Security update for SUSE Manager Client Tools and Salt Bundle Message-ID: <178368693641.1052.4513206106125206118@5ed4f61072e9> # Security update for SUSE Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22527-1 Release Date: 2025-02-03T09:00:46Z Rating: important References: * bsc#1219041 * bsc#1220357 * bsc#1222842 * bsc#1226141 * bsc#1226447 * bsc#1226448 * bsc#1226469 * bsc#1227547 * bsc#1228105 * bsc#1228780 * bsc#1229109 * bsc#1229539 * bsc#1229654 * bsc#1229704 * bsc#1229873 * bsc#1229994 * bsc#1229995 * bsc#1229996 * bsc#1230058 * bsc#1230059 * bsc#1230322 * jsc#MSQA-863 Cross-References: * CVE-2024-0397 * CVE-2024-3651 * CVE-2024-37891 * CVE-2024-4032 * CVE-2024-5569 * CVE-2024-6345 * CVE-2024-6923 * CVE-2024-7592 * CVE-2024-8088 CVSS scores: * CVE-2024-0397 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2024-0397 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-3651 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3651 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3651 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-37891 ( SUSE ): 4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2024-37891 ( NVD ): 4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2024-37891 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-4032 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-4032 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-5569 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2024-5569 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-6345 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-6345 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-6923 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-6923 ( NVD ): 5.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2024-7592 ( SUSE ): 2.6 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-7592 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7592 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8088 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-8088 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-8088 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:X/RE:L/U:X Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves nine vulnerabilities, contains one feature and has 12 fixes can now be installed. ## Description: This update for SUSE Manager Client Tools and Salt Bundle the following issues: uyuni-tools: venv-salt-minion: * Security fixes on Python 3.11 interpreter: * CVE-2024-7592: Fixed quadratic complexity in parsing -quoted cookie values with backslashes (bsc#1229873, bsc#1230059) * CVE-2024-8088: Prevent malformed payload to cause infinite loops in zipfile.Path (bsc#1229704, bsc#1230058) * CVE-2024-6923: Prevent email header injection due to unquoted newlines (bsc#1228780) * CVE-2024-4032: Rearranging definition of private global IP addresses (bsc#1226448) * CVE-2024-0397: ssl.SSLContext.cert_store_stats() and ssl.SSLContext.get_ca_certs() now correctly lock access to the certificate store, when the ssl.SSLContext is shared across multiple threads (bsc#1226447) * Security fixes on Python dependencies: * CVE-2024-5569: zipp: Fixed a Denial of Service (DoS) vulnerability in the jaraco/zipp library (bsc#1227547, bsc#1229996) * CVE-2024-6345: setuptools: Sanitize any VCS URL used for download (bsc#1228105, bsc#1229995) * CVE-2024-3651: idna: Fix a potential DoS via resource consumption via specially crafted inputs to idna.encode() (bsc#1222842, bsc#1229994) * CVE-2024-37891: urllib3: Added the `Proxy-Authorization` header to the list of headers to strip from requests when redirecting to a different host (bsc#1226469, bsc#1229654) * Other bugs fixed: * Fixed failing x509 tests with OpenSSL < 1.1 * Avoid explicit reading of /etc/salt/minion (bsc#1220357) * Allow NamedLoaderContexts to be returned from loader * Reverted the change making reactor less blocking (bsc#1230322) * Use --cachedir for extension_modules in salt-call (bsc#1226141) * Prevent using SyncWrapper with no reason * Enable post_start_cleanup.sh to work in a transaction * Fixed the SELinux context for Salt Minion service (bsc#1219041) * Increase warn_until_date date for code we still support * Avoid crash on wrong output of systemctl version (bsc#1229539) * Improved error handling with different OpenSSL versions * Fixed cloud Minion configuration for multiple Masters (bsc#1229109) * Use Pygit2 id instead of deprecated oid in gitfs * Added passlib Python module to the bundle ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-669=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-0.1.23-2.1 * mgrctl-0.1.23-2.1 * venv-salt-minion-3006.0-3.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.23-2.1 * mgrctl-lang-0.1.23-2.1 * mgrctl-bash-completion-0.1.23-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0397.html * https://www.suse.com/security/cve/CVE-2024-3651.html * https://www.suse.com/security/cve/CVE-2024-37891.html * https://www.suse.com/security/cve/CVE-2024-4032.html * https://www.suse.com/security/cve/CVE-2024-5569.html * https://www.suse.com/security/cve/CVE-2024-6345.html * https://www.suse.com/security/cve/CVE-2024-6923.html * https://www.suse.com/security/cve/CVE-2024-7592.html * https://www.suse.com/security/cve/CVE-2024-8088.html * https://bugzilla.suse.com/show_bug.cgi?id=1219041 * https://bugzilla.suse.com/show_bug.cgi?id=1220357 * https://bugzilla.suse.com/show_bug.cgi?id=1222842 * https://bugzilla.suse.com/show_bug.cgi?id=1226141 * https://bugzilla.suse.com/show_bug.cgi?id=1226447 * https://bugzilla.suse.com/show_bug.cgi?id=1226448 * https://bugzilla.suse.com/show_bug.cgi?id=1226469 * https://bugzilla.suse.com/show_bug.cgi?id=1227547 * https://bugzilla.suse.com/show_bug.cgi?id=1228105 * https://bugzilla.suse.com/show_bug.cgi?id=1228780 * https://bugzilla.suse.com/show_bug.cgi?id=1229109 * https://bugzilla.suse.com/show_bug.cgi?id=1229539 * https://bugzilla.suse.com/show_bug.cgi?id=1229654 * https://bugzilla.suse.com/show_bug.cgi?id=1229704 * https://bugzilla.suse.com/show_bug.cgi?id=1229873 * https://bugzilla.suse.com/show_bug.cgi?id=1229994 * https://bugzilla.suse.com/show_bug.cgi?id=1229995 * https://bugzilla.suse.com/show_bug.cgi?id=1229996 * https://bugzilla.suse.com/show_bug.cgi?id=1230058 * https://bugzilla.suse.com/show_bug.cgi?id=1230059 * https://bugzilla.suse.com/show_bug.cgi?id=1230322 * https://jira.suse.com/browse/MSQA-863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:36:12 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:36:12 -0000 Subject: SUSE-RU-2026:22526-1: moderate: Recommended update for uyuni-tools, venv-salt-minion, saltbundlepy-pyopenssl, saltbundlepy-cryptography Message-ID: <178368697224.1052.8995740097189640952@5ed4f61072e9> # Recommended update for uyuni-tools, venv-salt-minion, saltbundlepy-pyopenssl, saltbundlepy-cryptography Announcement ID: SUSE-RU-2026:22526-1 Release Date: 2025-02-03T08:49:59Z Rating: moderate References: * bsc#1220136 * bsc#1222684 * bsc#1224349 * bsc#1225349 * bsc#1226191 * bsc#1226284 * bsc#1226437 * bsc#1226759 * bsc#1226793 * bsc#1226847 * bsc#1226914 * bsc#1227195 * bsc#1227244 * bsc#1227245 * bsc#1227505 * bsc#1227584 * bsc#1227586 * bsc#1227588 * bsc#1227718 * bsc#1227951 * bsc#1228026 * bsc#1228183 Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that has 22 fixes can now be installed. ## Description: This update for uyuni-tools, venv-salt-minion, saltbundlepy-pyopenssl, saltbundlepy-cryptography fixes the following issues: saltbundlepy-cryptography: \- Apply fips-mode.patch and definitions- ERR_GET.patch on Ubuntu 24.04 and fix the condition in advance for future products saltbundlepy-pyopenssl: \- Make the module compatible with older OpenSSL versions not having `X509_CRL_set1_lastUpdate` and `X509_CRL_set1_nextUpdate` defined by using `X509_CRL_set_lastUpdate` and `X509_CRL_set_nextUpdate` instead. uyuni-tools: \- version 0.1.21-0 * mgrpxy: Fix typo on Systemd template \- version 0.1.20-0 * Update the push tag to 5.0.1 * mgrpxy: expose port on IPv6 network (bsc#1227951) \- version 0.1.19-0 * Skip updating Tomcat remote debug if conf file is not present \- version 0.1.18-0 * Setup Confidential Computing container during migration (bsc#1227588) * Add the /etc/uyuni/uyuni-tools.yaml path to the config help * Split systemd config files to not loose configuration at upgrade (bsc#1227718) * Use the same logic for image computation in mgradm and mgrpxy (bsc#1228026) * Allow building with different Helm and container default registry paths (bsc#1226191) * Fix recursion in mgradm upgrade podman list --help * Setup hub xmlrpc API service in migration to Podman (bsc#1227588) * Setup disabled hub xmlrpc API service in all cases (bsc#1227584) * Clean the inspection code to make it faster * Properly detect IPv6 enabled on Podman network (bsc#1224349) * Fix the log file path generation * Write scripts output to uyuni-tools.log file * Add uyuni-hubxml-rpc to the list of values in mgradm scale --help * Use path in mgradm support sql file input (bsc#1227505) * On Ubuntu build with go1.21 instead of go1.20 * Enforce Cobbler setup (bsc#1226847) * Expose port on IPv6 network (bsc#1227951) * show output of podman image search --list-tags command * Implement mgrpxy support config command * During migration, ignore /etc/sysconfig/tomcat and /etc/tomcat/tomcat.conf (bsc#1228183) * During migration, remove java.annotation,com.sun.xml.bind and UseConcMarkSweepGC settings * Disable node exporter port for Kubernetes * Fix start, stop and restart in Kubernetes * Increase start timeout in Kubernetes * Fix traefik query * Fix password entry usability (bsc#1226437) * Add --prepare option to migrate command * Fix random error during installation of CA certificate (bsc#1227245) * Clarify and fix distro name guessing when not provided (bsc#1226284) * Replace not working Fatal error by plain error return (bsc#1220136) * Allow server installation with preexisting storage volumes * Do not report error when purging mounted volume (bsc#1225349) * Preserve PAGER settings from the host for interactive sql usage (bsc#1226914) * Add mgrpxy command to clear the Squid cache * Use local images for Confidential Computing and Hub containers (bsc#1227586) \- version 0.1.17-0 * Allow GPG files to be loaded from the local file (bsc#1227195) \- version 0.1.16-0 * Prefer local images in all migration steps (bsc#1227244) \- version 0.1.15-0 * Define --registry flag behaviour (bsc#1226793) \- version 0.1.14-0 * Do not rely on hardcoded registry, remove any FQDN \- version 0.1.13-0 * Fix mgradm support config tarball creation (bsc#1226759) \- version 0.1.12-0 * Detection of k8s on Proxy was wrongly influenced by Server setting venv-salt-minion: \- Fix rich rule comparison in firewalld module (bsc#1222684) \- test_vultrpy: adjust test expectation to prevent failure after Debian 10 EOL \- Make auth.pam more robust with Salt Bundle and fix tests \- Fix performance of user.list_groups with many remote groups \- Fix "status.diskusage" function and exclude some tests for Salt Bundle ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-641=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-0.1.21-1.1 * venv-salt-minion-3006.0-2.1 * mgrctl-0.1.21-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.21-1.1 * mgrctl-bash-completion-0.1.21-1.1 * mgrctl-lang-0.1.21-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1220136 * https://bugzilla.suse.com/show_bug.cgi?id=1222684 * https://bugzilla.suse.com/show_bug.cgi?id=1224349 * https://bugzilla.suse.com/show_bug.cgi?id=1225349 * https://bugzilla.suse.com/show_bug.cgi?id=1226191 * https://bugzilla.suse.com/show_bug.cgi?id=1226284 * https://bugzilla.suse.com/show_bug.cgi?id=1226437 * https://bugzilla.suse.com/show_bug.cgi?id=1226759 * https://bugzilla.suse.com/show_bug.cgi?id=1226793 * https://bugzilla.suse.com/show_bug.cgi?id=1226847 * https://bugzilla.suse.com/show_bug.cgi?id=1226914 * https://bugzilla.suse.com/show_bug.cgi?id=1227195 * https://bugzilla.suse.com/show_bug.cgi?id=1227244 * https://bugzilla.suse.com/show_bug.cgi?id=1227245 * https://bugzilla.suse.com/show_bug.cgi?id=1227505 * https://bugzilla.suse.com/show_bug.cgi?id=1227584 * https://bugzilla.suse.com/show_bug.cgi?id=1227586 * https://bugzilla.suse.com/show_bug.cgi?id=1227588 * https://bugzilla.suse.com/show_bug.cgi?id=1227718 * https://bugzilla.suse.com/show_bug.cgi?id=1227951 * https://bugzilla.suse.com/show_bug.cgi?id=1228026 * https://bugzilla.suse.com/show_bug.cgi?id=1228183 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:36:19 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:36:19 -0000 Subject: SUSE-RU-2026:22525-1: critical: Recommended update for SUSE Manager Client Tools Message-ID: <178368697967.1052.853209316117432601@5ed4f61072e9> # Recommended update for SUSE Manager Client Tools Announcement ID: SUSE-RU-2026:22525-1 Release Date: 2025-02-03T08:45:43Z Rating: critical References: * bsc#1224081 * bsc#1226436 * jsc#MSQA-812 * jsc#PED-7843 Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that contains two features and has two fixes can now be installed. ## Description: This update for fixes the following issues: uyuni-tools: * Version 0.1.11-0 * Require Netavark network backend for Podman (bsc#1224081) * Fix --registry option (bsc#1226436) * Copy the server CA certificate to the host * Delete /etc/uyuni/proxy folder during mgrpxy uninstall * Check permissions of /etc/uyuni folder to prevent Squid failures * Correctly prepend default namespace for mgrpxy containers * Re-add Podman extra args for install and migrate * Version 0.1.10-0 * Provide mgrctl to SUSE Linux Enterprise 15 client tools (jsc#PED-7843) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-66=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-lang-0.1.11-1.1 * mgrctl-bash-completion-0.1.11-1.1 * mgrctl-zsh-completion-0.1.11-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-0.1.11-1.1 * mgrctl-debuginfo-0.1.11-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1224081 * https://bugzilla.suse.com/show_bug.cgi?id=1226436 * https://jira.suse.com/browse/MSQA-812 * https://jira.suse.com/browse/PED-7843 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:36:25 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:36:25 -0000 Subject: SUSE-RU-2026:22524-1: moderate: Recommended update for SUSE Manager Salt Bundle Message-ID: <178368698533.1052.7160886292604979550@5ed4f61072e9> # Recommended update for SUSE Manager Salt Bundle Announcement ID: SUSE-RU-2026:22524-1 Release Date: 2025-02-03T08:45:42Z Rating: moderate References: * bsc#1216063 * jsc#MSQA-808 Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that contains one feature and has one fix can now be installed. ## Description: This update fixes the following issues: venv-salt-minion: * Add a timer to delete old env post update for venv-minion * Several fixes for tests to avoid errors and failures in some OSes * Speed up salt.matcher.confirm_top by using **context** * Do not call the async wrapper calls with the separate thread * Prevent OOM with high amount of batch async calls (bsc#1216063) * Add missing contextvars dependency in salt.version * Skip tests for unsupported algorithm on old OpenSSL version * Remove redundant `_file_find` call to the master * Prevent possible exception in tornado.concurrent.Future._set_done * Make reactor engine less blocking the EventPublisher * Make salt-master self recoverable on killing EventPublisher * Improve broken events catching and reporting * Make logging calls lighter * Remove unused import causing delays on starting salt-master * Include libffi and libyaml to the bundle for all of the clients to avoid extra dependencies from the client OS. * Update Python version from 3.10 to 3.11 * Fix updating the venv-salt-minion pkg with itself * Enable build for SLE 11 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-65=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64) * mgrctl-5.2.12-1.2 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-1.2 * golang-github-prometheus-node_exporter-1.10.2-1.2 * venv-salt-minion-3006.0-13.1 * mgrctl-debuginfo-5.2.12-1.2 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-5.2.12-1.2 * supportutils-plugin-susemanager-client-5.2.3-1.1 * supportutils-plugin-salt-1.2.3-1.1 * mgrctl-lang-5.2.12-1.2 * mgrctl-bash-completion-5.2.12-1.2 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * venv-salt-minion-3006.0-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1216063 * https://jira.suse.com/browse/MSQA-808 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:36:34 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:36:34 -0000 Subject: SUSE-SU-2026:2838-1: moderate: Security update for libexif Message-ID: <178368699485.1052.3159066119804359522@5ed4f61072e9> # Security update for libexif Announcement ID: SUSE-SU-2026:2838-1 Release Date: 2026-07-10T08:02:27Z Rating: moderate References: * bsc#1259755 * bsc#1262000 * bsc#1262001 Cross-References: * CVE-2026-32775 * CVE-2026-40385 * CVE-2026-40386 CVSS scores: * CVE-2026-32775 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-32775 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-32775 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40385 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-40386 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for libexif fixes the following issues * CVE-2026-40385: Fixed information disclosure and crashes via integer overflow in Nikon MakerNote handling (bsc#1262000) * CVE-2026-40386: Fixed denial of service and information disclosure via integer underflow in MakerNote decoding (bsc#1262001) * CVE-2026-32775: Fixed Buffer overwrite via integer underflow in MakerNotes decoding (bsc#1259755) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2838=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libexif-debugsource-0.6.22-8.16.1 * libexif12-debuginfo-0.6.22-8.16.1 * libexif12-debuginfo-32bit-0.6.22-8.16.1 * libexif-devel-0.6.22-8.16.1 * libexif12-32bit-0.6.22-8.16.1 * libexif12-0.6.22-8.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32775.html * https://www.suse.com/security/cve/CVE-2026-40385.html * https://www.suse.com/security/cve/CVE-2026-40386.html * https://bugzilla.suse.com/show_bug.cgi?id=1259755 * https://bugzilla.suse.com/show_bug.cgi?id=1262000 * https://bugzilla.suse.com/show_bug.cgi?id=1262001 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:36:43 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:36:43 -0000 Subject: SUSE-SU-2026:2837-1: moderate: Security update for libexif Message-ID: <178368700390.1052.13352578028685615187@5ed4f61072e9> # Security update for libexif Announcement ID: SUSE-SU-2026:2837-1 Release Date: 2026-07-10T08:01:50Z Rating: moderate References: * bsc#1259755 * bsc#1262000 * bsc#1262001 Cross-References: * CVE-2026-32775 * CVE-2026-40385 * CVE-2026-40386 CVSS scores: * CVE-2026-32775 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-32775 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-32775 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40385 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-40386 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for libexif fixes the following issues * CVE-2026-40385: Fixed information disclosure and crashes via integer overflow in Nikon MakerNote handling (bsc#1262000) * CVE-2026-40386: Fixed denial of service and information disclosure via integer underflow in MakerNote decoding (bsc#1262001) * CVE-2026-32775: Fixed Buffer overwrite via integer underflow in MakerNotes decoding (bsc#1259755) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2837=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2837=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libexif12-0.6.22-150000.5.12.1 * libexif-debugsource-0.6.22-150000.5.12.1 * libexif12-debuginfo-0.6.22-150000.5.12.1 * libexif-devel-0.6.22-150000.5.12.1 * SUSE Package Hub 15 15-SP7 (x86_64) * libexif12-32bit-0.6.22-150000.5.12.1 * libexif12-32bit-debuginfo-0.6.22-150000.5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32775.html * https://www.suse.com/security/cve/CVE-2026-40385.html * https://www.suse.com/security/cve/CVE-2026-40386.html * https://bugzilla.suse.com/show_bug.cgi?id=1259755 * https://bugzilla.suse.com/show_bug.cgi?id=1262000 * https://bugzilla.suse.com/show_bug.cgi?id=1262001 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:36:49 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 12:36:49 -0000 Subject: SUSE-RU-2026:2836-1: moderate: Recommended update for sysconfig Message-ID: <178368700951.1052.12921388391464922615@5ed4f61072e9> # Recommended update for sysconfig Announcement ID: SUSE-RU-2026:2836-1 Release Date: 2026-07-10T06:27:20Z Rating: moderate References: * bsc#1263889 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for sysconfig fixes the following issues: * Update to version 0.85.11: * netconfig: Do not remove custom /etc/{resolv,yp}.conf on uninstall of sysconfig-netconfig, but only the symlinks to /run/netconfig files created by netconfig or tmpfiles.d(5) (bsc#1263889). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2836=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * sysconfig-debuginfo-0.85.11-150200.18.1 * sysconfig-debugsource-0.85.11-150200.18.1 * sysconfig-0.85.11-150200.18.1 * sysconfig-netconfig-0.85.11-150200.18.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1263889 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:30:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:30:07 -0000 Subject: SUSE-SU-2026:2849-1: important: Security update for krb5 Message-ID: <178370100780.1235.6267232160365622471@aaee731399ed> # Security update for krb5 Announcement ID: SUSE-SU-2026:2849-1 Release Date: 2026-07-10T11:39:24Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2849=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2849=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * krb5-debugsource-1.16.3-46.24.1 * krb5-server-debuginfo-1.16.3-46.24.1 * krb5-doc-1.16.3-46.24.1 * krb5-client-1.16.3-46.24.1 * krb5-plugin-preauth-otp-1.16.3-46.24.1 * krb5-plugin-kdb-ldap-1.16.3-46.24.1 * krb5-client-debuginfo-1.16.3-46.24.1 * krb5-1.16.3-46.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.16.3-46.24.1 * krb5-debuginfo-1.16.3-46.24.1 * krb5-devel-1.16.3-46.24.1 * krb5-plugin-preauth-otp-debuginfo-1.16.3-46.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.16.3-46.24.1 * krb5-plugin-preauth-pkinit-1.16.3-46.24.1 * krb5-server-1.16.3-46.24.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * krb5-32bit-1.16.3-46.24.1 * krb5-debuginfo-32bit-1.16.3-46.24.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * krb5-debugsource-1.16.3-46.24.1 * krb5-server-debuginfo-1.16.3-46.24.1 * krb5-doc-1.16.3-46.24.1 * krb5-client-1.16.3-46.24.1 * krb5-plugin-preauth-otp-1.16.3-46.24.1 * krb5-client-debuginfo-1.16.3-46.24.1 * krb5-debuginfo-32bit-1.16.3-46.24.1 * krb5-plugin-kdb-ldap-1.16.3-46.24.1 * krb5-1.16.3-46.24.1 * krb5-debuginfo-1.16.3-46.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.16.3-46.24.1 * krb5-devel-1.16.3-46.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.16.3-46.24.1 * krb5-plugin-preauth-otp-debuginfo-1.16.3-46.24.1 * krb5-32bit-1.16.3-46.24.1 * krb5-plugin-preauth-pkinit-1.16.3-46.24.1 * krb5-server-1.16.3-46.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:30:18 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:30:18 -0000 Subject: SUSE-SU-2026:2848-1: important: Security update for krb5, krb5-mini Message-ID: <178370101832.1235.4493235796200938191@aaee731399ed> # Security update for krb5, krb5-mini Announcement ID: SUSE-SU-2026:2848-1 Release Date: 2026-07-10T11:39:12Z Rating: important References: * bsc#1263366 * bsc#1263367 * bsc#1268131 Cross-References: * CVE-2026-11850 * CVE-2026-40355 * CVE-2026-40356 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40355 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40355 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for krb5, krb5-mini fixes the following issues * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). * CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). * CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2848=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2848=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2848=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2848=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2848=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * krb5-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150600.11.19.1 * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-devel-1.20.1-150600.11.19.1 * krb5-client-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150600.11.19.1 * krb5-client-debuginfo-1.20.1-150600.11.19.1 * Basesystem Module 15-SP7 (x86_64) * krb5-32bit-debuginfo-1.20.1-150600.11.19.1 * krb5-32bit-1.20.1-150600.11.19.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150600.11.19.1 * krb5-1.20.1-150600.11.19.1 * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-devel-1.20.1-150600.11.19.1 * krb5-server-debuginfo-1.20.1-150600.11.19.1 * krb5-client-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1 * krb5-server-1.20.1-150600.11.19.1 * krb5-client-debuginfo-1.20.1-150600.11.19.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * krb5-32bit-debuginfo-1.20.1-150600.11.19.1 * krb5-32bit-1.20.1-150600.11.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150600.11.19.1 * krb5-1.20.1-150600.11.19.1 * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-devel-1.20.1-150600.11.19.1 * krb5-client-1.20.1-150600.11.19.1 * krb5-server-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1 * krb5-server-1.20.1-150600.11.19.1 * krb5-client-debuginfo-1.20.1-150600.11.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * krb5-32bit-debuginfo-1.20.1-150600.11.19.1 * krb5-32bit-1.20.1-150600.11.19.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * krb5-1.20.1-150600.11.19.1 * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-mini-devel-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1 * krb5-client-debuginfo-1.20.1-150600.11.19.1 * krb5-devel-1.20.1-150600.11.19.1 * krb5-mini-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-spake-1.20.1-150600.11.19.1 * krb5-server-debuginfo-1.20.1-150600.11.19.1 * krb5-client-1.20.1-150600.11.19.1 * krb5-server-1.20.1-150600.11.19.1 * krb5-mini-debugsource-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-spake-debuginfo-1.20.1-150600.11.19.1 * krb5-mini-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150600.11.19.1 * openSUSE Leap 15.6 (x86_64) * krb5-devel-32bit-1.20.1-150600.11.19.1 * krb5-32bit-1.20.1-150600.11.19.1 * krb5-32bit-debuginfo-1.20.1-150600.11.19.1 * openSUSE Leap 15.6 (aarch64_ilp32) * krb5-64bit-debuginfo-1.20.1-150600.11.19.1 * krb5-64bit-1.20.1-150600.11.19.1 * krb5-devel-64bit-1.20.1-150600.11.19.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-server-debuginfo-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1 * krb5-server-1.20.1-150600.11.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://www.suse.com/security/cve/CVE-2026-40355.html * https://www.suse.com/security/cve/CVE-2026-40356.html * https://bugzilla.suse.com/show_bug.cgi?id=1263366 * https://bugzilla.suse.com/show_bug.cgi?id=1263367 * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:30:24 -0000 Subject: SUSE-SU-2026:2847-1: important: Security update for krb5 Message-ID: <178370102423.1235.17673771097048800797@aaee731399ed> # Security update for krb5 Announcement ID: SUSE-SU-2026:2847-1 Release Date: 2026-07-10T11:38:37Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2847=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2847=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2847=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2847=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2847=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2847=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * krb5-devel-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-mini-debugsource-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-mini-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-spake-debuginfo-1.20.1-150500.3.23.1 * krb5-devel-1.20.1-150500.3.23.1 * krb5-mini-debuginfo-1.20.1-150500.3.23.1 * krb5-mini-devel-1.20.1-150500.3.23.1 * krb5-plugin-preauth-spake-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * openSUSE Leap 15.5 (aarch64_ilp32) * krb5-devel-64bit-1.20.1-150500.3.23.1 * krb5-64bit-debuginfo-1.20.1-150500.3.23.1 * krb5-64bit-1.20.1-150500.3.23.1 * openSUSE Leap 15.5 (x86_64) * krb5-devel-32bit-1.20.1-150500.3.23.1 * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-devel-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-devel-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-devel-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:30:32 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:30:32 -0000 Subject: SUSE-RU-2026:2846-1: moderate: Recommended update for release-notes-sle_hpc Message-ID: <178370103260.1235.4925004629296051878@aaee731399ed> # Recommended update for release-notes-sle_hpc Announcement ID: SUSE-RU-2026:2846-1 Release Date: 2026-07-10T11:36:43Z Rating: moderate References: * bsc#1235732 * bsc#933411 Affected Products: * HPC Module 15-SP7 * SUSE Linux Enterprise Server 15 SP7 An update that has two fixes can now be installed. ## Description: This update for release-notes-sle_hpc fixes the following issues: * Update to version 15.7.20260709 (bsc#933411): * Added Spack 0.23 release notes (bsc#1235732) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-2846=1 ## Package List: * HPC Module 15-SP7 (noarch) * release-notes-sle_hpc-15.700000000.20260709-150700.3.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1235732 * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:30:45 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:30:45 -0000 Subject: SUSE-SU-2026:2845-1: important: Security update for perl-List-SomeUtils-XS Message-ID: <178370104557.1235.10888992099689468356@aaee731399ed> # Security update for perl-List-SomeUtils-XS Announcement ID: SUSE-SU-2026:2845-1 Release Date: 2026-07-10T10:31:06Z Rating: important References: * bsc#1269210 Cross-References: * CVE-2026-12844 CVSS scores: * CVE-2026-12844 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-12844 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12844 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-List-SomeUtils-XS fixes the following issue * CVE-2026-12844: heap buffer overflow in the `pairwise` function (bsc#1269210). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2845=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2845=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2845=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2845=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2845=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2845=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2845=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2845=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2845=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2845=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2845=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12844.html * https://bugzilla.suse.com/show_bug.cgi?id=1269210 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:31:00 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:31:00 -0000 Subject: SUSE-SU-2026:2844-1: important: Security update for gstreamer-plugins-good Message-ID: <178370106030.1235.10540787860276799100@aaee731399ed> # Security update for gstreamer-plugins-good Announcement ID: SUSE-SU-2026:2844-1 Release Date: 2026-07-10T10:29:20Z Rating: important References: * bsc#1268449 Cross-References: * CVE-2026-53705 CVSS scores: * CVE-2026-53705 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-good fixes the following issue * CVE-2026-53705: Heap buffer overflow in WavPack decoder via integer overflow (bsc#1268449). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2844=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2844=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2844=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2844=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2844=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * openSUSE Leap 15.4 (aarch64_ilp32) * gstreamer-plugins-good-extra-64bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-64bit-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-64bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-64bit-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-64bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-64bit-debuginfo-1.20.1-150400.3.17.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gstreamer-plugins-good-gtk-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-qtqml-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-qtqml-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-1.20.1-150400.3.17.1 * gstreamer-plugins-good-gtk-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-debuginfo-1.20.1-150400.3.17.1 * openSUSE Leap 15.4 (x86_64) * gstreamer-plugins-good-jack-32bit-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-32bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-32bit-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-32bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-32bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-32bit-debuginfo-1.20.1-150400.3.17.1 * openSUSE Leap 15.4 (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53705.html * https://bugzilla.suse.com/show_bug.cgi?id=1268449 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:31:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:31:07 -0000 Subject: SUSE-SU-2026:2843-1: important: Security update for gstreamer-plugins-good Message-ID: <178370106769.1235.6343902701507139713@aaee731399ed> # Security update for gstreamer-plugins-good Announcement ID: SUSE-SU-2026:2843-1 Release Date: 2026-07-10T10:28:30Z Rating: important References: * bsc#1268449 Cross-References: * CVE-2026-53705 CVSS scores: * CVE-2026-53705 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-good fixes the following issue * CVE-2026-53705: Heap buffer overflow in WavPack decoder via integer overflow (bsc#1268449). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2843=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2843=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2843=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2843=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2843=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gstreamer-plugins-good-lang-1.24.0-150600.3.10.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * Basesystem Module 15-SP7 (noarch) * gstreamer-plugins-good-lang-1.24.0-150600.3.10.1 * openSUSE Leap 15.6 (aarch64_ilp32) * gstreamer-plugins-good-jack-64bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-64bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-64bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-64bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-64bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-64bit-debuginfo-1.24.0-150600.3.10.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * gstreamer-plugins-good-gtk-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-gtk-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-1.24.0-150600.3.10.1 * gstreamer-plugins-good-qtqml-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-1.24.0-150600.3.10.1 * gstreamer-plugins-good-qtqml-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-1.24.0-150600.3.10.1 * openSUSE Leap 15.6 (x86_64) * gstreamer-plugins-good-32bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-32bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-32bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-32bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-32bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-32bit-1.24.0-150600.3.10.1 * openSUSE Leap 15.6 (noarch) * gstreamer-plugins-good-lang-1.24.0-150600.3.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gstreamer-plugins-good-lang-1.24.0-150600.3.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-gtk-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-gtk-1.24.0-150600.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53705.html * https://bugzilla.suse.com/show_bug.cgi?id=1268449 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:31:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:31:13 -0000 Subject: SUSE-SU-2026:2842-1: important: Security update for gstreamer-plugins-good Message-ID: <178370107369.1235.18066899527158902977@aaee731399ed> # Security update for gstreamer-plugins-good Announcement ID: SUSE-SU-2026:2842-1 Release Date: 2026-07-10T10:25:06Z Rating: important References: * bsc#1268449 Cross-References: * CVE-2026-53705 CVSS scores: * CVE-2026-53705 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-good fixes the following issue * CVE-2026-53705: Heap buffer overflow in WavPack decoder via integer overflow (bsc#1268449). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2842=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2842=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2842=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2842=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2842=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * gstreamer-plugins-good-qtqml-1.22.0-150500.4.13.1 * gstreamer-plugins-good-gtk-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-qtqml-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-gtk-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * openSUSE Leap 15.5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 * openSUSE Leap 15.5 (x86_64) * gstreamer-plugins-good-32bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-32bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-32bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-32bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-32bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-32bit-1.22.0-150500.4.13.1 * openSUSE Leap 15.5 (aarch64_ilp32) * gstreamer-plugins-good-jack-64bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-64bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-64bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-64bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-64bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-64bit-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53705.html * https://bugzilla.suse.com/show_bug.cgi?id=1268449 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:31:59 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:31:59 -0000 Subject: SUSE-SU-2026:2841-1: important: Security update for the Linux Kernel Message-ID: <178370111971.1235.11858064354655511873@aaee731399ed> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2841-1 Release Date: 2026-07-10T09:25:02Z Rating: important References: * bsc#1264097 * bsc#1264145 * bsc#1265421 * bsc#1267531 * bsc#1267567 * bsc#1267635 * bsc#1267684 * bsc#1267722 * bsc#1267918 * bsc#1267993 * bsc#1268022 * bsc#1268660 * bsc#1269022 * bsc#1269033 * bsc#1269036 * bsc#1269090 * bsc#1269100 * bsc#1269159 * bsc#1269184 * bsc#1269193 * bsc#1269195 * bsc#1269310 * bsc#1269398 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269821 * bsc#1270059 Cross-References: * CVE-2026-31771 * CVE-2026-43038 * CVE-2026-46090 * CVE-2026-46173 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46331 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52943 * CVE-2026-52955 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-52993 * CVE-2026-53016 * CVE-2026-53041 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53133 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves 28 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-31771: Bluetooth: Ignore HCI_ERROR_CANCELLED_BY_HOST on adv set terminated event (bsc#1264145). * CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2841=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2841=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2841=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2841=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.176.1 * kernel-rt-debugsource-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.176.1 * kernel-rt-debugsource-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.176.1 * kernel-rt-debugsource-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.176.1 * kernel-rt-debugsource-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.176.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1264097 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:33:21 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 16:33:21 -0000 Subject: SUSE-SU-2026:2839-1: important: Security update for the Linux Kernel Message-ID: <178370120112.1235.415793721564160119@aaee731399ed> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2839-1 Release Date: 2026-07-10T09:09:31Z Rating: important References: * bsc#1255416 * bsc#1264610 * bsc#1265421 * bsc#1266214 * bsc#1266969 * bsc#1267205 * bsc#1267531 * bsc#1267684 * bsc#1269100 * bsc#1269574 * bsc#1270059 Cross-References: * CVE-2025-68324 * CVE-2026-43198 * CVE-2026-45970 * CVE-2026-46090 * CVE-2026-46113 * CVE-2026-46266 * CVE-2026-46331 * CVE-2026-52918 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2025-68324 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 11 SP4 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE An update that solves 10 vulnerabilities and has one security fix can now be installed. ## Description: The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-2839=1 * SUSE Linux Enterprise Server 11 SP4 zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-2839=1 ## Package List: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (nosrc x86_64) * kernel-trace-3.0.101-108.213.1 * kernel-ec2-3.0.101-108.213.1 * kernel-xen-3.0.101-108.213.1 * kernel-default-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (x86_64) * kernel-trace-devel-debuginfo-3.0.101-108.213.1 * kernel-ec2-devel-debuginfo-3.0.101-108.213.1 * kernel-default-devel-debuginfo-3.0.101-108.213.1 * kernel-xen-debugsource-3.0.101-108.213.1 * kernel-xen-devel-3.0.101-108.213.1 * kernel-default-debugsource-3.0.101-108.213.1 * kernel-ec2-devel-3.0.101-108.213.1 * kernel-default-debuginfo-3.0.101-108.213.1 * kernel-trace-debuginfo-3.0.101-108.213.1 * kernel-source-3.0.101-108.213.1 * kernel-trace-base-3.0.101-108.213.1 * kernel-ec2-debugsource-3.0.101-108.213.1 * kernel-trace-debugsource-3.0.101-108.213.1 * kernel-xen-base-3.0.101-108.213.1 * kernel-ec2-base-3.0.101-108.213.1 * kernel-ec2-debuginfo-3.0.101-108.213.1 * kernel-default-base-3.0.101-108.213.1 * kernel-default-devel-3.0.101-108.213.1 * kernel-syms-3.0.101-108.213.1 * kernel-trace-devel-3.0.101-108.213.1 * kernel-xen-devel-debuginfo-3.0.101-108.213.1 * kernel-xen-debuginfo-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (noarch nosrc) * kernel-docs-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 (nosrc x86_64) * kernel-trace-3.0.101-108.213.1 * kernel-ec2-3.0.101-108.213.1 * kernel-xen-3.0.101-108.213.1 * kernel-default-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 (x86_64) * kernel-trace-devel-debuginfo-3.0.101-108.213.1 * kernel-ec2-devel-debuginfo-3.0.101-108.213.1 * kernel-default-devel-debuginfo-3.0.101-108.213.1 * kernel-xen-debugsource-3.0.101-108.213.1 * kernel-xen-devel-3.0.101-108.213.1 * kernel-default-debugsource-3.0.101-108.213.1 * kernel-ec2-devel-3.0.101-108.213.1 * kernel-default-debuginfo-3.0.101-108.213.1 * kernel-trace-debuginfo-3.0.101-108.213.1 * kernel-source-3.0.101-108.213.1 * kernel-trace-base-3.0.101-108.213.1 * kernel-ec2-debugsource-3.0.101-108.213.1 * kernel-trace-debugsource-3.0.101-108.213.1 * kernel-xen-base-3.0.101-108.213.1 * kernel-ec2-base-3.0.101-108.213.1 * kernel-ec2-debuginfo-3.0.101-108.213.1 * kernel-default-base-3.0.101-108.213.1 * kernel-default-devel-3.0.101-108.213.1 * kernel-syms-3.0.101-108.213.1 * kernel-trace-devel-3.0.101-108.213.1 * kernel-xen-devel-debuginfo-3.0.101-108.213.1 * kernel-xen-debuginfo-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 (noarch nosrc) * kernel-docs-3.0.101-108.213.1 ## References: * https://www.suse.com/security/cve/CVE-2025-68324.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1255416 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266969 * https://bugzilla.suse.com/show_bug.cgi?id=1267205 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 20:30:08 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 20:30:08 -0000 Subject: SUSE-SU-2026:2851-1: important: Security update for dracut Message-ID: <178371540893.1251.9603374778973614933@530c474df1e7> # Security update for dracut Announcement ID: SUSE-SU-2026:2851-1 Release Date: 2026-07-10T13:19:22Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.570.g2b84048d7: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2851=1 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-2851=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dracut-ima-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-debuginfo-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-fips-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-debugsource-059+suse.570.g2b84048d7-150700.3.17.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (ppc64le x86_64) * dracut-mkinitrd-deprecated-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-debugsource-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-debuginfo-059+suse.570.g2b84048d7-150700.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 20:30:18 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 20:30:18 -0000 Subject: SUSE-SU-2026:2850-1: important: Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Message-ID: <178371541882.1251.11947657811411501918@530c474df1e7> # Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Announcement ID: SUSE-SU-2026:2850-1 Release Date: 2026-07-10T12:48:09Z Rating: important References: * bsc#1265678 * bsc#1265700 Cross-References: * CVE-2026-33814 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for terraform-provider-aws, terraform-provider-azurerm, terraform- provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-random, terraform-provider- susepubliccloud, terraform-provider-tls fixes the following issue * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265678, bsc#1265700). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-2850=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2850=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-kubernetes-1.13.2-150200.6.9.1 * terraform-provider-susepubliccloud-0.0.1-150100.3.11.1 * terraform-provider-random-3.0.0-150200.6.12.1 * terraform-provider-tls-3.0.0-150200.5.12.1 * terraform-provider-aws-3.11.0-150200.6.15.2 * terraform-provider-google-3.43.0-150200.6.9.2 * terraform-provider-helm-2.9.0-150200.6.20.2 * terraform-provider-azurerm-2.32.0-150200.6.9.2 * terraform-provider-external-2.0.0-150200.6.9.2 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-kubernetes-1.13.2-150200.6.9.1 * terraform-provider-susepubliccloud-0.0.1-150100.3.11.1 * terraform-provider-random-3.0.0-150200.6.12.1 * terraform-provider-tls-3.0.0-150200.5.12.1 * terraform-provider-aws-3.11.0-150200.6.15.2 * terraform-provider-google-3.43.0-150200.6.9.2 * terraform-provider-helm-2.9.0-150200.6.20.2 * terraform-provider-azurerm-2.32.0-150200.6.9.2 * terraform-provider-external-2.0.0-150200.6.9.2 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://bugzilla.suse.com/show_bug.cgi?id=1265678 * https://bugzilla.suse.com/show_bug.cgi?id=1265700 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 20:31:04 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 10 Jul 2026 20:31:04 -0000 Subject: SUSE-SU-2026:2840-1: important: Security update for the Linux Kernel Message-ID: <178371546425.1251.15732059335919629249@530c474df1e7> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2840-1 Release Date: 2026-07-10T09:24:47Z Rating: important References: * bsc#1264097 * bsc#1264145 * bsc#1265421 * bsc#1267381 * bsc#1267531 * bsc#1267567 * bsc#1267635 * bsc#1267684 * bsc#1267722 * bsc#1267918 * bsc#1267993 * bsc#1268022 * bsc#1268049 * bsc#1268660 * bsc#1269022 * bsc#1269033 * bsc#1269036 * bsc#1269090 * bsc#1269100 * bsc#1269159 * bsc#1269184 * bsc#1269193 * bsc#1269195 * bsc#1269310 * bsc#1269398 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269821 * bsc#1270059 Cross-References: * CVE-2026-31771 * CVE-2026-43038 * CVE-2026-46090 * CVE-2026-46173 * CVE-2026-46197 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46330 * CVE-2026-46331 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52943 * CVE-2026-52955 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-52993 * CVE-2026-53016 * CVE-2026-53041 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53133 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46330 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46330 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46330 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves 30 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46330: Revert "net/smc: Introduce TCP ULP support" (bsc#1268049). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2840=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2840=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * kernel-rt-livepatch-5.14.21-150500.13.151.1 * kernel-rt-optional-5.14.21-150500.13.151.1 * kernel-rt_debug-devel-5.14.21-150500.13.151.1 * kernel-rt-optional-debuginfo-5.14.21-150500.13.151.1 * dlm-kmp-rt-5.14.21-150500.13.151.1 * kselftests-kmp-rt-5.14.21-150500.13.151.1 * kernel-rt_debug-vdso-debuginfo-5.14.21-150500.13.151.1 * kernel-rt_debug-debugsource-5.14.21-150500.13.151.1 * kselftests-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-devel-debuginfo-5.14.21-150500.13.151.1 * reiserfs-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-vdso-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-vdso-5.14.21-150500.13.151.1 * cluster-md-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-devel-5.14.21-150500.13.151.1 * ocfs2-kmp-rt-5.14.21-150500.13.151.1 * kernel-rt_debug-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-debugsource-5.14.21-150500.13.151.1 * kernel-rt_debug-devel-debuginfo-5.14.21-150500.13.151.1 * gfs2-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt_debug-vdso-5.14.21-150500.13.151.1 * cluster-md-kmp-rt-5.14.21-150500.13.151.1 * dlm-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * ocfs2-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-extra-debuginfo-5.14.21-150500.13.151.1 * kernel-syms-rt-5.14.21-150500.13.151.1 * kernel-rt-extra-5.14.21-150500.13.151.1 * kernel-rt-debuginfo-5.14.21-150500.13.151.1 * gfs2-kmp-rt-5.14.21-150500.13.151.1 * kernel-rt-livepatch-devel-5.14.21-150500.13.151.1 * reiserfs-kmp-rt-5.14.21-150500.13.151.1 * openSUSE Leap 15.5 (nosrc x86_64) * kernel-rt-5.14.21-150500.13.151.1 * kernel-rt_debug-5.14.21-150500.13.151.1 * openSUSE Leap 15.5 (noarch) * kernel-devel-rt-5.14.21-150500.13.151.1 * kernel-source-rt-5.14.21-150500.13.151.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * kernel-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-debugsource-5.14.21-150500.13.151.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * kernel-devel-rt-5.14.21-150500.13.151.1 * kernel-source-rt-5.14.21-150500.13.151.1 * SUSE Linux Enterprise Micro 5.5 (nosrc x86_64) * kernel-rt-5.14.21-150500.13.151.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46330.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1264097 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268049 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:30:46 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 08:30:46 -0000 Subject: SUSE-SU-2026:2864-1: important: Security update for the Linux Kernel (Live Patch 45 for SUSE Linux Enterprise 15 SP4) Message-ID: <178393144698.1654.18365031173539907254@aaee731399ed> # Security update for the Linux Kernel (Live Patch 45 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2864-1 Release Date: 2026-07-11T21:22:55Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.179 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2864=1 SUSE-2026-2865=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2865=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2864=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-14-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-14-150400.2.1 * kernel-livepatch-5_14_21-150400_24_170-default-20-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_42-debugsource-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-14-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-14-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-14-150400.2.1 * kernel-livepatch-5_14_21-150400_24_170-default-20-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_42-debugsource-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-14-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:31:01 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 08:31:01 -0000 Subject: SUSE-SU-2026:2863-1: important: Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393146177.1654.4272876690007885979@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2863-1 Release Date: 2026-07-11T06:44:07Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.59 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2863=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-SLE15-SP7-RT_Update_16-debugsource-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_59-rt-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_59-rt-debuginfo-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:31:19 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 08:31:19 -0000 Subject: SUSE-SU-2026:2862-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393147931.1654.12629966573981824733@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2862-1 Release Date: 2026-07-11T06:44:04Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.54 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2862=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-SLE15-SP7-RT_Update_15-debugsource-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_54-rt-debuginfo-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_54-rt-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:32:01 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 08:32:01 -0000 Subject: SUSE-SU-2026:2857-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393152149.1654.14679734765506018930@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2857-1 Release Date: 2026-07-11T04:04:28Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.28 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2857=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_28-rt-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_28-rt-debuginfo-9-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_8-debugsource-9-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:32:42 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 08:32:42 -0000 Subject: SUSE-SU-2026:2858-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393156214.1654.2989066508133427027@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2858-1 Release Date: 2026-07-11T04:04:32Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.34 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2858=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2856=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_34-rt-debuginfo-6-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_9-debugsource-8-150700.2.1 * kernel-livepatch-6_4_0-150700_7_31-rt-8-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_10-debugsource-6-150700.2.1 * kernel-livepatch-6_4_0-150700_7_31-rt-debuginfo-8-150700.2.1 * kernel-livepatch-6_4_0-150700_7_34-rt-6-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:33:18 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 08:33:18 -0000 Subject: SUSE-SU-2026:2855-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393159817.1654.3040688620731680381@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2855-1 Release Date: 2026-07-11T04:33:51Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.51 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2855=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2861=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2859=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2860=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_40-rt-5-150700.2.1 * kernel-livepatch-6_4_0-150700_7_40-rt-debuginfo-5-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_12-debugsource-5-150700.2.1 * kernel-livepatch-6_4_0-150700_7_51-rt-debuginfo-3-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_13-debugsource-4-150700.2.1 * kernel-livepatch-6_4_0-150700_7_51-rt-3-150700.2.1 * kernel-livepatch-6_4_0-150700_7_44-rt-debuginfo-4-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_11-debugsource-6-150700.2.1 * kernel-livepatch-6_4_0-150700_7_44-rt-4-150700.2.1 * kernel-livepatch-6_4_0-150700_7_37-rt-6-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_14-debugsource-3-150700.2.1 * kernel-livepatch-6_4_0-150700_7_37-rt-debuginfo-6-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:33:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 08:33:25 -0000 Subject: SUSE-SU-2026:2854-1: moderate: Security update for python-urllib3 Message-ID: <178393160533.1654.4975002679727082431@aaee731399ed> # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:2854-1 Release Date: 2026-07-10T17:58:58Z Rating: moderate References: * bsc#1254867 * bsc#1270365 Cross-References: * CVE-2025-66471 CVSS scores: * CVE-2025-66471 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66471 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66471 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66471 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python-urllib3 fixes the following issue * Regression introduced by CVE-2025-66471 fix during file download with pySSL (bsc#1270365). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2854=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2854=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2854=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2854=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2854=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2854=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2854=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * openSUSE Leap 15.3 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-66471.html * https://bugzilla.suse.com/show_bug.cgi?id=1254867 * https://bugzilla.suse.com/show_bug.cgi?id=1270365 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:33:33 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 08:33:33 -0000 Subject: SUSE-SU-2026:2853-1: important: Security update for tiff Message-ID: <178393161306.1654.11430820353938664236@aaee731399ed> # Security update for tiff Announcement ID: SUSE-SU-2026:2853-1 Release Date: 2026-07-10T17:54:45Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 * CVE-2026-4775 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-4775 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4775 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues: Update to version 4.7.2. Security issues fixed: * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Other updates and bugfixes: * Version 4.7.2: * Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. * Library changes: * New/improved functionalities:: * Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781) * Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824) * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. * Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2853=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2853=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2853=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2853=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2853=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libtiff6-4.7.2-150600.3.29.1 * libtiff6-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libtiff6-32bit-4.7.2-150600.3.29.1 * libtiff6-32bit-debuginfo-4.7.2-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libtiff6-4.7.2-150600.3.29.1 * libtiff6-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libtiff6-32bit-4.7.2-150600.3.29.1 * libtiff6-32bit-debuginfo-4.7.2-150600.3.29.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libtiff6-4.7.2-150600.3.29.1 * libtiff6-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * Basesystem Module 15-SP7 (x86_64) * libtiff6-32bit-4.7.2-150600.3.29.1 * libtiff6-32bit-debuginfo-4.7.2-150600.3.29.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * tiff-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libtiff6-4.7.2-150600.3.29.1 * libtiff6-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-4.7.2-150600.3.29.1 * tiff-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * openSUSE Leap 15.6 (x86_64) * libtiff6-32bit-4.7.2-150600.3.29.1 * libtiff-devel-32bit-4.7.2-150600.3.29.1 * libtiff6-32bit-debuginfo-4.7.2-150600.3.29.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libtiff6-64bit-4.7.2-150600.3.29.1 * libtiff6-64bit-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-64bit-4.7.2-150600.3.29.1 * openSUSE Leap 15.6 (noarch) * tiff-docs-4.7.2-150600.3.29.1 * libtiff-devel-docs-4.7.2-150600.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://www.suse.com/security/cve/CVE-2026-4775.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:33:39 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 08:33:39 -0000 Subject: SUSE-SU-2026:2852-1: important: Security update for MozillaThunderbird Message-ID: <178393161933.1654.5322089204668630118@aaee731399ed> # Security update for MozillaThunderbird Announcement ID: SUSE-SU-2026:2852-1 Release Date: 2026-07-10T17:49:29Z Rating: important References: * bsc#1268071 Cross-References: * CVE-2026-12289 * CVE-2026-12290 * CVE-2026-12291 * CVE-2026-12292 * CVE-2026-12294 * CVE-2026-12295 * CVE-2026-12296 * CVE-2026-12297 * CVE-2026-12298 * CVE-2026-12299 * CVE-2026-12302 * CVE-2026-12304 * CVE-2026-12305 * CVE-2026-12306 * CVE-2026-12307 * CVE-2026-12308 * CVE-2026-12309 * CVE-2026-12310 * CVE-2026-12311 * CVE-2026-12312 * CVE-2026-12313 * CVE-2026-12314 * CVE-2026-12315 * CVE-2026-12324 * CVE-2026-12325 * CVE-2026-12327 * CVE-2026-12328 * CVE-2026-12329 * CVE-2026-12330 CVSS scores: * CVE-2026-12289 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12289 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-12292 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12294 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12298 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12302 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12302 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12304 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12304 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12305 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12305 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12306 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12306 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12309 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12309 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12310 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12310 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12311 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12311 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12312 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12313 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12313 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12314 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12314 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12315 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12315 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12324 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12324 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12325 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12325 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12327 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12327 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12329 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12330 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12330 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 29 vulnerabilities can now be installed. ## Description: This update for MozillaThunderbird fixes the following issues Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): * CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. * CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12291: Use-after-free in the Networking: HTTP component. * CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. * CVE-2026-12294: Sandbox escape in the DOM: Workers component. * CVE-2026-12295: Sandbox escape in the DOM: Navigation component. * CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. * CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. * CVE-2026-12302: Mitigation bypass in the DOM: Security component. * CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. * CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12315: Mitigation bypass in the DOM: Security component. * CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. * CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2852=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2852=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * MozillaThunderbird-translations-common-140.12.0-150200.8.277.1 * MozillaThunderbird-140.12.0-150200.8.277.1 * MozillaThunderbird-translations-other-140.12.0-150200.8.277.1 * MozillaThunderbird-debuginfo-140.12.0-150200.8.277.1 * MozillaThunderbird-debugsource-140.12.0-150200.8.277.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * MozillaThunderbird-translations-common-140.12.0-150200.8.277.1 * MozillaThunderbird-140.12.0-150200.8.277.1 * MozillaThunderbird-translations-other-140.12.0-150200.8.277.1 * MozillaThunderbird-debuginfo-140.12.0-150200.8.277.1 * MozillaThunderbird-debugsource-140.12.0-150200.8.277.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12289.html * https://www.suse.com/security/cve/CVE-2026-12290.html * https://www.suse.com/security/cve/CVE-2026-12291.html * https://www.suse.com/security/cve/CVE-2026-12292.html * https://www.suse.com/security/cve/CVE-2026-12294.html * https://www.suse.com/security/cve/CVE-2026-12295.html * https://www.suse.com/security/cve/CVE-2026-12296.html * https://www.suse.com/security/cve/CVE-2026-12297.html * https://www.suse.com/security/cve/CVE-2026-12298.html * https://www.suse.com/security/cve/CVE-2026-12299.html * https://www.suse.com/security/cve/CVE-2026-12302.html * https://www.suse.com/security/cve/CVE-2026-12304.html * https://www.suse.com/security/cve/CVE-2026-12305.html * https://www.suse.com/security/cve/CVE-2026-12306.html * https://www.suse.com/security/cve/CVE-2026-12307.html * https://www.suse.com/security/cve/CVE-2026-12308.html * https://www.suse.com/security/cve/CVE-2026-12309.html * https://www.suse.com/security/cve/CVE-2026-12310.html * https://www.suse.com/security/cve/CVE-2026-12311.html * https://www.suse.com/security/cve/CVE-2026-12312.html * https://www.suse.com/security/cve/CVE-2026-12313.html * https://www.suse.com/security/cve/CVE-2026-12314.html * https://www.suse.com/security/cve/CVE-2026-12315.html * https://www.suse.com/security/cve/CVE-2026-12324.html * https://www.suse.com/security/cve/CVE-2026-12325.html * https://www.suse.com/security/cve/CVE-2026-12327.html * https://www.suse.com/security/cve/CVE-2026-12328.html * https://www.suse.com/security/cve/CVE-2026-12329.html * https://www.suse.com/security/cve/CVE-2026-12330.html * https://bugzilla.suse.com/show_bug.cgi?id=1268071 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 12:30:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 12:30:49 -0000 Subject: SUSE-SU-2026:2868-1: important: Security update for the Linux Kernel (Live Patch 32 for SUSE Linux Enterprise 15 SP5) Message-ID: <178394584952.1684.6968743877672070903@57e59d802799> # Security update for the Linux Kernel (Live Patch 32 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2868-1 Release Date: 2026-07-13T08:09:15Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.127 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2869=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-2870=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-2868=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2870=1 SUSE-2026-2868=1 SUSE-2026-2869=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_32-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_116-default-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-15-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-15-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_29-debugsource-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_127-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-15-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_32-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_116-default-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-15-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-15-150500.2.2 * kernel-livepatch-5_14_21-150500_55_127-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-15-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x) * kernel-livepatch-SLE15-SP5_Update_29-debugsource-18-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 12:31:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 12:31:25 -0000 Subject: SUSE-SU-2026:2867-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4) Message-ID: <178394588572.1684.12385478335578185854@57e59d802799> # Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2867-1 Release Date: 2026-07-13T08:05:06Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.167 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2867=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2867=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_167-default-21-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_41-debugsource-21-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-21-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_167-default-21-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_41-debugsource-21-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-21-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 12:32:04 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 12:32:04 -0000 Subject: SUSE-SU-2026:2866-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise 15 SP6) Message-ID: <178394592433.1684.15351211224729398457@57e59d802799> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2866-1 Release Date: 2026-07-12T23:25:50Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.95 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2866=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2866=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_22-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_95-default-6-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_22-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_95-default-6-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:30:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:30:11 -0000 Subject: SUSE-RU-2026:22556-1: important: Recommended update for s390-tools Message-ID: <178396021102.1820.6462796853027469804@530c474df1e7> # Recommended update for s390-tools Announcement ID: SUSE-RU-2026:22556-1 Release Date: 2026-07-07T16:32:20Z Rating: important References: * bsc#1266436 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for s390-tools fixes the following issues: * Upgrade to version 2.43.0: * For Linux kernel version: 7.1 * Set Rust MSRV to 1.85.0 * Changes of existing tools: * dbginfo.sh: Add IBM appliance specific files * lshwc: Show explicitly selected unnamed counters with --hide * pvattest: Add firmware check version 2 * zipl: Introduce verbosity levels of zipl session (--debug) * zkey: Remove the use of AF_ALG for calculating key verification patterns * Bug Fixes: * ebc: implement --version option for pvics * pvebc: Log services to journal+console * pvics: Fix virt-resize permission error * Ammended the .spec file for `chreipl_helper` (bsc#1266436): * Moved `chreipl_helper*` to the main package * Added `Requires: %{name} = %{version}` in `chreipl-fcp-mpath subpackage` * Re-vendor-ed vendor.tar.zst ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1171=1 ## Package List: * SUSE Linux Micro 6.2 (s390x) * s390-tools-debugsource-2.43.0-160000.1.1 * s390-tools-debuginfo-2.43.0-160000.1.1 * libkmipclient1-debuginfo-2.43.0-160000.1.1 * s390-tools-2.43.0-160000.1.1 * libekmfweb1-debuginfo-2.43.0-160000.1.1 * libkmipclient1-2.43.0-160000.1.1 * libekmfweb1-2.43.0-160000.1.1 * SUSE Linux Micro 6.2 (noarch) * s390-tools-genprotimg-data-2.43.0-160000.1.1 * s390-tools-chreipl-fcp-mpath-2.43.0-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1266436 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:30:19 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:30:19 -0000 Subject: SUSE-RU-2026:22555-1: moderate: Recommended update for systemd Message-ID: <178396021944.1820.15431020549200273064@530c474df1e7> # Recommended update for systemd Announcement ID: SUSE-RU-2026:22555-1 Release Date: 2026-07-09T12:40:27Z Rating: moderate References: * bsc#1270439 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for systemd fixes the following issues: Changes in systemd: * do not make mounting of debugfs optional yet. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1191=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * udev-debuginfo-257.13-160000.3.1 * systemd-portable-257.13-160000.3.1 * systemd-experimental-debuginfo-257.13-160000.3.1 * systemd-debuginfo-257.13-160000.3.1 * systemd-journal-remote-257.13-160000.3.1 * systemd-container-257.13-160000.3.1 * systemd-journal-remote-debuginfo-257.13-160000.3.1 * systemd-container-debuginfo-257.13-160000.3.1 * systemd-experimental-257.13-160000.3.1 * udev-257.13-160000.3.1 * libsystemd0-257.13-160000.3.1 * libudev1-debuginfo-257.13-160000.3.1 * systemd-257.13-160000.3.1 * systemd-debugsource-257.13-160000.3.1 * systemd-portable-debuginfo-257.13-160000.3.1 * libudev1-257.13-160000.3.1 * libsystemd0-debuginfo-257.13-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270439 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:30:38 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:30:38 -0000 Subject: SUSE-SU-2026:22554-1: important: Security update for rust-keylime Message-ID: <178396023869.1820.10814979871001238848@530c474df1e7> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:22554-1 Release Date: 2026-07-09T09:04:26Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for rust-keylime fixes the following issues: Update to version 0.2.9+49. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270614). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270699). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270842). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270999). Other updates and bugfixes: * Update openssl to 0.10.81. * Make tss-esai-sys depend on bindgen 72.1 to support llvm > 21. * Build with Clang <= 21 (bsc#1260596). * Version 0.2.9+49: * build(deps): bump uuid from 1.23.3 to 1.23.4 * build(deps): bump syn from 2.0.117 to 2.0.118 * build(deps): bump openssl from 0.10.80 to 0.10.81 * build(deps): bump rand from 0.9.4 to 0.10.1 * Added new regression test into packit-ci.yaml * build(deps): bump actions/checkout from 6 to 7 * build(deps): bump uuid from 1.23.1 to 1.23.3 * build(deps): bump log from 0.4.29 to 0.4.32 * build(deps): bump http from 1.4.0 to 1.4.2 * build(deps): bump codecov/codecov-action from 6 to 7 * build(deps): bump retry-policies from 0.5.1 to 0.5.2 * fix: Remove unused base64::Engine import in context_info tests * build(deps): bump reqwest-middleware from 0.5.1 to 0.5.2 * build(deps): bump serde_json from 1.0.149 to 1.0.150 * build(deps): bump openssl from 0.10.79 to 0.10.80 * agent: Hash agent ID before TPM2_Certify qualifying data * cargo: Bump tss-esapi, picky-asn1-x509, and picky-asn1-der * build(deps): bump openssl from 0.10.78 to 0.10.79 * build(deps): bump once_cell from 1.21.3 to 1.21.4 * build(deps): bump tempfile from 3.23.0 to 3.27.0 * push-model: cache UEFI event log bytes at startup * build(deps): bump quote from 1.0.40 to 1.0.45 * build(deps): bump chrono from 0.4.42 to 0.4.44 * build(deps): bump openssl from 0.10.73 to 0.10.78 * build(deps): bump serde_json from 1.0.143 to 1.0.149 * build(deps): bump syn from 2.0.106 to 2.0.117 * build(deps): bump libc from 0.2.175 to 0.2.184 * build(deps): bump rand from 0.9.2 to 0.9.4 * Version 0.2.9+21: * tests: use Express-style named params in Mockoon endpoints * build(deps): bump pest_derive from 2.8.1 to 2.8.6 * build(deps): bump trybuild from 1.0.110 to 1.0.115 * build(deps): bump log from 0.4.28 to 0.4.29 * build(deps): bump uuid from 1.19.0 to 1.20.0 * build(deps): bump codecov/codecov-action from 5 to 6 * build(deps): bump tracing-subscriber from 0.3.20 to 0.3.23 * build(deps): bump cfg-if from 1.0.3 to 1.0.4 * build(deps): bump tokio from 1.49.0 to 1.50.0 * build(deps): bump actix-web from 4.12.1 to 4.13.0 * build(deps): bump anyhow from 1.0.99 to 1.0.102 * build(deps): bump clap from 4.5.57 to 4.5.60 * build(deps): bump tracing from 0.1.36 to 0.1.44 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1190=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * rust-keylime-0.2.9+49-160000.1.1 * rust-keylime-debugsource-0.2.9+49-160000.1.1 * rust-keylime-debuginfo-0.2.9+49-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:30:55 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:30:55 -0000 Subject: SUSE-SU-2026:22553-1: important: Security update for curl Message-ID: <178396025596.1820.1146950941257807667@530c474df1e7> # Security update for curl Announcement ID: SUSE-SU-2026:22553-1 Release Date: 2026-07-08T13:45:27Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1187=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-160000.8.1 * curl-debuginfo-8.14.1-160000.8.1 * curl-debugsource-8.14.1-160000.8.1 * curl-8.14.1-160000.8.1 * libcurl4-debuginfo-8.14.1-160000.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:31:00 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:31:00 -0000 Subject: SUSE-RU-2026:22552-1: moderate: Recommended update for strace Message-ID: <178396026063.1820.18365006798764338876@530c474df1e7> # Recommended update for strace Announcement ID: SUSE-RU-2026:22552-1 Release Date: 2026-07-08T12:27:38Z Rating: moderate References: * jsc#PED-15928 Affected Products: * SUSE Linux Micro 6.2 An update that contains one feature can now be installed. ## Description: This update for strace fixes the following issues: * Update to strace 7.1: * Implemented wall-clock-aware columns for the -c/--summary-only report, allowing wall-clock and system CPU times to be displayed side by side in a single run. * Included out-of-range syscalls in the -c/--summary-only report. * Updated decoding of sched_getattr syscall. * Implemented decoding of FS_IOC_SHUTDOWN, PIDFD_GET_INFO and PIDFD_GET_*_NAMESPACE ioctl commands. * Implemented decoding of IFLA_BR_FDB_N_LEARNED, IFLA_BR_FDB_MAX_LEARNED and IFLA_BR_STP_MODE netlink attributes. * Updated lists of CLONE__, FSMOUNT__ , KT__, KVM__ , LANDLOCK__, NETDEV__ , NL80211__and PIDFD__ constants. * Updated lists of ioctl commands from Linux 7.1. * Implement EPERM diagnostics and give a hint about yama (jsc#PED-15928). * Update to strace 7.0: * Implemented optional colorized trace output. * Implemented decoding of rseq and rseq_slice_yield syscalls. * Implemented decoding of BPF_TRACE_FSESSION bpf attach type. * Implemented decoding of BPF_PROG_ASSOC_STRUCT_OPS bpf command. * Implemented decoding of UDMABUF_CREATE, UDMABUF_CREATE_LIST, and VIDIOC_QUERYMENU ioctl commands. * Updated decoding of statmount syscall flags. * Updated lists of BPF__, BTRFS__ , FS__, IORING__ , KEY__, KVM__ , NT__, OPEN_TREE__ , PR__, V4L2__ and *_MAGIC constants. * Updated lists of ioctl commands from Linux 7.0. * Update to strace 6.19: * Implemented decoding of listns syscall. * Implemented decoding of F_GET_RW_HINT, F_SET_RW_HINT, F_GET_FILE_RW_HINT, F_SET_FILE_RW_HINT, F_GETDELEG and F_SETDELEG fcntl commands. * Implemented decoding of IORING_REGISTER_SEND_MSG_RING, IORING_REGISTER_ZCRX_IFQ, IORING_REGISTER_RESIZE_RINGS, IORING_REGISTER_MEM_REGION, IORING_REGISTER_QUERY and IORING_REGISTER_ZCRX_CTRL opcodes of io_uring_register syscall. * Implemented decoding of extended argument structures for io_uring_enter syscall when IORING_ENTER_EXT_ARG or IORING_ENTER_EXT_ARG_REG flags are set. * Implemented decoding of attr_ptr and attr_type_mask fields of struct io_uring_sqe for io_uring_register syscall. * Implemented opcode-specific decoding of flags union and ioprio fields of struct io_uring_sqe for io_uring_register syscall. * Implemented decoding of 128-byte SQEs for io_uring_register syscall. * Implemented decoding of socket operations (SOCKET_URING_OP_*) for io_uring URING_CMD and URING_CMD128 operations when the file descriptor is a socket. * Updated decoding of struct mnt_id_req and struct perf_event_attr. * Updated lists of ABS__, BPF__ , ETHTOOL__, ETH_P__ , IORING__, KVM__ , PERF__, TLS__ , V4L2__and_ _MAGIC constants. * Updated lists of ioctl commands from Linux 6.19. * Update to strace 6.18: * Added -e kvm=vcpu+ option for kvm_run struct decoding. * Implemented decoding of FS_IOC_GETFSUUID, FS_IOC_GETFSSYSFSPATH and FS_IOC_GETLBMD_CAP ioctl commands. * Implemented decoding of BPF_PROG_STREAM_READ_BY_FD bpf command. * Updated decoding of BPF_BTF_LOAD, BPF_MAP_CREATE, BPF_PROG_ATTACH, BPF_PROG_DETACH, BPF_PROG_LOAD, BPF_PROG_QUERY and BPF___GET__ _ID bpf commands. * Updated decoding of bpf_map_info and bpf_prog_info structures. * Updated lists of AUDIT__, BR__ , FF__, IFLA__ , INPUT_PROP__, IORING__ , KEXEC_FILE__, KEY__ , KVM_CAP__, NL80211_CMD__ , RWF__and TEE__ constants. * Update to strace 6.17: * Implemented decoding of file_getattr and file_setattr syscalls. * Implemented decoding of SO_INQ socket option. * Updated lists of BPF__, BTN__ , BTRFS__, DEVCONF__ , ETHTOOL__, FALLOC__ , KEXEC__, KEY__ , KVM__, NETCONFA__ , NFT__, PR__ , SCM__, V4L2__ and XDP_* constants. * Updated lists of ioctl commands from Linux 6.17. * Update to strace 6.16: * Added -N/--arg-names option for printing syscall argument names. * Implemented setting of system call information using PTRACE_SET_SYSCALL_INFO ptrace API introduced in Linux 6.16. * Implemented decoding of SO_RCVPRIORITY and SO_PASSRIGHTS socket options. * Implemented decoding of RTA_NH_ID and RTA_FLOWLABEL netlink attributes. * Updated decoding of statx syscall. * Updated lists of BR__, CRYPTOCFGA__ , FUTEX2__, IORING__ , IPSET__, KVM__ , MDB__, NETDEV__ , PR__, RXRPC__ , SW__, THERMAL__ and V4L2_* constants. * Updated lists of ioctl commands from Linux 6.16. * Update to strace 6.15: * Implemented decoding of open_tree_attr syscall. * Implemented decoding of AF_TIPC socket addresses and socket options. * Updated decoding of statmount syscall. * Updated lists of AUDIT__, BPF__ , BTRFS__, COUNTER__ , FAN__, FRA__ , IFLA__, IORING__ , KVM__, LANDLOCK__ , PKEY__, RTPROT__ , TCP__and V4L2__ constants. * Updated lists of ioctl commands from Linux 6.15. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1185=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * strace-7.1-160000.1.1 * strace-debuginfo-7.1-160000.1.1 * strace-debugsource-7.1-160000.1.1 ## References: * https://jira.suse.com/browse/PED-15928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:31:07 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:31:07 -0000 Subject: SUSE-RU-2026:22551-1: important: Recommended update for python-kiwi, open-vmdk Message-ID: <178396026752.1820.6169354960536811149@530c474df1e7> # Recommended update for python-kiwi, open-vmdk Announcement ID: SUSE-RU-2026:22551-1 Release Date: 2026-07-08T09:20:26Z Rating: important References: * bsc#1260340 * bsc#1263973 * jsc#PED-15927 * jsc#PED-9497 Affected Products: * SUSE Linux Micro 6.2 An update that contains two features and has two fixes can now be installed. ## Description: This update for python-kiwi, open-vmdk fixes the following issues: Changes in python-kiwi: * Fix rereading DASD partition table with partprobe On s390 and with a DASD disk the rereading of the partition table can only be done properly with partprobe. This commit changes the dracut code to Require parted and partprobe only for DASD disks on s390. In addition this commit prevents the active device locking for parted and partprobe when called in the context of a DASD device. The reason for this change is because of a patch in libparted which applies flock() itself in this condition. This change however does not exist in the upstream version of parted which is causing problems that are hard to solve by kiwi. However, a dead-lock condition should be avoided and I think it's still better to have this change in kiwi and convince people to upstream the above parted fix, rather than living with a dead-lock condition due to double locking in kiwi. This Fixes bsc#1263973 * Do not hardcode dracut omit module in live builder This is a relict from the old days when the pure presence of multipath in a live ISO caused issues at boot time. kiwi should not maintain a hardcoded list of dracut modules except for those that are mandatory for live boot, if there should be any special setting needed it should come from an overlay setup in /etc/dracut.conf.d/*.conf as part of the image description. This is related to bsc#1260340 * Drop parted requirement for msdos partitioner parted was used in kiwi at one place to set the active flag on a partition in the DOS table. This action can also be done via sfdisk and drops the parted requirement from the kiwi builder code * Move OVA support to open-vmdk Finally this commit drops the use of the VMware ovftool and moves to the real opensource alternative open-vmdk This Fixes #2292 and Fixes #2627 and Fixes jira#PED-9497 * Limit workflow to SLE supported pythons * Refactor use of kiwi settings file KIWI supports an optional runtime configuration file for settings to control the behavior of the tools used by KIWI on the build host. So far this config file could be specified via --config or is searched in the user's HOME or looked up as /etc/kiwi.yml. With this commit the following changes to this heuristic are made: 1. Support reading of /etc/kiwi.yml.d/*.yml 2. Support reading of /usr/share/kiwi/kiwi.yml and /usr/share/kiwi/kiwi.yml.d/*.yml 3. Install default settings file as /usr/share/kiwi/kiwi.yml.example from the main package and drop it from kiwi-man-pages which was considered a weird place. 4. Add support for oci format for disk images The (oci|docker):image_format format is a special case that stores the disk image inside of an OCI-compliant container. The disk image is stored in the specified image_format in the disk/ directory of the container. The disk format can be one of the above formats or just raw if the disk should be stored as a raw disk inside of the container. Custom naming conventions for the disk image can be applied by using the bundle_format attribute. The derived_from attribute can be used to specify the source container. The resulting container image will be built by adding the disk image as a new layer on top of the specified reference container. If there is no derived_from attribute, the container image will be built from scratch using an empty root directory. This format is particularly useful for building an image which bundles the actual disk image and its runtime requirements into one artifact. This Fixes jira#PCT-1008 * Fix caller environment for non chroot scripts Make sure non chroot scripts also knows about the kiwi profile environment such that e.g. the current profile name or other settings from the build can be used in the script * Update spec file due to new package restrictions On SUSE new package restrictions where added to support the concept of the so called immutable mode. The new guideline says "Any files in the RPM spec %files section that are not in /usr or /etc is likely to break in Immutable Mode". For the kiwi packaging this applies to the kiwi-pxeboot sub package. This commit implements the suggested solution based on systemd-tmpfiles and only applies for SUSE. This Fixes jira#PCT-1055 * Fix result bundler for uncompressed container data When building container images with the respective runtime configuration: `yaml container: - compress: false` The resulting image output files will be uncompressed meaning there is no ".xz" extension present. When running the result bundler there is an index bug which causes the container format type of the filename name e.g. ".docker" to be dropped from the result names. This commit fixes it. * Fix spec file requirements for SUSE There is no erofs on SLES. This commit drops the respective requirement settings which we have upstream where it exists This Fixes jira#PCT-899 * Fix upstream merge README * Support SOURCE_DATE_EPOCH for OCI containers (jsc#PED-15927) If SOURCE_DATE_EPOCH is available, use it for the container creation time and history. open-vmdk is shipped as new package. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1183=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * dracut-kiwi-lib-10.2.33-160000.3.1 * dracut-kiwi-oem-dump-10.2.33-160000.3.1 * dracut-kiwi-oem-repart-10.2.33-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1260340 * https://bugzilla.suse.com/show_bug.cgi?id=1263973 * https://jira.suse.com/browse/PED-15927 * https://jira.suse.com/browse/PED-9497 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:31:18 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:31:18 -0000 Subject: SUSE-SU-2026:22550-1: important: Security update for qemu Message-ID: <178396027865.1820.18384505453984148561@530c474df1e7> # Security update for qemu Announcement ID: SUSE-SU-2026:22550-1 Release Date: 2026-07-07T17:46:01Z Rating: important References: * bsc#1199023 * bsc#1268061 * bsc#1268279 * bsc#1268794 * bsc#1270133 * jsc#PED-9266 Cross-References: * CVE-2026-3886 * CVE-2026-48004 * CVE-2026-48914 CVSS scores: * CVE-2026-3886 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-48004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48914 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H * CVE-2026-48914 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities, contains one feature and has two fixes can now be installed. ## Description: This update for qemu fixes the following issues: Update to version 10.0.11. Security issues fixed: * CVE-2026-3886: integer overflow leading to privilege escalation due to lack of proper validation of user-supplied data in the virtio-gpu driver (bsc#1268061). * CVE-2026-48914: heap buffer overflow due to improper size validation in virtio-blk SCSI request handling (bsc#1268794). * CVE-2026-48004: heap use-after-free race condition due to missing rename lock in v9fs_co_readdir_many (bsc#1270133). Other updates and bugfixes: * Version 10.0.11: * Full backport list here: https://lore.kernel.org/qemu- devel/20260627082646.D825717AB67 at think4mjt.localdomain/ * Version 10.0.10: * Full backport list here: https://lore.kernel.org/qemu- devel/20260528061820.CEE521691A9 at think4mjt.localdomain/ * ppc/spapr: Skip system reset for quiesced CPUs (bsc#1268279). * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266). * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266). * update Linux headers to v6.16-rc3 (jsc#PED-9266). * i386/cpu: Warn about why CPUID_EXT_PDCM is not available (jsc#PED-9266). * i386/cpu: Move adjustment of CPUID_EXT_PDCM before feature_dependencies[] check (jsc#PED-9266). * [openSUSE] qemu-ga: fix service file against no-autostart (bsc#1199023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1174=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * qemu-seabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-lang-10.0.11-160000.1.1 * qemu-ipxe-10.0.11-160000.1.1 * qemu-SLOF-10.0.11-160000.1.1 * qemu-vgabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * qemu-10.0.11-160000.1.1 * qemu-chardev-spice-10.0.11-160000.1.1 * qemu-ui-spice-core-10.0.11-160000.1.1 * qemu-hw-usb-host-10.0.11-160000.1.1 * qemu-chardev-spice-debuginfo-10.0.11-160000.1.1 * qemu-ui-opengl-debuginfo-10.0.11-160000.1.1 * qemu-audio-spice-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-10.0.11-160000.1.1 * qemu-guest-agent-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-10.0.11-160000.1.1 * qemu-ui-opengl-10.0.11-160000.1.1 * qemu-debugsource-10.0.11-160000.1.1 * qemu-block-iscsi-10.0.11-160000.1.1 * qemu-img-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-debuginfo-10.0.11-160000.1.1 * qemu-hw-usb-host-debuginfo-10.0.11-160000.1.1 * qemu-img-debuginfo-10.0.11-160000.1.1 * qemu-block-iscsi-debuginfo-10.0.11-160000.1.1 * qemu-audio-spice-10.0.11-160000.1.1 * qemu-hw-usb-redirect-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-debuginfo-10.0.11-160000.1.1 * qemu-hw-usb-redirect-10.0.11-160000.1.1 * qemu-pr-helper-10.0.11-160000.1.1 * qemu-pr-helper-debuginfo-10.0.11-160000.1.1 * qemu-ui-spice-core-debuginfo-10.0.11-160000.1.1 * qemu-ksm-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-10.0.11-160000.1.1 * qemu-debuginfo-10.0.11-160000.1.1 * qemu-guest-agent-10.0.11-160000.1.1 * qemu-hw-display-qxl-debuginfo-10.0.11-160000.1.1 * qemu-tools-10.0.11-160000.1.1 * qemu-hw-display-qxl-10.0.11-160000.1.1 * qemu-tools-debuginfo-10.0.11-160000.1.1 * SUSE Linux Micro 6.2 (x86_64) * qemu-vmsr-helper-debuginfo-10.0.11-160000.1.1 * qemu-vmsr-helper-10.0.11-160000.1.1 * qemu-x86-10.0.11-160000.1.1 * qemu-x86-debuginfo-10.0.11-160000.1.1 * SUSE Linux Micro 6.2 (s390x) * qemu-s390x-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-10.0.11-160000.1.1 * qemu-s390x-10.0.11-160000.1.1 * SUSE Linux Micro 6.2 (ppc64le) * qemu-ppc-10.0.11-160000.1.1 * qemu-ppc-debuginfo-10.0.11-160000.1.1 * SUSE Linux Micro 6.2 (aarch64) * qemu-arm-10.0.11-160000.1.1 * qemu-arm-debuginfo-10.0.11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3886.html * https://www.suse.com/security/cve/CVE-2026-48004.html * https://www.suse.com/security/cve/CVE-2026-48914.html * https://bugzilla.suse.com/show_bug.cgi?id=1199023 * https://bugzilla.suse.com/show_bug.cgi?id=1268061 * https://bugzilla.suse.com/show_bug.cgi?id=1268279 * https://bugzilla.suse.com/show_bug.cgi?id=1268794 * https://bugzilla.suse.com/show_bug.cgi?id=1270133 * https://jira.suse.com/browse/PED-9266 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:31:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:31:25 -0000 Subject: SUSE-RU-2026:22549-1: moderate: Recommended update for dpdk Message-ID: <178396028535.1820.7427854149470814903@530c474df1e7> # Recommended update for dpdk Announcement ID: SUSE-RU-2026:22549-1 Release Date: 2026-07-07T17:08:31Z Rating: moderate References: * bsc#1260007 * bsc#1262286 Affected Products: * SUSE Linux Micro 6.2 An update that has two fixes can now be installed. ## Description: This update for dpdk fixes the following issues: Changes in dpdk: Update to version 24.11.6: * docs: fix build issue due to missing spacing between paragraphs * Revert ?net: fix packet type for stacked VLAN? Update to version 24.11.5: * https://doc.dpdk.org/guides-24.11/rel_notes/release_24_11.html#id15 * Summary: * Fixed buffer overflows (dma-perf, openssl) and use-after-free's in vhost. * Intel: Fixes for i40e, iavf, ice, and ixgbe regarding flow parsing, memory leak, and MAC management. * NVIDIA/Mellanox: Fixes for mlx5 regarding bonding, HW steering (HWS) and secondary process logic. * Fixes race conditions and resource leaks in netvsc (Hyper-V) * Fixes for Marvell (cnxk), Broadcom (bnxt), and Amazon (mana). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1180=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * dpdk-tools-24.11.6-160000.1.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le x86_64) * libdpdk-25-24.11.6-160000.1.1 * dpdk-debuginfo-24.11.6-160000.1.1 * dpdk-debugsource-24.11.6-160000.1.1 * libdpdk-25-debuginfo-24.11.6-160000.1.1 * dpdk-24.11.6-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1260007 * https://bugzilla.suse.com/show_bug.cgi?id=1262286 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:31:30 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:31:30 -0000 Subject: SUSE-RU-2026:22548-1: important: Recommended update for blog Message-ID: <178396029059.1820.4653201861454736393@530c474df1e7> # Recommended update for blog Announcement ID: SUSE-RU-2026:22548-1 Release Date: 2026-07-07T16:51:38Z Rating: important References: * bsc#1264176 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for blog fixes the following issues: * Update to version 2.45: * Fix early boot LUKS prompt on s390x and resolve memory corruptions This update addresses several critical issues in the early boot phase, especially on s390x architectures, and hardens the daemon's architecture: * Initrd/Dracut: Properly include `systemd-ask-password-blog.path` in sysinit.target.wants during the initrd phase to ensure LUKS password prompts are captured early in the zipl phase. * Systemd Units: Drop restrictive `ConditionKernelCommandLine=!plymouth.enable=0` to prevent the agent from being disabled by standard mainframe boot parameters. * Memory Corruption: Fix a critical heap corruption by renaming the conflicting `alignof()` macro to `ALIGNED_SIZEOF()` and zeroing allocated memory for `struct request` (memset) to prevent reading uninitialized pointers. * Kernel Command Line: Improve `parse_cmdline()` to support boolean parameters without an explicit value (e.g., `blog.silent` defaults to `blog.silent=1`). * New Features: Introduce `blog.silent` to suppress console I/O and `blog.coldboot` to explicitly trigger the early coldstart password query. * Lifecycle: Switch `KillMode=none` to `KillMode=mixed` to comply with modern systemd process lifecycle management. * Fix: Passphrase prompt does not appear after installation with encryption enabled on s390x (bsc#1264176) * Update to version 2.44: * Harden blog and use shims units to handle plymouth * Disable coldstart requests via epoll * Avoid handling fd twice in epoll loop * Update to version 2.43: * Make sure that if blog is running it is identified as plymouth Latest also add conflicts to systemd-ask-password-console units in the systemd-ask-password-blog units: * This should avoid conflicting password agents asking the same question in s390x. * Update to version 2.42: * Fix possible memory leaks, eliminate type punning, and resolve I/O blocking: 1. Memory Safety and Leak Resolution: * Implemented lcons_shutdown destructor to automatically purge the console list and close FDs on exit. * Fixed password buffer leak by using in closeIO, correctly matching the mmap allocation in shm_malloc. * Added cleanup for pwprompt in closeIO. 2. Elimination of Dangerous Type Punning: * Replaced the unreliable address of the cons node pattern with a type-safe list_t lcons sentinel across the codebase. * Added **attribute**((may_alias)) to list_t in listing.h to prevent compiler strict aliasing optimizations from corrupting list traversals. 3. I/O Responsiveness and Stability: * Removed tcdrain() from the high-frequency epoll_console_in path to eliminate daemon freezes during heavy output. * Updated consinitIO to ensure CON_SERIAL devices remain in O_NONBLOCK mode, preventing freezes on slow serial lines. * Extended the tcdrain skip-list in closeIO to include CON_SERIAL, ensuring a hang-free shutdown. 4. Architectural Improvements: * Redesigned shm_malloc to use a tiered mapping strategy: prefers file-backed shared memory in /dev/shm with a graceful fallback to MAP_ANONYMOUS. * Optimized listing.h with always_inline attributes, __builtin_prefetch for cache efficiency, and list poisoning for safer debugging. * Update to version 2.41: * The **attribute**((noreturn)) for error() in libconsole.h added * The variable err with 0 initialized in thread_poll() * The variable cp.parity with {0} initialized in readpw() * feat(blogd): handle pending systemd password requests on coldstart * Initialize console pointer list as well * Check peer credentials before reading command * Make isinteger() string check usable for all architectures * Add some comments about warnings and translation for S390 * Update to version 2.40: * Protect password data stream on 3270 console as well: * On S390 the 3270 console is also logged and the passwords, even if hidden on the 3270 console, would be logged as well. * Update to version 2.39: * New feature to protect passwords to be logged: * On S390 now blogd use for 3215 console the command #CP SPOOL CONSOLE STOP to stop logging the plain password at prompting for the password. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1178=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libblogger2-debuginfo-2.45-160000.1.1 * libblogger2-2.45-160000.1.1 * blog-debuginfo-2.45-160000.1.1 * blog-debugsource-2.45-160000.1.1 * blog-2.45-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1264176 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:31:36 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:31:36 -0000 Subject: SUSE-RU-2026:22547-1: important: Recommended update for dracut Message-ID: <178396029612.1820.12664343810055513668@530c474df1e7> # Recommended update for dracut Announcement ID: SUSE-RU-2026:22547-1 Release Date: 2026-07-07T16:51:38Z Rating: important References: * bsc#1262515 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for dracut fixes the following issues: * fix (fips): handle zipl (bsc#1262515) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1176=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * dracut-debuginfo-059+suse.724.gaa87d1594-160000.1.1 * dracut-059+suse.724.gaa87d1594-160000.1.1 * dracut-debugsource-059+suse.724.gaa87d1594-160000.1.1 * dracut-fips-059+suse.724.gaa87d1594-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1262515 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:31:45 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:31:45 -0000 Subject: SUSE-SU-2026:22546-1: important: Security update for docker-compose Message-ID: <178396030533.1820.13131556505337741356@530c474df1e7> # Security update for docker-compose Announcement ID: SUSE-SU-2026:22546-1 Release Date: 2026-07-07T12:34:17Z Rating: important References: * bsc#1239340 * bsc#1239766 * bsc#1265782 * bsc#1266625 Cross-References: * CVE-2025-0495 * CVE-2025-22869 * CVE-2026-33814 * CVE-2026-39821 CVSS scores: * CVE-2025-0495 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-0495 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N * CVE-2025-0495 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker-compose fixes the following issues * CVE-2025-0495: buildx: credential leakage to telemetry endpoints when credentials allowed to be set as attribute values in cache-to/cache-from configuration (bsc#1239766). * CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239340). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1168=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * docker-compose-2.33.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0495.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1239340 * https://bugzilla.suse.com/show_bug.cgi?id=1239766 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:04 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:32:04 -0000 Subject: SUSE-SU-2026:22545-1: important: Security update for jq Message-ID: <178396032480.1820.3853268382503958340@530c474df1e7> # Security update for jq Announcement ID: SUSE-SU-2026:22545-1 Release Date: 2026-07-07T12:32:37Z Rating: important References: * bsc#1244116 * bsc#1262043 * bsc#1262044 * bsc#1262069 * bsc#1262070 * bsc#1262071 * bsc#1262072 * bsc#1265060 * bsc#1265061 * bsc#1265062 * bsc#1265070 Cross-References: * CVE-2025-48060 * CVE-2026-32316 * CVE-2026-33947 * CVE-2026-33948 * CVE-2026-39956 * CVE-2026-39979 * CVE-2026-40164 * CVE-2026-40612 * CVE-2026-41256 * CVE-2026-41257 * CVE-2026-43894 CVSS scores: * CVE-2025-48060 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-48060 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-48060 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32316 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-32316 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-32316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33947 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33948 ( SUSE ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-33948 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-39956 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39956 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39956 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39979 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39979 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-39979 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40164 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40612 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40612 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-40612 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40612 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41256 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41256 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41257 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41257 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-41257 ( NVD ): 6.4 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43894 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43894 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43894 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2025-48060: improper handling of string data in `jv_string_empty` can lead to heap buffer overflow and a crash when processing crafted input (bsc#1244116). * CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). * CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). * CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). * CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). * CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre- computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). * CVE-2026-40612: recursion into nested arrays/objects with no depth limit in `jv_contains` can lead to a C stack exhaustion when processing crafted input (bsc#1265060). * CVE-2026-41256: truncation of top-level jq programs loaded with `-f` and can lead to the execution of unintended programs (bsc#1265061). * CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS when processing jq bytecode (bsc#1265062). * CVE-2026-43894: signed integer overflow in the `decNumberFromString` `D2U()` macro can lead to an out-of-bounds memory write when processing large number literals (bsc#1265070). * CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1169=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libjq1-1.7.1-160000.3.1 * jq-debugsource-1.7.1-160000.3.1 * jq-1.7.1-160000.3.1 * jq-debuginfo-1.7.1-160000.3.1 * libjq1-debuginfo-1.7.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48060.html * https://www.suse.com/security/cve/CVE-2026-32316.html * https://www.suse.com/security/cve/CVE-2026-33947.html * https://www.suse.com/security/cve/CVE-2026-33948.html * https://www.suse.com/security/cve/CVE-2026-39956.html * https://www.suse.com/security/cve/CVE-2026-39979.html * https://www.suse.com/security/cve/CVE-2026-40164.html * https://www.suse.com/security/cve/CVE-2026-40612.html * https://www.suse.com/security/cve/CVE-2026-41256.html * https://www.suse.com/security/cve/CVE-2026-41257.html * https://www.suse.com/security/cve/CVE-2026-43894.html * https://bugzilla.suse.com/show_bug.cgi?id=1244116 * https://bugzilla.suse.com/show_bug.cgi?id=1262043 * https://bugzilla.suse.com/show_bug.cgi?id=1262044 * https://bugzilla.suse.com/show_bug.cgi?id=1262069 * https://bugzilla.suse.com/show_bug.cgi?id=1262070 * https://bugzilla.suse.com/show_bug.cgi?id=1262071 * https://bugzilla.suse.com/show_bug.cgi?id=1262072 * https://bugzilla.suse.com/show_bug.cgi?id=1265060 * https://bugzilla.suse.com/show_bug.cgi?id=1265061 * https://bugzilla.suse.com/show_bug.cgi?id=1265062 * https://bugzilla.suse.com/show_bug.cgi?id=1265070 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:32:11 -0000 Subject: SUSE-SU-2026:22544-1: important: Security update for haproxy Message-ID: <178396033152.1820.18042031114031490880@530c474df1e7> # Security update for haproxy Announcement ID: SUSE-SU-2026:22544-1 Release Date: 2026-07-07T10:11:29Z Rating: important References: * bsc#1268557 * bsc#1268558 Cross-References: * CVE-2026-55203 * CVE-2026-55204 CVSS scores: * CVE-2026-55203 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-55203 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55203 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N * CVE-2026-55204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues * Update to version 3.2.21+git0.dbe43be37 * CVE-2026-55203: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557). * CVE-2026-55204: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1166=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * haproxy-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-debuginfo-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-debugsource-3.2.21+git0.dbe43be37-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55203.html * https://www.suse.com/security/cve/CVE-2026-55204.html * https://bugzilla.suse.com/show_bug.cgi?id=1268557 * https://bugzilla.suse.com/show_bug.cgi?id=1268558 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:15 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:32:15 -0000 Subject: SUSE-RU-2026:22543-1: moderate: Recommended update for helm Message-ID: <178396033541.1820.17867810679883358853@530c474df1e7> # Recommended update for helm Announcement ID: SUSE-RU-2026:22543-1 Release Date: 2026-07-06T20:10:31Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.2 An update that can now be installed. ## Description: This update for helm fixes the following issues: * Update to 3.21.2: * chore(deps): bump the k8s-io group (dependabot[bot]): * Updates `k8s.io/apiserver` from 0.35.1 to 0.36.2 * Updates `k8s.io/apiextensions-apiserver` from 0.35.1 to 0.36.2 * Updates `k8s.io/apimachinery` from 0.35.1 to 0.36.2 * Updates `k8s.io/kubectl` from 0.35.1 to 0.36.2 * Updates dependencies * fixes regression (b52e276) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1152=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-160000.1.2 * helm-3.21.2-160000.1.2 * SUSE Linux Micro 6.2 (noarch) * helm-bash-completion-3.21.2-160000.1.2 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:32:20 -0000 Subject: SUSE-SU-2026:22542-1: moderate: Security update for dhcpcd Message-ID: <178396034051.1820.1680512983619553747@530c474df1e7> # Security update for dhcpcd Announcement ID: SUSE-SU-2026:22542-1 Release Date: 2026-07-06T20:10:31Z Rating: moderate References: * bsc#1268761 Cross-References: * CVE-2025-70102 CVSS scores: * CVE-2025-70102 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-70102 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-70102 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for dhcpcd fixes the following issue Update to 10.3.2: * CVE-2025-70102: NULL pointer dereference in `parse_option()` when processing a specially crafted configuration input (bsc#1268761). Changes for dhcpcd: * options: Ensure ldop is not NULL dereferenced * DHCP: Don't run double EXPIRE hooks on carrier loss * DHCP: free the state when dropping on state NONE * BSD: don't send uninitialised memory using ps_root_indirectioctl * Fix fallback_time option * IPv4: Ignore DHCP state when building routes * route: Routes may not have an interface assinged * options: Ensure that an overly long bitflag string does not crash * options: Don't assume vsio options have an argument * common: Cast via uintptr_t rather than unsigned long in UNCONST * privsep: Ensure we recv for real after a successful recv MSG_PEEK * DHCP: Add parentheses to macro definitions * ipv6nd: empty IPV6RA_EXPIRE eloop queue when dropping * privsep: enforce message boundaries with MSG_EOR on our messages * Protocols will notify when dhcpcd can exit * DHCP: Don't request T1 and T2 * DHCP: Don't request a lease time * DHCP6: Don't exit if using DHCP4 INFORM in non manager mode * ND: Route Information Option prefix is optional * ipv6: respect slaac hwaddr to really use the hwaddr * When stopping all interfaces at exit and releasing, remove persistance * NetBSD: Delete RTF_CONNECTED route when changing it * privsep: Drain the log when the root process is exiting * eloop: vastly reworked, kqueue and epoll support on by default ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1147=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * dhcpcd-debugsource-10.3.2-160000.1.2 * dhcpcd-10.3.2-160000.1.2 * dhcpcd-debuginfo-10.3.2-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-70102.html * https://bugzilla.suse.com/show_bug.cgi?id=1268761 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:32:25 -0000 Subject: SUSE-RU-2026:22541-1: moderate: Recommended update for tboot Message-ID: <178396034577.1820.17819673373221815053@530c474df1e7> # Recommended update for tboot Announcement ID: SUSE-RU-2026:22541-1 Release Date: 2026-07-08T12:27:38Z Rating: moderate References: * bsc#1266833 Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that has one fix can now be installed. ## Description: This update for tboot fixes the following issues: * Fix: [SLES16 SP1] grub-mkconfig fails version_find_latest command not found ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1184=1 ## Package List: * SUSE Linux Micro Extras 6.2 (x86_64) * tboot-debugsource-20250417_1.11.10-160000.2.1 * tboot-debuginfo-20250417_1.11.10-160000.2.1 * tboot-20250417_1.11.10-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1266833 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:31 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:32:31 -0000 Subject: SUSE-RU-2026:22540-1: moderate: Recommended update for systemd Message-ID: <178396035116.1820.4615309565134403834@530c474df1e7> # Recommended update for systemd Announcement ID: SUSE-RU-2026:22540-1 Release Date: 2026-07-09T12:37:51Z Rating: moderate References: * bsc#1270439 Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that has one fix can now be installed. ## Description: This update for systemd fixes the following issues: Changes in systemd: * do not make mounting of debugfs optional yet. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1191=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * systemd-debugsource-257.13-160000.3.1 * systemd-devel-257.13-160000.3.1 * systemd-debuginfo-257.13-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270439 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:43 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:32:43 -0000 Subject: SUSE-RU-2026:22539-1: important: Recommended update for python-kiwi, open-vmdk Message-ID: <178396036301.1820.16503588309655421365@530c474df1e7> # Recommended update for python-kiwi, open-vmdk Announcement ID: SUSE-RU-2026:22539-1 Release Date: 2026-07-08T09:20:51Z Rating: important References: * bsc#1260340 * bsc#1263973 * jsc#PED-15927 * jsc#PED-9497 Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that contains two features and has two fixes can now be installed. ## Description: This update for python-kiwi, open-vmdk fixes the following issues: Changes in python-kiwi: * Fix rereading DASD partition table with partprobe On s390 and with a DASD disk the rereading of the partition table can only be done properly with partprobe. This commit changes the dracut code to Require parted and partprobe only for DASD disks on s390. In addition this commit prevents the active device locking for parted and partprobe when called in the context of a DASD device. The reason for this change is because of a patch in libparted which applies flock() itself in this condition. This change however does not exist in the upstream version of parted which is causing problems that are hard to solve by kiwi. However, a dead-lock condition should be avoided and I think it's still better to have this change in kiwi and convince people to upstream the above parted fix, rather than living with a dead-lock condition due to double locking in kiwi. This Fixes bsc#1263973 * Do not hardcode dracut omit module in live builder This is a relict from the old days when the pure presence of multipath in a live ISO caused issues at boot time. kiwi should not maintain a hardcoded list of dracut modules except for those that are mandatory for live boot, if there should be any special setting needed it should come from an overlay setup in /etc/dracut.conf.d/*.conf as part of the image description. This is related to bsc#1260340 * Drop parted requirement for msdos partitioner parted was used in kiwi at one place to set the active flag on a partition in the DOS table. This action can also be done via sfdisk and drops the parted requirement from the kiwi builder code * Move OVA support to open-vmdk Finally this commit drops the use of the VMware ovftool and moves to the real opensource alternative open-vmdk This Fixes #2292 and Fixes #2627 and Fixes jira#PED-9497 * Limit workflow to SLE supported pythons * Refactor use of kiwi settings file KIWI supports an optional runtime configuration file for settings to control the behavior of the tools used by KIWI on the build host. So far this config file could be specified via --config or is searched in the user's HOME or looked up as /etc/kiwi.yml. With this commit the following changes to this heuristic are made: 1. Support reading of /etc/kiwi.yml.d/*.yml 2. Support reading of /usr/share/kiwi/kiwi.yml and /usr/share/kiwi/kiwi.yml.d/*.yml 3. Install default settings file as /usr/share/kiwi/kiwi.yml.example from the main package and drop it from kiwi-man-pages which was considered a weird place. 4. Add support for oci format for disk images The (oci|docker):image_format format is a special case that stores the disk image inside of an OCI-compliant container. The disk image is stored in the specified image_format in the disk/ directory of the container. The disk format can be one of the above formats or just raw if the disk should be stored as a raw disk inside of the container. Custom naming conventions for the disk image can be applied by using the bundle_format attribute. The derived_from attribute can be used to specify the source container. The resulting container image will be built by adding the disk image as a new layer on top of the specified reference container. If there is no derived_from attribute, the container image will be built from scratch using an empty root directory. This format is particularly useful for building an image which bundles the actual disk image and its runtime requirements into one artifact. This Fixes jira#PCT-1008 * Fix caller environment for non chroot scripts Make sure non chroot scripts also knows about the kiwi profile environment such that e.g. the current profile name or other settings from the build can be used in the script * Update spec file due to new package restrictions On SUSE new package restrictions where added to support the concept of the so called immutable mode. The new guideline says "Any files in the RPM spec %files section that are not in /usr or /etc is likely to break in Immutable Mode". For the kiwi packaging this applies to the kiwi-pxeboot sub package. This commit implements the suggested solution based on systemd-tmpfiles and only applies for SUSE. This Fixes jira#PCT-1055 * Fix result bundler for uncompressed container data When building container images with the respective runtime configuration: `yaml container: - compress: false` The resulting image output files will be uncompressed meaning there is no ".xz" extension present. When running the result bundler there is an index bug which causes the container format type of the filename name e.g. ".docker" to be dropped from the result names. This commit fixes it. * Fix spec file requirements for SUSE There is no erofs on SLES. This commit drops the respective requirement settings which we have upstream where it exists This Fixes jira#PCT-899 * Fix upstream merge README * Support SOURCE_DATE_EPOCH for OCI containers (jsc#PED-15927) If SOURCE_DATE_EPOCH is available, use it for the container creation time and history. open-vmdk is shipped as new package. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1183=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * python3-kiwi-10.2.33-160000.3.1 * kiwi-systemdeps-core-10.2.33-160000.3.1 * open-vmdk-debuginfo-0.3.12-160000.1.1 * open-vmdk-0.3.12-160000.1.1 * open-vmdk-debugsource-0.3.12-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1260340 * https://bugzilla.suse.com/show_bug.cgi?id=1263973 * https://jira.suse.com/browse/PED-15927 * https://jira.suse.com/browse/PED-9497 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:32:49 -0000 Subject: SUSE-SU-2026:22538-1: moderate: Security update for glibc Message-ID: <178396036996.1820.2280332996322839250@530c474df1e7> # Security update for glibc Announcement ID: SUSE-SU-2026:22538-1 Release Date: 2026-07-03T13:25:46Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1157=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * glibc-gconv-modules-extra-2.40-160000.6.1 * glibc-debuginfo-2.40-160000.6.1 * glibc-gconv-modules-extra-debuginfo-2.40-160000.6.1 * glibc-debugsource-2.40-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:33:10 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:33:10 -0000 Subject: SUSE-SU-2026:22537-1: important: Security update for systemd Message-ID: <178396039014.1820.4209885948992428615@530c474df1e7> # Security update for systemd Announcement ID: SUSE-SU-2026:22537-1 Release Date: 2026-07-03T08:47:49Z Rating: important References: * bsc#1245551 * bsc#1248261 * bsc#1251948 * bsc#1254924 * bsc#1259071 * bsc#1260357 * bsc#1261982 * bsc#1261983 * bsc#1262305 * bsc#1263117 * bsc#1267644 * bsc#1267647 * jsc#PED-15946 * jsc#PED-8812 Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that contains two features and has 12 fixes can now be installed. ## Description: This update for systemd fixes the following issues: Changes in systemd: * Better handle TLS allocation failure (bsc#1254924). * Disable mounting `debugfs` by default (jsc#PED-8812). * Import commit 9e8b5afe0fb2061f4a17a3022469dd62f2683960 (bsc#1267647 bsc#1267644 bsc#1262305 bsc#1263117). * Move `systemd-pcrlock` out from the experimental sub-package to `udev` (bsc#1248261 jsc#PED-15946). * Add a weak runtime dependency on `libtss2-tcti-device0` (bsc#1260357). * Import commit 59336000ef7850eba0963c6a690ff3371c425929 (bsc#1261982 bsc#1261983). * Add a weak runtime dependency on `polkit` (bsc#1259071). * systemd-update-helper: fix the clean-state command only removing `$STATE_DIR/system` instead of `$STATE_DIR/`. * systemd-update-helper: add `--root` option for testing convenience. * systemd-update-helper: fix incorrect skipping of `systemctl disable` during package removal (bsc#1245551). * systemd-update-helper: fix `do_install_units()` incorrectly returning 1 when no units need preset. * systemd.spec: introduce `%bcond_without` docs to allow skipping man pages and `devel-doc`. * systemd.spec: drop the `%{release}` number from the SBAT version (bsc#1251948). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1151=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * systemd-debugsource-257.13-160000.2.1 * systemd-devel-257.13-160000.2.1 * systemd-debuginfo-257.13-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1245551 * https://bugzilla.suse.com/show_bug.cgi?id=1248261 * https://bugzilla.suse.com/show_bug.cgi?id=1251948 * https://bugzilla.suse.com/show_bug.cgi?id=1254924 * https://bugzilla.suse.com/show_bug.cgi?id=1259071 * https://bugzilla.suse.com/show_bug.cgi?id=1260357 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1262305 * https://bugzilla.suse.com/show_bug.cgi?id=1263117 * https://bugzilla.suse.com/show_bug.cgi?id=1267644 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 * https://jira.suse.com/browse/PED-15946 * https://jira.suse.com/browse/PED-8812 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:33:48 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:33:48 -0000 Subject: SUSE-SU-2026:2895-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 15 SP7) Message-ID: <178396042882.1820.17958800807554440720@530c474df1e7> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2895-1 Release Date: 2026-07-13T12:11:50Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.31 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2895=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_31-default-8-150700.2.2 * kernel-livepatch-6_4_0-150700_53_31-default-debuginfo-8-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_9-debugsource-8-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:34:27 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:34:27 -0000 Subject: SUSE-SU-2026:2894-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP6) Message-ID: <178396046716.1820.17451076073914270223@530c474df1e7> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2894-1 Release Date: 2026-07-13T12:12:16Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.81 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2894=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2896=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-2897=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2894=1 SUSE-2026-2896=1 SUSE-2026-2897=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_53-default-20-150600.2.2 * kernel-livepatch-6_4_0-150600_23_81-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_70-default-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_15-debugsource-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-20-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_12-debugsource-20-150600.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_53-default-20-150600.2.2 * kernel-livepatch-6_4_0-150600_23_81-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_70-default-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-9-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_15-debugsource-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-20-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_12-debugsource-20-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:35:01 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:35:01 -0000 Subject: SUSE-SU-2026:2889-1: important: Security update for the Linux Kernel (Live Patch 44 for SUSE Linux Enterprise 15 SP4) Message-ID: <178396050140.1820.17978063999038828964@530c474df1e7> # Security update for the Linux Kernel (Live Patch 44 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2889-1 Release Date: 2026-07-13T10:20:19Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.176 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2889=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2889=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_44-debugsource-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-16-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_44-debugsource-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-16-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:35:34 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:35:34 -0000 Subject: SUSE-SU-2026:2888-1: important: Security update for the Linux Kernel (Live Patch 52 for SUSE Linux Enterprise 15 SP4) Message-ID: <178396053407.1820.1011046246052327975@530c474df1e7> # Security update for the Linux Kernel (Live Patch 52 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2888-1 Release Date: 2026-07-13T10:19:55Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.209 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2888=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2888=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_52-debugsource-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-4-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_52-debugsource-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-4-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:36:12 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:36:12 -0000 Subject: SUSE-SU-2026:2887-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 15 SP7) Message-ID: <178396057231.1820.4476467572756012975@530c474df1e7> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2887-1 Release Date: 2026-07-13T10:19:34Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.40 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2887=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_12-debugsource-5-150700.2.2 * kernel-livepatch-6_4_0-150700_53_40-default-debuginfo-5-150700.2.2 * kernel-livepatch-6_4_0-150700_53_40-default-5-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:36:50 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:36:50 -0000 Subject: SUSE-SU-2026:2890-1: important: Security update for the Linux Kernel (Live Patch 34 for SUSE Linux Enterprise 15 SP5) Message-ID: <178396061011.1820.9738714367908959299@530c474df1e7> # Security update for the Linux Kernel (Live Patch 34 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2890-1 Release Date: 2026-07-13T10:20:38Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.133 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2890=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-2872=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-2873=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2872=1 SUSE-2026-2873=1 SUSE-2026-2890=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_31-debugsource-13-150500.2.2 * kernel-livepatch-5_14_21-150500_55_130-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-13-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_124-default-13-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_133-default-10-150500.2.2 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_31-debugsource-13-150500.2.2 * kernel-livepatch-5_14_21-150500_55_130-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-13-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_124-default-13-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_133-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-10-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:36:57 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:36:57 -0000 Subject: SUSE-RU-2026:2893-1: moderate: Recommended update for postgresql Message-ID: <178396061723.1820.7998929478829923988@530c474df1e7> # Recommended update for postgresql Announcement ID: SUSE-RU-2026:2893-1 Release Date: 2026-07-13T11:41:08Z Rating: moderate References: * bsc#1245862 * jsc#PED-14820 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that contains one feature and has one fix can now be installed. ## Description: This update for postgresql fixes the following issues: Changes in postgresql: * Get rid of update-alternatives and support immutable mode. See README.SUSE for details. (bsc#1245862, jsc#PED-14820) * Bump default to 17 for SLE-15-SP7. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2893=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2893=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2893=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2893=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2893=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2893=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2893=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2893=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2893=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2893=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2893=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2893=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2893=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2893=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2893=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2893=1 ## Package List: * openSUSE Leap 15.6 (noarch) * postgresql-pltcl-18-150600.17.12.1 * postgresql-devel-18-150600.17.12.1 * postgresql-plpython-18-150600.17.12.1 * postgresql-docs-18-150600.17.12.1 * postgresql-test-18-150600.17.12.1 * postgresql-llvmjit-18-150600.17.12.1 * postgresql-contrib-18-150600.17.12.1 * postgresql-llvmjit-devel-18-150600.17.12.1 * postgresql-server-devel-18-150600.17.12.1 * postgresql-18-150600.17.12.1 * postgresql-server-18-150600.17.12.1 * postgresql-plperl-18-150600.17.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * postgresql-devel-18-150400.10.15.1 * postgresql-server-18-150400.10.15.1 * postgresql-contrib-18-150400.10.15.1 * postgresql-docs-18-150400.10.15.1 * postgresql-pltcl-18-150400.10.15.1 * postgresql-18-150400.10.15.1 * postgresql-plperl-18-150400.10.15.1 * postgresql-server-devel-18-150400.10.15.1 * postgresql-plpython-18-150400.10.15.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * postgresql-plpython-18-150400.10.15.1 * postgresql-plperl-18-150400.10.15.1 * postgresql-devel-18-150400.10.15.1 * postgresql-server-18-150400.10.15.1 * postgresql-docs-18-150400.10.15.1 * postgresql-18-150400.10.15.1 * postgresql-contrib-18-150400.10.15.1 * postgresql-server-devel-18-150400.10.15.1 * postgresql-pltcl-18-150400.10.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * postgresql-plperl-18-150400.10.15.1 * postgresql-devel-18-150400.10.15.1 * postgresql-server-18-150400.10.15.1 * postgresql-pltcl-18-150400.10.15.1 * postgresql-docs-18-150400.10.15.1 * postgresql-18-150400.10.15.1 * postgresql-contrib-18-150400.10.15.1 * postgresql-server-devel-18-150400.10.15.1 * postgresql-plpython-18-150400.10.15.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * postgresql-pltcl-18-150400.4.24.1 * postgresql-devel-18-150400.4.24.1 * postgresql-18-150400.4.24.1 * postgresql-plperl-18-150400.4.24.1 * postgresql-llvmjit-devel-18-150400.4.24.1 * postgresql-docs-18-150400.4.24.1 * postgresql-server-18-150400.4.24.1 * postgresql-contrib-18-150400.4.24.1 * postgresql-server-devel-18-150400.4.24.1 * postgresql-llvmjit-18-150400.4.24.1 * postgresql-plpython-18-150400.4.24.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * postgresql-pltcl-18-150600.17.12.1 * postgresql-devel-18-150600.17.12.1 * postgresql-plpython-18-150600.17.12.1 * postgresql-docs-18-150600.17.12.1 * postgresql-contrib-18-150600.17.12.1 * postgresql-server-devel-18-150600.17.12.1 * postgresql-18-150600.17.12.1 * postgresql-server-18-150600.17.12.1 * postgresql-plperl-18-150600.17.12.1 * SUSE Package Hub 15 15-SP7 (noarch) * postgresql-llvmjit-devel-18-150700.23.6.1 * postgresql-contrib-18-150700.23.6.1 * postgresql-18-150700.23.6.1 * postgresql-plpython-18-150700.23.6.1 * postgresql-devel-18-150700.23.6.1 * postgresql-plperl-18-150700.23.6.1 * postgresql-test-18-150700.23.6.1 * postgresql-server-devel-18-150700.23.6.1 * postgresql-llvmjit-18-150700.23.6.1 * postgresql-docs-18-150700.23.6.1 * postgresql-pltcl-18-150700.23.6.1 * postgresql-server-18-150700.23.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * postgresql-plperl-18-150400.10.15.1 * postgresql-plpython-18-150400.10.15.1 * postgresql-devel-18-150400.10.15.1 * postgresql-server-18-150400.10.15.1 * postgresql-docs-18-150400.10.15.1 * postgresql-18-150400.10.15.1 * postgresql-contrib-18-150400.10.15.1 * postgresql-server-devel-18-150400.10.15.1 * postgresql-pltcl-18-150400.10.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * postgresql-pltcl-18-150400.4.24.1 * postgresql-devel-18-150400.4.24.1 * postgresql-18-150400.4.24.1 * postgresql-plperl-18-150400.4.24.1 * postgresql-llvmjit-devel-18-150400.4.24.1 * postgresql-docs-18-150400.4.24.1 * postgresql-server-18-150400.4.24.1 * postgresql-contrib-18-150400.4.24.1 * postgresql-server-devel-18-150400.4.24.1 * postgresql-llvmjit-18-150400.4.24.1 * postgresql-plpython-18-150400.4.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * postgresql-pltcl-18-150400.4.24.1 * postgresql-devel-18-150400.4.24.1 * postgresql-18-150400.4.24.1 * postgresql-plperl-18-150400.4.24.1 * postgresql-llvmjit-devel-18-150400.4.24.1 * postgresql-docs-18-150400.4.24.1 * postgresql-server-18-150400.4.24.1 * postgresql-contrib-18-150400.4.24.1 * postgresql-server-devel-18-150400.4.24.1 * postgresql-llvmjit-18-150400.4.24.1 * postgresql-plpython-18-150400.4.24.1 * openSUSE Leap 15.4 (noarch) * postgresql-pltcl-18-150400.4.24.1 * postgresql-test-18-150400.4.24.1 * postgresql-devel-18-150400.4.24.1 * postgresql-18-150400.4.24.1 * postgresql-plperl-18-150400.4.24.1 * postgresql-llvmjit-devel-18-150400.4.24.1 * postgresql-docs-18-150400.4.24.1 * postgresql-server-18-150400.4.24.1 * postgresql-server-devel-18-150400.4.24.1 * postgresql-contrib-18-150400.4.24.1 * postgresql-llvmjit-18-150400.4.24.1 * postgresql-plpython-18-150400.4.24.1 * Basesystem Module 15-SP7 (noarch) * postgresql-18-150700.23.6.1 * Server Applications Module 15-SP7 (noarch) * postgresql-contrib-18-150700.23.6.1 * postgresql-plpython-18-150700.23.6.1 * postgresql-devel-18-150700.23.6.1 * postgresql-plperl-18-150700.23.6.1 * postgresql-server-devel-18-150700.23.6.1 * postgresql-docs-18-150700.23.6.1 * postgresql-pltcl-18-150700.23.6.1 * postgresql-server-18-150700.23.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * postgresql-pltcl-18-150400.4.24.1 * postgresql-devel-18-150400.4.24.1 * postgresql-18-150400.4.24.1 * postgresql-plperl-18-150400.4.24.1 * postgresql-llvmjit-devel-18-150400.4.24.1 * postgresql-docs-18-150400.4.24.1 * postgresql-server-18-150400.4.24.1 * postgresql-contrib-18-150400.4.24.1 * postgresql-server-devel-18-150400.4.24.1 * postgresql-llvmjit-18-150400.4.24.1 * postgresql-plpython-18-150400.4.24.1 * openSUSE Leap 15.5 (noarch) * postgresql-plpython-18-150400.10.15.1 * postgresql-plperl-18-150400.10.15.1 * postgresql-devel-18-150400.10.15.1 * postgresql-server-18-150400.10.15.1 * postgresql-llvmjit-18-150400.10.15.1 * postgresql-llvmjit-devel-18-150400.10.15.1 * postgresql-test-18-150400.10.15.1 * postgresql-docs-18-150400.10.15.1 * postgresql-18-150400.10.15.1 * postgresql-contrib-18-150400.10.15.1 * postgresql-server-devel-18-150400.10.15.1 * postgresql-pltcl-18-150400.10.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * postgresql-pltcl-18-150600.17.12.1 * postgresql-devel-18-150600.17.12.1 * postgresql-plpython-18-150600.17.12.1 * postgresql-docs-18-150600.17.12.1 * postgresql-contrib-18-150600.17.12.1 * postgresql-server-devel-18-150600.17.12.1 * postgresql-18-150600.17.12.1 * postgresql-server-18-150600.17.12.1 * postgresql-plperl-18-150600.17.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1245862 * https://jira.suse.com/browse/PED-14820 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:04 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:37:04 -0000 Subject: SUSE-SU-2026:2886-1: moderate: Security update for libslirp Message-ID: <178396062495.1820.13484982719792534581@530c474df1e7> # Security update for libslirp Announcement ID: SUSE-SU-2026:2886-1 Release Date: 2026-07-13T10:09:11Z Rating: moderate References: * bsc#1268903 Cross-References: * CVE-2026-9539 CVSS scores: * CVE-2026-9539 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9539 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for libslirp fixes the following issues: * CVE-2026-9539: crafted TCP segment with manipulated URG flags and urgent pointers can cause an integer underflow and host-heap memory leak (bsc#1268903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2886=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2886=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2886=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2886=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2886=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libslirp-debugsource-4.7.0+44-150300.18.1 * libslirp-devel-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp0-debuginfo-4.7.0+44-150300.18.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libslirp-debugsource-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp0-debuginfo-4.7.0+44-150300.18.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libslirp-debugsource-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp0-debuginfo-4.7.0+44-150300.18.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libslirp0-debuginfo-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp-debugsource-4.7.0+44-150300.18.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libslirp0-debuginfo-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp-debugsource-4.7.0+44-150300.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9539.html * https://bugzilla.suse.com/show_bug.cgi?id=1268903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:10 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:37:10 -0000 Subject: SUSE-SU-2026:2885-1: moderate: Security update for alsa Message-ID: <178396063051.1820.11541790076118753712@530c474df1e7> # Security update for alsa Announcement ID: SUSE-SU-2026:2885-1 Release Date: 2026-07-13T10:02:46Z Rating: moderate References: * bsc#1268853 Cross-References: * CVE-2026-56109 CVSS scores: * CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56109 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for alsa fixes the following issue * CVE-2026-56109: crafted ALSA configuration text with nested blocks can cause a double-free and memory corruption (bsc#1268853). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2885=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2885=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2885=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2885=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2885=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libasound2-1.2.6.1-150400.3.3.1 * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libasound2-1.2.6.1-150400.3.3.1 * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 * alsa-1.2.6.1-150400.3.3.1 * alsa-devel-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (x86_64) * libasound2-32bit-debuginfo-1.2.6.1-150400.3.3.1 * libatopology2-32bit-debuginfo-1.2.6.1-150400.3.3.1 * alsa-topology-devel-32bit-1.2.6.1-150400.3.3.1 * alsa-devel-32bit-1.2.6.1-150400.3.3.1 * libatopology2-32bit-1.2.6.1-150400.3.3.1 * libasound2-32bit-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le x86_64) * libatopology2-debuginfo-1.2.6.1-150400.3.3.1 * alsa-topology-devel-1.2.6.1-150400.3.3.1 * libatopology2-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libasound2-64bit-1.2.6.1-150400.3.3.1 * libatopology2-64bit-1.2.6.1-150400.3.3.1 * libatopology2-64bit-debuginfo-1.2.6.1-150400.3.3.1 * alsa-devel-64bit-1.2.6.1-150400.3.3.1 * alsa-topology-devel-64bit-1.2.6.1-150400.3.3.1 * libasound2-64bit-debuginfo-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (noarch) * alsa-docs-1.2.6.1-150400.3.3.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56109.html * https://bugzilla.suse.com/show_bug.cgi?id=1268853 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:16 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:37:16 -0000 Subject: SUSE-SU-2026:2883-1: moderate: Security update for nghttp2 Message-ID: <178396063636.1820.14739321424709769729@530c474df1e7> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:2883-1 Release Date: 2026-07-13T09:54:51Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2883=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2883=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2883=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2883=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2883=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:22 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:37:22 -0000 Subject: SUSE-SU-2026:2880-1: moderate: Security update for php8 Message-ID: <178396064245.1820.13982653522702800700@530c474df1e7> # Security update for php8 Announcement ID: SUSE-SU-2026:2880-1 Release Date: 2026-07-13T09:39:59Z Rating: moderate References: * bsc#1270351 Cross-References: * CVE-2026-14355 CVSS scores: * CVE-2026-14355 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-14355 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14355 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14355 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for php8 fixes the following issue * CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2880=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * php8-bcmath-debuginfo-8.0.30-150400.4.68.1 * php8-zip-debuginfo-8.0.30-150400.4.68.1 * php8-mysql-8.0.30-150400.4.68.1 * php8-pcntl-8.0.30-150400.4.68.1 * php8-bcmath-8.0.30-150400.4.68.1 * php8-embed-debuginfo-8.0.30-150400.4.68.1 * apache2-mod_php8-8.0.30-150400.4.68.1 * php8-openssl-debuginfo-8.0.30-150400.4.68.1 * php8-opcache-debuginfo-8.0.30-150400.4.68.1 * php8-sockets-debuginfo-8.0.30-150400.4.68.1 * php8-fileinfo-8.0.30-150400.4.68.1 * php8-phar-8.0.30-150400.4.68.1 * php8-ctype-debuginfo-8.0.30-150400.4.68.1 * php8-ftp-debuginfo-8.0.30-150400.4.68.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.68.1 * php8-fpm-debuginfo-8.0.30-150400.4.68.1 * php8-bz2-debuginfo-8.0.30-150400.4.68.1 * php8-readline-debuginfo-8.0.30-150400.4.68.1 * php8-tidy-8.0.30-150400.4.68.1 * php8-phar-debuginfo-8.0.30-150400.4.68.1 * php8-calendar-8.0.30-150400.4.68.1 * php8-gettext-debuginfo-8.0.30-150400.4.68.1 * php8-xsl-8.0.30-150400.4.68.1 * php8-fastcgi-debugsource-8.0.30-150400.4.68.1 * php8-gmp-debuginfo-8.0.30-150400.4.68.1 * php8-shmop-debuginfo-8.0.30-150400.4.68.1 * php8-posix-debuginfo-8.0.30-150400.4.68.1 * php8-readline-8.0.30-150400.4.68.1 * php8-bz2-8.0.30-150400.4.68.1 * php8-debuginfo-8.0.30-150400.4.68.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.68.1 * php8-sysvshm-8.0.30-150400.4.68.1 * php8-zip-8.0.30-150400.4.68.1 * php8-pcntl-debuginfo-8.0.30-150400.4.68.1 * php8-enchant-debuginfo-8.0.30-150400.4.68.1 * php8-opcache-8.0.30-150400.4.68.1 * php8-test-8.0.30-150400.4.68.1 * php8-ldap-8.0.30-150400.4.68.1 * php8-tokenizer-8.0.30-150400.4.68.1 * php8-pdo-debuginfo-8.0.30-150400.4.68.1 * php8-sodium-debuginfo-8.0.30-150400.4.68.1 * php8-curl-debuginfo-8.0.30-150400.4.68.1 * php8-devel-8.0.30-150400.4.68.1 * php8-sqlite-debuginfo-8.0.30-150400.4.68.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.68.1 * php8-dba-8.0.30-150400.4.68.1 * php8-sockets-8.0.30-150400.4.68.1 * php8-calendar-debuginfo-8.0.30-150400.4.68.1 * php8-sysvsem-8.0.30-150400.4.68.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.68.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.68.1 * php8-gd-debuginfo-8.0.30-150400.4.68.1 * php8-ftp-8.0.30-150400.4.68.1 * php8-enchant-8.0.30-150400.4.68.1 * php8-odbc-8.0.30-150400.4.68.1 * php8-pgsql-8.0.30-150400.4.68.1 * php8-soap-8.0.30-150400.4.68.1 * php8-dba-debuginfo-8.0.30-150400.4.68.1 * php8-gettext-8.0.30-150400.4.68.1 * php8-ctype-8.0.30-150400.4.68.1 * php8-snmp-8.0.30-150400.4.68.1 * php8-dom-debuginfo-8.0.30-150400.4.68.1 * php8-tidy-debuginfo-8.0.30-150400.4.68.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.68.1 * php8-snmp-debuginfo-8.0.30-150400.4.68.1 * php8-dom-8.0.30-150400.4.68.1 * php8-xmlwriter-8.0.30-150400.4.68.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.68.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.68.1 * php8-xmlreader-8.0.30-150400.4.68.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.68.1 * php8-pgsql-debuginfo-8.0.30-150400.4.68.1 * php8-sysvmsg-8.0.30-150400.4.68.1 * php8-xsl-debuginfo-8.0.30-150400.4.68.1 * php8-openssl-8.0.30-150400.4.68.1 * php8-fastcgi-8.0.30-150400.4.68.1 * php8-shmop-8.0.30-150400.4.68.1 * php8-8.0.30-150400.4.68.1 * php8-fpm-debugsource-8.0.30-150400.4.68.1 * php8-debugsource-8.0.30-150400.4.68.1 * php8-exif-8.0.30-150400.4.68.1 * php8-iconv-debuginfo-8.0.30-150400.4.68.1 * php8-odbc-debuginfo-8.0.30-150400.4.68.1 * php8-sqlite-8.0.30-150400.4.68.1 * php8-zlib-8.0.30-150400.4.68.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.68.1 * php8-fpm-8.0.30-150400.4.68.1 * php8-sodium-8.0.30-150400.4.68.1 * php8-embed-8.0.30-150400.4.68.1 * php8-soap-debuginfo-8.0.30-150400.4.68.1 * php8-embed-debugsource-8.0.30-150400.4.68.1 * php8-exif-debuginfo-8.0.30-150400.4.68.1 * php8-mysql-debuginfo-8.0.30-150400.4.68.1 * php8-intl-debuginfo-8.0.30-150400.4.68.1 * php8-cli-8.0.30-150400.4.68.1 * php8-iconv-8.0.30-150400.4.68.1 * php8-ldap-debuginfo-8.0.30-150400.4.68.1 * php8-curl-8.0.30-150400.4.68.1 * php8-intl-8.0.30-150400.4.68.1 * php8-posix-8.0.30-150400.4.68.1 * php8-gmp-8.0.30-150400.4.68.1 * php8-gd-8.0.30-150400.4.68.1 * php8-mbstring-8.0.30-150400.4.68.1 * php8-zlib-debuginfo-8.0.30-150400.4.68.1 * php8-cli-debuginfo-8.0.30-150400.4.68.1 * php8-pdo-8.0.30-150400.4.68.1 * php8-mbstring-debuginfo-8.0.30-150400.4.68.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14355.html * https://bugzilla.suse.com/show_bug.cgi?id=1270351 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:28 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:37:28 -0000 Subject: SUSE-SU-2026:2878-1: important: Security update for libpng15 Message-ID: <178396064829.1820.14526146644480613758@530c474df1e7> # Security update for libpng15 Announcement ID: SUSE-SU-2026:2878-1 Release Date: 2026-07-13T09:27:39Z Rating: important References: * bsc#1258020 Cross-References: * CVE-2026-25646 CVSS scores: * CVE-2026-25646 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-25646 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-25646 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25646 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-25646 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libpng15 fixes the following issue * CVE-2026-25646: heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2878=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2878=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpng15-15-debuginfo-1.5.30-10.16.1 * libpng15-debugsource-1.5.30-10.16.1 * libpng15-15-1.5.30-10.16.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpng15-15-debuginfo-1.5.30-10.16.1 * libpng15-debugsource-1.5.30-10.16.1 * libpng15-15-1.5.30-10.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25646.html * https://bugzilla.suse.com/show_bug.cgi?id=1258020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:38:29 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:38:29 -0000 Subject: SUSE-SU-2026:2877-1: important: Security update for ImageMagick Message-ID: <178396070980.1820.9674290843385231327@530c474df1e7> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:2877-1 Release Date: 2026-07-13T09:26:30Z Rating: important References: * bsc#1265048 * bsc#1268092 * bsc#1268094 * bsc#1268095 * bsc#1268096 * bsc#1268101 * bsc#1268102 * bsc#1268103 * bsc#1268105 * bsc#1268107 * bsc#1268108 * bsc#1268110 * bsc#1268111 * bsc#1268112 * bsc#1268113 * bsc#1268114 * bsc#1268116 * bsc#1268117 * bsc#1268120 * bsc#1268121 * bsc#1268122 * bsc#1268123 * bsc#1268124 * bsc#1268125 * bsc#1268126 * bsc#1268640 * bsc#1268645 * bsc#1268878 * bsc#1268879 * bsc#1268880 * bsc#1269063 * bsc#1269064 * bsc#1270001 * bsc#1270002 * bsc#1270003 * bsc#1270004 * bsc#1270073 * bsc#1270074 * bsc#1270077 * bsc#1270079 * bsc#1270080 * bsc#1271099 Cross-References: * CVE-2026-40169 * CVE-2026-42050 * CVE-2026-42326 * CVE-2026-45031 * CVE-2026-45358 * CVE-2026-45359 * CVE-2026-45624 * CVE-2026-45664 * CVE-2026-46520 * CVE-2026-46521 * CVE-2026-46522 * CVE-2026-46523 * CVE-2026-46557 * CVE-2026-46559 * CVE-2026-46692 * CVE-2026-46693 * CVE-2026-47165 * CVE-2026-47166 * CVE-2026-48724 * CVE-2026-48734 * CVE-2026-48994 * CVE-2026-49218 * CVE-2026-53460 * CVE-2026-53461 * CVE-2026-53463 * CVE-2026-53464 * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-55594 * CVE-2026-55595 * CVE-2026-55597 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56364 * CVE-2026-56365 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56370 * CVE-2026-56371 * CVE-2026-56374 * CVE-2026-56376 * CVE-2026-56379 CVSS scores: * CVE-2026-40169 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40169 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42326 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42326 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-42326 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45031 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45031 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45358 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45358 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-45358 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45359 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45359 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45624 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45624 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45664 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45664 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45664 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46520 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46520 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46521 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46557 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46559 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46559 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-46559 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46692 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46692 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46693 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46693 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46693 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-47165 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-47166 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-48724 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48724 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48724 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48734 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48994 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-49218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53460 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53461 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53463 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53463 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-53464 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53464 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53464 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55595 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56364 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56365 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56370 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56370 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56370 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56370 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56374 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56374 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56374 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56376 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56376 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56376 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 42 vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of- bounds read when a crafted image is read (bsc#1270073). * CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). * CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). * CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). * CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). * CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001). * CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002). * CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). * CVE-2026-56374: missing boundary checks can lead to a heap buffer overflow in the FTXT encoder when parsing `ftxt:format` (bsc#1271099). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * CVE-2026-42050: stack buffer overflow via a malicious MIFF file (bsc#1265048). * CVE-2026-42326: out-of-bounds read of single byte via malicious IPTC file (bsc#1268092). * CVE-2026-45031: missing check in the PSD decoder allows bypass of the list- length resource policy when decoding a PSD image (bsc#1268094). * CVE-2026-45358: off-by-one error in the meta encoder can lead to an out-of- bounds read of a single byte (bsc#1268102). * CVE-2026-45359: heap buffer overread via invalid `connected-components` value (bsc#1268095). * CVE-2026-45624: performing a polynomial distortion can lead to an out-of- bounds over-read of 24 bytes (bsc#1268096). * CVE-2026-45664: missing check in the MNG coder can lead to excessive resource use and a DoS (bsc#1268101). * CVE-2026-46520: out-of-bounds write when processing multiple images with different dimensions (bsc#1268112). * CVE-2026-46521: missing check when using LZMA compression in the MIFF encoder can lead to an out-of-bounds write (bsc#1268124). * CVE-2026-46522: missing check in the MIFF decoder can lead to a denial of service via crafted MIFF file (bsc#1268126). * CVE-2026-46523: heap use-after-free via a crafted MSL image (bsc#1268125). * CVE-2026-46557: missing depth check can lead to a stack buffer overflow in the fx operation when processing a crafted argument (bsc#1268123). * CVE-2026-46559: incorrect check in the JP2 can lead to a heap buffer overwrite of a single byte when specifying certain options (bsc#1268121). * CVE-2026-46692: heap buffer overwrite in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). * CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute- cache service (bsc#1268117). * CVE-2026-47165: distributed pixel cache was designed to operate without a challenge-response authentication model (bsc#1268114). * CVE-2026-47166: heap buffer overread in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). * CVE-2026-48724: heap buffer underwrite in the Floyd-Steinberg depth dithering (bsc#1268116). * CVE-2026-48734: missing depth or visited-set check can lead to a stack buffer overflow in the MVG decoder (bsc#1268122). * CVE-2026-48994: missing check of a return value in the MAT decoder can lead to a heap buffer overwrite on 32-bit systems (bsc#1268111). * CVE-2026-49218: missing check in the DCM decoder can lead to a DoS (bsc#1268110). * CVE-2026-53460: missing check for maximum memory request in `AcquireAlignedMemory` can lead to an OOM condition (bsc#1268108). * CVE-2026-53461: incorrect loop in the ICON decoder can lead to an out-of- bounds heap write (bsc#1268107). * CVE-2026-53463: passing incorrect arguments in the distort operation can lead to NULL pointer dereference (bsc#1268105). * CVE-2026-53464: providing invalid options to the wand option parser can lead to a memory leak (bsc#1268103). * CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path can lead to an heap out-of-bounds read (bsc#1268645). * CVE-2026-56368: improper memory management can lead to memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing `connected-components:*` artifacts with invalid indices (bsc#1269063). * CVE-2026-56371: memory leak in `coders/txt.c` when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2877=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2877=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-debugsource-7.1.1.43-150700.3.65.1 * libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.65.1 * libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.65.1 * libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.65.1 * libMagick++-devel-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.65.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-SUSE-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.65.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-devel-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.65.1 * ImageMagick-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.65.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-debugsource-7.1.1.43-150700.3.65.1 * perl-PerlMagick-debuginfo-7.1.1.43-150700.3.65.1 * perl-PerlMagick-7.1.1.43-150700.3.65.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40169.html * https://www.suse.com/security/cve/CVE-2026-42050.html * https://www.suse.com/security/cve/CVE-2026-42326.html * https://www.suse.com/security/cve/CVE-2026-45031.html * https://www.suse.com/security/cve/CVE-2026-45358.html * https://www.suse.com/security/cve/CVE-2026-45359.html * https://www.suse.com/security/cve/CVE-2026-45624.html * https://www.suse.com/security/cve/CVE-2026-45664.html * https://www.suse.com/security/cve/CVE-2026-46520.html * https://www.suse.com/security/cve/CVE-2026-46521.html * https://www.suse.com/security/cve/CVE-2026-46522.html * https://www.suse.com/security/cve/CVE-2026-46523.html * https://www.suse.com/security/cve/CVE-2026-46557.html * https://www.suse.com/security/cve/CVE-2026-46559.html * https://www.suse.com/security/cve/CVE-2026-46692.html * https://www.suse.com/security/cve/CVE-2026-46693.html * https://www.suse.com/security/cve/CVE-2026-47165.html * https://www.suse.com/security/cve/CVE-2026-47166.html * https://www.suse.com/security/cve/CVE-2026-48724.html * https://www.suse.com/security/cve/CVE-2026-48734.html * https://www.suse.com/security/cve/CVE-2026-48994.html * https://www.suse.com/security/cve/CVE-2026-49218.html * https://www.suse.com/security/cve/CVE-2026-53460.html * https://www.suse.com/security/cve/CVE-2026-53461.html * https://www.suse.com/security/cve/CVE-2026-53463.html * https://www.suse.com/security/cve/CVE-2026-53464.html * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-55594.html * https://www.suse.com/security/cve/CVE-2026-55595.html * https://www.suse.com/security/cve/CVE-2026-55597.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56364.html * https://www.suse.com/security/cve/CVE-2026-56365.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56370.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56374.html * https://www.suse.com/security/cve/CVE-2026-56376.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1265048 * https://bugzilla.suse.com/show_bug.cgi?id=1268092 * https://bugzilla.suse.com/show_bug.cgi?id=1268094 * https://bugzilla.suse.com/show_bug.cgi?id=1268095 * https://bugzilla.suse.com/show_bug.cgi?id=1268096 * https://bugzilla.suse.com/show_bug.cgi?id=1268101 * https://bugzilla.suse.com/show_bug.cgi?id=1268102 * https://bugzilla.suse.com/show_bug.cgi?id=1268103 * https://bugzilla.suse.com/show_bug.cgi?id=1268105 * https://bugzilla.suse.com/show_bug.cgi?id=1268107 * https://bugzilla.suse.com/show_bug.cgi?id=1268108 * https://bugzilla.suse.com/show_bug.cgi?id=1268110 * https://bugzilla.suse.com/show_bug.cgi?id=1268111 * https://bugzilla.suse.com/show_bug.cgi?id=1268112 * https://bugzilla.suse.com/show_bug.cgi?id=1268113 * https://bugzilla.suse.com/show_bug.cgi?id=1268114 * https://bugzilla.suse.com/show_bug.cgi?id=1268116 * https://bugzilla.suse.com/show_bug.cgi?id=1268117 * https://bugzilla.suse.com/show_bug.cgi?id=1268120 * https://bugzilla.suse.com/show_bug.cgi?id=1268121 * https://bugzilla.suse.com/show_bug.cgi?id=1268122 * https://bugzilla.suse.com/show_bug.cgi?id=1268123 * https://bugzilla.suse.com/show_bug.cgi?id=1268124 * https://bugzilla.suse.com/show_bug.cgi?id=1268125 * https://bugzilla.suse.com/show_bug.cgi?id=1268126 * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1268880 * https://bugzilla.suse.com/show_bug.cgi?id=1269063 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270003 * https://bugzilla.suse.com/show_bug.cgi?id=1270004 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 * https://bugzilla.suse.com/show_bug.cgi?id=1270077 * https://bugzilla.suse.com/show_bug.cgi?id=1270079 * https://bugzilla.suse.com/show_bug.cgi?id=1270080 * https://bugzilla.suse.com/show_bug.cgi?id=1271099 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:38:40 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:38:40 -0000 Subject: SUSE-SU-2026:2875-1: important: Security update for python-Pillow Message-ID: <178396072030.1820.9161986812693486043@530c474df1e7> # Security update for python-Pillow Announcement ID: SUSE-SU-2026:2875-1 Release Date: 2026-07-13T09:12:44Z Rating: important References: * bsc#1270409 * bsc#1270410 * bsc#1270411 * bsc#1270412 Cross-References: * CVE-2026-54059 * CVE-2026-54060 * CVE-2026-55379 * CVE-2026-55380 CVSS scores: * CVE-2026-54059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues * CVE-2026-54059: crafted PCF font data can cause excessive memory allocation (bsc#1270409). * CVE-2026-54060: a font can trigger excessive allocation during conversion or saving (bsc#1270410). * CVE-2026-55379: bypass of decompression bomb protection, allowing excessive memory allocation (bsc#1270411). * CVE-2026-55380: crafted .gd file can trigger excessive C-heap allocation when loaded (bsc#1270412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2875=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2875=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * python-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-debuginfo-7.2.0-150300.3.27.1 * python-Pillow-debugsource-7.2.0-150300.3.27.1 * python3-Pillow-7.2.0-150300.3.27.1 * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * python-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-tk-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-7.2.0-150300.3.27.1 * python3-Pillow-tk-7.2.0-150300.3.27.1 * python-Pillow-debugsource-7.2.0-150300.3.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54059.html * https://www.suse.com/security/cve/CVE-2026-54060.html * https://www.suse.com/security/cve/CVE-2026-55379.html * https://www.suse.com/security/cve/CVE-2026-55380.html * https://bugzilla.suse.com/show_bug.cgi?id=1270409 * https://bugzilla.suse.com/show_bug.cgi?id=1270410 * https://bugzilla.suse.com/show_bug.cgi?id=1270411 * https://bugzilla.suse.com/show_bug.cgi?id=1270412 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:38:45 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:38:45 -0000 Subject: SUSE-SU-2026:2874-1: moderate: Security update for sccache Message-ID: <178396072591.1820.2561168108760090455@530c474df1e7> # Security update for sccache Announcement ID: SUSE-SU-2026:2874-1 Release Date: 2026-07-13T09:11:08Z Rating: moderate References: * bsc#1270206 Cross-References: * CVE-2026-41676 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for sccache fixes the following issue * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270206). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2874=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * sccache-0.4.2~4-150400.3.12.1 * sccache-debuginfo-0.4.2~4-150400.3.12.1 * sccache-debugsource-0.4.2~4-150400.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:38:52 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 16:38:52 -0000 Subject: SUSE-RU-2026:2871-1: moderate: Recommended update for grub2 Message-ID: <178396073219.1820.14059912780691982905@530c474df1e7> # Recommended update for grub2 Announcement ID: SUSE-RU-2026:2871-1 Release Date: 2026-07-13T08:57:13Z Rating: moderate References: * bsc#1259543 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has one fix can now be installed. ## Description: This update for grub2 fixes the following issues: * Fix double free in xen booting if root filesystem is Btrfs (bsc#1259543) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2871=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2871=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * grub2-i386-pc-2.02-199.1 * grub2-x86_64-efi-2.02-199.1 * grub2-debugsource-2.02-199.1 * grub2-debuginfo-2.02-199.1 * grub2-2.02-199.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * grub2-systemd-sleep-plugin-2.02-199.1 * grub2-snapper-plugin-2.02-199.1 * grub2-x86_64-xen-2.02-199.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * grub2-systemd-sleep-plugin-2.02-199.1 * grub2-snapper-plugin-2.02-199.1 * grub2-x86_64-xen-2.02-199.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64) * grub2-arm64-efi-2.02-199.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * grub2-debuginfo-2.02-199.1 * grub2-2.02-199.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * grub2-i386-pc-2.02-199.1 * grub2-x86_64-efi-2.02-199.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le) * grub2-powerpc-ieee1275-2.02-199.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 s390x x86_64) * grub2-debugsource-2.02-199.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x) * grub2-s390x-emu-2.02-199.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1259543 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:31:42 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 20:31:42 -0000 Subject: SUSE-SU-2026:2914-1: important: Security update for the Linux Kernel Message-ID: <178397470210.1786.15035383718767768123@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2914-1 Release Date: 2026-07-13T14:56:44Z Rating: important References: * bsc#1255616 * bsc#1259891 * bsc#1261604 * bsc#1262655 * bsc#1262674 * bsc#1263072 * bsc#1263123 * bsc#1263169 * bsc#1263560 * bsc#1263563 * bsc#1263573 * bsc#1263993 * bsc#1263996 * bsc#1264033 * bsc#1264039 * bsc#1264065 * bsc#1264073 * bsc#1264088 * bsc#1264236 * bsc#1264254 * bsc#1264261 * bsc#1264294 * bsc#1264337 * bsc#1264414 * bsc#1264437 * bsc#1264449 * bsc#1264618 * bsc#1264734 * bsc#1264748 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266397 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1266971 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267473 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267920 * bsc#1267968 * bsc#1267993 * bsc#1268037 * bsc#1269033 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269137 * bsc#1269159 * bsc#1269195 * bsc#1269386 * bsc#1269397 * bsc#1269398 * bsc#1269506 * bsc#1269574 * bsc#1269690 * bsc#1269786 * bsc#1269904 * bsc#1270059 Cross-References: * CVE-2023-53995 * CVE-2026-23255 * CVE-2026-23451 * CVE-2026-31462 * CVE-2026-31499 * CVE-2026-31502 * CVE-2026-31580 * CVE-2026-31592 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-31680 * CVE-2026-31773 * CVE-2026-31781 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43043 * CVE-2026-43047 * CVE-2026-43051 * CVE-2026-43080 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43112 * CVE-2026-43117 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43279 * CVE-2026-43284 * CVE-2026-43336 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-45840 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45960 * CVE-2026-46028 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46082 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46275 * CVE-2026-46299 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52954 * CVE-2026-52955 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52972 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53075 * CVE-2026-53148 * CVE-2026-53150 * CVE-2026-53194 * CVE-2026-53253 * CVE-2026-53287 * CVE-2026-53359 CVSS scores: * CVE-2023-53995 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-53995 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23255 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23255 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23255 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31580 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31773 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31773 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31781 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31781 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43043 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43043 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43043 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43047 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43047 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43051 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43117 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43117 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43117 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43279 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43279 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45960 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45960 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45960 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46082 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46082 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46275 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46299 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53148 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53148 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53148 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53148 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53150 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53150 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53150 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53194 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53194 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53194 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 65 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616). * CVE-2026-23255: net: add proper RCU protection to /proc/net/ptype (bsc#1259891). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31773: Bluetooth: SMP: derive legacy responder STK authentication from MITM state (bsc#1264039). * CVE-2026-31781: drm/ioc32: stop speculation on the drm_compat_ioctl path (bsc#1264033). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43043: crypto: af-alg - fix NULL pointer dereference in scatterwalk (bsc#1264088). * CVE-2026-43047: HID: multitouch: Check to ensure report responses match the request (bsc#1264073). * CVE-2026-43051: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (bsc#1264065). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43117: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (bsc#1264414). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43279: ALSA: usb-audio: Add sanity check for OOB writes at silencing (bsc#1264618). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45960: hfsplus: return error when node already exists in hfs_bnode_create (bsc#1266971). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46082: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (bsc#1267473). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46275: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (bsc#1267968). * CVE-2026-46299: hfsplus: fix held lock freed on hfsplus_fill_super() (bsc#1267920). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53148: thunderbolt: Clamp XDomain response data copy to allocation size (bsc#1269786). * CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator (bsc#1269386). * CVE-2026-53194: USB: serial: kl5kusb105: fix bulk-out buffer overflow (bsc#1269904). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). The following non security issues were fixed: * btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (git-fixes). * libceph: add non-asserting rbtree insertion helper (bsc#1269137). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2914=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2914=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2914=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * kernel-default-devel-debuginfo-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gfs2-kmp-default-debuginfo-4.12.14-122.320.1 * cluster-md-kmp-default-4.12.14-122.320.1 * kernel-syms-4.12.14-122.320.1 * ocfs2-kmp-default-debuginfo-4.12.14-122.320.1 * gfs2-kmp-default-4.12.14-122.320.1 * ocfs2-kmp-default-4.12.14-122.320.1 * dlm-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-default-debuginfo-4.12.14-122.320.1 * dlm-kmp-default-4.12.14-122.320.1 * cluster-md-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-default-base-debuginfo-4.12.14-122.320.1 * kernel-default-debugsource-4.12.14-122.320.1 * kernel-default-base-4.12.14-122.320.1 * kernel-default-devel-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * kernel-source-4.12.14-122.320.1 * kernel-macros-4.12.14-122.320.1 * kernel-devel-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x) * kernel-default-man-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * cluster-md-kmp-default-4.12.14-122.320.1 * kernel-default-devel-debuginfo-4.12.14-122.320.1 * gfs2-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-syms-4.12.14-122.320.1 * ocfs2-kmp-default-debuginfo-4.12.14-122.320.1 * dlm-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-default-debuginfo-4.12.14-122.320.1 * gfs2-kmp-default-4.12.14-122.320.1 * ocfs2-kmp-default-4.12.14-122.320.1 * dlm-kmp-default-4.12.14-122.320.1 * cluster-md-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-default-base-debuginfo-4.12.14-122.320.1 * kernel-default-debugsource-4.12.14-122.320.1 * kernel-default-base-4.12.14-122.320.1 * kernel-default-devel-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * kernel-macros-4.12.14-122.320.1 * kernel-source-4.12.14-122.320.1 * kernel-devel-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (nosrc x86_64) * kernel-default-4.12.14-122.320.1 * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kernel-default-kgraft-4.12.14-122.320.1 * kgraft-patch-4_12_14-122_320-default-1-8.3.1 * kernel-default-kgraft-devel-4.12.14-122.320.1 * kernel-default-debuginfo-4.12.14-122.320.1 * kernel-default-debugsource-4.12.14-122.320.1 * SUSE Linux Enterprise Live Patching 12-SP5 (nosrc) * kernel-default-4.12.14-122.320.1 ## References: * https://www.suse.com/security/cve/CVE-2023-53995.html * https://www.suse.com/security/cve/CVE-2026-23255.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31580.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31773.html * https://www.suse.com/security/cve/CVE-2026-31781.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43043.html * https://www.suse.com/security/cve/CVE-2026-43047.html * https://www.suse.com/security/cve/CVE-2026-43051.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43117.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43279.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45960.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46082.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46275.html * https://www.suse.com/security/cve/CVE-2026-46299.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53148.html * https://www.suse.com/security/cve/CVE-2026-53150.html * https://www.suse.com/security/cve/CVE-2026-53194.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1255616 * https://bugzilla.suse.com/show_bug.cgi?id=1259891 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263169 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264033 * https://bugzilla.suse.com/show_bug.cgi?id=1264039 * https://bugzilla.suse.com/show_bug.cgi?id=1264065 * https://bugzilla.suse.com/show_bug.cgi?id=1264073 * https://bugzilla.suse.com/show_bug.cgi?id=1264088 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264414 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264618 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1266971 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267473 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267920 * https://bugzilla.suse.com/show_bug.cgi?id=1267968 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269386 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269786 * https://bugzilla.suse.com/show_bug.cgi?id=1269904 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:31:56 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 20:31:56 -0000 Subject: SUSE-SU-2026:2909-1: important: Security update for the Linux Kernel (Live Patch 72 for SUSE Linux Enterprise 12 SP5) Message-ID: <178397471696.1786.13471614666242249178@57e59d802799> # Security update for the Linux Kernel (Live Patch 72 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2909-1 Release Date: 2026-07-13T14:16:52Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.272 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2909=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_272-default-14-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:32:31 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 20:32:31 -0000 Subject: SUSE-SU-2026:2910-1: important: Security update for the Linux Kernel (Live Patch 47 for SUSE Linux Enterprise 15 SP4) Message-ID: <178397475196.1786.12901912530211342420@57e59d802799> # Security update for the Linux Kernel (Live Patch 47 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2910-1 Release Date: 2026-07-13T14:17:06Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.187 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2910=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2900=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2910=1 SUSE-2026-2900=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_187-default-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-10-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_187-default-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-10-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:33:09 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 20:33:09 -0000 Subject: SUSE-SU-2026:2899-1: important: Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP5) Message-ID: <178397478966.1786.9753620381169554749@57e59d802799> # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2899-1 Release Date: 2026-07-13T12:33:59Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.110 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2899=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2899=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-21-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-21-150500.2.2 * kernel-livepatch-5_14_21-150500_55_110-default-21-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-21-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-21-150500.2.2 * kernel-livepatch-5_14_21-150500_55_110-default-21-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:33:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 13 Jul 2026 20:33:49 -0000 Subject: SUSE-SU-2026:2902-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Message-ID: <178397482999.1786.12291038219908296373@57e59d802799> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2902-1 Release Date: 2026-07-13T15:45:10Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.28 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2911=1 SUSE-2026-2913=1 SUSE-2026-2912=1 SUSE-2026-2917=1 SUSE-2026-2908=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2916=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2915=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2902=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2906=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2904=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2898=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2903=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2905=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2901=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2907=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2908=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2911=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-2913=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-2912=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-2917=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_22-rt-10-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_2-debugsource-18-150700.2.1 * kernel-livepatch-6_4_0-150700_7_13-rt-14-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_1-debugsource-19-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_5-debugsource-11-150700.2.1 * kernel-livepatch-6_4_0-150700_5-rt-19-150700.3.1 * kernel-livepatch-6_4_0-150700_7_25-rt-debuginfo-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_22-rt-debuginfo-10-150700.2.1 * kernel-livepatch-6_4_0-150700_7_19-rt-debuginfo-11-150700.2.1 * kernel-livepatch-6_4_0-150700_7_8-rt-18-150700.2.1 * kernel-livepatch-6_4_0-150700_5-rt-debuginfo-19-150700.3.1 * kernel-livepatch-SLE15-SP7-RT_Update_3-debugsource-14-150700.2.1 * kernel-livepatch-6_4_0-150700_7_16-rt-debuginfo-14-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_0-debugsource-19-150700.3.1 * kernel-livepatch-SLE15-SP7-RT_Update_4-debugsource-14-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_6-debugsource-10-150700.2.1 * kernel-livepatch-6_4_0-150700_7_13-rt-debuginfo-14-150700.2.1 * kernel-livepatch-6_4_0-150700_7_8-rt-debuginfo-18-150700.2.1 * kernel-livepatch-6_4_0-150700_7_25-rt-9-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_7-debugsource-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_16-rt-14-150700.2.1 * kernel-livepatch-6_4_0-150700_7_3-rt-debuginfo-19-150700.2.1 * kernel-livepatch-6_4_0-150700_7_19-rt-11-150700.2.1 * kernel-livepatch-6_4_0-150700_7_3-rt-19-150700.2.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_28-default-debuginfo-9-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_8-debugsource-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_25-default-9-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_7-debugsource-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_25-default-debuginfo-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_28-default-9-150700.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_17-debugsource-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-11-150600.2.2 * kernel-livepatch-6_4_0-150600_23_73-default-11-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_16-debugsource-11-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_13-debugsource-18-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_19-debugsource-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_65-default-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_78-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-18-150600.2.2 * kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_84-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_60-default-18-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_17-debugsource-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-11-150600.2.2 * kernel-livepatch-6_4_0-150600_23_73-default-11-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_16-debugsource-11-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_19-debugsource-9-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_13-debugsource-18-150600.2.2 * kernel-livepatch-6_4_0-150600_23_65-default-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_78-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-18-150600.2.2 * kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_84-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_60-default-18-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:30:49 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:30:49 -0000 Subject: SUSE-SU-2026:2933-1: important: Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP5) Message-ID: <178401784937.27.7519326309970386333@178315a69387> # Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2933-1 Release Date: 2026-07-13T19:10:43Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.113 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2933=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2933=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_113-default-20-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-20-150500.2.2 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-20-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_113-default-20-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-20-150500.2.2 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-20-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:31:26 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:31:26 -0000 Subject: SUSE-SU-2026:2932-1: important: Security update for the Linux Kernel (Live Patch 50 for SUSE Linux Enterprise 15 SP4) Message-ID: <178401788698.27.6197172630248029697@178315a69387> # Security update for the Linux Kernel (Live Patch 50 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2932-1 Release Date: 2026-07-13T20:00:29Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.200 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2934=1 SUSE-2026-2935=1 SUSE-2026-2932=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2934=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2935=1 SUSE-SLE-Module-Live- Patching-15-SP4-2026-2932=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-8-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_48-debugsource-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_50-debugsource-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-6-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-8-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_48-debugsource-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_50-debugsource-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-6-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:32:11 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:32:11 -0000 Subject: SUSE-SU-2026:2920-1: important: Security update for the Linux Kernel (Live Patch 43 for SUSE Linux Enterprise 15 SP4) Message-ID: <178401793102.27.13463760347394908612@178315a69387> # Security update for the Linux Kernel (Live Patch 43 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2920-1 Release Date: 2026-07-13T16:50:39Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.173 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2920=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2920=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-17-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-17-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_43-debugsource-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-17-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:32:56 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:32:56 -0000 Subject: SUSE-SU-2026:2930-1: important: Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 15 SP7) Message-ID: <178401797601.27.11867398267379153741@178315a69387> # Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2930-1 Release Date: 2026-07-13T18:35:20Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.19 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2927=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2928=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2919=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2918=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2930=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2929=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2921=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_1-debugsource-19-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_6-debugsource-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_6-default-18-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_5-debugsource-11-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_4-debugsource-14-150700.2.2 * kernel-livepatch-6_4_0-150700_51-default-19-150700.3.54.1 * kernel-livepatch-SLE15-SP7_Update_0-debugsource-19-150700.3.54.1 * kernel-livepatch-6_4_0-150700_53_11-default-debuginfo-14-150700.2.2 * kernel-livepatch-6_4_0-150700_53_3-default-19-150700.2.2 * kernel-livepatch-6_4_0-150700_53_16-default-14-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_2-debugsource-18-150700.2.2 * kernel-livepatch-6_4_0-150700_53_16-default-debuginfo-14-150700.2.2 * kernel-livepatch-6_4_0-150700_53_11-default-14-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_3-debugsource-14-150700.2.2 * kernel-livepatch-6_4_0-150700_53_6-default-debuginfo-18-150700.2.2 * kernel-livepatch-6_4_0-150700_51-default-debuginfo-19-150700.3.54.1 * kernel-livepatch-6_4_0-150700_53_19-default-debuginfo-11-150700.2.2 * kernel-livepatch-6_4_0-150700_53_22-default-debuginfo-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_3-default-debuginfo-19-150700.2.2 * kernel-livepatch-6_4_0-150700_53_19-default-11-150700.2.2 * kernel-livepatch-6_4_0-150700_53_22-default-9-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:33:02 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:33:02 -0000 Subject: SUSE-SU-2026:2931-1: moderate: Security update for libslirp Message-ID: <178401798286.27.16481640667384290696@178315a69387> # Security update for libslirp Announcement ID: SUSE-SU-2026:2931-1 Release Date: 2026-07-13T18:43:58Z Rating: moderate References: * bsc#1268903 Cross-References: * CVE-2026-9539 CVSS scores: * CVE-2026-9539 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9539 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libslirp fixes the following issues: * CVE-2026-9539: TCP URG out of bounds heap read information leak (bsc#1268903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2931=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2931=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2931=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libslirp-devel-4.7.0+44-150500.4.3.1 * libslirp-debugsource-4.7.0+44-150500.4.3.1 * libslirp0-debuginfo-4.7.0+44-150500.4.3.1 * libslirp0-4.7.0+44-150500.4.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libslirp-devel-4.7.0+44-150500.4.3.1 * libslirp0-debuginfo-4.7.0+44-150500.4.3.1 * libslirp0-4.7.0+44-150500.4.3.1 * libslirp-debugsource-4.7.0+44-150500.4.3.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libslirp0-4.7.0+44-150500.4.3.1 * libslirp-debugsource-4.7.0+44-150500.4.3.1 * libslirp0-debuginfo-4.7.0+44-150500.4.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9539.html * https://bugzilla.suse.com/show_bug.cgi?id=1268903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:33:23 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:33:23 -0000 Subject: SUSE-SU-2026:2926-1: important: Security update for curl Message-ID: <178401800367.27.7801133166853182239@178315a69387> # Security update for curl Announcement ID: SUSE-SU-2026:2926-1 Release Date: 2026-07-13T17:55:14Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2926=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2926=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2926=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * curl-mini-debugsource-8.14.1-150600.4.46.1 * libcurl4-8.14.1-150600.4.46.1 * libcurl-mini4-8.14.1-150600.4.46.1 * curl-8.14.1-150600.4.46.1 * libcurl4-debuginfo-8.14.1-150600.4.46.1 * libcurl-mini4-debuginfo-8.14.1-150600.4.46.1 * curl-debugsource-8.14.1-150600.4.46.1 * curl-debuginfo-8.14.1-150600.4.46.1 * libcurl-devel-8.14.1-150600.4.46.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libcurl-devel-64bit-8.14.1-150600.4.46.1 * libcurl4-64bit-8.14.1-150600.4.46.1 * libcurl4-64bit-debuginfo-8.14.1-150600.4.46.1 * openSUSE Leap 15.6 (x86_64) * libcurl4-32bit-8.14.1-150600.4.46.1 * libcurl-devel-32bit-8.14.1-150600.4.46.1 * libcurl4-32bit-debuginfo-8.14.1-150600.4.46.1 * openSUSE Leap 15.6 (noarch) * curl-zsh-completion-8.14.1-150600.4.46.1 * libcurl-devel-doc-8.14.1-150600.4.46.1 * curl-fish-completion-8.14.1-150600.4.46.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150600.4.46.1 * curl-8.14.1-150600.4.46.1 * libcurl4-debuginfo-8.14.1-150600.4.46.1 * curl-debugsource-8.14.1-150600.4.46.1 * libcurl-devel-8.14.1-150600.4.46.1 * curl-debuginfo-8.14.1-150600.4.46.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libcurl4-32bit-8.14.1-150600.4.46.1 * libcurl4-32bit-debuginfo-8.14.1-150600.4.46.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libcurl4-8.14.1-150600.4.46.1 * curl-8.14.1-150600.4.46.1 * libcurl4-debuginfo-8.14.1-150600.4.46.1 * curl-debugsource-8.14.1-150600.4.46.1 * curl-debuginfo-8.14.1-150600.4.46.1 * libcurl-devel-8.14.1-150600.4.46.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.46.1 * libcurl4-32bit-8.14.1-150600.4.46.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:33:45 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:33:45 -0000 Subject: SUSE-SU-2026:2925-1: important: Security update for curl Message-ID: <178401802593.27.11859785075875369558@178315a69387> # Security update for curl Announcement ID: SUSE-SU-2026:2925-1 Release Date: 2026-07-13T17:53:33Z Rating: important References: * bsc#1262631 * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-4873 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4873 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-4873 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-4873 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2925=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libcurl-devel-8.14.1-150700.7.20.1 * curl-8.14.1-150700.7.20.1 * libcurl4-debuginfo-8.14.1-150700.7.20.1 * curl-debuginfo-8.14.1-150700.7.20.1 * libcurl4-8.14.1-150700.7.20.1 * curl-debugsource-8.14.1-150700.7.20.1 * Basesystem Module 15-SP7 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150700.7.20.1 * libcurl4-32bit-8.14.1-150700.7.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-4873.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1262631 * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:33:59 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:33:59 -0000 Subject: SUSE-SU-2026:2924-1: moderate: Security update for gnutls Message-ID: <178401803966.27.10441819834887728452@178315a69387> # Security update for gnutls Announcement ID: SUSE-SU-2026:2924-1 Release Date: 2026-07-13T17:51:20Z Rating: moderate References: * bsc#1263707 * bsc#1263710 * bsc#1263712 * bsc#1263713 * bsc#1263714 * bsc#1263715 Cross-References: * CVE-2026-3833 * CVE-2026-42011 * CVE-2026-42013 * CVE-2026-42014 * CVE-2026-42015 * CVE-2026-5260 CVSS scores: * CVE-2026-3833 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3833 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3833 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-3833 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42011 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42013 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42013 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42014 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42014 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42014 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-42015 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42015 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-42015 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5260 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-5260 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5260 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for gnutls fixes the following issues * CVE-2026-3833: incorrectly accepted domain names due to comparison during name constraints processing being case-sensitive (bsc#1263707). * CVE-2026-5260: heap overread when processing extremely short premaster secret as part of an RSA key exchange (bsc#1263715). * CVE-2026-42011: name constraint bypass leading to acceptance of invalid certificates during certificate validation (bsc#1263710). * CVE-2026-42013: certificate validation bypass when validating certificates with an oversized SAN (bsc#1263712). * CVE-2026-42014: use-after-free when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path (bsc#1263713). * CVE-2026-42015: memory corruption when appending to a PKCS#12 bag that already contains 32 elements (bsc#1263714). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2924=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libgnutls-openssl27-3.3.27-3.21.1 * libgnutls-devel-3.3.27-3.21.1 * libgnutls28-32bit-3.3.27-3.21.1 * libgnutls28-3.3.27-3.21.1 * gnutls-debugsource-3.3.27-3.21.1 * gnutls-3.3.27-3.21.1 * gnutls-debuginfo-3.3.27-3.21.1 * libgnutls28-debuginfo-32bit-3.3.27-3.21.1 * libgnutls-openssl27-debuginfo-3.3.27-3.21.1 * libgnutls28-debuginfo-3.3.27-3.21.1 * libgnutlsxx-devel-3.3.27-3.21.1 * libgnutls-openssl-devel-3.3.27-3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3833.html * https://www.suse.com/security/cve/CVE-2026-42011.html * https://www.suse.com/security/cve/CVE-2026-42013.html * https://www.suse.com/security/cve/CVE-2026-42014.html * https://www.suse.com/security/cve/CVE-2026-42015.html * https://www.suse.com/security/cve/CVE-2026-5260.html * https://bugzilla.suse.com/show_bug.cgi?id=1263707 * https://bugzilla.suse.com/show_bug.cgi?id=1263710 * https://bugzilla.suse.com/show_bug.cgi?id=1263712 * https://bugzilla.suse.com/show_bug.cgi?id=1263713 * https://bugzilla.suse.com/show_bug.cgi?id=1263714 * https://bugzilla.suse.com/show_bug.cgi?id=1263715 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:34:12 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:34:12 -0000 Subject: SUSE-SU-2026:2923-1: moderate: Security update for gnutls Message-ID: <178401805293.27.474161642196413036@178315a69387> # Security update for gnutls Announcement ID: SUSE-SU-2026:2923-1 Release Date: 2026-07-13T17:49:40Z Rating: moderate References: * bsc#1263707 * bsc#1263710 * bsc#1263712 * bsc#1263713 * bsc#1263714 * bsc#1263715 Cross-References: * CVE-2026-3833 * CVE-2026-42011 * CVE-2026-42013 * CVE-2026-42014 * CVE-2026-42015 * CVE-2026-5260 CVSS scores: * CVE-2026-3833 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3833 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3833 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-3833 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42011 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42013 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42013 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42014 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42014 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42014 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-42015 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42015 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-42015 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5260 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-5260 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5260 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for gnutls fixes the following issues * CVE-2026-3833: incorrectly accepted domain names due to comparison during name constraints processing being case-sensitive (bsc#1263707). * CVE-2026-5260: heap overread when processing extremely short premaster secret as part of an RSA key exchange (bsc#1263715). * CVE-2026-42011: name constraint bypass leading to acceptance of invalid certificates during certificate validation (bsc#1263710). * CVE-2026-42013: certificate validation bypass when validating certificates with an oversized SAN (bsc#1263712). * CVE-2026-42014: use-after-free when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path (bsc#1263713). * CVE-2026-42015: memory corruption when appending to a PKCS#12 bag that already contains 32 elements (bsc#1263714). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2923=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gnutls-debugsource-3.4.17-8.26.1 * libgnutls30-debuginfo-32bit-3.4.17-8.26.1 * libgnutls30-3.4.17-8.26.1 * libgnutls30-debuginfo-3.4.17-8.26.1 * libgnutls30-32bit-3.4.17-8.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3833.html * https://www.suse.com/security/cve/CVE-2026-42011.html * https://www.suse.com/security/cve/CVE-2026-42013.html * https://www.suse.com/security/cve/CVE-2026-42014.html * https://www.suse.com/security/cve/CVE-2026-42015.html * https://www.suse.com/security/cve/CVE-2026-5260.html * https://bugzilla.suse.com/show_bug.cgi?id=1263707 * https://bugzilla.suse.com/show_bug.cgi?id=1263710 * https://bugzilla.suse.com/show_bug.cgi?id=1263712 * https://bugzilla.suse.com/show_bug.cgi?id=1263713 * https://bugzilla.suse.com/show_bug.cgi?id=1263714 * https://bugzilla.suse.com/show_bug.cgi?id=1263715 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:34:23 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 08:34:23 -0000 Subject: SUSE-SU-2026:2922-1: low: Security update for patch Message-ID: <178401806319.27.14384344719110608623@178315a69387> # Security update for patch Announcement ID: SUSE-SU-2026:2922-1 Release Date: 2026-07-13T17:47:13Z Rating: low References: * bsc#1194037 * bsc#1271166 * bsc#1271167 Cross-References: * CVE-2021-45261 * CVE-2026-56288 * CVE-2026-56289 CVSS scores: * CVE-2021-45261 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2021-45261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56288 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56288 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56289 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2026-56289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56289 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56289 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for patch fixes the following issues * CVE-2021-45261: Invalid Pointer via another_hunk function (bsc#1194037). * CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167). * CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2922=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * patch-2.7.5-8.14.1 * patch-debugsource-2.7.5-8.14.1 * patch-debuginfo-2.7.5-8.14.1 ## References: * https://www.suse.com/security/cve/CVE-2021-45261.html * https://www.suse.com/security/cve/CVE-2026-56288.html * https://www.suse.com/security/cve/CVE-2026-56289.html * https://bugzilla.suse.com/show_bug.cgi?id=1194037 * https://bugzilla.suse.com/show_bug.cgi?id=1271166 * https://bugzilla.suse.com/show_bug.cgi?id=1271167 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:30:49 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 12:30:49 -0000 Subject: SUSE-SU-2026:2945-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Message-ID: <178403224936.94.2980103811413923306@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2945-1 Release Date: 2026-07-14T06:15:48Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.34 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2946=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2945=1 SUSE-2026-2944=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2944=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2945=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_25-debugsource-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_103-default-4-150600.2.2 * kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_109-default-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-4-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_24-debugsource-4-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_25-debugsource-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_103-default-4-150600.2.2 * kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_109-default-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-4-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_24-debugsource-4-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_34-default-6-150700.2.2 * kernel-livepatch-6_4_0-150700_53_34-default-debuginfo-6-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_10-debugsource-6-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:31:31 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 12:31:31 -0000 Subject: SUSE-SU-2026:2943-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Message-ID: <178403229126.94.18327938015006109736@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2943-1 Release Date: 2026-07-14T06:15:15Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.52 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2943=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_14-debugsource-3-150700.2.2 * kernel-livepatch-6_4_0-150700_53_52-default-3-150700.2.2 * kernel-livepatch-6_4_0-150700_53_52-default-debuginfo-3-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:32:09 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 12:32:09 -0000 Subject: SUSE-SU-2026:2938-1: important: Security update for the Linux Kernel (Live Patch 38 for SUSE Linux Enterprise 15 SP5) Message-ID: <178403232998.94.13605361483608111765@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 38 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2938-1 Release Date: 2026-07-14T04:32:24Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.149 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2940=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-2941=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-2938=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-2939=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2940=1 SUSE-2026-2941=1 SUSE-2026-2938=1 SUSE-2026-2939=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-5-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_35-debugsource-9-150500.2.2 * kernel-livepatch-5_14_21-150500_55_149-default-5-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_136-default-9-150500.2.2 * kernel-livepatch-5_14_21-150500_55_144-default-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_141-default-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_38-debugsource-5-150500.2.2 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-9-150500.2.2 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-5-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_35-debugsource-9-150500.2.2 * kernel-livepatch-5_14_21-150500_55_149-default-5-150500.2.2 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_136-default-9-150500.2.2 * kernel-livepatch-5_14_21-150500_55_144-default-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_141-default-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_38-debugsource-5-150500.2.2 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-9-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:32:45 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 12:32:45 -0000 Subject: SUSE-SU-2026:2937-1: important: Security update for the Linux Kernel (Live Patch 53 for SUSE Linux Enterprise 15 SP4) Message-ID: <178403236529.94.14173332741964328351@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 53 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2937-1 Release Date: 2026-07-13T21:16:08Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.214 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2937=1 SUSE-2026-2936=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2937=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2936=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_214-default-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-3-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_214-default-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-3-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:32:49 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 12:32:49 -0000 Subject: SUSE-SU-2026:2942-1: important: Security update for kubernetes Message-ID: <178403236988.94.9600491523200604843@1437f03ce14a> # Security update for kubernetes Announcement ID: SUSE-SU-2026:2942-1 Release Date: 2026-07-14T06:10:19Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for kubernetes rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2942=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2942=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * kubernetes1.35-client-1.35.4-150600.13.36.1 * kubernetes1.35-client-common-1.35.4-150600.13.36.1 * openSUSE Leap 15.6 (noarch) * kubernetes1.35-client-bash-completion-1.35.4-150600.13.36.1 * kubernetes1.35-client-fish-completion-1.35.4-150600.13.36.1 * Containers Module 15-SP7 (noarch) * kubernetes1.35-client-bash-completion-1.35.4-150600.13.36.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kubernetes1.35-client-1.35.4-150600.13.36.1 * kubernetes1.35-client-common-1.35.4-150600.13.36.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:30:04 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:30:04 -0000 Subject: SUSE-RU-2026:22588-1: moderate: Recommended update for trento-checks, trento-agent, mcp-server-trento, trento-web Message-ID: <178404660444.143.12845210784558923758@178315a69387> # Recommended update for trento-checks, trento-agent, mcp-server-trento, trento- web Announcement ID: SUSE-RU-2026:22588-1 Release Date: 2026-07-07T11:41:39Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for trento-checks, trento-agent, mcp-server-trento, trento-web fixes the following issues: Changes in trento-checks: * Release 1.3.1 ## What's Changed * Changing description ofcheck 9FAAD0 (#73) @balanza **Full Changelog** : https://github.com/trento- project/checks/compare/1.3.0...1.3.1 Changes in trento-agent: * Release 3.1.1 ## What's Changed * Bump golang.org/x/net to v0.55.0 (#593) @balanza * Bump contracts ref (#595) @balanza * Bump github.com/tidwall/gjson from 1.18.0 to 1.19.0 (#596) @balanza * Bump golang.org/x/mod from 0.34.0 to 0.36.0 (#597) @balanza * Bump gopkg.in/ini.v1 from 1.67.1 to 1.67.2 (#598) @balanza **Full Changelog** : https://github.com/trento- project/agent/compare/3.1.0...3.1.1 Changes in mcp-server-trento: * Release 1.1.1 ## What's Changed * Fix unhandled array parameters (#131) @balanza **Full Changelog** : https://github.com/trento-project/mcp- server/compare/1.1.0...1.1.1 Changes in trento-web: * Release 3.1.2 ## What's Changed * Fix loading checks execution detail when catalog is still loading (#4377) @balanza * Enforce using erlang26 on SLES15 (#4411) @balanza * Health summary - Application instances health (#4382) @balanza * Fix version 3.1.0 changelog typos (#4415) @balanza **Full Changelog** : https://github.com/trento-project/web/compare/3.1.1...3.1.2 * Release 3.1.1 ## What's Changed * Update analytics docs link profile form (#4376) @balanza * Flip activity log `from_date` and `to_date` logic (#4378) @balanza * Fix cluster registered broadcast (#4379) @balanza * Updated License in spec file (#4380) @balanza * Export version in rpm packages to use same value during compilation (#4381) @balanza * Normalize query string to list (#4383) @balanza **Full Changelog** : https://github.com/trento-project/web/compare/3.1.0...3.1.1 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1167=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * trento-checks-1.3.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * mcp-server-trento-1.1.1-160000.1.1 * trento-web-3.1.2-160000.1.1 * trento-agent-3.1.1-160000.1.1 * trento-web-debuginfo-3.1.2-160000.1.1 * trento-web-debugsource-3.1.2-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:30:18 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:30:18 -0000 Subject: SUSE-SU-2026:22587-1: important: Security update for haproxy Message-ID: <178404661887.143.13624738980552956240@178315a69387> # Security update for haproxy Announcement ID: SUSE-SU-2026:22587-1 Release Date: 2026-07-07T10:11:29Z Rating: important References: * bsc#1268557 * bsc#1268558 Cross-References: * CVE-2026-55203 * CVE-2026-55204 CVSS scores: * CVE-2026-55203 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-55203 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55203 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N * CVE-2026-55204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues * Update to version 3.2.21+git0.dbe43be37 * CVE-2026-55203: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557). * CVE-2026-55204: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1166=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * haproxy-debuginfo-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-debugsource-3.2.21+git0.dbe43be37-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55203.html * https://www.suse.com/security/cve/CVE-2026-55204.html * https://bugzilla.suse.com/show_bug.cgi?id=1268557 * https://bugzilla.suse.com/show_bug.cgi?id=1268558 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:30:24 -0000 Subject: SUSE-RU-2026:22586-1: moderate: Recommended update for tboot Message-ID: <178404662491.143.16423262172093033016@178315a69387> # Recommended update for tboot Announcement ID: SUSE-RU-2026:22586-1 Release Date: 2026-07-08T12:27:38Z Rating: moderate References: * bsc#1266833 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for tboot fixes the following issues: * Fix: [SLES16 SP1] grub-mkconfig fails version_find_latest command not found ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1184=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1184=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (x86_64) * tboot-20250417_1.11.10-160000.2.1 * tboot-debuginfo-20250417_1.11.10-160000.2.1 * tboot-debugsource-20250417_1.11.10-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * tboot-20250417_1.11.10-160000.2.1 * tboot-debuginfo-20250417_1.11.10-160000.2.1 * tboot-debugsource-20250417_1.11.10-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1266833 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:30:31 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:30:31 -0000 Subject: SUSE-RU-2026:22585-1: important: Recommended update for s390-tools Message-ID: <178404663147.143.298670582987526857@178315a69387> # Recommended update for s390-tools Announcement ID: SUSE-RU-2026:22585-1 Release Date: 2026-07-07T16:26:58Z Rating: important References: * bsc#1266436 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for s390-tools fixes the following issues: * Upgrade to version 2.43.0: * For Linux kernel version: 7.1 * Set Rust MSRV to 1.85.0 * Changes of existing tools: * dbginfo.sh: Add IBM appliance specific files * lshwc: Show explicitly selected unnamed counters with --hide * pvattest: Add firmware check version 2 * zipl: Introduce verbosity levels of zipl session (--debug) * zkey: Remove the use of AF_ALG for calculating key verification patterns * Bug Fixes: * ebc: implement --version option for pvics * pvebc: Log services to journal+console * pvics: Fix virt-resize permission error * Ammended the .spec file for `chreipl_helper` (bsc#1266436): * Moved `chreipl_helper*` to the main package * Added `Requires: %{name} = %{version}` in `chreipl-fcp-mpath subpackage` * Re-vendor-ed vendor.tar.zst ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1171=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1171=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (s390x) * s390-tools-hmcdrvfs-2.43.0-160000.1.1 * libekmfweb1-2.43.0-160000.1.1 * libekmfweb1-debuginfo-2.43.0-160000.1.1 * osasnmpd-debuginfo-2.43.0-160000.1.1 * s390-tools-zdsfs-debuginfo-2.43.0-160000.1.1 * s390-tools-debugsource-2.43.0-160000.1.1 * s390-tools-debuginfo-2.43.0-160000.1.1 * osasnmpd-2.43.0-160000.1.1 * libkmipclient1-debuginfo-2.43.0-160000.1.1 * libkmipclient1-2.43.0-160000.1.1 * s390-tools-hmcdrvfs-debuginfo-2.43.0-160000.1.1 * s390-tools-zdsfs-2.43.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * s390-tools-chreipl-fcp-mpath-2.43.0-160000.1.1 * s390-tools-genprotimg-data-2.43.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (s390x x86_64) * s390-tools-2.43.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * s390-tools-2.43.0-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1266436 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:30:36 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:30:36 -0000 Subject: SUSE-RU-2026:22584-1: moderate: Recommended update for systemd Message-ID: <178404663659.143.2821770139851742660@178315a69387> # Recommended update for systemd Announcement ID: SUSE-RU-2026:22584-1 Release Date: 2026-07-09T12:39:23Z Rating: moderate References: * bsc#1270439 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for systemd fixes the following issues: Changes in systemd: * do not make mounting of debugfs optional yet. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1191=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1191=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libudev1-debuginfo-257.13-160000.3.1 * systemd-debugsource-257.13-160000.3.1 * libsystemd0-257.13-160000.3.1 * systemd-container-debuginfo-257.13-160000.3.1 * libsystemd0-debuginfo-257.13-160000.3.1 * systemd-257.13-160000.3.1 * systemd-container-257.13-160000.3.1 * systemd-resolved-257.13-160000.3.1 * systemd-homed-debuginfo-257.13-160000.3.1 * libudev1-257.13-160000.3.1 * systemd-journal-remote-257.13-160000.3.1 * udev-257.13-160000.3.1 * systemd-homed-257.13-160000.3.1 * systemd-devel-257.13-160000.3.1 * systemd-experimental-257.13-160000.3.1 * systemd-journal-remote-debuginfo-257.13-160000.3.1 * systemd-portable-257.13-160000.3.1 * systemd-resolved-debuginfo-257.13-160000.3.1 * systemd-debuginfo-257.13-160000.3.1 * systemd-portable-debuginfo-257.13-160000.3.1 * udev-debuginfo-257.13-160000.3.1 * systemd-experimental-debuginfo-257.13-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * systemd-doc-257.13-160000.3.1 * systemd-lang-257.13-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * systemd-doc-257.13-160000.3.1 * systemd-lang-257.13-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libudev1-debuginfo-257.13-160000.3.1 * systemd-debugsource-257.13-160000.3.1 * libsystemd0-257.13-160000.3.1 * systemd-container-debuginfo-257.13-160000.3.1 * libsystemd0-debuginfo-257.13-160000.3.1 * systemd-257.13-160000.3.1 * systemd-container-257.13-160000.3.1 * systemd-resolved-257.13-160000.3.1 * systemd-homed-debuginfo-257.13-160000.3.1 * systemd-journal-remote-257.13-160000.3.1 * libudev1-257.13-160000.3.1 * udev-257.13-160000.3.1 * systemd-homed-257.13-160000.3.1 * systemd-devel-257.13-160000.3.1 * systemd-experimental-257.13-160000.3.1 * systemd-journal-remote-debuginfo-257.13-160000.3.1 * systemd-portable-257.13-160000.3.1 * systemd-resolved-debuginfo-257.13-160000.3.1 * systemd-portable-debuginfo-257.13-160000.3.1 * systemd-debuginfo-257.13-160000.3.1 * udev-debuginfo-257.13-160000.3.1 * systemd-experimental-debuginfo-257.13-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270439 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:30:59 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:30:59 -0000 Subject: SUSE-SU-2026:22583-1: important: Security update for rust-keylime Message-ID: <178404665948.143.11278767642796127277@178315a69387> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:22583-1 Release Date: 2026-07-09T09:06:27Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for rust-keylime fixes the following issues: Update to version 0.2.9+49. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270614). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270699). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270842). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270999). Other updates and bugfixes: * Update openssl to 0.10.81. * Make tss-esai-sys depend on bindgen 72.1 to support llvm > 21. * Build with Clang <= 21 (bsc#1260596). * Version 0.2.9+49: * build(deps): bump uuid from 1.23.3 to 1.23.4 * build(deps): bump syn from 2.0.117 to 2.0.118 * build(deps): bump openssl from 0.10.80 to 0.10.81 * build(deps): bump rand from 0.9.4 to 0.10.1 * Added new regression test into packit-ci.yaml * build(deps): bump actions/checkout from 6 to 7 * build(deps): bump uuid from 1.23.1 to 1.23.3 * build(deps): bump log from 0.4.29 to 0.4.32 * build(deps): bump http from 1.4.0 to 1.4.2 * build(deps): bump codecov/codecov-action from 6 to 7 * build(deps): bump retry-policies from 0.5.1 to 0.5.2 * fix: Remove unused base64::Engine import in context_info tests * build(deps): bump reqwest-middleware from 0.5.1 to 0.5.2 * build(deps): bump serde_json from 1.0.149 to 1.0.150 * build(deps): bump openssl from 0.10.79 to 0.10.80 * agent: Hash agent ID before TPM2_Certify qualifying data * cargo: Bump tss-esapi, picky-asn1-x509, and picky-asn1-der * build(deps): bump openssl from 0.10.78 to 0.10.79 * build(deps): bump once_cell from 1.21.3 to 1.21.4 * build(deps): bump tempfile from 3.23.0 to 3.27.0 * push-model: cache UEFI event log bytes at startup * build(deps): bump quote from 1.0.40 to 1.0.45 * build(deps): bump chrono from 0.4.42 to 0.4.44 * build(deps): bump openssl from 0.10.73 to 0.10.78 * build(deps): bump serde_json from 1.0.143 to 1.0.149 * build(deps): bump syn from 2.0.106 to 2.0.117 * build(deps): bump libc from 0.2.175 to 0.2.184 * build(deps): bump rand from 0.9.2 to 0.9.4 * Version 0.2.9+21: * tests: use Express-style named params in Mockoon endpoints * build(deps): bump pest_derive from 2.8.1 to 2.8.6 * build(deps): bump trybuild from 1.0.110 to 1.0.115 * build(deps): bump log from 0.4.28 to 0.4.29 * build(deps): bump uuid from 1.19.0 to 1.20.0 * build(deps): bump codecov/codecov-action from 5 to 6 * build(deps): bump tracing-subscriber from 0.3.20 to 0.3.23 * build(deps): bump cfg-if from 1.0.3 to 1.0.4 * build(deps): bump tokio from 1.49.0 to 1.50.0 * build(deps): bump actix-web from 4.12.1 to 4.13.0 * build(deps): bump anyhow from 1.0.99 to 1.0.102 * build(deps): bump clap from 4.5.57 to 4.5.60 * build(deps): bump tracing from 0.1.36 to 0.1.44 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1190=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1190=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * rust-keylime-debuginfo-0.2.9+49-160000.1.1 * keylime-ima-policy-0.2.9+49-160000.1.1 * rust-keylime-0.2.9+49-160000.1.1 * rust-keylime-debugsource-0.2.9+49-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * rust-keylime-debuginfo-0.2.9+49-160000.1.1 * keylime-ima-policy-0.2.9+49-160000.1.1 * rust-keylime-0.2.9+49-160000.1.1 * rust-keylime-debugsource-0.2.9+49-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:31:18 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:31:18 -0000 Subject: SUSE-SU-2026:22582-1: important: Security update for curl Message-ID: <178404667819.143.10423074574150783056@178315a69387> # Security update for curl Announcement ID: SUSE-SU-2026:22582-1 Release Date: 2026-07-08T13:46:40Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1187=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1187=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libcurl4-debuginfo-8.14.1-160000.8.1 * curl-8.14.1-160000.8.1 * curl-debuginfo-8.14.1-160000.8.1 * libcurl-mini4-debuginfo-8.14.1-160000.8.1 * curl-debugsource-8.14.1-160000.8.1 * libcurl-mini4-8.14.1-160000.8.1 * curl-mini-debugsource-8.14.1-160000.8.1 * libcurl-devel-8.14.1-160000.8.1 * libcurl4-8.14.1-160000.8.1 * SUSE Linux Enterprise Server 16.0 (noarch) * curl-zsh-completion-8.14.1-160000.8.1 * libcurl-devel-doc-8.14.1-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libcurl4-debuginfo-8.14.1-160000.8.1 * curl-8.14.1-160000.8.1 * curl-debuginfo-8.14.1-160000.8.1 * curl-mini-debugsource-8.14.1-160000.8.1 * curl-debugsource-8.14.1-160000.8.1 * libcurl-devel-8.14.1-160000.8.1 * libcurl-mini4-8.14.1-160000.8.1 * libcurl-mini4-debuginfo-8.14.1-160000.8.1 * libcurl4-8.14.1-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * curl-zsh-completion-8.14.1-160000.8.1 * libcurl-devel-doc-8.14.1-160000.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:31:22 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:31:22 -0000 Subject: SUSE-RU-2026:22581-1: moderate: Recommended update for strace Message-ID: <178404668240.143.2858293356803524721@178315a69387> # Recommended update for strace Announcement ID: SUSE-RU-2026:22581-1 Release Date: 2026-07-08T12:26:59Z Rating: moderate References: * jsc#PED-15928 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for strace fixes the following issues: * Update to strace 7.1: * Implemented wall-clock-aware columns for the -c/--summary-only report, allowing wall-clock and system CPU times to be displayed side by side in a single run. * Included out-of-range syscalls in the -c/--summary-only report. * Updated decoding of sched_getattr syscall. * Implemented decoding of FS_IOC_SHUTDOWN, PIDFD_GET_INFO and PIDFD_GET_*_NAMESPACE ioctl commands. * Implemented decoding of IFLA_BR_FDB_N_LEARNED, IFLA_BR_FDB_MAX_LEARNED and IFLA_BR_STP_MODE netlink attributes. * Updated lists of CLONE__, FSMOUNT__ , KT__, KVM__ , LANDLOCK__, NETDEV__ , NL80211__and PIDFD__ constants. * Updated lists of ioctl commands from Linux 7.1. * Implement EPERM diagnostics and give a hint about yama (jsc#PED-15928). * Update to strace 7.0: * Implemented optional colorized trace output. * Implemented decoding of rseq and rseq_slice_yield syscalls. * Implemented decoding of BPF_TRACE_FSESSION bpf attach type. * Implemented decoding of BPF_PROG_ASSOC_STRUCT_OPS bpf command. * Implemented decoding of UDMABUF_CREATE, UDMABUF_CREATE_LIST, and VIDIOC_QUERYMENU ioctl commands. * Updated decoding of statmount syscall flags. * Updated lists of BPF__, BTRFS__ , FS__, IORING__ , KEY__, KVM__ , NT__, OPEN_TREE__ , PR__, V4L2__ and *_MAGIC constants. * Updated lists of ioctl commands from Linux 7.0. * Update to strace 6.19: * Implemented decoding of listns syscall. * Implemented decoding of F_GET_RW_HINT, F_SET_RW_HINT, F_GET_FILE_RW_HINT, F_SET_FILE_RW_HINT, F_GETDELEG and F_SETDELEG fcntl commands. * Implemented decoding of IORING_REGISTER_SEND_MSG_RING, IORING_REGISTER_ZCRX_IFQ, IORING_REGISTER_RESIZE_RINGS, IORING_REGISTER_MEM_REGION, IORING_REGISTER_QUERY and IORING_REGISTER_ZCRX_CTRL opcodes of io_uring_register syscall. * Implemented decoding of extended argument structures for io_uring_enter syscall when IORING_ENTER_EXT_ARG or IORING_ENTER_EXT_ARG_REG flags are set. * Implemented decoding of attr_ptr and attr_type_mask fields of struct io_uring_sqe for io_uring_register syscall. * Implemented opcode-specific decoding of flags union and ioprio fields of struct io_uring_sqe for io_uring_register syscall. * Implemented decoding of 128-byte SQEs for io_uring_register syscall. * Implemented decoding of socket operations (SOCKET_URING_OP_*) for io_uring URING_CMD and URING_CMD128 operations when the file descriptor is a socket. * Updated decoding of struct mnt_id_req and struct perf_event_attr. * Updated lists of ABS__, BPF__ , ETHTOOL__, ETH_P__ , IORING__, KVM__ , PERF__, TLS__ , V4L2__and_ _MAGIC constants. * Updated lists of ioctl commands from Linux 6.19. * Update to strace 6.18: * Added -e kvm=vcpu+ option for kvm_run struct decoding. * Implemented decoding of FS_IOC_GETFSUUID, FS_IOC_GETFSSYSFSPATH and FS_IOC_GETLBMD_CAP ioctl commands. * Implemented decoding of BPF_PROG_STREAM_READ_BY_FD bpf command. * Updated decoding of BPF_BTF_LOAD, BPF_MAP_CREATE, BPF_PROG_ATTACH, BPF_PROG_DETACH, BPF_PROG_LOAD, BPF_PROG_QUERY and BPF___GET__ _ID bpf commands. * Updated decoding of bpf_map_info and bpf_prog_info structures. * Updated lists of AUDIT__, BR__ , FF__, IFLA__ , INPUT_PROP__, IORING__ , KEXEC_FILE__, KEY__ , KVM_CAP__, NL80211_CMD__ , RWF__and TEE__ constants. * Update to strace 6.17: * Implemented decoding of file_getattr and file_setattr syscalls. * Implemented decoding of SO_INQ socket option. * Updated lists of BPF__, BTN__ , BTRFS__, DEVCONF__ , ETHTOOL__, FALLOC__ , KEXEC__, KEY__ , KVM__, NETCONFA__ , NFT__, PR__ , SCM__, V4L2__ and XDP_* constants. * Updated lists of ioctl commands from Linux 6.17. * Update to strace 6.16: * Added -N/--arg-names option for printing syscall argument names. * Implemented setting of system call information using PTRACE_SET_SYSCALL_INFO ptrace API introduced in Linux 6.16. * Implemented decoding of SO_RCVPRIORITY and SO_PASSRIGHTS socket options. * Implemented decoding of RTA_NH_ID and RTA_FLOWLABEL netlink attributes. * Updated decoding of statx syscall. * Updated lists of BR__, CRYPTOCFGA__ , FUTEX2__, IORING__ , IPSET__, KVM__ , MDB__, NETDEV__ , PR__, RXRPC__ , SW__, THERMAL__ and V4L2_* constants. * Updated lists of ioctl commands from Linux 6.16. * Update to strace 6.15: * Implemented decoding of open_tree_attr syscall. * Implemented decoding of AF_TIPC socket addresses and socket options. * Updated decoding of statmount syscall. * Updated lists of AUDIT__, BPF__ , BTRFS__, COUNTER__ , FAN__, FRA__ , IFLA__, IORING__ , KVM__, LANDLOCK__ , PKEY__, RTPROT__ , TCP__and V4L2__ constants. * Updated lists of ioctl commands from Linux 6.15. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1185=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1185=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * strace-7.1-160000.1.1 * strace-debuginfo-7.1-160000.1.1 * strace-debugsource-7.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * strace-debuginfo-7.1-160000.1.1 * strace-debugsource-7.1-160000.1.1 * strace-7.1-160000.1.1 ## References: * https://jira.suse.com/browse/PED-15928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:31:26 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:31:26 -0000 Subject: SUSE-RU-2026:22580-1: moderate: Recommended update for javapackages-tools Message-ID: <178404668636.143.10664989712507909944@178315a69387> # Recommended update for javapackages-tools Announcement ID: SUSE-RU-2026:22580-1 Release Date: 2026-07-08T12:25:18Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for javapackages-tools fixes the following issues: * For the Python packaging use the modern style of %pyproject_* macros * Add `python-rpm-packaging` as BR ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1186=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1186=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * javapackages-ivy-6.5.1-160000.2.1 * python313-javapackages-6.5.1-160000.2.1 * javapackages-local-6.5.1-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * javapackages-tools-6.5.1-160000.2.1 * javapackages-filesystem-6.5.1-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * javapackages-ivy-6.5.1-160000.2.1 * python313-javapackages-6.5.1-160000.2.1 * javapackages-local-6.5.1-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * javapackages-tools-6.5.1-160000.2.1 * javapackages-filesystem-6.5.1-160000.2.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:31:34 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:31:34 -0000 Subject: SUSE-RU-2026:22579-1: important: Recommended update for python-kiwi, open-vmdk Message-ID: <178404669450.143.11825470421733601590@178315a69387> # Recommended update for python-kiwi, open-vmdk Announcement ID: SUSE-RU-2026:22579-1 Release Date: 2026-07-08T09:21:39Z Rating: important References: * bsc#1260340 * bsc#1263973 * jsc#PED-15927 * jsc#PED-9497 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains two features and has two fixes can now be installed. ## Description: This update for python-kiwi, open-vmdk fixes the following issues: Changes in python-kiwi: * Fix rereading DASD partition table with partprobe On s390 and with a DASD disk the rereading of the partition table can only be done properly with partprobe. This commit changes the dracut code to Require parted and partprobe only for DASD disks on s390. In addition this commit prevents the active device locking for parted and partprobe when called in the context of a DASD device. The reason for this change is because of a patch in libparted which applies flock() itself in this condition. This change however does not exist in the upstream version of parted which is causing problems that are hard to solve by kiwi. However, a dead-lock condition should be avoided and I think it's still better to have this change in kiwi and convince people to upstream the above parted fix, rather than living with a dead-lock condition due to double locking in kiwi. This Fixes bsc#1263973 * Do not hardcode dracut omit module in live builder This is a relict from the old days when the pure presence of multipath in a live ISO caused issues at boot time. kiwi should not maintain a hardcoded list of dracut modules except for those that are mandatory for live boot, if there should be any special setting needed it should come from an overlay setup in /etc/dracut.conf.d/*.conf as part of the image description. This is related to bsc#1260340 * Drop parted requirement for msdos partitioner parted was used in kiwi at one place to set the active flag on a partition in the DOS table. This action can also be done via sfdisk and drops the parted requirement from the kiwi builder code * Move OVA support to open-vmdk Finally this commit drops the use of the VMware ovftool and moves to the real opensource alternative open-vmdk This Fixes #2292 and Fixes #2627 and Fixes jira#PED-9497 * Limit workflow to SLE supported pythons * Refactor use of kiwi settings file KIWI supports an optional runtime configuration file for settings to control the behavior of the tools used by KIWI on the build host. So far this config file could be specified via --config or is searched in the user's HOME or looked up as /etc/kiwi.yml. With this commit the following changes to this heuristic are made: 1. Support reading of /etc/kiwi.yml.d/*.yml 2. Support reading of /usr/share/kiwi/kiwi.yml and /usr/share/kiwi/kiwi.yml.d/*.yml 3. Install default settings file as /usr/share/kiwi/kiwi.yml.example from the main package and drop it from kiwi-man-pages which was considered a weird place. 4. Add support for oci format for disk images The (oci|docker):image_format format is a special case that stores the disk image inside of an OCI-compliant container. The disk image is stored in the specified image_format in the disk/ directory of the container. The disk format can be one of the above formats or just raw if the disk should be stored as a raw disk inside of the container. Custom naming conventions for the disk image can be applied by using the bundle_format attribute. The derived_from attribute can be used to specify the source container. The resulting container image will be built by adding the disk image as a new layer on top of the specified reference container. If there is no derived_from attribute, the container image will be built from scratch using an empty root directory. This format is particularly useful for building an image which bundles the actual disk image and its runtime requirements into one artifact. This Fixes jira#PCT-1008 * Fix caller environment for non chroot scripts Make sure non chroot scripts also knows about the kiwi profile environment such that e.g. the current profile name or other settings from the build can be used in the script * Update spec file due to new package restrictions On SUSE new package restrictions where added to support the concept of the so called immutable mode. The new guideline says "Any files in the RPM spec %files section that are not in /usr or /etc is likely to break in Immutable Mode". For the kiwi packaging this applies to the kiwi-pxeboot sub package. This commit implements the suggested solution based on systemd-tmpfiles and only applies for SUSE. This Fixes jira#PCT-1055 * Fix result bundler for uncompressed container data When building container images with the respective runtime configuration: `yaml container: - compress: false` The resulting image output files will be uncompressed meaning there is no ".xz" extension present. When running the result bundler there is an index bug which causes the container format type of the filename name e.g. ".docker" to be dropped from the result names. This commit fixes it. * Fix spec file requirements for SUSE There is no erofs on SLES. This commit drops the respective requirement settings which we have upstream where it exists This Fixes jira#PCT-899 * Fix upstream merge README * Support SOURCE_DATE_EPOCH for OCI containers (jsc#PED-15927) If SOURCE_DATE_EPOCH is available, use it for the container creation time and history. open-vmdk is shipped as new package. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1183=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1183=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * kiwi-systemdeps-core-10.2.33-160000.3.1 * kiwi-systemdeps-filesystems-10.2.33-160000.3.1 * kiwi-systemdeps-iso-media-10.2.33-160000.3.1 * dracut-kiwi-verity-10.2.33-160000.3.1 * open-vmdk-0.3.12-160000.1.1 * open-vmdk-debuginfo-0.3.12-160000.1.1 * dracut-kiwi-overlay-10.2.33-160000.3.1 * kiwi-man-pages-10.2.33-160000.3.1 * python3-kiwi-10.2.33-160000.3.1 * kiwi-systemdeps-image-validation-10.2.33-160000.3.1 * open-vmdk-debugsource-0.3.12-160000.1.1 * dracut-kiwi-oem-dump-10.2.33-160000.3.1 * kiwi-systemdeps-containers-10.2.33-160000.3.1 * kiwi-systemdeps-10.2.33-160000.3.1 * kiwi-systemdeps-bootloaders-10.2.33-160000.3.1 * dracut-kiwi-verity-debuginfo-10.2.33-160000.3.1 * dracut-kiwi-live-10.2.33-160000.3.1 * kiwi-systemdeps-disk-images-10.2.33-160000.3.1 * dracut-kiwi-oem-repart-10.2.33-160000.3.1 * kiwi-systemdeps-containers-wsl-10.2.33-160000.3.1 * dracut-kiwi-lib-10.2.33-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * kiwi-bash-completion-10.2.33-160000.3.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * kiwi-pxeboot-10.2.33-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kiwi-systemdeps-core-10.2.33-160000.3.1 * kiwi-systemdeps-filesystems-10.2.33-160000.3.1 * kiwi-systemdeps-iso-media-10.2.33-160000.3.1 * dracut-kiwi-verity-10.2.33-160000.3.1 * open-vmdk-0.3.12-160000.1.1 * open-vmdk-debuginfo-0.3.12-160000.1.1 * dracut-kiwi-overlay-10.2.33-160000.3.1 * kiwi-man-pages-10.2.33-160000.3.1 * python3-kiwi-10.2.33-160000.3.1 * kiwi-systemdeps-image-validation-10.2.33-160000.3.1 * open-vmdk-debugsource-0.3.12-160000.1.1 * dracut-kiwi-oem-dump-10.2.33-160000.3.1 * kiwi-systemdeps-containers-10.2.33-160000.3.1 * kiwi-systemdeps-10.2.33-160000.3.1 * kiwi-systemdeps-bootloaders-10.2.33-160000.3.1 * dracut-kiwi-verity-debuginfo-10.2.33-160000.3.1 * dracut-kiwi-live-10.2.33-160000.3.1 * kiwi-systemdeps-disk-images-10.2.33-160000.3.1 * dracut-kiwi-oem-repart-10.2.33-160000.3.1 * kiwi-systemdeps-containers-wsl-10.2.33-160000.3.1 * dracut-kiwi-lib-10.2.33-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * kiwi-pxeboot-10.2.33-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * kiwi-bash-completion-10.2.33-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1260340 * https://bugzilla.suse.com/show_bug.cgi?id=1263973 * https://jira.suse.com/browse/PED-15927 * https://jira.suse.com/browse/PED-9497 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:31:40 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:31:40 -0000 Subject: SUSE-RU-2026:22578-1: important: Recommended update for nodejs22 Message-ID: <178404670001.143.12768306466131039088@178315a69387> # Recommended update for nodejs22 Announcement ID: SUSE-RU-2026:22578-1 Release Date: 2026-07-07T18:51:20Z Rating: important References: * bsc#1269825 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for nodejs22 fixes the following issues: Changes in nodejs22: Update to 22.23.1: http: avoid stream listeners on idle agent sockets (bsc#1269825) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1182=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1182=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * nodejs22-devel-22.23.1-160000.1.1 * nodejs22-22.23.1-160000.1.1 * nodejs22-debuginfo-22.23.1-160000.1.1 * corepack22-22.23.1-160000.1.1 * npm22-22.23.1-160000.1.1 * nodejs22-debugsource-22.23.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * nodejs22-docs-22.23.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * nodejs22-devel-22.23.1-160000.1.1 * nodejs22-22.23.1-160000.1.1 * nodejs22-debuginfo-22.23.1-160000.1.1 * corepack22-22.23.1-160000.1.1 * npm22-22.23.1-160000.1.1 * nodejs22-debugsource-22.23.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * nodejs22-docs-22.23.1-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269825 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:31:46 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:31:46 -0000 Subject: SUSE-RU-2026:22577-1: moderate: Recommended update for dpdk Message-ID: <178404670673.143.12974599070204651061@178315a69387> # Recommended update for dpdk Announcement ID: SUSE-RU-2026:22577-1 Release Date: 2026-07-07T17:21:47Z Rating: moderate References: * bsc#1260007 * bsc#1262286 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for dpdk fixes the following issues: Changes in dpdk: Update to version 24.11.6: * docs: fix build issue due to missing spacing between paragraphs * Revert ?net: fix packet type for stacked VLAN? Update to version 24.11.5: * https://doc.dpdk.org/guides-24.11/rel_notes/release_24_11.html#id15 * Summary: * Fixed buffer overflows (dma-perf, openssl) and use-after-free's in vhost. * Intel: Fixes for i40e, iavf, ice, and ixgbe regarding flow parsing, memory leak, and MAC management. * NVIDIA/Mellanox: Fixes for mlx5 regarding bonding, HW steering (HWS) and secondary process logic. * Fixes race conditions and resource leaks in netvsc (Hyper-V) * Fixes for Marvell (cnxk), Broadcom (bnxt), and Amazon (mana). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1180=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1180=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * dpdk-devel-static-24.11.6-160000.1.1 * dpdk-24.11.6-160000.1.1 * dpdk-debuginfo-24.11.6-160000.1.1 * libdpdk-25-debuginfo-24.11.6-160000.1.1 * dpdk-devel-24.11.6-160000.1.1 * dpdk-debugsource-24.11.6-160000.1.1 * libdpdk-25-24.11.6-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * dpdk-doc-24.11.6-160000.1.1 * dpdk-tools-24.11.6-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dpdk-devel-static-24.11.6-160000.1.1 * dpdk-24.11.6-160000.1.1 * dpdk-debuginfo-24.11.6-160000.1.1 * libdpdk-25-debuginfo-24.11.6-160000.1.1 * dpdk-devel-24.11.6-160000.1.1 * dpdk-debugsource-24.11.6-160000.1.1 * libdpdk-25-24.11.6-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * dpdk-doc-24.11.6-160000.1.1 * dpdk-tools-24.11.6-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1260007 * https://bugzilla.suse.com/show_bug.cgi?id=1262286 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:31:57 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:31:57 -0000 Subject: SUSE-SU-2026:22576-1: important: Security update for qemu Message-ID: <178404671711.143.11232869873187415431@178315a69387> # Security update for qemu Announcement ID: SUSE-SU-2026:22576-1 Release Date: 2026-07-07T17:20:48Z Rating: important References: * bsc#1199023 * bsc#1268061 * bsc#1268279 * bsc#1268794 * bsc#1270133 * jsc#PED-9266 Cross-References: * CVE-2026-3886 * CVE-2026-48004 * CVE-2026-48914 CVSS scores: * CVE-2026-3886 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-48004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48914 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H * CVE-2026-48914 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities, contains one feature and has two fixes can now be installed. ## Description: This update for qemu fixes the following issues: Update to version 10.0.11. Security issues fixed: * CVE-2026-3886: integer overflow leading to privilege escalation due to lack of proper validation of user-supplied data in the virtio-gpu driver (bsc#1268061). * CVE-2026-48914: heap buffer overflow due to improper size validation in virtio-blk SCSI request handling (bsc#1268794). * CVE-2026-48004: heap use-after-free race condition due to missing rename lock in v9fs_co_readdir_many (bsc#1270133). Other updates and bugfixes: * Version 10.0.11: * Full backport list here: https://lore.kernel.org/qemu- devel/20260627082646.D825717AB67 at think4mjt.localdomain/ * Version 10.0.10: * Full backport list here: https://lore.kernel.org/qemu- devel/20260528061820.CEE521691A9 at think4mjt.localdomain/ * ppc/spapr: Skip system reset for quiesced CPUs (bsc#1268279). * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266). * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266). * update Linux headers to v6.16-rc3 (jsc#PED-9266). * i386/cpu: Warn about why CPUID_EXT_PDCM is not available (jsc#PED-9266). * i386/cpu: Move adjustment of CPUID_EXT_PDCM before feature_dependencies[] check (jsc#PED-9266). * [openSUSE] qemu-ga: fix service file against no-autostart (bsc#1199023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1174=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1174=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * qemu-ppc-10.0.11-160000.1.1 * qemu-audio-alsa-10.0.11-160000.1.1 * qemu-arm-debuginfo-10.0.11-160000.1.1 * qemu-ivshmem-tools-10.0.11-160000.1.1 * qemu-extra-10.0.11-160000.1.1 * qemu-img-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-10.0.11-160000.1.1 * qemu-debugsource-10.0.11-160000.1.1 * qemu-audio-oss-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-debuginfo-10.0.11-160000.1.1 * qemu-audio-dbus-10.0.11-160000.1.1 * qemu-tools-10.0.11-160000.1.1 * qemu-debuginfo-10.0.11-160000.1.1 * qemu-arm-10.0.11-160000.1.1 * qemu-linux-user-10.0.11-160000.1.1 * qemu-s390x-10.0.11-160000.1.1 * qemu-10.0.11-160000.1.1 * qemu-hw-usb-smartcard-10.0.11-160000.1.1 * qemu-guest-agent-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-10.0.11-160000.1.1 * qemu-vhost-user-gpu-10.0.11-160000.1.1 * qemu-block-iscsi-10.0.11-160000.1.1 * qemu-headless-10.0.11-160000.1.1 * qemu-audio-jack-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-debuginfo-10.0.11-160000.1.1 * qemu-hw-usb-redirect-debuginfo-10.0.11-160000.1.1 * qemu-audio-dbus-debuginfo-10.0.11-160000.1.1 * qemu-extra-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-10.0.11-160000.1.1 * qemu-block-nfs-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-10.0.11-160000.1.1 * qemu-audio-alsa-debuginfo-10.0.11-160000.1.1 * qemu-ksm-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-10.0.11-160000.1.1 * qemu-hw-usb-redirect-10.0.11-160000.1.1 * qemu-x86-10.0.11-160000.1.1 * qemu-vhost-user-gpu-debuginfo-10.0.11-160000.1.1 * qemu-block-nfs-10.0.11-160000.1.1 * qemu-block-curl-debuginfo-10.0.11-160000.1.1 * qemu-s390x-debuginfo-10.0.11-160000.1.1 * qemu-block-iscsi-debuginfo-10.0.11-160000.1.1 * qemu-tools-debuginfo-10.0.11-160000.1.1 * qemu-ivshmem-tools-debuginfo-10.0.11-160000.1.1 * qemu-pr-helper-10.0.11-160000.1.1 * qemu-block-dmg-10.0.11-160000.1.1 * qemu-block-curl-10.0.11-160000.1.1 * qemu-x86-debuginfo-10.0.11-160000.1.1 * qemu-hw-usb-host-10.0.11-160000.1.1 * qemu-block-dmg-debuginfo-10.0.11-160000.1.1 * qemu-ppc-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-debuginfo-10.0.11-160000.1.1 * qemu-linux-user-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-10.0.11-160000.1.1 * qemu-audio-oss-10.0.11-160000.1.1 * qemu-guest-agent-debuginfo-10.0.11-160000.1.1 * qemu-audio-jack-debuginfo-10.0.11-160000.1.1 * qemu-pr-helper-debuginfo-10.0.11-160000.1.1 * qemu-linux-user-debugsource-10.0.11-160000.1.1 * qemu-hw-usb-smartcard-debuginfo-10.0.11-160000.1.1 * qemu-img-10.0.11-160000.1.1 * qemu-hw-usb-host-debuginfo-10.0.11-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * qemu-SLOF-10.0.11-160000.1.1 * qemu-skiboot-10.0.11-160000.1.1 * qemu-ipxe-10.0.11-160000.1.1 * qemu-seabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-doc-10.0.11-160000.1.1 * qemu-microvm-10.0.11-160000.1.1 * qemu-vgabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-lang-10.0.11-160000.1.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * qemu-vmsr-helper-10.0.11-160000.1.1 * qemu-vmsr-helper-debuginfo-10.0.11-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * qemu-ppc-10.0.11-160000.1.1 * qemu-audio-alsa-10.0.11-160000.1.1 * qemu-arm-debuginfo-10.0.11-160000.1.1 * qemu-ivshmem-tools-10.0.11-160000.1.1 * qemu-extra-10.0.11-160000.1.1 * qemu-img-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-10.0.11-160000.1.1 * qemu-debugsource-10.0.11-160000.1.1 * qemu-audio-oss-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-debuginfo-10.0.11-160000.1.1 * qemu-audio-dbus-10.0.11-160000.1.1 * qemu-tools-10.0.11-160000.1.1 * qemu-debuginfo-10.0.11-160000.1.1 * qemu-arm-10.0.11-160000.1.1 * qemu-linux-user-10.0.11-160000.1.1 * qemu-s390x-10.0.11-160000.1.1 * qemu-10.0.11-160000.1.1 * qemu-hw-usb-smartcard-10.0.11-160000.1.1 * qemu-guest-agent-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-10.0.11-160000.1.1 * qemu-audio-jack-10.0.11-160000.1.1 * qemu-vhost-user-gpu-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-debuginfo-10.0.11-160000.1.1 * qemu-block-iscsi-10.0.11-160000.1.1 * qemu-hw-usb-redirect-debuginfo-10.0.11-160000.1.1 * qemu-audio-dbus-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-10.0.11-160000.1.1 * qemu-block-nfs-debuginfo-10.0.11-160000.1.1 * qemu-extra-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-10.0.11-160000.1.1 * qemu-audio-alsa-debuginfo-10.0.11-160000.1.1 * qemu-ksm-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-10.0.11-160000.1.1 * qemu-hw-usb-redirect-10.0.11-160000.1.1 * qemu-x86-10.0.11-160000.1.1 * qemu-block-iscsi-debuginfo-10.0.11-160000.1.1 * qemu-vhost-user-gpu-debuginfo-10.0.11-160000.1.1 * qemu-s390x-debuginfo-10.0.11-160000.1.1 * qemu-block-curl-debuginfo-10.0.11-160000.1.1 * qemu-block-nfs-10.0.11-160000.1.1 * qemu-tools-debuginfo-10.0.11-160000.1.1 * qemu-ivshmem-tools-debuginfo-10.0.11-160000.1.1 * qemu-pr-helper-10.0.11-160000.1.1 * qemu-block-curl-10.0.11-160000.1.1 * qemu-block-dmg-10.0.11-160000.1.1 * qemu-hw-usb-host-10.0.11-160000.1.1 * qemu-x86-debuginfo-10.0.11-160000.1.1 * qemu-block-dmg-debuginfo-10.0.11-160000.1.1 * qemu-headless-10.0.11-160000.1.1 * qemu-ppc-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-10.0.11-160000.1.1 * qemu-guest-agent-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-debuginfo-10.0.11-160000.1.1 * qemu-linux-user-debuginfo-10.0.11-160000.1.1 * qemu-audio-oss-10.0.11-160000.1.1 * qemu-pr-helper-debuginfo-10.0.11-160000.1.1 * qemu-audio-jack-debuginfo-10.0.11-160000.1.1 * qemu-linux-user-debugsource-10.0.11-160000.1.1 * qemu-hw-usb-smartcard-debuginfo-10.0.11-160000.1.1 * qemu-img-10.0.11-160000.1.1 * qemu-hw-usb-host-debuginfo-10.0.11-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * qemu-vgabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-SLOF-10.0.11-160000.1.1 * qemu-skiboot-10.0.11-160000.1.1 * qemu-ipxe-10.0.11-160000.1.1 * qemu-doc-10.0.11-160000.1.1 * qemu-seabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-microvm-10.0.11-160000.1.1 * qemu-lang-10.0.11-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * qemu-vmsr-helper-debuginfo-10.0.11-160000.1.1 * qemu-vmsr-helper-10.0.11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3886.html * https://www.suse.com/security/cve/CVE-2026-48004.html * https://www.suse.com/security/cve/CVE-2026-48914.html * https://bugzilla.suse.com/show_bug.cgi?id=1199023 * https://bugzilla.suse.com/show_bug.cgi?id=1268061 * https://bugzilla.suse.com/show_bug.cgi?id=1268279 * https://bugzilla.suse.com/show_bug.cgi?id=1268794 * https://bugzilla.suse.com/show_bug.cgi?id=1270133 * https://jira.suse.com/browse/PED-9266 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:32:14 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:32:14 -0000 Subject: SUSE-SU-2026:22575-1: important: Security update for alloy Message-ID: <178404673454.143.12423865838938960153@178315a69387> # Security update for alloy Announcement ID: SUSE-SU-2026:22575-1 Release Date: 2026-07-07T17:00:29Z Rating: important References: * bsc#1260981 * bsc#1265440 * bsc#1266196 * bsc#1266654 * bsc#1267185 * bsc#1267333 * bsc#1267481 * bsc#1267485 * bsc#1267488 * bsc#1267489 Cross-References: * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33532 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41889 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-44740 * CVE-2026-45678 * CVE-2026-45682 * CVE-2026-45685 * CVE-2026-45686 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33532 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33532 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33532 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41889 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41889 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41889 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41889 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44740 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45678 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45678 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45678 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45682 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45685 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45685 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45685 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45686 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45686 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45686 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 26 vulnerabilities can now be installed. ## Description: This update for alloy fixes the following issues: Update to version 1.17.0. Security issues fixed: * CVE-2026-25680: golang.org/x/net/html: parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service (bsc#1267185). * CVE-2026-25681: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree and allows for XSS (bsc#1267185). * CVE-2026-27136: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree and allows for XSS (bsc#1267185). * CVE-2026-33532: yaml: parsing input with deeply nestes collections may throw a `RangeError` due to a stack overflow and cause to a denial of service (bsc#1260981). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266654). * CVE-2026-39827: golang.org/x/crypto/ssh: authenticated SSH clients that repeatedly open channels which were rejected by the server can cause unbounded memory growth and a crash (bsc#1266196). * CVE-2026-39828: golang.org/x/crypto/ssh: permissions discarded when an SSH server authentication callback returns `PartialSuccessError` with non-`nil` permissions (bsc#1266196). * CVE-2026-39829: golang.org/x/crypto/ssh: unenforced size limits on key parameters by the the RSA and DSA public key parsers can lead to excessive CPU consumption when processing a crafted public key (bsc#1266196). * CVE-2026-39830: golang.org/x/crypto/ssh: malicious SSH peers sending unsolicited global request responses can block a connection's read loop and cause a resource leak (bsc#1266196). * CVE-2026-39831: golang.org/x/crypto/ssh: missing `User Presence` flag checks in the `Verify()` method for FIDO/U2F security key types cause signatures generated without physical touch to be accepted (bsc#1266196). * CVE-2026-39832: golang.org/x/crypto/ssh: destination restrictions are silently stripped when forwarding keys and allow for unrestricted use of a key on a remote host (bsc#1266196). * CVE-2026-39833: golang.org/x/crypto/ssh: in-memory keyring returned by `NewKeyring()` silently accepts keys with the `ConfirmBeforeUse` constraint but never enforces it (bsc#1266196). * CVE-2026-39834: golang.org/x/crypto/ssh: writing data larger than 4GB in a single `Write` call on an SSH channel leads to an integer overflow and an infinite loop that sends empty packets (bsc#1266196). * CVE-2026-39835: golang.org/x/crypto/ssh: processing of certificates by SSH servers using `CertChecker` as a public key callback without setting `IsUserAuthority` or `IsHostAuthority` can lead to a panic (bsc#1266196). * CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: use placeholders in dollar-quoted string literals in an SQL query can lead to a SQL injection (bsc#1265440). * CVE-2026-42502: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree and allows for XSS (bsc#1267185). * CVE-2026-42506: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree and allows for XSS (bsc#1267185). * CVE-2026-42508: golang.org/x/crypto/ssh: revoked `SignatureKey`s belonging to a CA are not correctly checked for revocation (bsc#1266196). * CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267333). * CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are processed (bsc#1267481). * CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by `CappedConcurrentHashMap` after removals allows repeated connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485). * CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS (bsc#1267488). * CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process and cause denial of service (bsc#1267489). * CVE-2026-46595: golang.org/x/crypto/ssh: source-address validation is skipped if any other type of callback is passed other than public key (bsc#1266196). * CVE-2026-46597: golang.org/x/crypto/ssh: incorrectly placed cast from bytes to int in the AES-GCM packet decoder when processing specially crafted input can lead to for server-side panic (bsc#1266196). * CVE-2026-46598: golang.org/x/crypto/ssh: `ed25519.PrivateKey` created by casting malformed wire bytes due to processing of certain crafted inputs can lead to panic when used (bsc#1266196). Other updates and bugfixes: * Version 1.17.0: * Features * Add GraphQL server and `gql` subcommand. * `otelcol`: Add Nginx receiver. * `otelcol.exporter.prometheus`: Convert classic histograms to NHCB. * `database_observability`: Various enhancements for MySQL and Postgres. * `faro.receiver`: Support gzip-compressed request bodies. * Update to Beyla 3.9.8. * Bug Fixes * security: Update `x/crypto`, `x/net`, `jackc/pgx/v5`, and `obi`. * cluster: Fix nodes failing to join the cluster with TLS enabled. * `loki.process`: Fix potential deadlocks and limit stage shutdown. * Update Go to v1.26.4. * Version 1.16.3: * cluster: Fix nodes failing to join the cluster when TLS is enabled. * Version 1.16.2: * `loki.process`: No longer mutate rules in `stage.truncate` causing every config update to reload pipeline when this stage is used. * `loki.process`: Potential deadlock on update with stage and receiver changes. * `otelcol.exporter.awss3`: Add missing `unique_key_func_name` attribute. * Remove dependency on vulnerable `yaml` library. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1172=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1172=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * alloy-debuginfo-1.17.0-160000.1.1 * alloy-1.17.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * alloy-debuginfo-1.17.0-160000.1.1 * alloy-1.17.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33532.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41889.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-44740.html * https://www.suse.com/security/cve/CVE-2026-45678.html * https://www.suse.com/security/cve/CVE-2026-45682.html * https://www.suse.com/security/cve/CVE-2026-45685.html * https://www.suse.com/security/cve/CVE-2026-45686.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1260981 * https://bugzilla.suse.com/show_bug.cgi?id=1265440 * https://bugzilla.suse.com/show_bug.cgi?id=1266196 * https://bugzilla.suse.com/show_bug.cgi?id=1266654 * https://bugzilla.suse.com/show_bug.cgi?id=1267185 * https://bugzilla.suse.com/show_bug.cgi?id=1267333 * https://bugzilla.suse.com/show_bug.cgi?id=1267481 * https://bugzilla.suse.com/show_bug.cgi?id=1267485 * https://bugzilla.suse.com/show_bug.cgi?id=1267488 * https://bugzilla.suse.com/show_bug.cgi?id=1267489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:32:29 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:32:29 -0000 Subject: SUSE-SU-2026:22574-1: important: Security update for clamav Message-ID: <178404674967.143.17338156860334025061@178315a69387> # Security update for clamav Announcement ID: SUSE-SU-2026:22574-1 Release Date: 2026-07-07T16:59:27Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues: Update to version 1.5.3. Security issues fixed: * CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning (bsc#1270107). * CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning (bsc#1270085). * CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning (bsc#1270088). * CVE-2026-20216: denial of service due to improper handling of temporary resources during InstallShield file scanning (bsc#1270089). * CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning (bsc#1270091). * CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning (bsc#1270092). * CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning (bsc#1270106). * CVE-2026-41676: buffer overflow due to missing checks via `Deriver:derive`, `PkeyCtxRef:derive` and OpenSSL 1.1.1 (bsc#1270138). Other updates and bugfixes: * Version 1.5.3: * Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner. * Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE file and lead to a heap buffer overflow write. * Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and exhaust temporary storage. * Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file. * Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip expected scan-limit handling. * Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them while reading a malformed archive. * Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit scanner builds. * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the Rust openssl dependency to resolve CVE-2026-41676. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1173=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1173=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libclamav12-1.5.3-160000.1.1 * clamav-debuginfo-1.5.3-160000.1.1 * clamav-milter-1.5.3-160000.1.1 * libclammspack0-debuginfo-1.5.3-160000.1.1 * clamav-milter-debuginfo-1.5.3-160000.1.1 * clamav-debugsource-1.5.3-160000.1.1 * libclamav12-debuginfo-1.5.3-160000.1.1 * libfreshclam4-1.5.3-160000.1.1 * libclammspack0-1.5.3-160000.1.1 * libfreshclam4-debuginfo-1.5.3-160000.1.1 * clamav-devel-1.5.3-160000.1.1 * clamav-1.5.3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * clamav-docs-html-1.5.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libclamav12-1.5.3-160000.1.1 * clamav-debuginfo-1.5.3-160000.1.1 * clamav-milter-1.5.3-160000.1.1 * libclammspack0-debuginfo-1.5.3-160000.1.1 * clamav-milter-debuginfo-1.5.3-160000.1.1 * clamav-debugsource-1.5.3-160000.1.1 * libclamav12-debuginfo-1.5.3-160000.1.1 * libfreshclam4-1.5.3-160000.1.1 * libclammspack0-1.5.3-160000.1.1 * libfreshclam4-debuginfo-1.5.3-160000.1.1 * clamav-devel-1.5.3-160000.1.1 * clamav-1.5.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * clamav-docs-html-1.5.3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:32:35 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:32:35 -0000 Subject: SUSE-SU-2026:22573-1: important: Security update for ffmpeg-7 Message-ID: <178404675525.143.7631834452504391118@178315a69387> # Security update for ffmpeg-7 Announcement ID: SUSE-SU-2026:22573-1 Release Date: 2026-07-07T16:58:28Z Rating: important References: * bsc#1262047 * jsc#PED-15827 Cross-References: * CVE-2026-30997 CVSS scores: * CVE-2026-30997 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-30997 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-30997 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for ffmpeg-7 fixes the following issue: * CVE-2026-30997: out-of-bounds read in the `read_global_param()` function allows for a DoS via crafted input (bsc#1262047). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1179=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1179=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * ffmpeg-7-debuginfo-7.1.4-160000.2.1 * libpostproc58-7.1.4-160000.2.1 * libavformat61-7.1.4-160000.2.1 * libswresample5-debuginfo-7.1.4-160000.2.1 * libavutil59-7.1.4-160000.2.1 * libavutil59-debuginfo-7.1.4-160000.2.1 * libavformat61-debuginfo-7.1.4-160000.2.1 * libswresample5-7.1.4-160000.2.1 * libavdevice61-debuginfo-7.1.4-160000.2.1 * libavdevice61-7.1.4-160000.2.1 * libpostproc58-debuginfo-7.1.4-160000.2.1 * libswscale8-7.1.4-160000.2.1 * libswscale8-debuginfo-7.1.4-160000.2.1 * libavcodec61-7.1.4-160000.2.1 * libavfilter10-debuginfo-7.1.4-160000.2.1 * libavfilter10-7.1.4-160000.2.1 * ffmpeg-7-7.1.4-160000.2.1 * libavcodec61-debuginfo-7.1.4-160000.2.1 * ffmpeg-7-debugsource-7.1.4-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * ffmpeg-7-debuginfo-7.1.4-160000.2.1 * libpostproc58-7.1.4-160000.2.1 * libavformat61-7.1.4-160000.2.1 * libswresample5-debuginfo-7.1.4-160000.2.1 * libavutil59-7.1.4-160000.2.1 * libavutil59-debuginfo-7.1.4-160000.2.1 * libavformat61-debuginfo-7.1.4-160000.2.1 * libswresample5-7.1.4-160000.2.1 * libavdevice61-debuginfo-7.1.4-160000.2.1 * libavdevice61-7.1.4-160000.2.1 * libpostproc58-debuginfo-7.1.4-160000.2.1 * libswscale8-7.1.4-160000.2.1 * libswscale8-debuginfo-7.1.4-160000.2.1 * libavcodec61-7.1.4-160000.2.1 * libavfilter10-debuginfo-7.1.4-160000.2.1 * libavfilter10-7.1.4-160000.2.1 * ffmpeg-7-7.1.4-160000.2.1 * libavcodec61-debuginfo-7.1.4-160000.2.1 * ffmpeg-7-debugsource-7.1.4-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-30997.html * https://bugzilla.suse.com/show_bug.cgi?id=1262047 * https://jira.suse.com/browse/PED-15827 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:33:16 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:33:16 -0000 Subject: SUSE-SU-2026:22572-1: important: Security update for go1.26-openssl Message-ID: <178404679632.143.8754469239729384629@178315a69387> # Security update for go1.26-openssl Announcement ID: SUSE-SU-2026:22572-1 Release Date: 2026-07-07T16:57:26Z Rating: important References: * bsc#1170826 * bsc#1245878 * bsc#1255111 * bsc#1261653 * bsc#1261654 * bsc#1261655 * bsc#1261656 * bsc#1261657 * bsc#1261658 * bsc#1261659 * bsc#1261660 * bsc#1261661 * bsc#1261662 * bsc#1264395 * bsc#1264499 * bsc#1264500 * bsc#1264501 * bsc#1264502 * bsc#1264503 * bsc#1264504 * bsc#1264505 * bsc#1264506 * bsc#1264507 * bsc#1264508 * bsc#1264509 * bsc#1267442 * bsc#1267444 * bsc#1267450 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-27140 * CVE-2026-27143 * CVE-2026-27144 * CVE-2026-27145 * CVE-2026-32280 * CVE-2026-32281 * CVE-2026-32282 * CVE-2026-32283 * CVE-2026-32288 * CVE-2026-32289 * CVE-2026-33810 * CVE-2026-33811 * CVE-2026-33814 * CVE-2026-39817 * CVE-2026-39819 * CVE-2026-39820 * CVE-2026-39823 * CVE-2026-39825 * CVE-2026-39826 * CVE-2026-39836 * CVE-2026-42499 * CVE-2026-42501 * CVE-2026-42504 * CVE-2026-42507 CVSS scores: * CVE-2026-27140 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2026-27143 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-27144 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-27144 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32282 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32283 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32288 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-32288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-32288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-32289 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-32289 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-32289 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33810 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33810 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-33810 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L * CVE-2026-33810 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33811 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39817 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39817 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39817 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39819 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39819 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39819 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39820 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39823 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39823 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39825 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39825 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39826 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39826 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39836 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42501 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42501 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 24 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: This update for go1.26-openssl fixes the following issues: Update to go1.26.4 (bsc#1255111). Security issues fixed: * CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653). * CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination (bsc#1261654). * CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking (bsc#1261655). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-32280: crypto/x509: unexpected work during chain building (bsc#1261656). * CVE-2026-32281: crypto/x509: inefficient policy validation (bsc#1261657). * CVE-2026-32282: os: `Root.Chmod` can follow symlinks out of the root on Linux (bsc#1261658). * CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock (bsc#1261659). * CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map (bsc#1261660). * CVE-2026-32289: html/template: JS template literal context incorrectly tracked (bsc#1261661). * CVE-2026-33810: crypto/x509: excluded DNS constraints not properly applied to wildcard domains (bsc#1261662). * CVE-2026-33811: net: crash when handling long `CNAME` response (bsc#1264508). * CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` (bsc#1264506). * CVE-2026-39817: cmd/go: `go tool pack` does not sanitize output paths (bsc#1264505). * CVE-2026-39819: cmd/go: `go bug` follows symlinks in predictable temporary filenames (bsc#1264504). * CVE-2026-39820: net/mail: quadratic string concatentation in `consumeComment` (bsc#1264503). * CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509). * CVE-2026-39825: net/http/httputil: `ReverseProxy` forwards queries with more than `urlmaxqueryparams` parameters (bsc#1264500). * CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507). * CVE-2026-39836: net: panic in `Dial` and `LookupPort` when handling `NUL` byte on Windows (bsc#1264501). * CVE-2026-42499: net/mail: quadratic string concatenation in `consumePhrase` (bsc#1264502). * CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499). * CVE-2026-42504: mime: quadratic complexity in `WordDecoder.DecodeHeader` (bsc#1267442). * CVE-2026-42507: net/textproto: arbitrary input is included in errors without any escaping (bsc#1267444). Other updates and security fixes: * Go packages miss `binutils-gold` dependency (bsc#1170826). * Drop subpackage `go1.x-libstd` `std` library `.so` refs (jsc#PED-1962). * Use `libalternatives` only on `suse_version >= 1610` and keep `update- alternatives` support for older distributions. * Drop the `update-alternatives` migration path for `libalternatives` builds. * Enable `libalternatives` for SLE16.1 and Tumbleweed (bsc#1245878). * Drop go1.26 dependency on `update-alternatives` (bsc#1264395) * Update to version 1.26.3 cut from the `go1.25-fips-release` branch at the revision tagged `go1.26.3-1-openssl-fips` (jsc#SLE-18320). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1175=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1175=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.26-openssl-race-1.26.4-160000.1.1 * go1.26-openssl-1.26.4-160000.1.1 * go1.26-openssl-doc-1.26.4-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.26-openssl-race-1.26.4-160000.1.1 * go1.26-openssl-1.26.4-160000.1.1 * go1.26-openssl-doc-1.26.4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27140.html * https://www.suse.com/security/cve/CVE-2026-27143.html * https://www.suse.com/security/cve/CVE-2026-27144.html * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-32280.html * https://www.suse.com/security/cve/CVE-2026-32281.html * https://www.suse.com/security/cve/CVE-2026-32282.html * https://www.suse.com/security/cve/CVE-2026-32283.html * https://www.suse.com/security/cve/CVE-2026-32288.html * https://www.suse.com/security/cve/CVE-2026-32289.html * https://www.suse.com/security/cve/CVE-2026-33810.html * https://www.suse.com/security/cve/CVE-2026-33811.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39817.html * https://www.suse.com/security/cve/CVE-2026-39819.html * https://www.suse.com/security/cve/CVE-2026-39820.html * https://www.suse.com/security/cve/CVE-2026-39823.html * https://www.suse.com/security/cve/CVE-2026-39825.html * https://www.suse.com/security/cve/CVE-2026-39826.html * https://www.suse.com/security/cve/CVE-2026-39836.html * https://www.suse.com/security/cve/CVE-2026-42499.html * https://www.suse.com/security/cve/CVE-2026-42501.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1170826 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1261653 * https://bugzilla.suse.com/show_bug.cgi?id=1261654 * https://bugzilla.suse.com/show_bug.cgi?id=1261655 * https://bugzilla.suse.com/show_bug.cgi?id=1261656 * https://bugzilla.suse.com/show_bug.cgi?id=1261657 * https://bugzilla.suse.com/show_bug.cgi?id=1261658 * https://bugzilla.suse.com/show_bug.cgi?id=1261659 * https://bugzilla.suse.com/show_bug.cgi?id=1261660 * https://bugzilla.suse.com/show_bug.cgi?id=1261661 * https://bugzilla.suse.com/show_bug.cgi?id=1261662 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1264499 * https://bugzilla.suse.com/show_bug.cgi?id=1264500 * https://bugzilla.suse.com/show_bug.cgi?id=1264501 * https://bugzilla.suse.com/show_bug.cgi?id=1264502 * https://bugzilla.suse.com/show_bug.cgi?id=1264503 * https://bugzilla.suse.com/show_bug.cgi?id=1264504 * https://bugzilla.suse.com/show_bug.cgi?id=1264505 * https://bugzilla.suse.com/show_bug.cgi?id=1264506 * https://bugzilla.suse.com/show_bug.cgi?id=1264507 * https://bugzilla.suse.com/show_bug.cgi?id=1264508 * https://bugzilla.suse.com/show_bug.cgi?id=1264509 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:33:20 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:33:20 -0000 Subject: SUSE-RU-2026:22571-1: moderate: Recommended update for libtcnative-1-0 Message-ID: <178404680083.143.3250540060853604998@178315a69387> # Recommended update for libtcnative-1-0 Announcement ID: SUSE-RU-2026:22571-1 Release Date: 2026-07-07T16:52:53Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for libtcnative-1-0 fixes the following issues: Changes in libtcnative-1-0: Update to 1.3.8: * Changes * Fix a memory leak when parsing certificates * Fix two potential memory leaks on error paths identified by Copilot * Fix post handshake authentication when Tomcat is configured with a trust store using JSSE style configuration * Correct expected size of tickets when calling SSLContext.setSessionTicketKeys ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1181=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1181=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libtcnative-1-0-debuginfo-1.3.8-160000.1.1 * libtcnative-1-0-1.3.8-160000.1.1 * libtcnative-1-0-debugsource-1.3.8-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libtcnative-1-0-debuginfo-1.3.8-160000.1.1 * libtcnative-1-0-1.3.8-160000.1.1 * libtcnative-1-0-debugsource-1.3.8-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:33:26 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:33:26 -0000 Subject: SUSE-RU-2026:22570-1: important: Recommended update for blog Message-ID: <178404680618.143.12989944007437386366@178315a69387> # Recommended update for blog Announcement ID: SUSE-RU-2026:22570-1 Release Date: 2026-07-07T16:51:38Z Rating: important References: * bsc#1264176 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for blog fixes the following issues: * Update to version 2.45: * Fix early boot LUKS prompt on s390x and resolve memory corruptions This update addresses several critical issues in the early boot phase, especially on s390x architectures, and hardens the daemon's architecture: * Initrd/Dracut: Properly include `systemd-ask-password-blog.path` in sysinit.target.wants during the initrd phase to ensure LUKS password prompts are captured early in the zipl phase. * Systemd Units: Drop restrictive `ConditionKernelCommandLine=!plymouth.enable=0` to prevent the agent from being disabled by standard mainframe boot parameters. * Memory Corruption: Fix a critical heap corruption by renaming the conflicting `alignof()` macro to `ALIGNED_SIZEOF()` and zeroing allocated memory for `struct request` (memset) to prevent reading uninitialized pointers. * Kernel Command Line: Improve `parse_cmdline()` to support boolean parameters without an explicit value (e.g., `blog.silent` defaults to `blog.silent=1`). * New Features: Introduce `blog.silent` to suppress console I/O and `blog.coldboot` to explicitly trigger the early coldstart password query. * Lifecycle: Switch `KillMode=none` to `KillMode=mixed` to comply with modern systemd process lifecycle management. * Fix: Passphrase prompt does not appear after installation with encryption enabled on s390x (bsc#1264176) * Update to version 2.44: * Harden blog and use shims units to handle plymouth * Disable coldstart requests via epoll * Avoid handling fd twice in epoll loop * Update to version 2.43: * Make sure that if blog is running it is identified as plymouth Latest also add conflicts to systemd-ask-password-console units in the systemd-ask-password-blog units: * This should avoid conflicting password agents asking the same question in s390x. * Update to version 2.42: * Fix possible memory leaks, eliminate type punning, and resolve I/O blocking: 1. Memory Safety and Leak Resolution: * Implemented lcons_shutdown destructor to automatically purge the console list and close FDs on exit. * Fixed password buffer leak by using in closeIO, correctly matching the mmap allocation in shm_malloc. * Added cleanup for pwprompt in closeIO. 2. Elimination of Dangerous Type Punning: * Replaced the unreliable address of the cons node pattern with a type-safe list_t lcons sentinel across the codebase. * Added **attribute**((may_alias)) to list_t in listing.h to prevent compiler strict aliasing optimizations from corrupting list traversals. 3. I/O Responsiveness and Stability: * Removed tcdrain() from the high-frequency epoll_console_in path to eliminate daemon freezes during heavy output. * Updated consinitIO to ensure CON_SERIAL devices remain in O_NONBLOCK mode, preventing freezes on slow serial lines. * Extended the tcdrain skip-list in closeIO to include CON_SERIAL, ensuring a hang-free shutdown. 4. Architectural Improvements: * Redesigned shm_malloc to use a tiered mapping strategy: prefers file-backed shared memory in /dev/shm with a graceful fallback to MAP_ANONYMOUS. * Optimized listing.h with always_inline attributes, __builtin_prefetch for cache efficiency, and list poisoning for safer debugging. * Update to version 2.41: * The **attribute**((noreturn)) for error() in libconsole.h added * The variable err with 0 initialized in thread_poll() * The variable cp.parity with {0} initialized in readpw() * feat(blogd): handle pending systemd password requests on coldstart * Initialize console pointer list as well * Check peer credentials before reading command * Make isinteger() string check usable for all architectures * Add some comments about warnings and translation for S390 * Update to version 2.40: * Protect password data stream on 3270 console as well: * On S390 the 3270 console is also logged and the passwords, even if hidden on the 3270 console, would be logged as well. * Update to version 2.39: * New feature to protect passwords to be logged: * On S390 now blogd use for 3215 console the command #CP SPOOL CONSOLE STOP to stop logging the plain password at prompting for the password. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1178=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1178=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * blog-debugsource-2.45-160000.1.1 * blog-debuginfo-2.45-160000.1.1 * blog-devel-2.45-160000.1.1 * libblogger2-debuginfo-2.45-160000.1.1 * blog-plymouth-2.45-160000.1.1 * libblogger2-2.45-160000.1.1 * blog-2.45-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * blog-debugsource-2.45-160000.1.1 * blog-debuginfo-2.45-160000.1.1 * blog-devel-2.45-160000.1.1 * libblogger2-debuginfo-2.45-160000.1.1 * blog-plymouth-2.45-160000.1.1 * libblogger2-2.45-160000.1.1 * blog-2.45-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1264176 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:33:31 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:33:31 -0000 Subject: SUSE-RU-2026:22569-1: important: Recommended update for az-cli-cmd, aws-cli-cmd Message-ID: <178404681158.143.11773177281055616295@178315a69387> # Recommended update for az-cli-cmd, aws-cli-cmd Announcement ID: SUSE-RU-2026:22569-1 Release Date: 2026-07-07T16:51:38Z Rating: important References: * bsc#1269510 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for az-cli-cmd, aws-cli-cmd fixes the following issues: * Add /etc/ssl as path to share with the container (bsc#1269510) * Fix typo in spec: * The %ghost reference contained a superfluous quote sign at the end of the line ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1177=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1177=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * az-cli-cmd-1.37.1-160000.5.1 * aws-cli-cmd-1.36.2-160000.6.1 * SUSE Linux Enterprise Server 16.0 (noarch) * az-cli-cmd-1.37.1-160000.5.1 * aws-cli-cmd-1.36.2-160000.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269510 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:33:37 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:33:37 -0000 Subject: SUSE-RU-2026:22568-1: important: Recommended update for dracut Message-ID: <178404681708.143.1283179574131926878@178315a69387> # Recommended update for dracut Announcement ID: SUSE-RU-2026:22568-1 Release Date: 2026-07-07T16:51:38Z Rating: important References: * bsc#1262515 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for dracut fixes the following issues: * fix (fips): handle zipl (bsc#1262515) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1176=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1176=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dracut-debugsource-059+suse.724.gaa87d1594-160000.1.1 * dracut-debuginfo-059+suse.724.gaa87d1594-160000.1.1 * dracut-ima-059+suse.724.gaa87d1594-160000.1.1 * dracut-extra-059+suse.724.gaa87d1594-160000.1.1 * dracut-fips-059+suse.724.gaa87d1594-160000.1.1 * dracut-tools-059+suse.724.gaa87d1594-160000.1.1 * dracut-059+suse.724.gaa87d1594-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dracut-debugsource-059+suse.724.gaa87d1594-160000.1.1 * dracut-debuginfo-059+suse.724.gaa87d1594-160000.1.1 * dracut-ima-059+suse.724.gaa87d1594-160000.1.1 * dracut-extra-059+suse.724.gaa87d1594-160000.1.1 * dracut-fips-059+suse.724.gaa87d1594-160000.1.1 * dracut-tools-059+suse.724.gaa87d1594-160000.1.1 * dracut-059+suse.724.gaa87d1594-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1262515 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:33:46 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:33:46 -0000 Subject: SUSE-SU-2026:22567-1: important: Security update for docker-compose Message-ID: <178404682623.143.1802221988956934131@178315a69387> # Security update for docker-compose Announcement ID: SUSE-SU-2026:22567-1 Release Date: 2026-07-07T12:35:23Z Rating: important References: * bsc#1239340 * bsc#1239766 * bsc#1265782 * bsc#1266625 Cross-References: * CVE-2025-0495 * CVE-2025-22869 * CVE-2026-33814 * CVE-2026-39821 CVSS scores: * CVE-2025-0495 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-0495 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N * CVE-2025-0495 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker-compose fixes the following issues * CVE-2025-0495: buildx: credential leakage to telemetry endpoints when credentials allowed to be set as attribute values in cache-to/cache-from configuration (bsc#1239766). * CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239340). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1168=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1168=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * docker-compose-2.33.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * docker-compose-2.33.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0495.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1239340 * https://bugzilla.suse.com/show_bug.cgi?id=1239766 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:34:06 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:34:06 -0000 Subject: SUSE-SU-2026:22566-1: important: Security update for jq Message-ID: <178404684685.143.212594076206750867@178315a69387> # Security update for jq Announcement ID: SUSE-SU-2026:22566-1 Release Date: 2026-07-07T12:32:56Z Rating: important References: * bsc#1244116 * bsc#1262043 * bsc#1262044 * bsc#1262069 * bsc#1262070 * bsc#1262071 * bsc#1262072 * bsc#1265060 * bsc#1265061 * bsc#1265062 * bsc#1265070 Cross-References: * CVE-2025-48060 * CVE-2026-32316 * CVE-2026-33947 * CVE-2026-33948 * CVE-2026-39956 * CVE-2026-39979 * CVE-2026-40164 * CVE-2026-40612 * CVE-2026-41256 * CVE-2026-41257 * CVE-2026-43894 CVSS scores: * CVE-2025-48060 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-48060 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-48060 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32316 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-32316 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-32316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33947 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33948 ( SUSE ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-33948 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-39956 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39956 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39956 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39979 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39979 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-39979 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40164 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40612 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40612 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-40612 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40612 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41256 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41256 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41257 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41257 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-41257 ( NVD ): 6.4 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43894 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43894 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43894 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2025-48060: improper handling of string data in `jv_string_empty` can lead to heap buffer overflow and a crash when processing crafted input (bsc#1244116). * CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). * CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). * CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). * CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). * CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre- computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). * CVE-2026-40612: recursion into nested arrays/objects with no depth limit in `jv_contains` can lead to a C stack exhaustion when processing crafted input (bsc#1265060). * CVE-2026-41256: truncation of top-level jq programs loaded with `-f` and can lead to the execution of unintended programs (bsc#1265061). * CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS when processing jq bytecode (bsc#1265062). * CVE-2026-43894: signed integer overflow in the `decNumberFromString` `D2U()` macro can lead to an out-of-bounds memory write when processing large number literals (bsc#1265070). * CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1169=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1169=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * jq-debugsource-1.7.1-160000.3.1 * jq-debuginfo-1.7.1-160000.3.1 * libjq1-debuginfo-1.7.1-160000.3.1 * libjq1-1.7.1-160000.3.1 * libjq-devel-1.7.1-160000.3.1 * jq-1.7.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jq-debugsource-1.7.1-160000.3.1 * libjq-devel-1.7.1-160000.3.1 * libjq1-debuginfo-1.7.1-160000.3.1 * jq-debuginfo-1.7.1-160000.3.1 * libjq1-1.7.1-160000.3.1 * jq-1.7.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48060.html * https://www.suse.com/security/cve/CVE-2026-32316.html * https://www.suse.com/security/cve/CVE-2026-33947.html * https://www.suse.com/security/cve/CVE-2026-33948.html * https://www.suse.com/security/cve/CVE-2026-39956.html * https://www.suse.com/security/cve/CVE-2026-39979.html * https://www.suse.com/security/cve/CVE-2026-40164.html * https://www.suse.com/security/cve/CVE-2026-40612.html * https://www.suse.com/security/cve/CVE-2026-41256.html * https://www.suse.com/security/cve/CVE-2026-41257.html * https://www.suse.com/security/cve/CVE-2026-43894.html * https://bugzilla.suse.com/show_bug.cgi?id=1244116 * https://bugzilla.suse.com/show_bug.cgi?id=1262043 * https://bugzilla.suse.com/show_bug.cgi?id=1262044 * https://bugzilla.suse.com/show_bug.cgi?id=1262069 * https://bugzilla.suse.com/show_bug.cgi?id=1262070 * https://bugzilla.suse.com/show_bug.cgi?id=1262071 * https://bugzilla.suse.com/show_bug.cgi?id=1262072 * https://bugzilla.suse.com/show_bug.cgi?id=1265060 * https://bugzilla.suse.com/show_bug.cgi?id=1265061 * https://bugzilla.suse.com/show_bug.cgi?id=1265062 * https://bugzilla.suse.com/show_bug.cgi?id=1265070 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:34:40 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:34:40 -0000 Subject: SUSE-SU-2026:22565-1: important: Security update for nodejs24 Message-ID: <178404688090.143.12516989238325649754@178315a69387> # Security update for nodejs24 Announcement ID: SUSE-SU-2026:22565-1 Release Date: 2026-07-06T20:22:33Z Rating: important References: * bsc#1259853 * bsc#1262274 * bsc#1266318 * bsc#1268097 * bsc#1268477 * bsc#1268478 * bsc#1268479 * bsc#1268480 * bsc#1268481 * bsc#1268482 * bsc#1268554 * bsc#1268555 * bsc#1268592 * bsc#1268593 * bsc#1268598 * bsc#1268605 * bsc#1268606 * bsc#1268608 * bsc#1268609 * bsc#1268611 * bsc#1268618 * bsc#1269825 Cross-References: * CVE-2026-11525 * CVE-2026-12151 * CVE-2026-2581 * CVE-2026-27135 * CVE-2026-40170 * CVE-2026-42338 * CVE-2026-48615 * CVE-2026-48617 * CVE-2026-48618 * CVE-2026-48619 * CVE-2026-48928 * CVE-2026-48930 * CVE-2026-48931 * CVE-2026-48933 * CVE-2026-48934 * CVE-2026-48935 * CVE-2026-48937 * CVE-2026-6733 * CVE-2026-9496 * CVE-2026-9678 * CVE-2026-9679 CVSS scores: * CVE-2026-11525 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-11525 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-12151 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2581 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2581 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27135 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40170 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42338 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-48615 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48615 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48617 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48617 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N * CVE-2026-48617 ( NVD ): 1.8 CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N * CVE-2026-48618 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48618 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-48618 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48619 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48928 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48928 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-48928 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48928 ( NVD ): 4.2 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48930 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48930 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-48930 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48930 ( NVD ): 5.6 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-48931 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48931 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48933 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48933 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48934 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48934 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48934 ( NVD ): 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48935 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48935 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48935 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48937 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48937 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6733 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-6733 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-9496 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9496 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9496 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9678 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9678 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9679 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-9679 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 21 vulnerabilities and has one fix can now be installed. ## Description: This update for nodejs24 fixes the following issues Update to version 24.18.0 (bsc#1269825). Security issues fixed: * CVE-2026-2581: undici: denial of service due to uncontrolled resource consumption (bsc#1268480). * CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS (bsc#1266318). * CVE-2026-9678: undici: information disclosure due to improper `cache- control` header parsing (bsc#1268478). * CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent- decoding (bsc#1268477). * CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to incorrect parsing of `Set-Cookie` header (bsc#1268481). * CVE-2026-12151: undici: denial of service due to unbounded memory growth via WebSocket frames (bsc#1268482). * CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853). * CVE-2026-40170: ngtcp2: qlog `parameters_set` stack buffer overflow (bsc#1262274). * CVE-2026-42338: ip-address: cross-site scripting due to improper HTML escaping of untrusted input (bsc#1268097). * CVE-2026-48615: proxy credentials leaked in `ERR_PROXY_TUNNEL` error message (bsc#1268598). * CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation (bsc#1268554). * CVE-2026-48618: unicode dot separator handling can lead to TLS wildcard- depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593). * CVE-2026-48619: unbounded memory growth in `node:http2` clients via attacker-controlled `ORIGIN` frames (bsc#1268618). * CVE-2026-48928: uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605). * CVE-2026-48930: `embedded-nul` hostnames can lead to silent authority rebinding due to `c-string` truncation in resolver bindings (bsc#1268606). * CVE-2026-48931: HTTP response queue poisoning via TOCTOU race condition in `http.Agent` (bsc#1268611). * CVE-2026-48933: WebCrypto AES integer overflow leads to remote process abort (bsc#1268592). * CVE-2026-48934: TLS host identity verification bypass via session reuse with different `servername` leads to unauthorized connections (bsc#1268608). * CVE-2026-48935: permission model bypass via `FileHandle.utimes()` in the `promises` API (bsc#1268609). * CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555). Other updates and bugfixes: \- Version 24.18.0: \- doc: update `blockList` stability status to release candidate \- fs: support caller-supplied `readFile()` buffers \- http: close pre-request sockets in `closeIdleConnections` \- loader: implement package maps \- net: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` \- tls: add `certificateCompression` option \- vfs: dispatch `node:fs/promises` to mounted VFS instances \- vfs: add minimal `node:vfs` subsystem \- For changes in older versions, see https://github.com/nodejs/node/releases. \- Remove `update- alternatives` from scriptlets if not available. \- Explicitly `BuildRequire` `update-alternatives` and mark it as being used in post/postun. \- Add `-fno- lifetime-dse` to `CXXFLAGS` to avoid parallel/test-snapshot-reproducible testsuite failure with GCC 16. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1150=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1150=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * nodejs24-docs-24.18.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * nodejs24-debugsource-24.18.0-160000.1.1 * nodejs24-devel-24.18.0-160000.1.1 * nodejs24-24.18.0-160000.1.1 * npm24-24.18.0-160000.1.1 * nodejs24-debuginfo-24.18.0-160000.1.1 * corepack24-24.18.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * nodejs24-debugsource-24.18.0-160000.1.1 * nodejs24-devel-24.18.0-160000.1.1 * nodejs24-24.18.0-160000.1.1 * npm24-24.18.0-160000.1.1 * nodejs24-debuginfo-24.18.0-160000.1.1 * corepack24-24.18.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * nodejs24-docs-24.18.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11525.html * https://www.suse.com/security/cve/CVE-2026-12151.html * https://www.suse.com/security/cve/CVE-2026-2581.html * https://www.suse.com/security/cve/CVE-2026-27135.html * https://www.suse.com/security/cve/CVE-2026-40170.html * https://www.suse.com/security/cve/CVE-2026-42338.html * https://www.suse.com/security/cve/CVE-2026-48615.html * https://www.suse.com/security/cve/CVE-2026-48617.html * https://www.suse.com/security/cve/CVE-2026-48618.html * https://www.suse.com/security/cve/CVE-2026-48619.html * https://www.suse.com/security/cve/CVE-2026-48928.html * https://www.suse.com/security/cve/CVE-2026-48930.html * https://www.suse.com/security/cve/CVE-2026-48931.html * https://www.suse.com/security/cve/CVE-2026-48933.html * https://www.suse.com/security/cve/CVE-2026-48934.html * https://www.suse.com/security/cve/CVE-2026-48935.html * https://www.suse.com/security/cve/CVE-2026-48937.html * https://www.suse.com/security/cve/CVE-2026-6733.html * https://www.suse.com/security/cve/CVE-2026-9496.html * https://www.suse.com/security/cve/CVE-2026-9678.html * https://www.suse.com/security/cve/CVE-2026-9679.html * https://bugzilla.suse.com/show_bug.cgi?id=1259853 * https://bugzilla.suse.com/show_bug.cgi?id=1262274 * https://bugzilla.suse.com/show_bug.cgi?id=1266318 * https://bugzilla.suse.com/show_bug.cgi?id=1268097 * https://bugzilla.suse.com/show_bug.cgi?id=1268477 * https://bugzilla.suse.com/show_bug.cgi?id=1268478 * https://bugzilla.suse.com/show_bug.cgi?id=1268479 * https://bugzilla.suse.com/show_bug.cgi?id=1268480 * https://bugzilla.suse.com/show_bug.cgi?id=1268481 * https://bugzilla.suse.com/show_bug.cgi?id=1268482 * https://bugzilla.suse.com/show_bug.cgi?id=1268554 * https://bugzilla.suse.com/show_bug.cgi?id=1268555 * https://bugzilla.suse.com/show_bug.cgi?id=1268592 * https://bugzilla.suse.com/show_bug.cgi?id=1268593 * https://bugzilla.suse.com/show_bug.cgi?id=1268598 * https://bugzilla.suse.com/show_bug.cgi?id=1268605 * https://bugzilla.suse.com/show_bug.cgi?id=1268606 * https://bugzilla.suse.com/show_bug.cgi?id=1268608 * https://bugzilla.suse.com/show_bug.cgi?id=1268609 * https://bugzilla.suse.com/show_bug.cgi?id=1268611 * https://bugzilla.suse.com/show_bug.cgi?id=1268618 * https://bugzilla.suse.com/show_bug.cgi?id=1269825 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:03 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:35:03 -0000 Subject: SUSE-SU-2026:22564-1: important: Security update for apache2 Message-ID: <178404690319.143.14849377911971311779@178315a69387> # Security update for apache2 Announcement ID: SUSE-SU-2026:22564-1 Release Date: 2026-07-06T20:21:38Z Rating: important References: * bsc#1267503 * bsc#1267955 * bsc#1267956 * bsc#1267962 * bsc#1267963 * bsc#1267965 * bsc#1267969 * bsc#1267970 * bsc#1267971 * bsc#1267972 * bsc#1267976 * bsc#1267977 * bsc#1267978 Cross-References: * CVE-2026-29167 * CVE-2026-29170 * CVE-2026-34355 * CVE-2026-34356 * CVE-2026-42535 * CVE-2026-42536 * CVE-2026-43951 * CVE-2026-44119 * CVE-2026-44185 * CVE-2026-44186 * CVE-2026-44631 * CVE-2026-48913 * CVE-2026-49975 CVSS scores: * CVE-2026-29167 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29167 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29170 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-29170 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34355 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34356 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42535 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42535 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-42535 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42536 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43951 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43951 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-43951 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44119 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44119 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44186 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44186 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44186 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44631 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44631 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48913 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48913 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48913 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-49975 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-49975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978). * CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955). * CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956). * CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962). * CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963). * CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965). * CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969). * CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of service (bsc#1267970). * CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971). * CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free (bsc#1267972). * CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1149=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1149=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * apache2-utils-2.4.66-160000.3.1 * apache2-prefork-debuginfo-2.4.66-160000.3.1 * apache2-worker-debuginfo-2.4.66-160000.3.1 * apache2-prefork-debugsource-2.4.66-160000.3.1 * apache2-event-debugsource-2.4.66-160000.3.1 * apache2-prefork-2.4.66-160000.3.1 * apache2-event-debuginfo-2.4.66-160000.3.1 * apache2-debugsource-2.4.66-160000.3.1 * apache2-2.4.66-160000.3.1 * apache2-worker-debugsource-2.4.66-160000.3.1 * apache2-devel-2.4.66-160000.3.1 * apache2-utils-debuginfo-2.4.66-160000.3.1 * apache2-debuginfo-2.4.66-160000.3.1 * apache2-utils-debugsource-2.4.66-160000.3.1 * apache2-event-2.4.66-160000.3.1 * apache2-worker-2.4.66-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * apache2-manual-2.4.66-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * apache2-utils-2.4.66-160000.3.1 * apache2-prefork-debuginfo-2.4.66-160000.3.1 * apache2-worker-debuginfo-2.4.66-160000.3.1 * apache2-prefork-debugsource-2.4.66-160000.3.1 * apache2-event-debugsource-2.4.66-160000.3.1 * apache2-event-2.4.66-160000.3.1 * apache2-event-debuginfo-2.4.66-160000.3.1 * apache2-2.4.66-160000.3.1 * apache2-worker-2.4.66-160000.3.1 * apache2-devel-2.4.66-160000.3.1 * apache2-utils-debuginfo-2.4.66-160000.3.1 * apache2-worker-debugsource-2.4.66-160000.3.1 * apache2-debuginfo-2.4.66-160000.3.1 * apache2-utils-debugsource-2.4.66-160000.3.1 * apache2-debugsource-2.4.66-160000.3.1 * apache2-prefork-2.4.66-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * apache2-manual-2.4.66-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29167.html * https://www.suse.com/security/cve/CVE-2026-29170.html * https://www.suse.com/security/cve/CVE-2026-34355.html * https://www.suse.com/security/cve/CVE-2026-34356.html * https://www.suse.com/security/cve/CVE-2026-42535.html * https://www.suse.com/security/cve/CVE-2026-42536.html * https://www.suse.com/security/cve/CVE-2026-43951.html * https://www.suse.com/security/cve/CVE-2026-44119.html * https://www.suse.com/security/cve/CVE-2026-44185.html * https://www.suse.com/security/cve/CVE-2026-44186.html * https://www.suse.com/security/cve/CVE-2026-44631.html * https://www.suse.com/security/cve/CVE-2026-48913.html * https://www.suse.com/security/cve/CVE-2026-49975.html * https://bugzilla.suse.com/show_bug.cgi?id=1267503 * https://bugzilla.suse.com/show_bug.cgi?id=1267955 * https://bugzilla.suse.com/show_bug.cgi?id=1267956 * https://bugzilla.suse.com/show_bug.cgi?id=1267962 * https://bugzilla.suse.com/show_bug.cgi?id=1267963 * https://bugzilla.suse.com/show_bug.cgi?id=1267965 * https://bugzilla.suse.com/show_bug.cgi?id=1267969 * https://bugzilla.suse.com/show_bug.cgi?id=1267970 * https://bugzilla.suse.com/show_bug.cgi?id=1267971 * https://bugzilla.suse.com/show_bug.cgi?id=1267972 * https://bugzilla.suse.com/show_bug.cgi?id=1267976 * https://bugzilla.suse.com/show_bug.cgi?id=1267977 * https://bugzilla.suse.com/show_bug.cgi?id=1267978 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:07 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:35:07 -0000 Subject: SUSE-RU-2026:22563-1: moderate: Recommended update for helm Message-ID: <178404690739.143.3740697984574917282@178315a69387> # Recommended update for helm Announcement ID: SUSE-RU-2026:22563-1 Release Date: 2026-07-06T20:10:17Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for helm fixes the following issues: * Update to 3.21.2: * chore(deps): bump the k8s-io group (dependabot[bot]): * Updates `k8s.io/apiserver` from 0.35.1 to 0.36.2 * Updates `k8s.io/apiextensions-apiserver` from 0.35.1 to 0.36.2 * Updates `k8s.io/apimachinery` from 0.35.1 to 0.36.2 * Updates `k8s.io/kubectl` from 0.35.1 to 0.36.2 * Updates dependencies * fixes regression (b52e276) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1152=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1152=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * helm-debuginfo-3.21.2-160000.1.2 * helm-3.21.2-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * helm-bash-completion-3.21.2-160000.1.2 * helm-fish-completion-3.21.2-160000.1.2 * helm-zsh-completion-3.21.2-160000.1.2 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-160000.1.2 * helm-3.21.2-160000.1.2 * SUSE Linux Enterprise Server 16.0 (noarch) * helm-bash-completion-3.21.2-160000.1.2 * helm-fish-completion-3.21.2-160000.1.2 * helm-zsh-completion-3.21.2-160000.1.2 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:12 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:35:12 -0000 Subject: SUSE-SU-2026:22562-1: moderate: Security update for jline3 Message-ID: <178404691292.143.5026895137030117753@178315a69387> # Security update for jline3 Announcement ID: SUSE-SU-2026:22562-1 Release Date: 2026-07-06T20:10:17Z Rating: moderate References: * bsc#1269021 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for jline3 fixes the following issues: Changes in jline3: * unauthenticated remote memory exhaustion via unbounded Telnet 'NEW-ENVIRON variables (bsc#1269021) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1148=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1148=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * jline3-curses-3.30.13-160000.3.2 * jline3-terminal-jni-3.30.13-160000.3.2 * jline3-console-ui-3.30.13-160000.3.2 * jline3-remote-telnet-3.30.13-160000.3.2 * jline3-style-3.30.13-160000.3.2 * jline3-javadoc-3.30.13-160000.3.2 * jline3-terminal-jansi-3.30.13-160000.3.2 * jline3-jansi-core-3.30.13-160000.3.2 * jline3-terminal-3.30.13-160000.3.2 * jline3-console-3.30.13-160000.3.2 * jline3-terminal-jna-3.30.13-160000.3.2 * jline3-reader-3.30.13-160000.3.2 * jline3-builtins-3.30.13-160000.3.2 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jline3-3.30.13-160000.3.2 * jline3-jansi-3.30.13-160000.3.2 * jline3-debugsource-3.30.13-160000.3.2 * jline3-native-3.30.13-160000.3.2 * jline3-native-debuginfo-3.30.13-160000.3.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * jline3-terminal-jni-3.30.13-160000.3.2 * jline3-curses-3.30.13-160000.3.2 * jline3-console-ui-3.30.13-160000.3.2 * jline3-remote-telnet-3.30.13-160000.3.2 * jline3-style-3.30.13-160000.3.2 * jline3-javadoc-3.30.13-160000.3.2 * jline3-terminal-jansi-3.30.13-160000.3.2 * jline3-jansi-core-3.30.13-160000.3.2 * jline3-terminal-3.30.13-160000.3.2 * jline3-console-3.30.13-160000.3.2 * jline3-terminal-jna-3.30.13-160000.3.2 * jline3-reader-3.30.13-160000.3.2 * jline3-builtins-3.30.13-160000.3.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * jline3-3.30.13-160000.3.2 * jline3-jansi-3.30.13-160000.3.2 * jline3-debugsource-3.30.13-160000.3.2 * jline3-native-3.30.13-160000.3.2 * jline3-native-debuginfo-3.30.13-160000.3.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269021 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:18 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:35:18 -0000 Subject: SUSE-SU-2026:22561-1: moderate: Security update for dhcpcd Message-ID: <178404691881.143.9817064288274474363@178315a69387> # Security update for dhcpcd Announcement ID: SUSE-SU-2026:22561-1 Release Date: 2026-07-06T20:10:17Z Rating: moderate References: * bsc#1268761 Cross-References: * CVE-2025-70102 CVSS scores: * CVE-2025-70102 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-70102 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-70102 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for dhcpcd fixes the following issue Update to 10.3.2: * CVE-2025-70102: NULL pointer dereference in `parse_option()` when processing a specially crafted configuration input (bsc#1268761). Changes for dhcpcd: * options: Ensure ldop is not NULL dereferenced * DHCP: Don't run double EXPIRE hooks on carrier loss * DHCP: free the state when dropping on state NONE * BSD: don't send uninitialised memory using ps_root_indirectioctl * Fix fallback_time option * IPv4: Ignore DHCP state when building routes * route: Routes may not have an interface assinged * options: Ensure that an overly long bitflag string does not crash * options: Don't assume vsio options have an argument * common: Cast via uintptr_t rather than unsigned long in UNCONST * privsep: Ensure we recv for real after a successful recv MSG_PEEK * DHCP: Add parentheses to macro definitions * ipv6nd: empty IPV6RA_EXPIRE eloop queue when dropping * privsep: enforce message boundaries with MSG_EOR on our messages * Protocols will notify when dhcpcd can exit * DHCP: Don't request T1 and T2 * DHCP: Don't request a lease time * DHCP6: Don't exit if using DHCP4 INFORM in non manager mode * ND: Route Information Option prefix is optional * ipv6: respect slaac hwaddr to really use the hwaddr * When stopping all interfaces at exit and releasing, remove persistance * NetBSD: Delete RTF_CONNECTED route when changing it * privsep: Drain the log when the root process is exiting * eloop: vastly reworked, kqueue and epoll support on by default ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1147=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1147=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dhcpcd-debugsource-10.3.2-160000.1.2 * dhcpcd-debuginfo-10.3.2-160000.1.2 * dhcpcd-10.3.2-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dhcpcd-debugsource-10.3.2-160000.1.2 * dhcpcd-debuginfo-10.3.2-160000.1.2 * dhcpcd-10.3.2-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-70102.html * https://bugzilla.suse.com/show_bug.cgi?id=1268761 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:23 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:35:23 -0000 Subject: SUSE-RU-2026:22560-1: moderate: Recommended update for apache-commons-pool2, apache-commons-net, apache-commons-daemon, apache-commons-configuration2 Message-ID: <178404692353.143.5957121908258119914@178315a69387> # Recommended update for apache-commons-pool2, apache-commons-net, apache- commons-daemon, apache-commons-configuration2 Announcement ID: SUSE-RU-2026:22560-1 Release Date: 2026-07-06T20:10:17Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for apache-commons-pool2, apache-commons-net, apache-commons-daemon, apache-commons-configuration2 fixes the following issues: Changes in apache-commons-pool2: * Update to 2.13.1 * Fixed Bugs: * POOL-427: The fix for POOL-425 introduced a regression where addObject fails when maxIdle is negative (indicating no limit) * Update to 2.13.0 * New features: * Add org.apache.commons.pool2.PooledObject .nonNull(PooledObject) * Add org.apache.commons.pool2.PooledObject .getObject(PooledObject) * Made statistics collection optional in BaseGenericObjectPool #429 * Fixed Bugs: * POOL-424: GenericObjectPool.invalidateObject() can leave other threads waiting to borrow hanging. The fix for this issue changes behavior of invalidateObject. This method now always tries to add a new instance to the pool to replace the invalidated and destroyed instance. As a result of this change, abandoned object removal now attemps to replace abandoned objects * POOL-425: GenericObjectPool addObject does not respect maxIdle * POOL-350: Make placement of calls to GKOP reuseCapacity configurable * POOL-290: TestSoftRefOutOfMemory (unit test) can loop infinitely on failure * POOL-419: GenericObjectPool counters and object collections can be corrupted when returnObject and invalidate are invoked concurrently by client threads on the same pooled object * POOL-421: GenericObjectPool addObject should return immediately when there is no capacity to add * POOL-420: The maximum wait time for GenericKeyedObjectPool .borrowObject(*) may exceed configured maximum wait time. This is the same issue as POOL-418, but for GKOP. Also included in this fix is a change to addObject that prevents it from waiting for capacity to create. That method now returns immediately when there is no capcity to add to the pool under the given key * Remove -nouses directive from maven-bundle-plugin. OSGi package imports now state 'uses' definitions for package imports, this doesn't affect JPMS (from org.apache.commons:commons-parent:80) * POOL-418: The maximum wait time for GenericObjectPool .borrowObject(*) may exceed expectations due to a spurious thread wakeup. he remaining duration was incorrectly calculated and the method did not end up waiting long enough. Recompute the remaining duration an additional time when we block when exhausted * Fix site link from the About page to the Download page, see also #387 * Operation on the "idleHighWaterMark" shared variable in "ErodingFactor" class is not atomic [org.apache.commons.pool2.PoolUtils$ErodingFactor] At PoolUtils.java:[line 98] AT_NONATOMIC_OPERATIONS_ON_SHARED_VARIABLE * org.apache.commons.pool2.impl.GenericObjectPool .create(Duration) should normalize a negative duration to zero * Fix potential ConcurrentModificationException in EvictionTimer thread clean-up * Fix potential ConcurrentModificationException in EvictionTimer tasks * Update to 2.12.1 * Fixed Bugs: * Use java.time.Instant precision in org.apache.commons.pool2 .impl.ThrowableCallStack.Snapshot throwable message * GenericObjectPool.borrowObject(Duration) doesn't obey its borrowMaxWait Duration argument when the argument is different from GenericObjectPool.getMaxWaitDuration() * POOL-418: The maximum wait time for GenericObjectPool .borrowObject(*) may exceed expectations due to a spurious thread wakeup * Javadoc is missing its Overview page * Migrate site generation templates to https://maven.apache.org/xsd/xdoc-2.0.xsd * Update to 2.12.0 * New features: * Add PooledObject.getFullDuration() * Add GenericKeyedObjectPool.getKeys() * Add KeyedObjectPool.getKeys() * Add github/codeql-action. * Add BaseGenericObjectPool.Evictor.toString(). * Make BaseGenericObjectPool implement AutoCloseable. * Add BaseGenericObjectPool methods that return Duration and deprecate equivalents that return milliseconds as long * Add BaseObjectPoolConfig.DEFAULT_DURATION_BETWEEN_EVICTION_RUNS and deprecate BaseObjectPoolConfig .DEFAULT_TIME_BETWEEN_EVICTION_RUNS * Fixed Bugs: * POOL-401: Ensure that capacity freed by invalidateObject is available to all keyed pools * POOL-391: Ensure capacity freed by clear is made available to GKOP borrowers * POOL-402: Check blockWhenExhausted in hasBorrowWaiters #116 * Simplify test assertion with similar call but simpler. #131 * POOL-405: NullPointerException GenericKeyedObjectPool .invalidateObject(GenericKeyedObjectPool.java:1343) * POOL-408: Fix a typo related to KeyedPooledObjectFactory on the site and Javadoc * Fail-fast on null input for DefaultPooledObjectInfo .DefaultPooledObjectInfo(PooledObject) with a NullPointerException * POOL-393: Improve BaseGenericObjectPool's JMX Register performance when creating many pools * Null-guard in GenericObjectPool.use(T) like other call sites of GenericObjectPool.getPooledObject(T) * POOL-411: Guard against NPE when deregistering a key at the end of borrow * Make private GenericKeyedObjectPool.ObjectDeque class static * Make private BaseGenericObjectPool.StatsStore class static * [StepSecurity] ci: Harden GitHub Actions #225 * Fix possible NPE in DefaultPooledObjectInfo .getPooledObjectToString() * Fix possible NPE in DefaultPooledObjectInfo .getPooledObjectType() * Update to 2.11.1 * Fixed Bugs: * Getting a PooledObject's active duration returns a negative duration when the object is borrowed but not returned. Affects: ? PooledObject.getActiveDuration() ? PooledObject.getActiveTime() ? PooledObject.getActiveTimeMillis() * The default implementation of TrackedUse.getLastUsedInstant() uses seconds instead of milliseconds * This interface is not implemented within Apache Commons Pool but affects Apache Commons DBCP * DefaultPooledObject.getIdleTime() drops nanoseconds on Java 9 and greater * Fix field label in BaseGenericObjectPool toString() builder: From timeBetweenEvictionRunsMillis to durationBetweenEvictionRuns * Fix field label in BaseObjectPoolConfig toString() builder: From maxWaitMillis to maxWaitDuration * Fix field label in NoSuchElementException message for GenericObjectPool.borrowObject(Duration): From borrowMaxWaitMillis to borrowMaxWaitDuration * Reimplement DefaultPooledObject.getIdleDuration() using Duration computation * Reimplement BaseGenericObjectPool.maxBorrowWait as a Duration instead of a long * Minors Changes #89 * Update to 2.11.0 * New features: * Track timestamps with Instants instead of longs. There is currently no increased precision on Java 8, but starting with Java 9, the JRE SystemClock precision is increased usually down to microseconds, or tenth of microseconds, depending on the OS, Hardware, and JVM implementation. Add and use: ? DefaultPooledObject.getCreateInstant() ? DefaultPooledObject.getLastUsedInstant() ? PooledObject.getCreateInstant() ? PooledObject.getLastBorrowInstant() ? PooledObject.getLastReturnInstant() ? PooledObject.getLastUsedInstant() ? TrackedUse#getLastUsedInstant() * Add BaseObjectPoolConfig.setEvictorShutdownTimeoutDuration(Duration), deprecate setEvictorShutdownTimeoutMillis(Duration) * Add BaseGenericObjectPool.{get|set}MaxWaitDuration(Duration) and deprecate {get|set}MaxWaitMillis(long) * Add BaseObjectPoolConfig.{get|set}MaxWaitDuration(Duration) and deprecate {get|set}MaxWaitMillis(long) * Add and use Duration APIs instead of ints or longs. ? Add and use Duration APIs in BaseGenericObjectPool: getDurationBetweenEvictionRuns(), getEvictorShutdownTimeoutDuration(), getMinEvictableIdleDuration(), getSoftMinEvictableIdleDuration(), setMaxWait(Duration), setMinEvictableIdle(Duration), setSoftMinEvictableIdle(Duration) ? Add and use Duration APIs in BaseObjectPoolConfig: getDurationBetweenEvictionRuns(), getEvictorShutdownTimeoutDuration(), getMinEvictableIdleDuration(), getSoftMinEvictableIdleDuration() ? Add and use Duration APIs in EvictionConfig: getIdleEvictDuration(), getIdleSoftEvictDuration() ? Add and use Duration APIs in PooledObject: getIdleDuration(), getActiveDuration() ? No need to initialize instance variables to their default values ? Update Javadocs. ? Update toString() implementations with duration labels * POOL-396: Handle validation exceptions during eviction. #85 * POOL-395: Improve exception thrown in GenericObjectPool .borrowObject when pool is exhausted. Added BaseGenericObjectPool.setMessagesStatistics(boolean) * Add and use AbandonedConfig.copy(AbandonedConfig) to fix CPD code duplication issues in GenericKeyedObjectPool and GenericObjectPool * Pull up AbandonedConfig and related methods from GenericKeyedObjectPool and GenericObjectPool to BaseGenericObjectPool (fix for CPD issues). ? BaseGenericObjectPool.getLogAbandoned() ? BaseGenericObjectPool.getRemoveAbandonedOnBorrow() ? BaseGenericObjectPool.getRemoveAbandonedOnMaintenance() ? BaseGenericObjectPool.getRemoveAbandonedTimeout() ? BaseGenericObjectPool.getRemoveAbandonedTimeoutDuration() ? BaseGenericObjectPool.isAbandonedConfig() ? BaseGenericObjectPool.setAbandonedConfig(AbandonedConfig) * Fixed Bugs: * Fix "[WARNING] Old version of checkstyle detected. Consider updating to >= v8.30." Update Checktyle to 8.44 * Make Duration setters use their respective default values when null * Call swallowException(Exception) instead of printing exceptions to the console in GenericKeyedObjectPool .removeAbandoned(AbandonedConfig) and GenericObjectPool .removeAbandoned(AbandonedConfig) * Fix Javadoc link reference #91 * No need to initialize to default values. #90 * Update to 2.10.0 * New features: * Add and use java.time.Duration APIs timeouts instead of using ints for seconds. * Implement AbandonedConfig for GenericKeyedObjectPool #67 * Fixed Bugs: * Simplify Assertions in tests #77 * Replace C-style array declaration with Java style #80 * Use Objects.equals(); Use Anonymous type; Use method reference instead Lambda; Replace Loop with Collection.removeIf(). #81 * Use diamond operator. #82 * Code clean ups. #83 * Update to 2.9.0 * Changes: * POOL-387: Object factory destroy method should carry information on activation context * Update spotbugs from 4.0.6 to 4.1.3, #37, #41, #46 * Update actions/checkout from v2.3.1 to v2.3.3 #56, #45 * Update actions/setup-java from v1.4.0 to v1.4.2 #42 * Update optional asm-util from 8.0.1 to 9.0 #44 * Update to 2.8.1 * New features: * POOL-385: Added Automatic-Module-Name to support JPMS #31 * Fixed Bugs: * POOL-386: Refactored EvictionTimer usage tracking to fix POOL-386 and handle abandoned pools. #32 * [Javadoc] Add missing @throws comment in PoolUtils. #27 * Changes: * POOL-384: Update optional library org.ow2.asm:asm-util from 7.2 to 8.0.1 * Update site reports from org.apache.bcel:bcel 6.4.1 to 6.5.0 * Update site reports from maven-pmd-plugin 3.12.0 to 3.13.0 * Update build from biz.aQute.bnd:biz.aQute.bndlib 5.1.0 -> 5.1.2 * Update actions/checkout from v1 to v2.3.1 #33 * Update commons-parent from 50 to 51 #36 * Update Checkstyle plugin from 3.0.0 to 3.1.1 * Update JApiCmp from 0.14.1 to 0.14.3 * Update animal-sniffer-maven-plugin from 1.16 to 1.19 * Update to 2.8.0 * New features: * POOL-378: Deprecate PoolUtils.prefill(ObjectPool, int) in favor of ObjectPool.addObjects(int) * POOL-379: Deprecate PoolUtils.prefill(KeyedObjectPool, K, int) in favor of KeyedObjectPool.addObjects(K, int) * POOL-380: Deprecate PoolUtils.prefill(KeyedObjectPool, Collection, int) in favor of KeyedObjectPool .addObjects(Collection, int) * Fixed Bugs: * POOL-374: org.apache.commons.pool2.impl.GenericKeyedObjectPool .returnObject(K, T) should throw IllegalStateException instead of NullPointerException when a key is not found in the pool map * POOL-376: Fixed regression from original fix for POOL-356 which could result in NPE when destroying objects * POOL-326: Eliminated NPE / ISE exceptions due to keyed pools being prematurely removed * Close BufferedOutputStream in test before calling toString on underlying BufferedOutputStream #26 * [Javadoc] Add missing @throws comment in SoftReferenceObjectPool. #28 * Changes: * POOL-375: Update optional library cglib from 3.2.12 to 3.3.0 * Update site build from Apache Commons BCEL 6.3.1 to 6.4.1 * POOL-377: Update optional library org.ow2.asm:asm-util from 7.1 to 7.2 * Update to 2.7.0 * New features: * POOL-370: Add org.apache.commons.pool2.PooledObject #getBorrowedCount() * POOL-371: Add org.apache.commons.pool2.PooledObject #setRequireFullStackTrace(boolean) * Fixed Bugs: * POOL-361: Move validation for newly created objects into create(). Fixes #23 * Changes: * POOL-364: Update from Java 7 to Java 8 * POOL-365: Update ASM from 7.0 to 7.1 * POOL-366: Update optional library cglib from 3.2.10 to 3.2.12 * POOL-367: Fix typo in package private method name stopEvitor() -> stopEvictor() #22 * Update to 2.6.2 * Fixed Bugs: * POLL-362: Always null out org.apache.commons.pool2.impl .BaseGenericObjectPool.evictionIterator to match org.apache.commons.pool2.impl.BaseGenericObjectPool.evictor * POLL-363: Evictor Thread prevents Spring Context shutdown in standalone app * POLL-348: The commons-pool-evictor-thread should run as a Deamon * Update to 2.6.1 * Fixed Bugs: * POOL-340: Correct validateObject with concurrent borrowObject * POOL-356: Fix deadlock on massive concurrent requests * POOL-347: Method borrowObject waits for maxWaitMillis over in pool full * POOL-359: NullPointerException closing multiple GenericObjectPools * POOL-326: Threading issue, NullPointerException and IllegalStateException in GenericKeyedObjectPool * POOL-352: CallStackUtils mishandles security manager check (partial fix.) * Changes: * POOL-345: Update optional library cglib from 3.2.6 to 3.2.9 * POOL-346: Move common configuration setter to BaseGenericObjectPool #9 * POOL-349: Update optional library asm-util from 6.2 to 7.0 * POOL-360: Update optional library cglib from 3.2.9 to 3.2.10 * Update to 2.6.0 * Fixed Bugs: * POOL-337: Ensure cancelled eviction tasks are removed from scheduler * POOL-338: GenericObjectPool constructor may throw an exception under OSGi * POOL-324: org.apache.commons.pool2.impl.GenericObjectPool .getFactoryType() throws java.lang.ClassCastException * POOL-344: Delete repeated call startEvictor * Changes: * POOL-336: GenericObjectPool's borrowObject lock if create() fails with Error * POOL-339: Update optional library cglib from 3.2.5 to 3.2.6 * POOL-341: Update optional library asm-util from 6.0 to 6.1.1 * POOL-342: Update optional library asm-util from 6.1.1 to 6.2 * Update to 2.5.0 * New features: * POOL-332: ObjectPool and KeyedObject pool should extend Closeable. * POOL-335: Make abandoned logging stack trace requirements configurable. This also reverts the default behavior introduced by POOL-320. * Changes: * POOL-331: Update from Java 6 to 7. * POOL-333: Update optional dependency asm-util from 5.2 to 6.0 * POOL-334: org.apache.commons.pool2.impl.ThrowableCallStack .Snapshot is missing serialVersionUID * Update to 2.4.3 * New features: * POOL-320: Use more efficient stack walking mechanisms for usage tracking when possible. * Fixed Bugs: * POOL-328: Documentation with repeated words (sources, tests, and examples) * POOL-317: Correction of default value of softMinEvictableIdleTimeMillis in BaseObjectPoolConfig * POOL-309: Fix misspellings from "destory" to "destroy" * POOL-306: Ensure BaseGenericObjectPool .IdentityWrapper#equals() follows the expected contract for equals() * POOL-303: Ensure that threads do not block indefinitely if more than maxTotal threads try to borrow an object at the same time and the factory fails to create any objects. * POOL-310: Ensure that threads using GKOP do not block indefinitely if more than maxTotal threads try to borrow objects with different keys at the same time and the factory destroys objects on return * Ensure that any class name used for evictionPolicyClassName represents a class that implements EvictionPolicy. * POOL-315: Add a configurable delay (default 10 seconds) to wait when shutting down an Evictor to allow the associated thread time to complete and current evictions and to terminate * Ensure that a call to GKOP preparePool() takes account of other threads that might create objects concurrently, particularly the Evictor. * Changes: * POOL-280: Small refactoring of borrowObject() to reduce code duplication * POOL-307: Replace inefficient use of keySet with entrySet in GKOP * POOL-322: Update optional cglib library from 3.1 to 3.2.5. * POOL-323: Update optional OW2 ASM from 5.0.4 to 5.2. * set source=1.4 for java Changes in apache-commons-net: * Upgrade to 3.13.0 * New features * Add DatagramSocketClient.getDefaultTimeoutDuration() and deprecate getDefaultTimeout() * NET-741: Add subnet IPv6 handling with SubnetUtils6 #391 * Fixed Bugs * DaytimeTCPClientTest now should now pass inside most VPNs * Migrate tests to JUnit5 #358, #359 * Fix malformed Javadoc comments * IMAPExportMbox now restores the current thread's interrupt flag when catching InterruptedException * IOUtil.readWrite() now restores the current thread's interrupt flag when catching InterruptedException * TelnetInputStream now restores the current thread's interrupt flag when catching InterruptedException * NET-740: FTP fails to parse listings for Linux vsftpd in Chinese or Japanese #393 * TelnetInputStream.read() doesn't preserve the original InterruptedException as the cause of its InterruptedIOException * FTPClient._storeFile(String, String, InputStream) doesn't always close it's internal socket when an exception is thrown early in processing * ListenerList.removeListener(T) now ignores null input to avoid a NullPointerException * ListenerList.addListener(T) now ignores null input * Fix typo in FTPConnectionClosedException message from FTP .getReply(boolean) * Reimplement Util.copyReader() with IOUtils.copyLarge() * Reimplement Util.copyStream() with IOUtils.copyLarge() * Reimplement Util.copyStream() with IOUtils.copyLarge() * Deprecate Util.copyReader(Reader, Writer) in favor of IOUtils .copyLarge(Reader, Writer) * Upgrade to 3.12.0 * New features * Add org.apache.commons.net.nntp.Article#getChild() * Add org.apache.commons.net.nntp.Article#getNext() * Add private SubnetAddressStringIterable and private SubnetAddressStringIterator to implement SubnetInfo.iterableAddressStrings() and SubnetInfo.streamAddressStrings() #298 * Add SubnetInfo.iterableAddressStrings() * Add SubnetInfo.streamAddressStrings() * Add FTPCmd.OPTS * Add FTP.opts(String, String) * Add FTP.opts(String...) * Add FTP.setControlEncoding(Charset) * Add --OPTS to FTPClientExample * NET-727: Add accessing options map for TFTP request packet and allow using 'blksize' option #331 * Add org.apache.commons.net.util.ListenerList.isEmpty() * Add org.apache.commons.net.ftp.FTPClient .getSystemTypeOverride() * Add generics to ListenerList * Add module-info.class in the JAR file instead of an Automatic-Module-Name in MANIFEST.MF * Fixed Bugs * Increase message limit in IMAPReply.TAGGED_RESPONSE from 80 to 500 characters * Increase message limit in IMAPReply.UNTAGGED_RESPONSE from 160 to 500 characters * Remove InvalidKeySpecException from AuthenticatingIMAPClient .auth(AUTH_METHOD, String, String) never throws, it's not thrown * Remove InvalidKeySpecException from AuthenticatingIMAPClient .authenticate(AUTH_METHOD, String, String) never throws, it's not thrown * Remove InvalidKeySpecException from ExtendedPOP3Client .auth(AUTH_METHOD, String, String) never throws, it's not thrown * Remove InvalidKeySpecException from org.apache.commons.net.smtp.AuthenticatingSMTPClient .auth(AUTH_METHOD, String, String) never throws, it's not thrown * Fix SpotBugs RCN_REDUNDANT_NULLCHECK_OF_NONNULL_VALUE in SSLSocketUtils * Fix PMD UnnecessaryFullyQualifiedName * Fix PMD UnusedFormalParameter * Fix PMD AvoidBranchingStatementAsLastInLoop in org.apache .commons.net.bsd.RCommandClient * Fix PMD UselessOverridingMethod in org.apache.commons.net .telnet.TelnetClient * Fix PMD UnnecessaryModifier * Deprecate MLSxEntryParser default constructor in favor of MLSxEntryParser.getInstance() * Deprecate direct access to org.apache.commons.net.nntp.Article .kid and next fields * Fix SpotBugs CT_CONSTRUCTOR_THROW in Base64 by implementing finalize() as a noop to avoid finalizer attacks * Add missing Javadoc to ListenerList * Add missing Javadoc to SubnetUtils * Deprecate PrintCommandListeners.PrintCommandListeners() * Deprecate NtpUtils.NtpUtils() * Deprecate FTPFileFilters.FTPFileFilters() * Avoid multiple possible NullPointerException in SocketClient .verifyRemote(Socket) * PrintCommandListener.protocolReplyReceived(ProtocolCommandEvent) doesn't always use an end-of-line * FTPClientExample uses the wrong FTP system type to parse file lines * Base64 does not call super.finalize() * TFTPServer does not call super.finalize() * KeyManagerUtils.loadStore(String, File, String) shouldn't ignore an IOException closing a keystore stream; use try-with-resources * NNTPClient.readNewsgroupListing() can use an ArrayList instead of a Vector * Deprecate org.apache.commons.net.util.Charsets * Performance: NTFTPEntryParser.parseFTPEntry(String) doesn't need to parse timestamps if there is no name * Improve error handling in org.apache.commons.net.ftp.parser .DefaultFTPFileEntryParserFactory .createFileEntryParser(String, FTPClientConfig) * Fail-fast in org.apache.commons.net.PrintCommandListener .PrintCommandListener(PrintWriter, boolean, char, boolean) if the PrintWriter is null * Avoid NullPointerException in org.apache.commons.net .PrintCommandListener.protocolCommandSent(ProtocolCommandEvent) * Avoid NullPointerException in org.apache.commons.net .PrintCommandListener.protocolReplyReceived(ProtocolCommandEvent) * Upgrade to 3.11.1 * Fixed Bugs * Allow longer data in pattern IMAPReply.UNTAGGED_RESPONSE * Fix Reproducible Builds issues #259 * Upgrade to 3.11.0 * New features * NET-726: Add protected getters to FTPSClient #204 * Add SubnetUtils.toString() * Add Maven property project.build.outputTimestamp for build reproducibility * Add FTP.DEFLATE_TRANSFER_MODE to support the "deflate" compression format in FTPClient.setFileTransferMode(int) * Add org.apache.commons.net.SocketClient.checkOpenOutputStream() * Fixed Bugs * Precompile regular expression in UnixFTPEntryParser .preParse(List) * Guard against polynomial regular expression used on uncontrolled data in VMSVersioningFTPEntryParser.REGEX * Guard against polynomial regular expression used on uncontrolled data in IMAPReply.TAGGED_RESPONSE * Guard against polynomial regular expression used on uncontrolled data in IMAPReply.UNTAGGED_RESPONSE * NET-730: Cannot connect to FTP server with HTTP proxy * Base 64 Encoding with URL and Filename Safe Alphabet should not chunk per RFC 4648 * Deprecate org.apache.commons.net.util.Charsets.Charsets() for removal * Deprecate org.apache.commons.net.util.TrustManagerUtils .TrustManagerUtils() for removal * Upgrade to 3.10.0 * New features * Add and use DatagramSocketClient.setDefaultTimeout(Duration) and deprecate DatagramSocketClient.setDefaultTimeout(int) * Add and use TFTP.DEFAULT_TIMEOUT_DURATION and deprecate org.apache.commons.net.tftp.TFTP.DEFAULT_TIMEOUT * Add and use DatagramSocketClient#getSoTimeoutDuration() * Add and use DatagramSocketClient#setSoTimeout(Duration) * Add and use DatagramSocketClient.checkOpen() * Add TelnetClient.sendAYT(Duration) * TFTPServer implements AutoCloseable * DatagramSocketClient implements AutoCloseable * Add IMAP package tests, include junit-jupiter-params artifact #166 * Add Base64 missing tests and documentation fixes #161 * Add FTPFile tests and fix Javadoc typos #162 * Add IMAPReply tests and documentation fixes #165 * Fixed Bugs * NET-650: Delegate host resolution to Socket.connect() #138 * Fixes many grammar issues and typos in JavaDoc and code comments #141 * Remove redundant (null) initializations and other clean ups #155 * TFTPServer.setMaxTimeoutRetries() now throws IllegalArgumentException instead of RuntimeException * TFTPServer.setSocketTimeout() now throws IllegalArgumentException instead of RuntimeException * FTPCommand.checkArray() now throws IllegalStateException instead of RuntimeException * org.apache.commons.net.nntp.Threader now throws IllegalStateException instead of RuntimeException * POP3Command static initializer now throws IllegalStateException instead of RuntimeException * SMTPCommand static initializer now throws IllegalStateException instead of RuntimeException * SubnetUtils.SubnetInfo.getPreviousAddress() now throws IllegalStateException instead of RuntimeException * IMAPExportMbox.MboxListener.chunkReceived(IMAP) now throws UncheckedIOException instead of RuntimeException * IMAPUtils.imapLogin(URI, int, ProtocolCommandListener) now throws IOException instead of RuntimeException while maintaining method signature source compatibility * [StepSecurity] ci: Harden GitHub Actions #156 * NET-722: Javadoc for FtpClient .setControlKeepAliveReplyTimeout(Duration) says timeout is in milliseconds * Change class org.apache.commons.net.ftp.parser .MVSFTPEntryParser to support more datasets #182 * Bulletproof TFTPServerPathTest #173 * Deprecate org.apache.commons.net.util.Base64 in favor of java.util.Base64 * Replace use of org.apache.commons.net.util.Base64 with java.util.Base64 in org.apache.commons.net.ftp * Replace use of org.apache.commons.net.util.Base64 with java.util.Base64 in org.apache.commons.net.imap * Replace use of org.apache.commons.net.util.Base64 with java.util.Base64 in org.apache.commons.net.pop3 * Replace use of org.apache.commons.net.util.Base64 with java.util.Base64 in org.apache.commons.net.smtp Changes in apache-commons-daemon: * Upgrade to 1.6.1 * Bug Fixes: * Remove -nouses directive from maven-bundle-plugin. OSGi package imports now state 'uses' definitions for package imports, this doesn't affect JPMS (from org.apache.commons:commons-parent:80) * Document --enable-preview * Fix first appearance of --enable-native-access * Procrun. Fix redirection issues on some OS versions by using recommended method to redirect stdout and stderr. Fixes DAEMON-398. * Procrun. Fix updating of startup mode to 'Automatic (delayed)' being incorrectly processed as an update to 'Manual'. Fixes DAEMON-439. * Procrun. Fix timeout handling #238. Fixes DAEMON-468. * Procrun. Replace RTF version of license header with plain text version of full license in about box for monitor application. Fixes DAEMON-472. * Procrun. Service should be marked as stopped if the service worker crashes. Fixes DAEMON-475. * jsvc. Fix compilation warnings. * jsvc. Fix a regression in 1.5.1 that exposed long standing bugs around the locking and unlocking of pid files. Also fix the locking/unlocking bugs. * Detaches from console when the service stops #307. Fixes DAEMON-477. * jsvc. Correct a packaging error in the 1.6.0 native source tarball for *nix systems. Thanks to Michael Osipov. * New Features: * Add support for --enable-native-access Java startup option in jsvc. Fixes DAEMON-471. * Add tests for prunsrv on Windows #260. * Add Java API compatibility report to the site (JApiCmp). * Procun. Build binaries for Windows using the static hybrid CRT strategy by default. * jsvc. Use FreeBSD's setproctitle(3) to pass -procname similar to daemon(8). * procrun. Add ARM64 support for Windows binaries. Fixes DAEMON-462. * Update dependencies: * Bump org.apache.commons:commons-parent from 78 to 91 #253, #255, #287. * Update to use new ASF logo * Bump org.apache.commons:commons-parent from 93 to 99. * jsvc. Consistently use strerror(3) for log output. Changes in apache-commons-configuration2: * Upgrade to version 2.15.1 * Fixed Bugs * CONFIGURATION-856: The artifact commons-io:commons-io is a normal dependency * Avoid NPE when combined location strategy sub strategies is immutable list (#639) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1146=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1146=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * apache-commons-daemon-jsvc-1.6.1-160000.1.2 * apache-commons-daemon-1.6.1-160000.1.2 * apache-commons-daemon-jsvc-debuginfo-1.6.1-160000.1.2 * apache-commons-daemon-debugsource-1.6.1-160000.1.2 * SUSE Linux Enterprise Server 16.0 (noarch) * apache-commons-pool2-2.13.1-160000.1.2 * apache-commons-daemon-javadoc-1.6.1-160000.1.2 * apache-commons-net-javadoc-3.13.0-160000.1.2 * apache-commons-configuration2-javadoc-2.15.1-160000.1.2 * apache-commons-pool2-javadoc-2.13.1-160000.1.2 * apache-commons-net-3.13.0-160000.1.2 * apache-commons-configuration2-2.15.1-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * apache-commons-pool2-2.13.1-160000.1.2 * apache-commons-daemon-javadoc-1.6.1-160000.1.2 * apache-commons-net-javadoc-3.13.0-160000.1.2 * apache-commons-configuration2-javadoc-2.15.1-160000.1.2 * apache-commons-pool2-javadoc-2.13.1-160000.1.2 * apache-commons-net-3.13.0-160000.1.2 * apache-commons-configuration2-2.15.1-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * apache-commons-daemon-jsvc-1.6.1-160000.1.2 * apache-commons-daemon-1.6.1-160000.1.2 * apache-commons-daemon-jsvc-debuginfo-1.6.1-160000.1.2 * apache-commons-daemon-debugsource-1.6.1-160000.1.2 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:28 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:35:28 -0000 Subject: SUSE-SU-2026:22559-1: important: Security update for perl-List-SomeUtils-XS Message-ID: <178404692897.143.6529556562203904152@178315a69387> # Security update for perl-List-SomeUtils-XS Announcement ID: SUSE-SU-2026:22559-1 Release Date: 2026-07-06T20:10:17Z Rating: important References: * bsc#1269210 Cross-References: * CVE-2026-12844 CVSS scores: * CVE-2026-12844 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-12844 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12844 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-List-SomeUtils-XS fixes the following issue * CVE-2026-12844: heap buffer overflow in the `pairwise` function (bsc#1269210). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1144=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1144=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-debuginfo-0.58-160000.3.2 * perl-List-SomeUtils-XS-debugsource-0.58-160000.3.2 * perl-List-SomeUtils-XS-0.58-160000.3.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-List-SomeUtils-XS-debuginfo-0.58-160000.3.2 * perl-List-SomeUtils-XS-debugsource-0.58-160000.3.2 * perl-List-SomeUtils-XS-0.58-160000.3.2 ## References: * https://www.suse.com/security/cve/CVE-2026-12844.html * https://bugzilla.suse.com/show_bug.cgi?id=1269210 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:46 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:35:46 -0000 Subject: SUSE-SU-2026:22558-1: important: Security update for google-osconfig-agent Message-ID: <178404694694.143.9988729327763661513@178315a69387> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:22558-1 Release Date: 2026-07-06T20:10:17Z Rating: important References: * bsc#1210938 * bsc#1251453 * bsc#1251704 * bsc#1260264 * bsc#1262926 * bsc#1264923 * bsc#1265762 * bsc#1266171 * bsc#1266603 Cross-References: * CVE-2023-45288 * CVE-2025-22868 * CVE-2025-47911 * CVE-2025-58190 * CVE-2026-33186 * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22868 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22868 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41506 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41506 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-41506 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-41506 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for google-osconfig-agent fixes the following issues * CVE-2023-45288: golang.org/x/net/http2: close connections when receiving too many headers. * CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (bsc#1251453). * CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input (bsc#1251704). * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265762). * CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262926). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266171). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264923). Changes for google-osconfig-agent: * Update to version 20260615.01 * Upgrade golang.org/x/crypto & golang.org/x/net (#1006) * from version 20260615.00 * Add unit tests for ospatch_apt_upgrade.go (#938) * Update to version 20260611.00 * Add unit tests for policies/policies.go PART 5 (#998) * from version 20260610.00 * Add unit tests for policies/policies.go PART 4 (#997) * from version 20260609.02 * squash commits (#936) * from version 20260609.01 * Add unit tests for policies/policies.go PART 3 (#996) * from version 20260609.00 * Add unit tests for policies/policies.go PART 2 (#991) * from version 20260602.01 * Align format of dates and timestamp collected across Windows packages (#973) * from version 20260602.00 * Add unit tests for config/config,go (#979) * from version 20260528.00 * Bump github.com/containerd/containerd (#990) * from version 20260521.00 * Cover agentconfig functionality by unit tests (#925) * from version 20260520.04 * Add unit tests for policies/googet.go (#961) * Bump github.com/go-git/go-git/v5 (#987) * from version 20260520.02 * Add unit tests for policies/yum.go (#952) * Add unit tests for policies/apt.go PART 3 (#951) * from version 20260520.00 * Add unit tests for policies/zypper.go (#953) * from version 20260519.00 * Add unit tests for policies/policies.go PART 1 (#949) * from version 20260513.01 * Bump github.com/go-git/go-git/v5 (#981), this also updates golang.org/x/net to v0.53.0 (bsc#1265762, CVE-2026-33814) * from version 20260513.00 * upgrade a few packages (#980) * from version 20260512.02 * Add/improve unit tests for agentendpoint/exec_task.go (#933) * from version 20260512.01 * Cover google_update.go by unit tests (#941) * from version 20260512.00 * Change zone for arm64 builds because of stockout (#978) * Update to version 20260511.00 * switch to t2a-standard-2 on ARM package build (#977) * from version 20260505.03 * Cover zypper_patch by unit tests (#958) * from version 20260505.02 * Remove unused functions DisableAutoUpdates (#970) * from version 20260505.01 * Bump go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc (#966) * from version 20260505.00 * Upgrade a few dependencies across the repo (#968) * github.com/go-git/go-git/v5 5.16.2->5.18.0 (bsc#1264923, CVE-2026-41506) * github.com/go-jose/go-jose/v4 4.1.3->4.1.4 (bsc#1262926, CVE-2026-34986) * github.com/go-viper/mapstructure/v2 2.3.0->2.4.0 * go.opentelemetry.io/otel 1.40.0->1.41.0 * go.opentelemetry.io/otel/sdk 1.39.0->1.43.0 * from version 20260504.01 * bump github.com/docker/cli to 29.2.0 (#962) * from version 20260504.00 * Bump github.com/opencontainers/selinux (#960) * Update to version 20260428.00 * Add/improve unit tests for agentendpoint/agentendpoint.go (#930) * from version 20260427.03 * Cover config/file.go by unit tests (#935) * from version 20260422.01 * Cover patch_linux.go by unit tests (#932) * from version 20260422.00 * upgrade grpc package in main package and e2e tests (#959) (bsc#1260264, CVE-2026-33186) * from version 20260417.04 * Bump OSV-Scalibr version to v0.4.3 (#956) * from version 20260417.03 * Add unit tests for updates_linux.go (#937) * from version 20260417.02 * Add zone to CreateDisk step (#955) * from version 20260417.01 * Change disk type for deb11 (#954) * from version 20260417.00 * Add unit tests for policies/apt.go PART 1 (#950) * from version 20260410.02 * Add unit tests for packages/pty_linux.go (#943) * from version 20260410.01 * fix disk type for arm workflows (#948) * from version 20260410.00 * Change machine type for arm based workflows (#946) * Update to version 20260330.00 * bump timeouts for all workflows (#940) * from version 20260326.00 * Cover exec_resource.go by unit tests (#934) * from version 20260318.00 * Integrate OSConfig agent with ReportVmInventory (#923) * from version 20260313.02 * remove cacheonly flag from yum upgrade (#924) * from version 20260313.01 * conditions python version override (#927) * from version 20260313.00 * Fix presubmits by explicitly set python version for rpm based systems (#926) * from version 20260311.00 * Bump osconfig version (#922) * from version 20260309.02 * Extend OSV scalibr extractor (#921) * from version 20260309.01 * upgrade golang.org/x/crypto and it's transitive deps (#918) * from version 20260309.00 * Add purl to pkg info (#920) * from version 20260306.00 * Add 'Type' field to PkgInfo (#919) * from version 20260303.01 * Upgrade go.opentelemetry.io/otel/sdk (#913) * from version 20260303.00 * Bump github.com/vbatts/tar-split from 0.11.5 to 0.12.2 (#908) * from version 20260302.00 * Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.7 (#906) * from version 20260126.00 * Bump go.opentelemetry.io/otel/sdk from 1.38.0 to 1.39.0 (#905) * Bump github.com/sirupsen/logrus (#894) * Update to version 20260119.00 * Bump cloud.google.com/go/storage from 1.56.0 to 1.58.0 (#899) * Update to version 20251230.00 * chore: Migrate gsutil usage to gcloud storage (#904) * from version 20251223.00 * fix e2e tests for report inventory (#903) * from version 20251222.01 * Revert "Bump cloud.google.com/go/longrunning from 0.6.3 to 0.7.0 (#882)" (#902) * from version 20251222.00 * Bump golang to the new version (#900) * from version 20251218.00 * add new CODEOWNERS (#901) * from version 20251217.00 * Bump cloud.google.com/go/longrunning from 0.6.3 to 0.7.0 (#882) * Bump the golang compiler version to 1.24.5 * Update to version 20251202.00 * Revert "Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.5 (#887)" (#893) * Update to version 20251201.00 * Revert "Bump github.com/containerd/containerd (#890)" (#892) * Update to version 20251126.00 * Bump github.com/containerd/containerd (#890) * Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.5 (#887) * Update to version 20251028.00 * Bump go.opentelemetry.io/otel/sdk/metric from 1.35.0 to 1.38.0 (#886) * Bump github.com/tidwall/pretty from 1.2.0 to 1.2.1 (#880) * from version 20251023.02 * Create multiple_os.yaml (#883) * from version 20251023.00 * Bump github.com/docker/go-connections from 0.4.0 to 0.6.0 (#877) * Add test runner for e2e tests (#876) * Update to version 20250925.00 * Bump cloud.google.com/go/auth/oauth2adapt from 0.2.7 to 0.2.8 (#870) * Bump google.golang.org/protobuf from 1.36.6 to 1.36.9 (#874) * Bump go.opentelemetry.io/otel from 1.35.0 to 1.38.0 (#872) * Bump github.com/golang/glog from 1.2.4 to 1.2.5 (#830) * Update to version 20250902.01 * Bump github.com/googleapis/enterprise-certificate-proxy (#829) * from version 20250902.00 * update github.com/go-jose/go-jose/v4 (#869) * Upgrade scalibr and other deps (#866) * from version 20250901.00 * Fix possibility of path traversal for zip and tar archival (#868) * from version 20250825.00 * set CODEOWNERS file as required by org (#863) * from version 20250819.00 * Fix/rhel10 build centos image (#860) * from version 20250814.00 * Fix/rhel10 build image (#859) * from version 20250813.00 * Fix: Add RHEL 10 support to RPM startup script (#858) * from version 20250811.00 * Remove old/sles-15-sp4-sap as image is deprecated (#857) * Update to version 20250806.00 * Fixed JSON identifier for the universe domain (#855) * from version 20250729.00 * Bump github.com/google/s2a-go from 0.1.8 to 0.1.9 (#828) * from version 20250725.02 * Update utils.go (#854) * Upgrade golang.org/x/oauth2 package to the latest. (#853) * Bump golang.org/x/time from 0.9.0 to 0.12.0 (#839) * from version 20250725.01 * Bump golang.org/x/oauth2 (#848) * Port fix for debian 11 to goo package manager. (#852) * from version 20250725.00 * Update Golang version in common.sh and skip backports repo for debian 11 (#850) * from version 20250723.01 * Add workflows to build package for el10 (#849) * from version 20250721.00 * Make OS Config agent TPC aware (#846) * from version 20250718.00 * Create workflows for new Debian 13. (#847) * Update to version 20250703.00 * Fix sles images (#844) * from version 20250702.00 * Remove rhel-sap 8-4 add rhel-sap 8-10 (#843) * from version 20250701.00 * Bump the go_modules group across 1 directory with 2 updates (#840) * Update to version 20250606.00 * Change base docker images Google's official base images. (#838) * Update to version 20250523.01 * Add a simple no-op OS policy for user testing (#837) * from version 20250523.00 * Introduce scalibr inventory extractor for dpkg/rpm/cos os/filesystem extractors (linux) (#834) * Trace GetInstalledPackages memory levels (#835) * from version 20250520.00 * Update to version 20250513.00 * Fix rpm extractor, handle (none) value correctly. (#833) * from version 20250512.01 * Bump github.com/envoyproxy/go-control-plane from 0.13.1 to 0.13.4 (#816) * from version 20250512.00 * Bump golang.org/x/net from 0.39.0 to 0.40.0 (#819) * from version 20250508.01 * cosmetic refactoring to osinfo package (#826) * from version 20250508.00 * Refactor /inventory with dependency injection (#825) * Add debian, ubuntu (InstalledDebPackages) snapshots (#821) * cover packages_linux.go file with tests (#824) * Add debian (10,11,12) GetPackageUpdates output snapshots (#822) * from version 20250507.00 * Add InstalledRPMPackages snapshot tests (#823) * from version 20250506.02 * Yum tests: simplify initialization of exit errors (#820) * from version 20250506.01 * Improve test coverage for gem package manager (#818) * from version 20250506.00 * after go/x/crypto update 0.32.0 -> 0.37.0 (#817) * from version 20250505.01 * Improve packages package coverage (#814) * Bump golang.org/x/net from 0.34.0 to 0.39.0 (#807) * from version 20250505.00 * Bump golang.org/x/crypto from 0.32.0 to 0.37.0 (#806) * from version 20250430.00 * Snapshot YumUpdates (GetPackageUpdates) output (#813) * from version 20250428.00 * Snapshot ZypperPatches, ZypperUpdates (GetPackageUpdates) output for sles 12, 15 testdata (#812) * from version 20250423.00 * Introduce MatchSnapshot large test results matcher function, snapshot apt- deb GetPackageUpdates (#811) * from version 20250416.02 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1136=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1136=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * google-osconfig-agent-20260615.01-160000.1.2 * google-osconfig-agent-debuginfo-20260615.01-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * google-osconfig-agent-20260615.01-160000.1.2 * google-osconfig-agent-debuginfo-20260615.01-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22868.html * https://www.suse.com/security/cve/CVE-2025-47911.html * https://www.suse.com/security/cve/CVE-2025-58190.html * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1210938 * https://bugzilla.suse.com/show_bug.cgi?id=1251453 * https://bugzilla.suse.com/show_bug.cgi?id=1251704 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1262926 * https://bugzilla.suse.com/show_bug.cgi?id=1264923 * https://bugzilla.suse.com/show_bug.cgi?id=1265762 * https://bugzilla.suse.com/show_bug.cgi?id=1266171 * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:54 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:35:54 -0000 Subject: SUSE-SU-2026:22557-1: important: Security update for haproxy Message-ID: <178404695418.143.13587885648329529382@178315a69387> # Security update for haproxy Announcement ID: SUSE-SU-2026:22557-1 Release Date: 2026-07-07T10:14:15Z Rating: important References: * bsc#1268557 * bsc#1268558 Cross-References: * CVE-2026-55203 * CVE-2026-55204 CVSS scores: * CVE-2026-55203 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-55203 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55203 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N * CVE-2026-55204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server High Availability Extension 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues * Update to version 3.2.21+git0.dbe43be37 * CVE-2026-55203: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557). * CVE-2026-55204: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server High Availability Extension 16.0 zypper in -t patch SUSE-SLES-HA-16.0-1166=1 ## Package List: * SUSE Linux Enterprise Server High Availability Extension 16.0 (ppc64le s390x x86_64) * haproxy-debuginfo-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-debugsource-3.2.21+git0.dbe43be37-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55203.html * https://www.suse.com/security/cve/CVE-2026-55204.html * https://bugzilla.suse.com/show_bug.cgi?id=1268557 * https://bugzilla.suse.com/show_bug.cgi?id=1268558 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:36:28 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:36:28 -0000 Subject: SUSE-SU-2026:2961-1: important: Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5) Message-ID: <178404698883.143.9121959134698207634@178315a69387> # Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2961-1 Release Date: 2026-07-14T10:33:59Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.163 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2961=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2961=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-4-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-4-150500.2.2 * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-4-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-4-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-4-150500.2.2 * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-4-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:37:08 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:37:08 -0000 Subject: SUSE-SU-2026:2957-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise 15 SP6) Message-ID: <178404702858.143.322674440948299968@178315a69387> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2957-1 Release Date: 2026-07-14T10:19:59Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.87 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2959=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2958=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-2957=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2959=1 SUSE-2026-2958=1 SUSE-2026-2957=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_87-default-8-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-5-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-8-150600.2.2 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-8-150600.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_87-default-8-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-5-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-8-150600.2.2 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-8-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:37:42 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:37:42 -0000 Subject: SUSE-SU-2026:2956-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7) Message-ID: <178404706251.143.2359150418343934723@178315a69387> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2956-1 Release Date: 2026-07-14T10:20:15Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.45 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2956=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2960=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_45-default-4-150700.2.2 * kernel-livepatch-6_4_0-150700_53_37-default-debuginfo-6-150700.2.2 * kernel-livepatch-6_4_0-150700_53_37-default-6-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_11-debugsource-6-150700.2.2 * kernel-livepatch-6_4_0-150700_53_45-default-debuginfo-4-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_13-debugsource-4-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:37:56 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:37:56 -0000 Subject: SUSE-SU-2026:2955-1: important: Security update for the Linux Kernel (Live Patch 76 for SUSE Linux Enterprise 12 SP5) Message-ID: <178404707620.143.5178538187615253838@178315a69387> # Security update for the Linux Kernel (Live Patch 76 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2955-1 Release Date: 2026-07-14T11:34:07Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.290 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2955=1 SUSE-SLE-Live- Patching-12-SP5-2026-2973=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_290-default-10-2.1 * kgraft-patch-4_12_14-122_269-default-15-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:38:12 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:38:12 -0000 Subject: SUSE-SU-2026:2977-1: important: Security update for afterburn Message-ID: <178404709209.143.15966209616920094125@178315a69387> # Security update for afterburn Announcement ID: SUSE-SU-2026:2977-1 Release Date: 2026-07-14T11:44:35Z Rating: important References: * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves nine vulnerabilities can now be installed. ## Description: This update for afterburn fixes the following issues Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ? * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2977=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2977=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-debugsource-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-debugsource-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:38:30 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:38:30 -0000 Subject: SUSE-SU-2026:2976-1: important: Security update for afterburn Message-ID: <178404711041.143.3932734557698591390@178315a69387> # Security update for afterburn Announcement ID: SUSE-SU-2026:2976-1 Release Date: 2026-07-14T11:39:57Z Rating: important References: * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that solves nine vulnerabilities can now be installed. ## Description: This update for afterburn fixes the following issues: Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ? * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2976=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2976=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-debugsource-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-debugsource-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:38:46 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:38:46 -0000 Subject: SUSE-SU-2026:2975-1: important: Security update for afterburn Message-ID: <178404712602.143.5529040608994096894@178315a69387> # Security update for afterburn Announcement ID: SUSE-SU-2026:2975-1 Release Date: 2026-07-14T11:38:45Z Rating: important References: * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for afterburn fixes the following issues: Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ? * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2975=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150500.3.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 x86_64) * afterburn-debugsource-5.10.0.git73.b97f772-150500.3.6.1 * afterburn-debuginfo-5.10.0.git73.b97f772-150500.3.6.1 * afterburn-5.10.0.git73.b97f772-150500.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:38:52 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:38:52 -0000 Subject: SUSE-SU-2026:2974-1: important: Security update for dnsmasq Message-ID: <178404713292.143.11042840228783825300@178315a69387> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:2974-1 Release Date: 2026-07-14T11:36:52Z Rating: important References: * bsc#1268764 * bsc#1268882 Cross-References: * CVE-2026-12725 * CVE-2026-12969 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12969 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues: * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). * CVE-2026-12969: out-of-bounds read in `find_soa()` due to missing extrabytes validation (bsc#1268882). Changes for dnsmasq: * Update to 2.93: * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2974=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2974=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-2.93-18.32.1 * dnsmasq-debuginfo-2.93-18.32.1 * dnsmasq-debugsource-2.93-18.32.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * dnsmasq-2.93-18.32.1 * dnsmasq-debuginfo-2.93-18.32.1 * dnsmasq-debugsource-2.93-18.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-12969.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 * https://bugzilla.suse.com/show_bug.cgi?id=1268882 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:38:58 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:38:58 -0000 Subject: SUSE-RU-2026:2972-1: moderate: Recommended update for lifecycle-data-sle-module-development-tools Message-ID: <178404713875.143.7555460021594593070@178315a69387> # Recommended update for lifecycle-data-sle-module-development-tools Announcement ID: SUSE-RU-2026:2972-1 Release Date: 2026-07-14T11:33:47Z Rating: moderate References: Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for lifecycle-data-sle-module-development-tools fixes the following issues: * lifecycle of gcc14 got extended until end of july. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2972=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2972=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2972=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2972=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2972=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2972=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2972=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2972=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2972=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2972=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2972=1 ## Package List: * Development Tools Module 15-SP7 (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * lifecycle-data-sle-module-development-tools-1-150200.3.39.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:39:05 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:39:05 -0000 Subject: SUSE-RU-2026:2971-1: important: Recommended update for rasdaemon Message-ID: <178404714548.143.11227170071370103584@178315a69387> # Recommended update for rasdaemon Announcement ID: SUSE-RU-2026:2971-1 Release Date: 2026-07-14T11:32:10Z Rating: important References: * bsc#1240542 * bsc#1252733 Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has two fixes can now be installed. ## Description: This update for rasdaemon fixes the following issues: * Avoid races which may let the rasdaemon fail to start at bootup (bsc#1252733) * skip not existing events * Fix: on systems where no DIMMs are installed and the systems only have HBM memory, the ras-mc-ctl --register-labels and --print-labels return an error instead of an info message (bsc#1240542) * Change service from localonly to manual to avoid service run on check-in ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2971=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2971=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rasdaemon-0.8.0.49.git+f9cb13b-150600.3.3.1 * rasdaemon-debugsource-0.8.0.49.git+f9cb13b-150600.3.3.1 * rasdaemon-debuginfo-0.8.0.49.git+f9cb13b-150600.3.3.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * rasdaemon-0.8.0.49.git+f9cb13b-150600.3.3.1 * rasdaemon-debugsource-0.8.0.49.git+f9cb13b-150600.3.3.1 * rasdaemon-debuginfo-0.8.0.49.git+f9cb13b-150600.3.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1240542 * https://bugzilla.suse.com/show_bug.cgi?id=1252733 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:39:10 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:39:10 -0000 Subject: SUSE-SU-2026:2970-1: important: Security update for pacemaker Message-ID: <178404715089.143.9756571165278967128@178315a69387> # Security update for pacemaker Announcement ID: SUSE-SU-2026:2970-1 Release Date: 2026-07-14T11:27:53Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 12 SP5 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2970=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2026-2970=1 * SUSE Linux Enterprise High Availability Extension 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2026-2970=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2970=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * pacemaker-cts-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * libpacemaker3-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cli-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-remote-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-remote-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-debugsource-1.1.24+20210811.f5abda0ee-3.52.1 * libpacemaker3-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cts-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cli-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * SUSE Linux Enterprise High Availability Extension 12 SP5 (ppc64le s390x x86_64) * pacemaker-cts-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * libpacemaker3-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cli-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-remote-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-remote-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-debugsource-1.1.24+20210811.f5abda0ee-3.52.1 * libpacemaker3-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cts-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cli-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpacemaker-devel-1.1.24+20210811.f5abda0ee-3.52.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpacemaker-devel-1.1.24+20210811.f5abda0ee-3.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:39:35 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:39:35 -0000 Subject: SUSE-SU-2026:2969-1: moderate: Security update for wireshark Message-ID: <178404717593.143.9947145390186397546@178315a69387> # Security update for wireshark Announcement ID: SUSE-SU-2026:2969-1 Release Date: 2026-07-14T11:23:14Z Rating: moderate References: * bsc#1263725 * bsc#1263728 * bsc#1263731 * bsc#1263734 * bsc#1263739 * bsc#1263743 * bsc#1263744 * bsc#1263750 * bsc#1263752 * bsc#1263753 * bsc#1263754 * bsc#1263756 * bsc#1263758 * bsc#1263765 * bsc#1263766 Cross-References: * CVE-2026-5401 * CVE-2026-5403 * CVE-2026-5404 * CVE-2026-5406 * CVE-2026-5407 * CVE-2026-5408 * CVE-2026-5653 * CVE-2026-6521 * CVE-2026-6522 * CVE-2026-6527 * CVE-2026-6532 * CVE-2026-6535 * CVE-2026-6538 * CVE-2026-6870 * CVE-2026-7379 CVSS scores: * CVE-2026-5401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5401 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5403 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5403 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5404 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5404 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5404 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5406 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5407 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5408 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5408 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5653 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5653 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5653 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6522 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6527 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6532 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6532 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6535 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6535 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6538 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6870 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7379 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for wireshark fixes the following issues * CVE-2026-5401: AFP dissector crash (bsc#1263756). * CVE-2026-5403: SBC audio codec crash (bsc#1263765). * CVE-2026-5404: K12 RF5 file parser crash (bsc#1263766). * CVE-2026-5406: FC-SWILS dissector crash (bsc#1263754). * CVE-2026-5407: SMB2 dissector infinite loop (bsc#1263753). * CVE-2026-5408: BT-DHT dissector crash (bsc#1263752). * CVE-2026-5653: DCP-ETSI dissector crash (bsc#1263750). * CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops (bsc#1263744). * CVE-2026-6522: RPKI-Router protocol dissector infinite loop (bsc#1263743). * CVE-2026-6527: ASN.1 PER dissector crash (bsc#1263739). * CVE-2026-6532: Kismet protocol dissector crash (bsc#1263734). * CVE-2026-6535: Dissection engine zlib decompression crash (bsc#1263731). * CVE-2026-6538: BEEP dissector crash (bsc#1263728). * CVE-2026-6870: GSM RP protocol dissector crash (bsc#1263725). * CVE-2026-7379: Sharkd utility memory leak (bsc#1263758). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2969=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libwiretap7-debuginfo-2.4.16-48.69.1 * libwsutil8-2.4.16-48.69.1 * wireshark-debuginfo-2.4.16-48.69.1 * libwsutil8-debuginfo-2.4.16-48.69.1 * wireshark-devel-2.4.16-48.69.1 * libwireshark9-debuginfo-2.4.16-48.69.1 * wireshark-gtk-debuginfo-2.4.16-48.69.1 * libwiretap7-2.4.16-48.69.1 * libwireshark9-2.4.16-48.69.1 * wireshark-debugsource-2.4.16-48.69.1 * wireshark-2.4.16-48.69.1 * libwscodecs1-2.4.16-48.69.1 * libwscodecs1-debuginfo-2.4.16-48.69.1 * wireshark-gtk-2.4.16-48.69.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5401.html * https://www.suse.com/security/cve/CVE-2026-5403.html * https://www.suse.com/security/cve/CVE-2026-5404.html * https://www.suse.com/security/cve/CVE-2026-5406.html * https://www.suse.com/security/cve/CVE-2026-5407.html * https://www.suse.com/security/cve/CVE-2026-5408.html * https://www.suse.com/security/cve/CVE-2026-5653.html * https://www.suse.com/security/cve/CVE-2026-6521.html * https://www.suse.com/security/cve/CVE-2026-6522.html * https://www.suse.com/security/cve/CVE-2026-6527.html * https://www.suse.com/security/cve/CVE-2026-6532.html * https://www.suse.com/security/cve/CVE-2026-6535.html * https://www.suse.com/security/cve/CVE-2026-6538.html * https://www.suse.com/security/cve/CVE-2026-6870.html * https://www.suse.com/security/cve/CVE-2026-7379.html * https://bugzilla.suse.com/show_bug.cgi?id=1263725 * https://bugzilla.suse.com/show_bug.cgi?id=1263728 * https://bugzilla.suse.com/show_bug.cgi?id=1263731 * https://bugzilla.suse.com/show_bug.cgi?id=1263734 * https://bugzilla.suse.com/show_bug.cgi?id=1263739 * https://bugzilla.suse.com/show_bug.cgi?id=1263743 * https://bugzilla.suse.com/show_bug.cgi?id=1263744 * https://bugzilla.suse.com/show_bug.cgi?id=1263750 * https://bugzilla.suse.com/show_bug.cgi?id=1263752 * https://bugzilla.suse.com/show_bug.cgi?id=1263753 * https://bugzilla.suse.com/show_bug.cgi?id=1263754 * https://bugzilla.suse.com/show_bug.cgi?id=1263756 * https://bugzilla.suse.com/show_bug.cgi?id=1263758 * https://bugzilla.suse.com/show_bug.cgi?id=1263765 * https://bugzilla.suse.com/show_bug.cgi?id=1263766 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:39:42 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:39:42 -0000 Subject: SUSE-SU-2026:2968-1: moderate: Security update for python-Authlib Message-ID: <178404718294.143.10393951270727396459@178315a69387> # Security update for python-Authlib Announcement ID: SUSE-SU-2026:2968-1 Release Date: 2026-07-14T11:15:55Z Rating: moderate References: * bsc#1263114 * bsc#1266665 Cross-References: * CVE-2026-41425 * CVE-2026-44681 CVSS scores: * CVE-2026-41425 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-41425 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-41425 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-44681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-Authlib fixes the following issues * CVE-2026-41425: no CSRF protection on the cache feature in `authlib.integrations.starlette_client.OAuth` (bsc#1263114). * CVE-2026-44681: unauthenticated open redirect in the `OpenIDImplicitGrant` and `OpenIDHybridGrant` authorization endpoints (bsc#1266665). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2968=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2968=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-Authlib-1.3.1-150600.3.22.1 * openSUSE Leap 15.6 (noarch) * python311-Authlib-1.3.1-150600.3.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41425.html * https://www.suse.com/security/cve/CVE-2026-44681.html * https://bugzilla.suse.com/show_bug.cgi?id=1263114 * https://bugzilla.suse.com/show_bug.cgi?id=1266665 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:39:58 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:39:58 -0000 Subject: SUSE-SU-2026:2967-1: moderate: Security update for libgnt, meson, pidgin Message-ID: <178404719807.143.11090309033857316165@178315a69387> # Security update for libgnt, meson, pidgin Announcement ID: SUSE-SU-2026:2967-1 Release Date: 2026-07-14T11:11:18Z Rating: moderate References: * bsc#1057701 * bsc#1062785 * bsc#1068818 * bsc#1125736 * bsc#1184786 * bsc#1191780 * bsc#1260058 * jsc#SLE-21105 Cross-References: * CVE-2019-25544 CVSS scores: * CVE-2019-25544 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2019-25544 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2019-25544 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2019-25544 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2019-25544 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability, contains one feature and has six security fixes can now be installed. ## Description: This update for libgnt, meson, pidgin fixes the following issues Security issue: * CVE-2019-25544: denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation (bsc#1260058). Non security issues: Changes for meson: * Update to version 0.46.0. * Require python2-devel for the testsuite (bsc#1125736) * Update to version 0.45.0: * Config-Tool based dependencies can be specified in a cross file. * Visual Studio C# compiler support. * Removed two deprecated features: * Generator outputs can preserve directory structure. * Hexadecimal string literals. * install_data()`defaults to``.}/{projectname * install_subdir() supports strip_directory. * Integer options. * New method meson.project_license(). * Rust cross-compilation. * Rust compiler-private library disambiguation. * Project templates. * Improve test setup selection. * Yielding subproject option to superproject. * Update to version 0.44.1: * Support running out-of-tree tests against a meson in PATH. * Don't add rpaths to system libraries. * Fix meson location detection from other meson tools. * Various boost, pkg-config and vala related fixes. * Update to version 0.44.0: * New features: * Added warning function. * Adds support for additional Qt5-Module keyword moc_extra_arguments. * Prefix-dependent defaults for sysconfdir, localstatedir and sharedstatedir. * An array type for user options. * LLVM dependency supports both dynamic and static linking. * Added if_found to subdir. * get_unquoted() method for the configuration data object. * Added disabler object. * Config-Tool based dependencies gained a method to get arbitrary options. * Disable tests for static llvm: we don't ship the static libs. * Add cmake(Qt5LinguistTools), libwmf-devel BuildRequires and zlib-devel- static: new dependencies for various tests. * Require python3-xml: mesonbuild/modules/qt5.py imports the xml module (bsc#1068818). * Update to version 0.43.0: * Generator learned capture: Generators can now be configured to capture the standard output. * Can index CustomTarget objects: The CustomTarget object can now be indexed like an array. The resulting object can be used as a source file for other Targets, this will create a dependency on the original CustomTarget, but will only insert the generated file corresponding to the index value of the CustomTarget's output keyword. * The cross file can now be used for overriding the result of find_program. Then issuing the command find_program('objdump') will return the version specified in the cross file. * Easier handling of supported compiler arguments. * Better support for shared libraries in non-system paths: This release adds feature parity to shared libraries that are either in non-standard system paths or shipped as part of your project. On systems that support rpath, Meson automatically adds rpath entries to built targets using manually found external libraries. * The Wrap dependency system now supports Subversion (svn). This support is rudimentary. The repository url has to point to a specific (sub)directory containing the meson.build file (typically trunk/). However, providing a revision is supported. * Don't use obsolete boost-devel for openSUSE Leap 15.0 and newer (bsc#1062785). * Update to version 0.42.1. * Tumbleweed meson 0.42.0-1.1fails for clang++ projects (bsc#1057701). * Update to version 0.42.0: * Distribution tarballs from Mercurial repositories. Creating distribution tarballs can now be made out of projects based on Mercurial. As before, this remains possible only with the Ninja backend. * Keyword argument verification. Meson will now check the keyword arguments used when calling any function and print a warning if any of the keyword arguments is not known. In the future this will become a hard error. * Add support for Genie to Vala compiler. The Vala compiler has an alternative syntax, Genie, that uses the .gs file extension. Meson now recognises and uses Genie files. * Pkgconfig support for additional cflags. The Pkgconfig module object can add arbitrary extra cflags to the Cflags value in the .pc file, using the "extra_cflags" keyword. * Base options accessible via get_option(). Base options are now accessible via the get_option() function. * Allow crate type configuration for Rust compiler. Rust targets now take an optional rust_crate_type keyword, allowing you to set the crate type of the resulting artifact. Valid crate types are dylib or cdylib for shared libraries, and rlib or staticlib for static libraries. For more, see Rust's linkage reference. * Simultaneous use of Address- and Undefined Behavior Sanitizers. Both the address- and undefined behavior sanitizers can now be used simultaneously by passing -Db_sanitize=address,undefined to Meson. * Unstable SIMD module. A new experimental module to compile code with many different SIMD instruction sets and selecting the best one at runtime. This module is unstable, meaning it's API is subject to change in later releases. It might also be removed altogether. * Import libraries for executables on Windows. The new keyword implib to executable() allows generation of an import library for the executable. * Added build_rpath keyword argument. You can specify build_rpath: '/foo/bar' in build targets and the given path will get added to the target's rpath in the build tree. It is removed during the install step. * Meson will print a warning when the user tries to add an rpath linker flag manually, e.g. via link_args to a target. This is not recommended because having multiple rpath causes them to stomp on each other. This warning will become a hard error in some future release. * Vulkan dependency module. Vulkan can now be used as native dependency. The dependency module will detect the VULKAN_SDK environment variable or otherwise try to receive the vulkan library and header via pkgconfig or from the system. * Limiting the maximum number of linker processes. With the Ninja backend it is now possible to limit the maximum number of concurrent linker processes. This is usually only needed for projects that have many large link steps that cause the system to run out of memory if they are run in parallel. This limit can be set with the new backend_max_links option. * Disable implicit include directories. By default Meson adds the current source and build directories to the header search path. On some rare occasions this is not desired. Setting the implicit_include_directories keyword argument to false these directories are not used. * Support for MPI dependency. MPI is now supported as a dependency. Because dependencies are language-specific, you must specify the requested language with the language keyword, i.e., dependency('mpi', language='c') will request the C MPI headers and libraries. See the MPI dependency for more information. * Allow excluding files or directories from install_subdir. The install_subdir command accepts the new exclude_files and exclude_directories keyword arguments that allow specified files or directories to be excluded from the installed subdirectory. * Make all Meson functionality invokable via the main executable. Previously Meson had multiple executables such as mesonintrospect and mesontest. They are now invokable via the main Meson executable like this: meson configure # equivalent to mesonconf meson test # equivalent to mesontest The old commands are still available but they are deprecated and will be removed in some future release. * Pcap dependency detector. Meson will automatically obtain dependency information for pcap using the pcap-config tool. It is used like any other dependency. * GNOME module mkenums_simple() addition. Most libraries and applications use the same standard templates for glib-mkenums. There is now a new mkenums_simple() convenience method that passes those default templates to glib-mkenums and allows some tweaks such as optional function decorators or leading underscores. * Update to version 0.41.2: * Various gtkdoc fixes. * Fix how rpath directories are handled. * pkgconfig: avoid appending slash at Cflags. * Fix a missing path issue causing Python traceback. * Qt4 support. * Skip handling non-available dependencies. * vala: Only add --use-header for unity builds regression. * Tag functions in asm properly. * Update to version 0.41.1: * wxwidgets: Fix usage of multiple dependency() calls. * Make external library no-op when used with incompatible target (gh#mesonbuild/meson#1941). * Failing test for -D dedupping. * Preserve standalone -D arguments always. * Handle both pkg-config and pkgconf argument order (gh#mesonbuild/meson#1934). * Update to version 0.41.0: * Native support for linking against LLVM using the dependency function. * Pkgconfig support for custom variables. * A target for creating tarballs using 'ninja dist'. * Support for passing arguments to Rust compiler. * All known issues regarding reproducible builds are fixed. * Extended template substitution in configure_file for @BASENAME@ and @PLAINNAME@ . * Support for capturing stdout of a command in configure_file. * Update to version 0.40.1: * Outputs of generators can be used in custom targets in the VS * Visual Studio 2017 support. * Automatic initialization of subprojects that are git submodules. * No download mode for wraps. * Overriding options per target. * Compiler object get define. * Cygwin support. * Multiple install directories. * Can specify method of obtaining dependencies. * Link whole contents of static libraries. * Unity builds only for subprojects. * Running mesonintrospect from scripts. * Update to version 0.39.1: * Allow specifying extra arguments for tests. * Bug fixes and minor polishes. * Update to version 0.38.1: * New Uninstall target. * Support for arbitrary test setups. * Intel C/C++ compiler support. * Get values from configuration data objects. * Python 3 module support simplified. * Default options to subprojects. * Set targets to be built (or not) by default. * Add option to mesonconf to wipe cached data. * Can specify file permissions and owner when installing data. * has_header() checks are now faster. * Array indexing now supports fallback values. * Silent mode for Mesontest. * Update to version 0.37.1. * Update to version 0.37.0: * Mesontest: a new testing tool that allows you to run your tests in many different ways. * New shared_module function allows shared modules creation. * GNOME module now detects required programs and prints useful errors if any are missing. * GNOME module uses depfile support available in GLib >= 2.52.0. * i18n module has a new merge_file() function for creating translated files. * LLVM IR compilation is now supported. * .wrap files for subprojects can now include a separate push URL to allow developers to push changes directly from a subproject git checkout. * Multiple version restrictions while searching for pkg-config dependencies is now supported. * Support for localstatedir has been added. * You can now pass arguments to install scripts added with meson.add_install_script(). * Added new options sbindir and infodir that can be used for installation. * Update to version 0.36.0: * Add option to run under gdb. * Always specify installed data with a File object (gh#mesonbuild/meson#858). * Made has_function survive optimization flags (gh#mesonbuild/meson#1053). * Can give many alternative names to find_program to simplify searching. * Can set compiler arguments in Java. * Changes from version 0.34.0: * Correctly install .typelib files to libdir. * Add option for as-needed link option. * Print the CFLAGS/LDFLAGS/etc inherited from the environment. * Only append compile flags to the link flags when appropriate. * Update to version 0.32.0. * Update to version 0.31.0. * Update to 0.29.0. * Update to 0.28.0. * Update to 0.27.0. * Update to 0.26.0. Changes for libgnt: * update to 2.14.3: * Added an option to disable python2 support. * Add an option to disable building the docs. * Fix a SEGFAULT in gnt_combo_box_get_dropdown. * Fix an invalid read/write when hiding widgets * Look for python-2.7.pc as well as python2.pc * Bump the minimum meson version from 0.37.0 to 0.41.0 * Fix a buffer size in gntwm.c Changes for pidgin: * Update to version 2.14.8: * Fix a regression in purple_str_to_time * Update to version 2.14.7: * Fix leak in purple_markup_find_tag on error * Fix an assert in purple_markup_html_to_xhtml * Correctly free parse tags at end of purple_html_to_xhtml * Fix leak that may occur when xmlnode_from_str fails * Port purple_str_to_time to use a regular expressions * Update to version 2.14.6: * Update references to point to our current websites. * Add a donate link to the help menu. Finch: * Check pkg-config for ncurses before looking for it manually. Pidgin: * Replace newlines in topics with spaces. libpurple: * Added support for the no_proxy environment variable. * Added infrastructure for fuzzing as well as some initial fuzzers. * Fix an out of bounds write in purple_markup_linkify. XMPP: * Enable session management after binding a resource. Zephyr: * Fix a clang logical-not-parentheses warning. * Update to version 2.14.5: * static code analysis fixes * Disable UPnP and NAT-PMP by default for new user * IRC: Change the default server to irc.libera.chat * Update to version 2.14.4: * Use LT_LIB_M to find the math library. This should simplify things for various distros including the BSD's. (RR #608) (and, Justin Lechner) * Update purple-remote and purple-url-handler to have a Python 3 shebang. * Install our AppData file into the $prefix/share/metainfo. Windows-Specific Changes: * Output pkg-config files so that our Windows builds can be seen by meson. Grim owes a blog post on how this works. * Update the debug symbols download in the installer to the inetc plugin. * Make sure the uninstaller removes all files that we install. * Removed the AIM protocol plugin. AIM has been shut down since December 15th of 2017. We left it around because of a third party server, but our plugin no longer works with it. (RR #598) (Gary Kramlich) * Standardize on wprintf in pidgin/win32/winpidgin.c * Use the inetc nsis plugin that supports https * If building under msys2 copy libgcc_s_dw2-1.dll and libwinpthread to the install directory. (RR #593) (PIDGIN-17511) (Gary Kramlich) * Fix a build issue when compiling with gstreamer but without voice and video. * Enable cyrus-sasl by default. * Fix an issue with opening link in Firefox. * Fix a regression from 2.14.0 where extra whitespace would be displayed when pasting

elements from HTML. * Require Python 3 for generating the D-Bus bindings. * Fix an issue where pasting


's and other HTML elements would eventually lead to a crash. * Update to version 2.14.1: * Fix an issue that caused the Mercurial revision in the About box to be "unknown". * Update to version 2.14.0: General: \+ Fixed a memory leak in search results (pidgin.im#17292). \+ Support SNI with GnuTLS (pidgin.im#17300 tiagosalem). \+ Add additional error handling to NSS and GnuTLS. \+ libpurple: \+ Add invisible buddy support to support presence/name/photos for non-buddies (pidgin.im#17295). \+ Make purple-remote compatible with both Python 2 and Python 3. \+ Fix some leaky deprecation warnings. \+ Fix HTML logs which were writing invalid HTML (pidgin.im#17280). \+ Fix use after free in purple_smiley_set_data_impl. \+ Added the chat_send_file ability to protocol plugins. Pidgin: \+ Treat

tags as line breaks when pasting. \+ Reverted pidgin.im#17232. It caused more harm than good. Bonjour: \+ Always use port fallback for IPv4 addresses. \+ XMPP: \+ Support for XEP-0198 Stream Management. \+ Decrease delay for file transfer using streamhosts. \+ Voice & Video: \+ Improve webcam failure handling. \+ Show error when creating media pipeline fails. \+ Clip audio level reporting (pidgin.im#14426). \+ Keep track of devices managed by GstDeviceMonitor. \+ Ignore PulseAudio monitors. \+ Backport native Voice & Video prefs from 3.0. \+ Fix building against GStreamer 0.10. \+ Fix initial delay on incoming audio. \+ Properly cleanup timeouts. \+ Add an audio mixer so mixed sources don't cause a pipe failure. \+ Add screen share support for Wayland via XDP Portal. \+ Handle unplug and replug events of selected media device. * Update to version 2.13.0: * Unified string comparison. * Properlly shell escape URI's when opening them. * Fix a one byte buffer overread in function purple_markup_linkify. * Fix an issue were utf8 was incorrectly truncated which could lead to crashes as we were potentially feeding garbage into glib/gtk. libgnt: * Partially fix building against curses 6.0 with opaque structs set (pidgin.im#16764). * Fix a crash when resizing the window (pidgin.im#16680). * Fix a bashism in autotools (pidgin.im#16836). * Show XEP-0066 OOB URLs in any message, not just headlines. * Fix a user after free (pidgin.im#17200). * Remove pipelining from BOSH connections (pidgin.im#17025). * Don't try to TLS already secured BOSH connections (pidgin.im#17270). IRC: * Fix "Registration timeout" on SASL auth with InspIRCd servers (and possibly others not based on charybdis/ratbox/ircd-seven). * Fix issues with plugins that modify outgoing messages (such as the custom PART/QUIT feature of the IRC More plugin). * Fix IRC buffer handling (pidgin.im#12562). * Properly handle AUTHENTICATE as a normal command with server prefix. * Fix a crash caused by a use after free of the MOTD. * Fix an out of bounds read in irc_nick_skip_mode. * Fix a write of a single byte before the start of a buffer in irc_parse_ctcp. * Better support for dark themes (pidgin.im#12572). * Fix IPv6 links by not escaping []'s. (pidgin.im#16391). * Only write buddy icons to the cache if they're not already cached. * Rejoin persistent chats after reconnect (pidgin.im#15687). * Make the WIN32 Transparency plugin work on all platforms (pidgin.im#3124). * Ensure search results buttons are labelled. * Fix matching unicode emoticons (pidgin.im#17232). * Correctly update mute/unmute status when the remote side mutes/unmutes us (pidgin.im#17273). * Rework the status icon blinking to not use deprecated API (pidgin.im#17174). * Do not allow adding a buddy to protocols that don't have an add_buddy callback. * Finch: * Fix handling of search results (pidgin.im#17238). * Port backend-fs to newer api for farstream relay-info property (pidgin.im#17274). * Add purple-import-empathy Recommends for SLE15 (FATE#322984). * Remove obsolete translation-update-upstream support (jsc#SLE-21105). * Extract libpurple.so._and libpurple-client.so._ to own packages (bsc#1191780). * don't package directories owned by filesystem rpm (bsc#1184786) * Drop support for openSUSE older than Leap 15.0. * No longer recommend -lang: supplements are in use * Drop pkgconfig(NetworkManager) BuildRequires and Requires: this legacy symbol is no longer maintained and pidgin is not yet ready to move to libnm. As a side-effect, we no longer depend on NM for all situations, even if the system were to run wicked. * Replace --enable-nm configure parameter with --disable-nm. * Instead of removing the libjabber.so, liboscar.so symlinks, move them to the devel package. * Export PYTHON=python3 in %build. * Adjust scripts to invoke python3, not python2. * Drop support for SLE 11 and openSUSE older than 42.x. * Correct the licence to GPL-2.0. * Explicitly require python2 * Drop dependency over silc-toolkit-devel as we want to remove it from the distribution ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2967=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2967=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * farstream-devel-0.2.8-5.2.4 * libnice-debugsource-0.1.13-7.2.3 * libfarstream-0_2-5-0.2.8-5.2.4 * libgnt-devel-2.14.3-4.3.8 * gstreamer-plugins-farstream-0.2.8-5.2.4 * libgupnp-1_0-4-0.20.18-8.5.2 * libpurple-debuginfo-2.14.8-3.9.3 * libpurple-client0-debuginfo-2.14.8-3.9.3 * libnice-devel-0.1.13-7.2.3 * libgupnp-devel-0.20.18-8.5.2 * libpurple-tcl-debuginfo-2.14.8-3.9.3 * libgnt-debugsource-2.14.3-4.3.8 * gssdp-debugsource-0.14.16-7.2.1 * finch-devel-2.14.8-3.9.3 * libnice-debuginfo-0.1.13-7.2.3 * libgupnp-igd-devel-0.2.4-6.2.2 * libgssdp-1_0-3-debuginfo-0.14.16-7.2.1 * farstream-debugsource-0.2.8-5.2.4 * typelib-1_0-Farstream-0_2-0.2.8-5.2.4 * libgupnp-1_0-4-debuginfo-0.20.18-8.5.2 * finch-debuginfo-2.14.8-3.9.3 * libpurple0-2.14.8-3.9.3 * finch-2.14.8-3.9.3 * gupnp-debugsource-0.20.18-8.5.2 * libpurple-client0-2.14.8-3.9.3 * typelib-1_0-GUPnPIgd-1_0-0.2.4-6.2.2 * libpurple-2.14.8-3.9.3 * libpurple-tcl-2.14.8-3.9.3 * libnice10-0.1.13-7.2.3 * libgnt0-2.14.3-4.3.8 * libgnt-devel-debuginfo-2.14.3-4.3.8 * libpurple-devel-2.14.8-3.9.3 * libgssdp-1_0-3-0.14.16-7.2.1 * typelib-1_0-GUPnP-1_0-0.20.18-8.5.2 * libgnt0-debuginfo-2.14.3-4.3.8 * libgssdp-devel-0.14.16-7.2.1 * libpurple0-debuginfo-2.14.8-3.9.3 * typelib-1_0-GSSDP-1_0-0.14.16-7.2.1 * libgupnp-igd-1_0-4-0.2.4-6.2.2 * libfarstream-0_2-5-debuginfo-0.2.8-5.2.4 * libgupnp-igd-1_0-4-debuginfo-0.2.4-6.2.2 * libnice10-debuginfo-0.1.13-7.2.3 * pidgin-devel-2.14.8-3.9.3 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * libpurple-lang-2.14.8-3.9.3 * libpurple-branding-upstream-2.14.8-3.9.3 * farstream-data-0.2.8-5.2.4 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libgnt0-32bit-2.14.3-4.3.8 * libgnt0-debuginfo-32bit-2.14.3-4.3.8 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * farstream-devel-0.2.8-5.2.4 * libnice-debugsource-0.1.13-7.2.3 * libfarstream-0_2-5-0.2.8-5.2.4 * libpurple-debuginfo-2.14.8-3.9.3 * gstreamer-plugins-farstream-0.2.8-5.2.4 * libgupnp-1_0-4-0.20.18-8.5.2 * libgnt-devel-2.14.3-4.3.8 * libpurple-client0-debuginfo-2.14.8-3.9.3 * libnice-devel-0.1.13-7.2.3 * libgupnp-devel-0.20.18-8.5.2 * libpurple-tcl-debuginfo-2.14.8-3.9.3 * libgnt-debugsource-2.14.3-4.3.8 * gssdp-debugsource-0.14.16-7.2.1 * finch-devel-2.14.8-3.9.3 * libnice-debuginfo-0.1.13-7.2.3 * libgupnp-igd-devel-0.2.4-6.2.2 * libgssdp-1_0-3-debuginfo-0.14.16-7.2.1 * farstream-debugsource-0.2.8-5.2.4 * typelib-1_0-Farstream-0_2-0.2.8-5.2.4 * libgupnp-1_0-4-debuginfo-0.20.18-8.5.2 * finch-debuginfo-2.14.8-3.9.3 * libpurple0-2.14.8-3.9.3 * finch-2.14.8-3.9.3 * gupnp-debugsource-0.20.18-8.5.2 * libpurple-client0-2.14.8-3.9.3 * typelib-1_0-GUPnPIgd-1_0-0.2.4-6.2.2 * libpurple-tcl-2.14.8-3.9.3 * libpurple-2.14.8-3.9.3 * libnice10-0.1.13-7.2.3 * libgnt0-2.14.3-4.3.8 * libgnt-devel-debuginfo-2.14.3-4.3.8 * libpurple-devel-2.14.8-3.9.3 * libgssdp-1_0-3-0.14.16-7.2.1 * typelib-1_0-GUPnP-1_0-0.20.18-8.5.2 * libgssdp-devel-0.14.16-7.2.1 * libpurple0-debuginfo-2.14.8-3.9.3 * libgnt0-debuginfo-2.14.3-4.3.8 * typelib-1_0-GSSDP-1_0-0.14.16-7.2.1 * libgupnp-igd-1_0-4-0.2.4-6.2.2 * libfarstream-0_2-5-debuginfo-0.2.8-5.2.4 * libgnt0-32bit-2.14.3-4.3.8 * libgupnp-igd-1_0-4-debuginfo-0.2.4-6.2.2 * libnice10-debuginfo-0.1.13-7.2.3 * pidgin-devel-2.14.8-3.9.3 * libgnt0-debuginfo-32bit-2.14.3-4.3.8 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libpurple-lang-2.14.8-3.9.3 * libpurple-branding-upstream-2.14.8-3.9.3 * farstream-data-0.2.8-5.2.4 ## References: * https://www.suse.com/security/cve/CVE-2019-25544.html * https://bugzilla.suse.com/show_bug.cgi?id=1057701 * https://bugzilla.suse.com/show_bug.cgi?id=1062785 * https://bugzilla.suse.com/show_bug.cgi?id=1068818 * https://bugzilla.suse.com/show_bug.cgi?id=1125736 * https://bugzilla.suse.com/show_bug.cgi?id=1184786 * https://bugzilla.suse.com/show_bug.cgi?id=1191780 * https://bugzilla.suse.com/show_bug.cgi?id=1260058 * https://jira.suse.com/browse/SLE-21105 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:04 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:04 -0000 Subject: SUSE-RU-2026:2966-1: moderate: Recommended update for polkit-default-privs Message-ID: <178404720408.143.17732372669879579547@178315a69387> # Recommended update for polkit-default-privs Announcement ID: SUSE-RU-2026:2966-1 Release Date: 2026-07-14T11:10:36Z Rating: moderate References: * bsc#1269542 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for polkit-default-privs fixes the following issues: Update to version 13.2+20260709.4543787: * profiles: backport fwupd actions from Factory (bsc#1269542) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2966=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * polkit-default-privs-13.2+20260709.4543787-150700.3.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269542 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:08 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:08 -0000 Subject: SUSE-SU-2026:2965-1: important: Security update for kubernetes-old Message-ID: <178404720815.143.17199798206227063736@178315a69387> # Security update for kubernetes-old Announcement ID: SUSE-SU-2026:2965-1 Release Date: 2026-07-14T11:10:09Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for kubernetes-old rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2965=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2965=1 ## Package List: * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kubernetes1.33-client-1.33.11-150600.13.34.1 * kubernetes1.33-client-common-1.33.11-150600.13.34.1 * Containers Module 15-SP7 (noarch) * kubernetes1.33-client-bash-completion-1.33.11-150600.13.34.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * kubernetes1.33-client-1.33.11-150600.13.34.1 * kubernetes1.33-client-common-1.33.11-150600.13.34.1 * openSUSE Leap 15.6 (noarch) * kubernetes1.33-client-fish-completion-1.33.11-150600.13.34.1 * kubernetes1.33-client-bash-completion-1.33.11-150600.13.34.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:12 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:12 -0000 Subject: SUSE-SU-2026:2964-1: important: Security update for buildah Message-ID: <178404721231.143.15835494103024518184@178315a69387> # Security update for buildah Announcement ID: SUSE-SU-2026:2964-1 Release Date: 2026-07-14T11:09:44Z Rating: important References: Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that can now be installed. ## Description: This update for buildah rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2964=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2964=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2964=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2964=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2964=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * buildah-1.35.5-150400.3.70.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * buildah-1.35.5-150400.3.70.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * buildah-1.35.5-150400.3.70.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150400.3.70.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * buildah-1.35.5-150400.3.70.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:18 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:18 -0000 Subject: SUSE-SU-2026:2963-1: moderate: Security update for ucode-intel Message-ID: <178404721829.143.15414628866771036544@178315a69387> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:2963-1 Release Date: 2026-07-14T11:08:50Z Rating: moderate References: * bsc#1265189 Cross-References: * CVE-2025-35979 CVSS scores: * CVE-2025-35979 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35979 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-35979 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for ucode-intel fixes the following issue: * CVE-2025-35979: data leaks fixed in 20260512 release (bsc#1265189). Other changes: * Intel CPU Microcode was updated to the 20260512 release (bsc#1265189). **New Platforms** Processor Stepping F-M-S/PI Old Ver New Ver Products PTL 404 A1 06-cc-03/90 0000011b Intel Core Ultra Processor (Series 3) PTL-H 484/12Xe A0/B0 06-cc-02/90 0000011b Intel Core Ultra Processor (Series 3) **Updated Platforms** Processor Stepping F-M-S/PI Old Ver New Ver Products ARL-H A1 06-c5-02/82 0000011b 00000121 Core Ultra Processor (Series 2) ARL-S/HX (8P) B0 06-c6-02/82 0000011b 00000121 Core Ultra Processor (Series 2) EMR-SP A1 06-cf-02/87 210002d3 210002e0 Xeon Scalable Gen5 GNR-AP/SP Bx/Hx/Lx 06-ad-01/95 01000405 01000423 Xeon 6900/6700/6500 Series Processors with P-Cores GNR-D B0/B1 06-ae-01/97 01000303 01000307 Xeon 6700P-B/6500P-B Series SoC with P-Cores GNR-SP R1S Bx/Hx/Lx 06-ad-01/20 0a000133 0a000142 Xeon 6700/6500-Series Processors with P-Cores LNL B0 06-bd-01/80 00000125 00000126 Core Ultra 200 V Series Processor SPR-SP E4/S2 06-8f-07/87 2b000661 2b000670 Xeon Scalable Gen4 SPR-SP E5/S3 06-8f-08/87 2b000661 2b000670 Xeon Scalable Gen4 SRF-AP/SP C0 06-af-03/01 03000382 030003a3 Xeon 6900/6700-Series Processors with E-Cores ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2963=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2963=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2963=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2963=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2963=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2963=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2963=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2963=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2963=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2963=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2963=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2963=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2963=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2963=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2963=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2963=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * ucode-intel-20260512-150200.65.1 * Basesystem Module 15-SP7 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * ucode-intel-20260512-150200.65.1 ## References: * https://www.suse.com/security/cve/CVE-2025-35979.html * https://bugzilla.suse.com/show_bug.cgi?id=1265189 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:23 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:23 -0000 Subject: SUSE-SU-2026:2962-1: moderate: Security update for perl-libwww-perl Message-ID: <178404722376.143.15949814827669827917@178315a69387> # Security update for perl-libwww-perl Announcement ID: SUSE-SU-2026:2962-1 Release Date: 2026-07-14T10:55:03Z Rating: moderate References: * bsc#1265156 Cross-References: * CVE-2026-8368 CVSS scores: * CVE-2026-8368 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-8368 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-libwww-perl fixes the following issue * CVE-2026-8368: LWP: UserAgent: Authorization and Proxy-Authorization headers are leaked on cross-origin redirects (bsc#1265156). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2962=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * perl-libwww-perl-6.31-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8368.html * https://bugzilla.suse.com/show_bug.cgi?id=1265156 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:29 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:29 -0000 Subject: SUSE-SU-2026:2954-1: important: Security update for krb5 Message-ID: <178404722906.143.3555397136791488518@178315a69387> # Security update for krb5 Announcement ID: SUSE-SU-2026:2954-1 Release Date: 2026-07-14T09:57:42Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2954=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2954=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2954=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2954=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2954=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2954=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2954=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2954=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2954=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-mini-debugsource-1.19.2-150400.3.24.1 * krb5-plugin-preauth-spake-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-mini-debuginfo-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-mini-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-mini-devel-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-plugin-preauth-spake-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * openSUSE Leap 15.4 (aarch64_ilp32) * krb5-64bit-debuginfo-1.19.2-150400.3.24.1 * krb5-devel-64bit-1.19.2-150400.3.24.1 * krb5-64bit-1.19.2-150400.3.24.1 * openSUSE Leap 15.4 (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-devel-32bit-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:34 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:34 -0000 Subject: SUSE-RU-2026:2953-1: moderate: Recommended update for nvidia-open-driver-G07-signed Message-ID: <178404723471.143.9163734673675790750@178315a69387> # Recommended update for nvidia-open-driver-G07-signed Announcement ID: SUSE-RU-2026:2953-1 Release Date: 2026-07-14T09:33:29Z Rating: moderate References: * bsc#1268792 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one fix can now be installed. ## Description: This update for nvidia-open-driver-G07-signed fixes the following issues: * update non-CUDA variant to 595.84 (bsc#1268792) * changes to build also against the nvidia kernel, which is planned to be available for SLE16.1-aarch64 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2953=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2953=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2953=1 ## Package List: * openSUSE Leap 15.6 (aarch64 x86_64) * nvidia-open-driver-G07-signed-kmp-default-debuginfo-595.84_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-default-devel-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-default-595.84_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-debuginfo-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-debugsource-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-debugsource-610.43.02-150600.13.18.1 * nv-prefer-signed-open-driver-G07-610.43.02-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-default-devel-610.43.02-150600.13.18.1 * openSUSE Leap 15.6 (noarch) * nvidia-open-driver-G07-signed-check-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-check-610.43.02-150600.13.18.1 * openSUSE Leap 15.6 (aarch64) * nvidia-open-driver-G07-signed-cuda-kmp-64kb-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-64kb-debuginfo-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-64kb-devel-610.43.02-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-64kb-debuginfo-595.84_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-64kb-devel-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-64kb-595.84_k6.4.0_150600.23.115-150600.13.18.1 * openSUSE Leap 15.6 (x86_64) * nvidia-open-driver-G07-signed-cuda-azure-devel-610.43.02-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-azure-debuginfo-610.43.02_k6.4.0_150600.8.58-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-azure-595.84_k6.4.0_150600.8.58-150600.13.18.1 * nvidia-open-driver-G07-signed-azure-devel-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-azure-debuginfo-595.84_k6.4.0_150600.8.58-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-azure-610.43.02_k6.4.0_150600.8.58-150600.13.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * nvidia-open-driver-G07-signed-cuda-default-devel-610.43.02-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-default-debuginfo-595.84_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-default-devel-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-debuginfo-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-debugsource-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-debugsource-610.43.02-150600.13.18.1 * nv-prefer-signed-open-driver-G07-610.43.02-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-default-595.84_k6.4.0_150600.23.115-150600.13.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64) * nvidia-open-driver-G07-signed-cuda-kmp-64kb-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-64kb-debuginfo-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-64kb-devel-610.43.02-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-64kb-debuginfo-595.84_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-64kb-devel-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-64kb-595.84_k6.4.0_150600.23.115-150600.13.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * nvidia-open-driver-G07-signed-cuda-default-devel-610.43.02-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-default-debuginfo-595.84_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-default-devel-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-debuginfo-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-debugsource-595.84-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-610.43.02_k6.4.0_150600.23.115-150600.13.18.1 * nvidia-open-driver-G07-signed-cuda-debugsource-610.43.02-150600.13.18.1 * nv-prefer-signed-open-driver-G07-610.43.02-150600.13.18.1 * nvidia-open-driver-G07-signed-kmp-default-595.84_k6.4.0_150600.23.115-150600.13.18.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268792 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:40 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:40 -0000 Subject: SUSE-RU-2026:2952-1: moderate: Recommended update for nvidia-open-driver-G07-signed Message-ID: <178404724081.143.14246520606337482195@178315a69387> # Recommended update for nvidia-open-driver-G07-signed Announcement ID: SUSE-RU-2026:2952-1 Release Date: 2026-07-14T09:33:13Z Rating: moderate References: * bsc#1268792 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for nvidia-open-driver-G07-signed fixes the following issues: * update non-CUDA variant to 595.84 (bsc#1268792) * changes to build also against the nvidia kernel, which is planned to be available for SLE16.1-aarch64 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2952=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 x86_64) * nvidia-open-driver-G07-signed-cuda-kmp-default-610.43.02_k6.4.0_150700.53.60-150700.16.14.1 * nvidia-open-driver-G07-signed-debugsource-595.84-150700.16.14.1 * nvidia-open-driver-G07-signed-cuda-default-devel-610.43.02-150700.16.14.1 * nv-prefer-signed-open-driver-G07-610.43.02-150700.16.14.1 * nvidia-open-driver-G07-signed-kmp-default-debuginfo-595.84_k6.4.0_150700.53.60-150700.16.14.1 * nvidia-open-driver-G07-signed-cuda-kmp-default-debuginfo-610.43.02_k6.4.0_150700.53.60-150700.16.14.1 * nvidia-open-driver-G07-signed-default-devel-595.84-150700.16.14.1 * nvidia-open-driver-G07-signed-cuda-debugsource-610.43.02-150700.16.14.1 * nvidia-open-driver-G07-signed-kmp-default-595.84_k6.4.0_150700.53.60-150700.16.14.1 * Basesystem Module 15-SP7 (aarch64) * nvidia-open-driver-G07-signed-kmp-64kb-595.84_k6.4.0_150700.53.60-150700.16.14.1 * nvidia-open-driver-G07-signed-cuda-kmp-64kb-610.43.02_k6.4.0_150700.53.60-150700.16.14.1 * nvidia-open-driver-G07-signed-cuda-kmp-64kb-debuginfo-610.43.02_k6.4.0_150700.53.60-150700.16.14.1 * nvidia-open-driver-G07-signed-64kb-devel-595.84-150700.16.14.1 * nvidia-open-driver-G07-signed-kmp-64kb-debuginfo-595.84_k6.4.0_150700.53.60-150700.16.14.1 * nvidia-open-driver-G07-signed-cuda-64kb-devel-610.43.02-150700.16.14.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268792 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:44 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:44 -0000 Subject: SUSE-RU-2026:2951-1: moderate: Recommended update for dmidecode Message-ID: <178404724464.143.2117073715166976951@178315a69387> # Recommended update for dmidecode Announcement ID: SUSE-RU-2026:2951-1 Release Date: 2026-07-14T09:33:06Z Rating: moderate References: * jsc#PED-16217 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains one feature can now be installed. ## Description: This update for dmidecode fixes the following issues: * Update to upstream version 3.7 (jsc#PED-16217): * Support for SMBIOS 3.8.0. This includes a new processor family. * Support for SMBIOS 3.9.0. This includes chassis type name adjustments, new rack attributes, slot ID for more slot types, and new memory device form factors and types. * Decode HPE OEM records 193, 195, 202, 211, 226, 229, 232 and 244. * Update HPE OEM records 203, 216, 242 and 245. * EDSFF slot names now include their .S/.L suffix. * Preserve the use of term "BIOS" to avoid breaking customer scripts. * Preserve the use of non-binary units to avoid breaking customer scripts. * Drop legacy "Provides:" and "Obsoletes:" tags. The split from the pmtools package happened 15 years ago so they are no longer relevant. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2951=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2951=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2951=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2951=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2951=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2951=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2951=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2951=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2951=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2951=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2951=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2951=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2951=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2951=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2951=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2951=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2951=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * Basesystem Module 15-SP7 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * dmidecode-3.7-150400.16.14.1 * dmidecode-debuginfo-3.7-150400.16.14.1 * dmidecode-debugsource-3.7-150400.16.14.1 ## References: * https://jira.suse.com/browse/PED-16217 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:51 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:51 -0000 Subject: SUSE-SU-2026:2950-1: moderate: Security update for perl-HTML-Parser Message-ID: <178404725189.143.7517269073778303846@178315a69387> # Security update for perl-HTML-Parser Announcement ID: SUSE-SU-2026:2950-1 Release Date: 2026-07-14T09:24:36Z Rating: moderate References: * bsc#1267606 Cross-References: * CVE-2026-8829 CVSS scores: * CVE-2026-8829 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-8829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTML-Parser fixes the following issue * CVE-2026-8829: HTML:Entities versions before 3.84 for Perl read freed heap memory in _decode_entities (bsc#1267606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2950=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-HTML-Parser-debugsource-3.830.0-150000.3.6.1 * perl-HTML-Parser-debuginfo-3.830.0-150000.3.6.1 * perl-HTML-Parser-3.830.0-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8829.html * https://bugzilla.suse.com/show_bug.cgi?id=1267606 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:57 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:40:57 -0000 Subject: SUSE-SU-2026:2949-1: moderate: Security update for python-mistune Message-ID: <178404725746.143.1281162419320306804@178315a69387> # Security update for python-mistune Announcement ID: SUSE-SU-2026:2949-1 Release Date: 2026-07-14T09:23:51Z Rating: moderate References: * bsc#1265052 Cross-References: * CVE-2026-44898 CVSS scores: * CVE-2026-44898 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-44898 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44898 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-mistune fixes the following issue * CVE-2026-44898: improper sanitization of user-supplied HTML input in `render_toc_ul` can lead to XSS (bsc#1265052). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2949=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2949=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-mistune-2.0.5-150400.11.8.1 * openSUSE Leap 15.4 (noarch) * python311-mistune-2.0.5-150400.11.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44898.html * https://bugzilla.suse.com/show_bug.cgi?id=1265052 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:41:03 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 16:41:03 -0000 Subject: SUSE-SU-2026:2948-1: moderate: Security update for perl-HTML-Parser Message-ID: <178404726322.143.2960352722490483373@178315a69387> # Security update for perl-HTML-Parser Announcement ID: SUSE-SU-2026:2948-1 Release Date: 2026-07-14T09:23:13Z Rating: moderate References: * bsc#1267606 Cross-References: * CVE-2026-8829 CVSS scores: * CVE-2026-8829 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-8829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTML-Parser fixes the following issue * CVE-2026-8829: HTML:Entities versions before 3.84 for Perl read freed heap memory in _decode_entities (bsc#1267606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2948=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * perl-HTML-Parser-3.71-3.3.1 * perl-HTML-Parser-debuginfo-3.71-3.3.1 * perl-HTML-Parser-debugsource-3.71-3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8829.html * https://bugzilla.suse.com/show_bug.cgi?id=1267606 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:30:30 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:30:30 -0000 Subject: SUSE-SU-2026:2991-1: important: Security update for the Linux Kernel (Live Patch 54 for SUSE Linux Enterprise 15 SP4) Message-ID: <178406103040.173.13530381440798274369@178315a69387> # Security update for the Linux Kernel (Live Patch 54 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2991-1 Release Date: 2026-07-14T16:05:09Z Rating: important References: * bsc#1264094 * bsc#1265197 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-31758 * CVE-2026-43037 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.219 fixes various security issues The following security issues were fixed: * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2991=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2991=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_219-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_54-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-2-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_219-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_54-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-2-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:30:57 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:30:57 -0000 Subject: SUSE-SU-2026:2989-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5) Message-ID: <178406105760.173.15642009710863580120@178315a69387> # Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2989-1 Release Date: 2026-07-14T15:46:16Z Rating: important References: * bsc#1264094 * bsc#1265117 * bsc#1265197 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-31758 * CVE-2026-43037 * CVE-2026-43366 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.166 fixes various security issues The following security issues were fixed: * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2989=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2989=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_166-default-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_40-debugsource-2-150500.2.2 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_166-default-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_40-debugsource-2-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:13 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:31:13 -0000 Subject: SUSE-SU-2026:2992-1: important: Security update for the Linux Kernel (Live Patch 77 for SUSE Linux Enterprise 12 SP5) Message-ID: <178406107362.173.6346439330219629229@178315a69387> # Security update for the Linux Kernel (Live Patch 77 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2992-1 Release Date: 2026-07-14T16:05:27Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.293 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2992=1 SUSE-SLE-Live- Patching-12-SP5-2026-2985=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_266-default-18-2.1 * kgraft-patch-4_12_14-122_293-default-9-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:17 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:31:17 -0000 Subject: SUSE-RU-2026:2988-1: moderate: Recommended update for hplip Message-ID: <178406107775.173.9389634765954630573@178315a69387> # Recommended update for hplip Announcement ID: SUSE-RU-2026:2988-1 Release Date: 2026-07-14T15:11:40Z Rating: moderate References: Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for hplip fixes the following issues: * hp-plugin: fix plugin installation from local file * fix errors with python2-incompatible syntax * Spec file: fix python-gobject2 dependency under SLE12 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2988=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2988=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * hplip-sane-3.26.4-150700.4.8.1 * hplip-devel-3.26.4-150700.4.8.1 * hplip-sane-debuginfo-3.26.4-150700.4.8.1 * hplip-hpijs-3.26.4-150700.4.8.1 * hplip-debugsource-3.26.4-150700.4.8.1 * hplip-debuginfo-3.26.4-150700.4.8.1 * hplip-udev-rules-3.26.4-150700.4.8.1 * hplip-hpijs-debuginfo-3.26.4-150700.4.8.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * hplip-debuginfo-3.26.4-150700.4.8.1 * hplip-3.26.4-150700.4.8.1 * hplip-debugsource-3.26.4-150700.4.8.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:24 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:31:24 -0000 Subject: SUSE-SU-2026:2987-1: moderate: Security update for glibc Message-ID: <178406108446.173.13001561799708905408@178315a69387> # Security update for glibc Announcement ID: SUSE-SU-2026:2987-1 Release Date: 2026-07-14T14:37:38Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues: * CVE-2026-5435: resolv: More types as unknown in ns_sprintrrf (bsc#1263656, BZ #34033) * resolv: Check for inet_ntop failure in ns_sprintrrf * CVE-2026-6238: resolv: Fix buffer overreads in ns_sprintrrf (bsc#1263658, BZ #34069) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2987=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * glibc-devel-static-2.22-114.49.1 * glibc-profile-2.22-114.49.1 * nscd-2.22-114.49.1 * glibc-locale-debuginfo-2.22-114.49.1 * nscd-debuginfo-2.22-114.49.1 * glibc-profile-32bit-2.22-114.49.1 * glibc-devel-debuginfo-2.22-114.49.1 * glibc-locale-debuginfo-32bit-2.22-114.49.1 * glibc-debuginfo-32bit-2.22-114.49.1 * glibc-devel-debuginfo-32bit-2.22-114.49.1 * glibc-2.22-114.49.1 * glibc-devel-2.22-114.49.1 * glibc-debugsource-2.22-114.49.1 * glibc-devel-32bit-2.22-114.49.1 * glibc-locale-2.22-114.49.1 * glibc-locale-32bit-2.22-114.49.1 * glibc-32bit-2.22-114.49.1 * glibc-debuginfo-2.22-114.49.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * glibc-info-2.22-114.49.1 * glibc-i18ndata-2.22-114.49.1 * glibc-html-2.22-114.49.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:28 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:31:28 -0000 Subject: SUSE-RU-2026:2986-1: moderate: Recommended update for wicked2nm Message-ID: <178406108862.173.146390285343424543@178315a69387> # Recommended update for wicked2nm Announcement ID: SUSE-RU-2026:2986-1 Release Date: 2026-07-14T14:05:21Z Rating: moderate References: Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for wicked2nm fixes the following issues: * Update v1.5.0: * Respect create-cid and client-id in interface xml * Require at least one file for migrate and show commands * Perform extra validation for correct xml file * Improve dhcp.update default and user info * Update dependencies * Allow DHCP+staticIP addresses * Fix DHCLIENT_SET_DEFAULT_ROUTE="no" * Handle 'STATIC_FALLBACK' and 'NetworkManager' in netconfig * Implement team to bond migration * Update agama-network to remove dependency on curl * Reenable `update` in cargo vendor service ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2986=1 ## Package List: * Basesystem Module 15-SP7 (s390x) * wicked2nm-1.5.0-150700.15.21.1 * wicked2nm-debuginfo-1.5.0-150700.15.21.1 * wicked2nm-debugsource-1.5.0-150700.15.21.1 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * wicked2nm-debuginfo-1.5.0-150700.15.19.1 * wicked2nm-1.5.0-150700.15.19.1 * wicked2nm-debugsource-1.5.0-150700.15.19.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:34 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:31:34 -0000 Subject: SUSE-SU-2026:2984-1: moderate: Security update for python3-dulwich Message-ID: <178406109468.173.5410808617302055079@178315a69387> # Security update for python3-dulwich Announcement ID: SUSE-SU-2026:2984-1 Release Date: 2026-07-14T13:21:03Z Rating: moderate References: * bsc#1268138 Cross-References: * CVE-2026-47734 CVSS scores: * CVE-2026-47734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47734 ( NVD ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python3-dulwich fixes the following issues: * CVE-2026-47734: Do not honour receive.maxInputSize to bound received packs (bsc#1268138) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2984=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2984=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-dulwich-debugsource-0.20.24-150400.8.1 * python3-dulwich-debuginfo-0.20.24-150400.8.1 * python3-dulwich-0.20.24-150400.8.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python3-dulwich-debugsource-0.20.24-150400.8.1 * python3-dulwich-debuginfo-0.20.24-150400.8.1 * python3-dulwich-0.20.24-150400.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47734.html * https://bugzilla.suse.com/show_bug.cgi?id=1268138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:46 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:31:46 -0000 Subject: SUSE-SU-2026:2983-1: moderate: Security update for jq Message-ID: <178406110647.173.17564779089743895727@178315a69387> # Security update for jq Announcement ID: SUSE-SU-2026:2983-1 Release Date: 2026-07-14T13:19:55Z Rating: moderate References: * bsc#1262044 * bsc#1262069 * bsc#1262070 * bsc#1262071 * bsc#1262072 Cross-References: * CVE-2026-32316 * CVE-2026-33947 * CVE-2026-39956 * CVE-2026-39979 * CVE-2026-40164 CVSS scores: * CVE-2026-32316 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-32316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32316 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-33947 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33947 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39956 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39956 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39956 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39979 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39979 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-39979 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40164 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). * CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). * CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). * CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). * CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre- computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2983=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2983=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2983=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2983=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2983=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2983=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libjq-devel-1.6-150000.3.20.1 * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32316.html * https://www.suse.com/security/cve/CVE-2026-33947.html * https://www.suse.com/security/cve/CVE-2026-39956.html * https://www.suse.com/security/cve/CVE-2026-39979.html * https://www.suse.com/security/cve/CVE-2026-40164.html * https://bugzilla.suse.com/show_bug.cgi?id=1262044 * https://bugzilla.suse.com/show_bug.cgi?id=1262069 * https://bugzilla.suse.com/show_bug.cgi?id=1262070 * https://bugzilla.suse.com/show_bug.cgi?id=1262071 * https://bugzilla.suse.com/show_bug.cgi?id=1262072 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:54 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:31:54 -0000 Subject: SUSE-SU-2026:2982-1: moderate: Security update for python-WebOb Message-ID: <178406111488.173.8876743901109174749@178315a69387> # Security update for python-WebOb Announcement ID: SUSE-SU-2026:2982-1 Release Date: 2026-07-14T13:15:39Z Rating: moderate References: * bsc#1268324 Cross-References: * CVE-2026-44889 CVSS scores: * CVE-2026-44889 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-44889 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44889 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-WebOb fixes the following issue * CVE-2026-44889: Location header normalization during redirect leads to open redirect (bsc#1268324). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2982=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2982=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * python3-WebOb-1.7.4-150000.3.6.1 * SUSE Package Hub 15 15-SP7 (noarch) * python2-WebOb-1.7.4-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44889.html * https://bugzilla.suse.com/show_bug.cgi?id=1268324 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:32:00 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:32:00 -0000 Subject: SUSE-SU-2026:2981-1: moderate: Security update for ucode-intel Message-ID: <178406112086.173.7095312920605086831@178315a69387> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:2981-1 Release Date: 2026-07-14T13:13:41Z Rating: moderate References: * bsc#1265189 Cross-References: * CVE-2025-35979 CVSS scores: * CVE-2025-35979 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35979 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-35979 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for ucode-intel fixes the following issue: * CVE-2025-35979: data leaks fixed in 20260512 release (bsc#1265189). Changes for ucode-intel: * Intel CPU Microcode was updated to the 20260512 release (bsc#1265189). **New Platforms** Processor Stepping F-M-S/PI Old Ver New Ver Products PTL 404 A1 06-cc-03/90 0000011b Intel Core Ultra Processor (Series 3) PTL-H 484/12Xe A0/B0 06-cc-02/90 0000011b Intel Core Ultra Processor (Series 3) **Updated Platforms** Processor Stepping F-M-S/PI Old Ver New Ver Products ARL-H A1 06-c5-02/82 0000011b 00000121 Core Ultra Processor (Series 2) ARL-S/HX (8P) B0 06-c6-02/82 0000011b 00000121 Core Ultra Processor (Series 2) EMR-SP A1 06-cf-02/87 210002d3 210002e0 Xeon Scalable Gen5 GNR-AP/SP Bx/Hx/Lx 06-ad-01/95 01000405 01000423 Xeon 6900/6700/6500 Series Processors with P-Cores GNR-D B0/B1 06-ae-01/97 01000303 01000307 Xeon 6700P-B/6500P-B Series SoC with P-Cores GNR-SP R1S Bx/Hx/Lx 06-ad-01/20 0a000133 0a000142 Xeon 6700/6500-Series Processors with P-Cores LNL B0 06-bd-01/80 00000125 00000126 Core Ultra 200 V Series Processor SPR-SP E4/S2 06-8f-07/87 2b000661 2b000670 Xeon Scalable Gen4 SPR-SP E5/S3 06-8f-08/87 2b000661 2b000670 Xeon Scalable Gen4 SRF-AP/SP C0 06-af-03/01 03000382 030003a3 Xeon 6900/6700-Series Processors with E-Cores ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2981=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2981=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * ucode-intel-debugsource-20260512-161.1 * ucode-intel-debuginfo-20260512-161.1 * ucode-intel-20260512-161.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * ucode-intel-debugsource-20260512-161.1 * ucode-intel-debuginfo-20260512-161.1 * ucode-intel-20260512-161.1 ## References: * https://www.suse.com/security/cve/CVE-2025-35979.html * https://bugzilla.suse.com/show_bug.cgi?id=1265189 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:32:04 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 14 Jul 2026 20:32:04 -0000 Subject: SUSE-RU-2026:2980-1: moderate: Recommended update for dpdk Message-ID: <178406112483.173.3156802595410873230@178315a69387> # Recommended update for dpdk Announcement ID: SUSE-RU-2026:2980-1 Release Date: 2026-07-14T13:08:06Z Rating: moderate References: Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for dpdk fixes the following issues: * Update to version 24.11.6: * docs: fix build issue due to missing spacing between paragraphs * Revert "net: fix packet type for stacked VLAN" ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2980=1 ## Package List: * Server Applications Module 15-SP7 (aarch64) * dpdk-thunderx-debugsource-24.11.6-150700.3.14.1 * dpdk-thunderx-24.11.6-150700.3.14.1 * dpdk-thunderx-debuginfo-24.11.6-150700.3.14.1 * dpdk-thunderx-devel-24.11.6-150700.3.14.1 * Server Applications Module 15-SP7 (aarch64 ppc64le x86_64) * dpdk-debuginfo-24.11.6-150700.3.14.1 * dpdk-24.11.6-150700.3.14.1 * dpdk-devel-24.11.6-150700.3.14.1 * dpdk-debugsource-24.11.6-150700.3.14.1 * libdpdk-25-24.11.6-150700.3.14.1 * libdpdk-25-debuginfo-24.11.6-150700.3.14.1 * dpdk-tools-24.11.6-150700.3.14.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 08:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 08:30:24 -0000 Subject: SUSE-SU-2026:2994-1: important: Security update for the Linux Kernel (Live Patch 80 for SUSE Linux Enterprise 12 SP5) Message-ID: <178410422484.225.15008233833441002675@f4f3e2688bac> # Security update for the Linux Kernel (Live Patch 80 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2994-1 Release Date: 2026-07-14T19:33:35Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.302 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2994=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_302-default-5-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 08:30:37 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 08:30:37 -0000 Subject: SUSE-SU-2026:2993-1: important: Security update for the Linux Kernel (Live Patch 55 for SUSE Linux Enterprise 15 SP4) Message-ID: <178410423769.225.17953712634986585710@f4f3e2688bac> # Security update for the Linux Kernel (Live Patch 55 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2993-1 Release Date: 2026-07-14T16:33:46Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.222 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2993=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2993=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_55-debugsource-2-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_55-debugsource-2-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:30:18 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:30:18 -0000 Subject: SUSE-SU-2026:3008-1: important: Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP6) Message-ID: <178411861805.328.1462950967175262362@178315a69387> # Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:3008-1 Release Date: 2026-07-15T07:34:00Z Rating: important References: * bsc#1267723 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46173 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.118 fixes various security issues The following security issues were fixed: * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3008=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3008=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-2-150600.2.2 * kernel-livepatch-6_4_0-150600_23_118-default-2-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_28-debugsource-2-150600.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_118-default-2-150600.2.2 * kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-2-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_28-debugsource-2-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:30:29 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:30:29 -0000 Subject: SUSE-SU-2026:3009-1: important: Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5) Message-ID: <178411862995.328.16773926535782695726@178315a69387> # Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3009-1 Release Date: 2026-07-15T07:34:15Z Rating: important References: * bsc#1267723 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-46173 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.172 fixes various security issues The following security issues were fixed: * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3009=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3007=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3007=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3009=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_56-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-2-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_56-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-2-150400.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_172-default-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_42-debugsource-2-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_172-default-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_42-debugsource-2-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:30:44 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:30:44 -0000 Subject: SUSE-SU-2026:3002-1: important: Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP6) Message-ID: <178411864450.328.10181548051834470127@178315a69387> # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:3002-1 Release Date: 2026-07-15T06:05:21Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.115 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3002=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3002=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_115-default-2-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_27-debugsource-2-150600.2.2 * kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-2-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_115-default-2-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_27-debugsource-2-150600.2.2 * kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-2-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:03 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:31:03 -0000 Subject: SUSE-SU-2026:3001-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP5) Message-ID: <178411866340.328.14377208944503185550@178315a69387> # Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3001-1 Release Date: 2026-07-15T06:05:06Z Rating: important References: * bsc#1264094 * bsc#1265117 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-31758 * CVE-2026-43366 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.169 fixes various security issues The following security issues were fixed: * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3001=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3001=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_169-default-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_41-debugsource-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-2-150500.2.2 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_41-debugsource-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_169-default-2-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:25 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:31:25 -0000 Subject: SUSE-SU-2026:2997-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6) Message-ID: <178411868528.328.14638358338919913362@178315a69387> # Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2997-1 Release Date: 2026-07-15T04:04:34Z Rating: important References: * bsc#1264094 * bsc#1265197 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31758 * CVE-2026-43037 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.112 fixes various security issues The following security issues were fixed: * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2997=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2997=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_26-debugsource-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_112-default-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-3-150600.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_26-debugsource-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_112-default-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-3-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:40 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:31:40 -0000 Subject: SUSE-SU-2026:2995-1: important: Security update for the Linux Kernel (Live Patch 79 for SUSE Linux Enterprise 12 SP5) Message-ID: <178411870088.328.6452676626765208120@178315a69387> # Security update for the Linux Kernel (Live Patch 79 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2995-1 Release Date: 2026-07-15T06:49:39Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.299 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2995=1 SUSE-SLE-Live- Patching-12-SP5-2026-3003=1 SUSE-SLE-Live-Patching-12-SP5-2026-2999=1 SUSE-SLE- Live-Patching-12-SP5-2026-2996=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_283-default-10-2.1 * kgraft-patch-4_12_14-122_299-default-6-2.1 * kgraft-patch-4_12_14-122_275-default-12-2.1 * kgraft-patch-4_12_14-122_261-default-18-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:47 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:31:47 -0000 Subject: SUSE-OU-2026:3010-1: low: Optional update for python-Cerberus Message-ID: <178411870742.328.7302241434593428071@178315a69387> # Optional update for python-Cerberus Announcement ID: SUSE-OU-2026:3010-1 Release Date: 2026-07-15T07:37:41Z Rating: low References: * bsc#1259855 Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has one fix can now be installed. ## Description: This update for python-Cerberus fixes the following issue: * Add python3-Cerberus required for product migration scenarios, no source changes. (bsc#1259855) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3010=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3010=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3010=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3010=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3010=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3010=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3010=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3010=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3010=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3010=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 * Public Cloud Module 15-SP5 (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 * Public Cloud Module 15-SP7 (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 * Public Cloud Module 15-SP6 (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 * Public Cloud Module 15-SP4 (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python3-Cerberus-1.3.2-150100.7.13.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1259855 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:51 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:31:51 -0000 Subject: SUSE-RU-2026:3006-1: moderate: Recommended update for perl-DBD-SQLite Message-ID: <178411871152.328.11600969283825164021@178315a69387> # Recommended update for perl-DBD-SQLite Announcement ID: SUSE-RU-2026:3006-1 Release Date: 2026-07-15T07:32:44Z Rating: moderate References: Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for perl-DBD-SQLite fixes the following issues: * update to 1.76 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3006=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3006=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-DBD-SQLite-debuginfo-1.760.0-150600.10.6.5 * perl-DBD-SQLite-debugsource-1.760.0-150600.10.6.5 * perl-DBD-SQLite-1.760.0-150600.10.6.5 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * perl-DBD-SQLite-debuginfo-1.760.0-150600.10.6.5 * perl-DBD-SQLite-debugsource-1.760.0-150600.10.6.5 * perl-DBD-SQLite-1.760.0-150600.10.6.5 * openSUSE Leap 15.6 (noarch) * perl-Test-MockModule-0.179.0-150600.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:58 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:31:58 -0000 Subject: SUSE-SU-2026:3005-1: moderate: Security update for openssl-3 Message-ID: <178411871892.328.6335771062606696447@178315a69387> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3005-1 Release Date: 2026-07-15T07:26:31Z Rating: moderate References: * bsc#1266344 * bsc#1266350 Cross-References: * CVE-2026-34182 * CVE-2026-42767 CVSS scores: * CVE-2026-34182 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34182 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for openssl-3 fixes the following issues * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3005=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3005=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3005=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3005=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3005=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 * openSUSE Leap 15.5 (noarch) * openssl-3-doc-3.0.8-150500.5.69.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libopenssl3-64bit-3.0.8-150500.5.69.1 * libopenssl-3-devel-64bit-3.0.8-150500.5.69.1 * libopenssl3-64bit-debuginfo-3.0.8-150500.5.69.1 * openSUSE Leap 15.5 (x86_64) * libopenssl3-32bit-3.0.8-150500.5.69.1 * libopenssl-3-devel-32bit-3.0.8-150500.5.69.1 * libopenssl3-32bit-debuginfo-3.0.8-150500.5.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34182.html * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266344 * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:32:05 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:32:05 -0000 Subject: SUSE-SU-2026:3004-1: moderate: Security update for openssl-3 Message-ID: <178411872502.328.17652873028857881985@178315a69387> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3004-1 Release Date: 2026-07-15T07:26:12Z Rating: moderate References: * bsc#1266350 Cross-References: * CVE-2026-42767 CVSS scores: * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-3 fixes the following issue * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3004=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3004=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3004=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libopenssl-3-devel-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-3.1.4-150600.5.56.1 * libopenssl3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-3.1.4-150600.5.56.1 * libopenssl3-3.1.4-150600.5.56.1 * openssl-3-debugsource-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.56.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.56.1 * libopenssl3-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libopenssl-3-devel-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-3.1.4-150600.5.56.1 * libopenssl3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-3.1.4-150600.5.56.1 * libopenssl3-3.1.4-150600.5.56.1 * openssl-3-debugsource-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (x86_64) * libopenssl-3-devel-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-32bit-3.1.4-150600.5.56.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (noarch) * openssl-3-doc-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libopenssl-3-devel-64bit-3.1.4-150600.5.56.1 * libopenssl3-64bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-64bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-64bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-64bit-debuginfo-3.1.4-150600.5.56.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.56.1 * libopenssl3-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.56.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl-3-devel-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-3.1.4-150600.5.56.1 * libopenssl3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-3.1.4-150600.5.56.1 * libopenssl3-3.1.4-150600.5.56.1 * openssl-3-debugsource-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.56.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:32:09 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:32:09 -0000 Subject: SUSE-SU-2026:3000-1: important: Security update for rootlesskit Message-ID: <178411872992.328.474016100424807182@178315a69387> # Security update for rootlesskit Announcement ID: SUSE-SU-2026:3000-1 Release Date: 2026-07-15T05:04:34Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for rootlesskit rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3000=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3000=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3000=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3000=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * rootlesskit-1.1.1-150600.3.8.1 * rootlesskit-debuginfo-1.1.1-150600.3.8.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rootlesskit-1.1.1-150600.3.8.1 * rootlesskit-debuginfo-1.1.1-150600.3.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rootlesskit-1.1.1-150600.3.8.1 * rootlesskit-debuginfo-1.1.1-150600.3.8.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rootlesskit-1.1.1-150600.3.8.1 * rootlesskit-debuginfo-1.1.1-150600.3.8.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:32:22 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 12:32:22 -0000 Subject: SUSE-RU-2026:2998-1: moderate: Recommended update for yast2-rmt Message-ID: <178411874274.328.10466314531059831094@178315a69387> # Recommended update for yast2-rmt Announcement ID: SUSE-RU-2026:2998-1 Release Date: 2026-07-15T04:11:40Z Rating: moderate References: * bsc#1127676 * bsc#1146403 * bsc#1218084 * bsc#1235462 Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has four fixes can now be installed. ## Description: This update for yast2-rmt fixes the following issues: * Ensure compatibility with FIPS mode (bsc#1235462) * Remove 'Forward systems to SCC' checkbox * Fix ERB initialization for older Ruby versions (bsc#1146403) * Mark strings on UI dialogs for tranlation (bsc#1127676) * Adds UI dialog to allow the user to retry the SCC credential validation when the request times out (bsc#1218084) * Adds HTTP User-Agent to requests to the SCC API and changes the enpoint for credential validation ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2998=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2998=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2998=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2998=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2998=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2998=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2998=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2998=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2998=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2998=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2998=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * yast2-rmt-1.3.7-150200.3.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * yast2-rmt-1.3.7-150200.3.13.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1127676 * https://bugzilla.suse.com/show_bug.cgi?id=1146403 * https://bugzilla.suse.com/show_bug.cgi?id=1218084 * https://bugzilla.suse.com/show_bug.cgi?id=1235462 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:07 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:30:07 -0000 Subject: SUSE-RU-2026:22611-1: moderate: Recommended update for libica Message-ID: <178413300785.13854.9092265200699739909@fcb35a5fe5ab> # Recommended update for libica Announcement ID: SUSE-RU-2026:22611-1 Release Date: 2026-07-14T10:05:33Z Rating: moderate References: * bsc#1265602 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for libica fixes the following issues: Changes in libica: * FIPS: Extend RSA KAT coverage to 3072 and 4096 bits (bsc#1265602) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1242=1 ## Package List: * SUSE Linux Micro 6.2 (s390x) * libica-tools-debuginfo-4.4.2-160000.2.1 * libica4-4.4.2-160000.2.1 * libica-debuginfo-4.4.2-160000.2.1 * libica4-debuginfo-4.4.2-160000.2.1 * libica-debugsource-4.4.2-160000.2.1 * libica-tools-4.4.2-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265602 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:15 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:30:15 -0000 Subject: SUSE-RU-2026:22610-1: important: Recommended update for ServiceReport Message-ID: <178413301502.13854.312741205099302316@fcb35a5fe5ab> # Recommended update for ServiceReport Announcement ID: SUSE-RU-2026:22610-1 Release Date: 2026-07-10T09:55:45Z Rating: important References: * bsc#1270052 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for ServiceReport fixes the following issues: Changes in ServiceReport: * Update to version 2.2.4+git12.bc007b2 (bsc#1270052 ltc#218889): * [kdump] Fix TypeError in kdump component check Update to version 2.2.4+git11.8bf0f05: * Remove PrivateDevices=true * remove type=oneshot * add new plugin Spyre card configuration * Update to version 2.2.4+git3.f65dad0: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1209=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * ServiceReport-2.2.4+git12.bc007b2-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270052 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:18 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:30:18 -0000 Subject: SUSE-RU-2026:22607-1: moderate: Recommended update for synce4l Message-ID: <178413301888.13854.10147799652276945708@fcb35a5fe5ab> # Recommended update for synce4l Announcement ID: SUSE-RU-2026:22607-1 Release Date: 2026-07-14T10:41:18Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.2 An update that can now be installed. ## Description: This update for synce4l fixes the following issues: * update to 1.1.2: * fix infinite loop in dpll_mon_destroy() without DPLL ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1244=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * synce4l-debugsource-1.1.2-160000.1.1 * synce4l-1.1.2-160000.1.1 * synce4l-debuginfo-1.1.2-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:30:24 -0000 Subject: SUSE-RU-2026:22606-1: moderate: Recommended update for policycoreutils Message-ID: <178413302491.13854.6247374407395906879@fcb35a5fe5ab> # Recommended update for policycoreutils Announcement ID: SUSE-RU-2026:22606-1 Release Date: 2026-07-14T10:32:29Z Rating: moderate References: * bsc#1270534 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for policycoreutils fixes the following issues: Changes in policycoreutils: * Remove sandbox package as it will be provided as a separate package: selinux-sandbox (bsc#1270534) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1241=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * python313-policycoreutils-3.8.1-160000.4.1 * policycoreutils-python-utils-3.8.1-160000.4.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * policycoreutils-debugsource-3.8.1-160000.4.1 * policycoreutils-debuginfo-3.8.1-160000.4.1 * policycoreutils-3.8.1-160000.4.1 * policycoreutils-devel-3.8.1-160000.4.1 * policycoreutils-devel-debuginfo-3.8.1-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270534 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:28 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:30:28 -0000 Subject: SUSE-RU-2026:22605-1: moderate: Recommended update for protobuf Message-ID: <178413302862.13854.1828134539368735618@fcb35a5fe5ab> # Recommended update for protobuf Announcement ID: SUSE-RU-2026:22605-1 Release Date: 2026-07-14T08:20:34Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.2 An update that can now be installed. ## Description: This update for protobuf fixes the following issues: * Add missing python-rpm-macros BR ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1239=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libutf8_range-28_3_0-28.3-160000.5.1 * protobuf-debugsource-28.3-160000.5.1 * libprotobuf28_3_0-debuginfo-28.3-160000.5.1 * libprotobuf28_3_0-28.3-160000.5.1 * libutf8_range-28_3_0-debuginfo-28.3-160000.5.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:41 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:30:41 -0000 Subject: SUSE-SU-2026:22604-1: low: Security update for patch Message-ID: <178413304154.13854.16683101182474092258@fcb35a5fe5ab> # Security update for patch Announcement ID: SUSE-SU-2026:22604-1 Release Date: 2026-07-13T19:29:50Z Rating: low References: * bsc#1271166 * bsc#1271167 Cross-References: * CVE-2026-56288 * CVE-2026-56289 CVSS scores: * CVE-2026-56288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56288 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56288 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56289 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2026-56289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56289 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56289 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for patch fixes the following issues * CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167). * CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1236=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * patch-2.7.6-160000.4.1 * patch-debugsource-2.7.6-160000.4.1 * patch-debuginfo-2.7.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56288.html * https://www.suse.com/security/cve/CVE-2026-56289.html * https://bugzilla.suse.com/show_bug.cgi?id=1271166 * https://bugzilla.suse.com/show_bug.cgi?id=1271167 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:47 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:30:47 -0000 Subject: SUSE-SU-2026:22603-1: low: Security update for helm Message-ID: <178413304716.13854.9904626716015552433@fcb35a5fe5ab> # Security update for helm Announcement ID: SUSE-SU-2026:22603-1 Release Date: 2026-07-13T19:24:02Z Rating: low References: * bsc#1270127 Cross-References: * CVE-2026-48978 CVSS scores: * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). Changes for helm: * Update to version 3.21.2. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1235=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 s390x x86_64) * helm-debuginfo-3.21.2-160000.2.1 * helm-3.21.2-160000.2.1 * SUSE Linux Micro 6.2 (noarch) * helm-bash-completion-3.21.2-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48978.html * https://bugzilla.suse.com/show_bug.cgi?id=1270127 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:54 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:30:54 -0000 Subject: SUSE-SU-2026:22602-1: moderate: Security update for cryptsetup Message-ID: <178413305438.13854.15053864997660263334@fcb35a5fe5ab> # Security update for cryptsetup Announcement ID: SUSE-SU-2026:22602-1 Release Date: 2026-07-13T16:23:16Z Rating: moderate References: * bsc#1270252 * bsc#1270254 Affected Products: * SUSE Linux Micro 6.2 An update that has two fixes can now be installed. ## Description: This update for cryptsetup fixes the following issues: Changes in cryptsetup: * Fix for (bsc#1270254) to avoid undesired pinning of all volume keys (via the thread keyring) through the caller's credentials when the kernel opens a file. This is due to the refactoring in kernel commit a28d893eb327 ("md: port block device access to file") that accidentally causes the caller's thread keyring to be kept alive long beyond the caller's lifetime, the kernel part is tracked in (bsc#1270252). * Add keyring key type. [b6fb6fc0] * Load volume keys in intermediary keyring linked in thread keyring. [413a3dd0] * Use unique intermediary keyring name per device. [04ef07a7] * Add regression tests. [bfcb0c38, bb5e8e9f, e6573494, aa214c09] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1229=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * cryptsetup-debugsource-2.8.4-160000.2.1 * cryptsetup-2.8.4-160000.2.1 * libcryptsetup12-2.8.4-160000.2.1 * cryptsetup-debuginfo-2.8.4-160000.2.1 * libcryptsetup12-debuginfo-2.8.4-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270252 * https://bugzilla.suse.com/show_bug.cgi?id=1270254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:31:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:31:02 -0000 Subject: SUSE-RU-2026:22601-1: moderate: Recommended update for python-gcemetadata Message-ID: <178413306271.13854.13291654861166754788@fcb35a5fe5ab> # Recommended update for python-gcemetadata Announcement ID: SUSE-RU-2026:22601-1 Release Date: 2026-07-13T16:21:51Z Rating: moderate References: * bsc#1269423 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for python-gcemetadata fixes the following issues: * Update to version 1.1.1: * Fix UnboundLocalError when using --xml with --query (bsc#1269423) * Update comments ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1230=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * python-gcemetadata-1.1.1-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269423 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:31:07 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:31:07 -0000 Subject: SUSE-RU-2026:22600-1: moderate: Recommended update for adcli Message-ID: <178413306773.13854.16437708441562211544@fcb35a5fe5ab> # Recommended update for adcli Announcement ID: SUSE-RU-2026:22600-1 Release Date: 2026-07-13T13:56:55Z Rating: moderate References: * jsc#PED-16504 Affected Products: * SUSE Linux Micro 6.2 An update that contains one feature can now be installed. ## Description: This update for adcli fixes the following issues: Changes in adcli: * Split selinux policy to its own package * Fix issues if default keytab is used, strip 'FILE:' prefix before calling libselinux functions; Add patch Update to 0.9.3.1; (jsc#PED-16504); * fix typo in tests * add enable switches for SELinux and offline join support * include tests in release tar archive includes changes from 0.9.3: * enroll: check if AD accepts new password * enroll: allow to add SPNs to manages service accounts * enroll: add new SPNs from AD to keytab during update * conn: use 10s timeout for connect() * enroll: restore SELinux file context of keytab files * enroll: remove USE_DES_KEY_ONLY during join * entry: check user and group names for illegal characters * tools: add --recursive option to delete-computer * tools: testjoin, use realm from keytab as domain name * enroll: use realm form the HOST$ entry in the keytab * Tests: initial framework and tests for adcli based on sssd-test-framework * krb5: add adcli_krb5_get_error_message() * Various fixes for issues found by static code scanners * enroll: Populate Samba's secrets database using offline domain join ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1226=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * adcli-0.9.3.1-160000.1.1 * adcli-debugsource-0.9.3.1-160000.1.1 * adcli-debuginfo-0.9.3.1-160000.1.1 * SUSE Linux Micro 6.2 (noarch) * adcli-selinux-0.9.3.1-160000.1.1 ## References: * https://jira.suse.com/browse/PED-16504 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:31:14 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:31:14 -0000 Subject: SUSE-SU-2026:22599-1: moderate: Security update for pam Message-ID: <178413307400.13854.3549145529553032738@fcb35a5fe5ab> # Security update for pam Announcement ID: SUSE-SU-2026:22599-1 Release Date: 2026-07-13T13:54:56Z Rating: moderate References: * bsc#1268290 Cross-References: * CVE-2026-54411 CVSS scores: * CVE-2026-54411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-54411 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X * CVE-2026-54411 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for pam fixes the following issue * CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext- password comparison (bsc#1268290). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1224=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * pam-extra-debuginfo-1.7.1-160000.5.1 * pam-extra-1.7.1-160000.5.1 * pam-1.7.1-160000.5.1 * pam-debuginfo-1.7.1-160000.5.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x) * pam-full-src-debugsource-1.7.1-160000.5.1 * pam-debugsource-1.7.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54411.html * https://bugzilla.suse.com/show_bug.cgi?id=1268290 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:31:47 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:31:47 -0000 Subject: SUSE-SU-2026:22598-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise 16) Message-ID: <178413310789.13854.5127025640007371907@fcb35a5fe5ab> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22598-1 Release Date: 2026-07-13T11:25:37Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.30.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1222=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_9-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_30-rt-4-160000.1.1 * kernel-livepatch-6_12_0-160000_30-rt-debuginfo-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:31:58 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:31:58 -0000 Subject: SUSE-SU-2026:22597-1: important: Security update for jq Message-ID: <178413311860.13854.9872620383565106186@fcb35a5fe5ab> # Security update for jq Announcement ID: SUSE-SU-2026:22597-1 Release Date: 2026-07-13T10:47:46Z Rating: important References: * bsc#1265075 * bsc#1265076 * bsc#1269220 * bsc#1269390 Cross-References: * CVE-2026-43896 * CVE-2026-44777 * CVE-2026-49839 * CVE-2026-54679 CVSS scores: * CVE-2026-43896 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43896 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44777 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44777 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44777 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49839 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-49839 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-54679 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-54679 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves four vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues * CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075). * CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). * CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized- string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220). * CVE-2026-54679: integer overflow in jvp_string_append can lead to a buffer overrun on 32-bit systems (bsc#1269390). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1221=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * jq-1.7.1-160000.4.1 * jq-debuginfo-1.7.1-160000.4.1 * jq-debugsource-1.7.1-160000.4.1 * libjq1-1.7.1-160000.4.1 * libjq1-debuginfo-1.7.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43896.html * https://www.suse.com/security/cve/CVE-2026-44777.html * https://www.suse.com/security/cve/CVE-2026-49839.html * https://www.suse.com/security/cve/CVE-2026-54679.html * https://bugzilla.suse.com/show_bug.cgi?id=1265075 * https://bugzilla.suse.com/show_bug.cgi?id=1265076 * https://bugzilla.suse.com/show_bug.cgi?id=1269220 * https://bugzilla.suse.com/show_bug.cgi?id=1269390 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:06 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:32:06 -0000 Subject: SUSE-SU-2026:22596-1: important: Security update for libxml2 Message-ID: <178413312659.13854.9817941868003033122@fcb35a5fe5ab> # Security update for libxml2 Announcement ID: SUSE-SU-2026:22596-1 Release Date: 2026-07-13T07:49:58Z Rating: important References: * bsc#1262719 * bsc#1269790 Cross-References: * CVE-2026-11979 * CVE-2026-6732 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6732 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6732 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6732 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6732 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for libxml2 fixes the following issues * CVE-2026-6732: crafted XSD-validated document can cause a denial of service (bsc#1262719). * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1220=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libxml2-tools-debuginfo-2.13.8-160000.5.1 * libxml2-2-debuginfo-2.13.8-160000.5.1 * libxml2-2-2.13.8-160000.5.1 * python313-libxml2-debuginfo-2.13.8-160000.5.1 * libxml2-debugsource-2.13.8-160000.5.1 * python313-libxml2-2.13.8-160000.5.1 * libxml2-python-debugsource-2.13.8-160000.5.1 * libxml2-tools-2.13.8-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://www.suse.com/security/cve/CVE-2026-6732.html * https://bugzilla.suse.com/show_bug.cgi?id=1262719 * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:10 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:32:10 -0000 Subject: SUSE-RU-2026:22595-1: moderate: Recommended update for vim Message-ID: <178413313055.13854.5293230661912451745@fcb35a5fe5ab> # Recommended update for vim Announcement ID: SUSE-RU-2026:22595-1 Release Date: 2026-07-11T19:14:24Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.2 An update that can now be installed. ## Description: This update for vim fixes the following issues: * Updated to version 9.2.0725: * fixes issues ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1215=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * vim-small-9.2.0725-160000.1.1 * vim-debuginfo-9.2.0725-160000.1.1 * vim-debugsource-9.2.0725-160000.1.1 * vim-small-debuginfo-9.2.0725-160000.1.1 * SUSE Linux Micro 6.2 (noarch) * vim-data-common-9.2.0725-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:16 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:32:16 -0000 Subject: SUSE-SU-2026:22594-1: moderate: Security update for nghttp2 Message-ID: <178413313614.13854.9609825338217670258@fcb35a5fe5ab> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:22594-1 Release Date: 2026-07-10T13:25:42Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1213=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * nghttp2-debugsource-1.64.0-160000.4.1 * libnghttp2-14-1.64.0-160000.4.1 * nghttp2-debuginfo-1.64.0-160000.4.1 * libnghttp2-14-debuginfo-1.64.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:33 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:32:33 -0000 Subject: SUSE-SU-2026:22593-1: important: Security update for python-cryptography Message-ID: <178413315396.13854.1801849917647357160@fcb35a5fe5ab> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:22593-1 Release Date: 2026-07-10T09:12:46Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1205=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * python313-cryptography-44.0.3-160000.4.1 * python-cryptography-debugsource-44.0.3-160000.4.1 * python313-cryptography-debuginfo-44.0.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:41 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:32:41 -0000 Subject: SUSE-SU-2026:22592-1: important: Security update for perl-DBI Message-ID: <178413316109.13854.6389107344165540164@fcb35a5fe5ab> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:22592-1 Release Date: 2026-07-10T09:10:39Z Rating: important References: * bsc#1271017 * bsc#1271018 Cross-References: * CVE-2026-14380 * CVE-2026-14740 CVSS scores: * CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). * CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1204=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.647.0-160000.4.1 * perl-DBI-1.647.0-160000.4.1 * perl-DBI-debuginfo-1.647.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14380.html * https://www.suse.com/security/cve/CVE-2026-14740.html * https://bugzilla.suse.com/show_bug.cgi?id=1271017 * https://bugzilla.suse.com/show_bug.cgi?id=1271018 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:47 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:32:47 -0000 Subject: SUSE-SU-2026:22591-1: important: Security update for sssd Message-ID: <178413316780.13854.10623473701157616516@fcb35a5fe5ab> # Security update for sssd Announcement ID: SUSE-SU-2026:22591-1 Release Date: 2026-07-10T08:58:36Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1201=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libsss_certmap0-2.10.2-160000.3.1 * sssd-tools-debuginfo-2.10.2-160000.3.1 * sssd-dbus-2.10.2-160000.3.1 * libsss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-2.10.2-160000.3.1 * sssd-ad-debuginfo-2.10.2-160000.3.1 * python3-sssd-config-debuginfo-2.10.2-160000.3.1 * sssd-debugsource-2.10.2-160000.3.1 * sssd-debuginfo-2.10.2-160000.3.1 * libsss_certmap0-debuginfo-2.10.2-160000.3.1 * sssd-krb5-2.10.2-160000.3.1 * sssd-ldap-2.10.2-160000.3.1 * sssd-dbus-debuginfo-2.10.2-160000.3.1 * sssd-2.10.2-160000.3.1 * sssd-ad-2.10.2-160000.3.1 * sssd-ldap-debuginfo-2.10.2-160000.3.1 * libsss_idmap0-debuginfo-2.10.2-160000.3.1 * sssd-krb5-common-debuginfo-2.10.2-160000.3.1 * sssd-krb5-common-2.10.2-160000.3.1 * sssd-krb5-debuginfo-2.10.2-160000.3.1 * sssd-tools-2.10.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:55 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:32:55 -0000 Subject: SUSE-SU-2026:22590-1: important: Security update for tiff Message-ID: <178413317552.13854.180300743608664578@fcb35a5fe5ab> # Security update for tiff Announcement ID: SUSE-SU-2026:22590-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 * CVE-2026-4775 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-4775 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4775 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Changes for tiff: * Update to 4.7.2: Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss- fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg- turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss- fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1200=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * tiff-debugsource-4.7.2-160000.1.1 * libtiff6-4.7.2-160000.1.1 * libtiff6-debuginfo-4.7.2-160000.1.1 * tiff-debuginfo-4.7.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://www.suse.com/security/cve/CVE-2026-4775.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:33:12 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:33:12 -0000 Subject: SUSE-SU-2026:22589-1: important: Security update for python-maturin Message-ID: <178413319253.13854.486146332820711592@fcb35a5fe5ab> # Security update for python-maturin Announcement ID: SUSE-SU-2026:22589-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-maturin fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1196=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * python313-maturin-1.8.7-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:33:16 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:33:16 -0000 Subject: SUSE-RU-2026:22590-1: moderate: Recommended update for vim Message-ID: <178413319650.13854.3422939909463892479@fcb35a5fe5ab> # Recommended update for vim Announcement ID: SUSE-RU-2026:22590-1 Release Date: 2026-07-11T19:17:04Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that can now be installed. ## Description: This update for vim fixes the following issues: * Updated to version 9.2.0725: * fixes issues ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1215=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * xxd-debuginfo-9.2.0725-160000.1.1 * vim-debuginfo-9.2.0725-160000.1.1 * vim-debugsource-9.2.0725-160000.1.1 * vim-9.2.0725-160000.1.1 * xxd-9.2.0725-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:33:20 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:33:20 -0000 Subject: SUSE-RU-2026:22589-1: moderate: Recommended update for python-rpm-macros Message-ID: <178413320029.13854.2208846267960112250@fcb35a5fe5ab> # Recommended update for python-rpm-macros Announcement ID: SUSE-RU-2026:22589-1 Release Date: 2026-07-10T09:54:27Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that can now be installed. ## Description: This update for python-rpm-macros fixes the following issues: Changes in python-rpm-macros: Update to version 20260629.bcd36db: * don't use realpath to the interpreter binary * doc: add a shot documentation text for %python_site{lib,arch}_module. * Add initial pyproject declarative buildsystem * fix: handle the situation when either `name` or `meta_name` is not found * Consolidate site directory name normalization into %__python_sitedir_name * Normalize the name of the directory * Definitions of %python_site{lib,arch}_module macros. Update to version 20260601.4a231f4: * fix: allow function of `%pythonXX_provides` w/o /usr/bin/python3 * Update python version handling in default-prjconf * Rewrite README.md to have headlines for each macro. Update to version 20260317.5e02b19: * fix: don't double escape %{**} code. * Copy libalternatives binaries from buildroot to flavorbin Update to version 20250923.c3cfac8: * Remove py_setup_args macro completely. * Move libalternative conf creation to FLAVOR_alternative_conf * Update default-prjconf for primary python: python313 * Drop python38, add python314 * Make RPM macro expansions POSIX sh-compatible ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1210=1 ## Package List: * SUSE Linux Micro Extras 6.2 (noarch) * python-rpm-macros-20260629.bcd36db-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:33:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:33:36 -0000 Subject: SUSE-SU-2026:3011-1: important: Security update for the Linux Kernel (Live Patch 82 for SUSE Linux Enterprise 12 SP5) Message-ID: <178413321611.13854.11668741831685486804@fcb35a5fe5ab> # Security update for the Linux Kernel (Live Patch 82 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3011-1 Release Date: 2026-07-15T08:46:04Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.307 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3011=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_307-default-3-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:34:20 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:34:20 -0000 Subject: SUSE-SU-2026:3044-1: important: Security update for the Linux Kernel Message-ID: <178413326094.13854.5894852844810004305@fcb35a5fe5ab> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:3044-1 Release Date: 2026-07-15T11:59:54Z Rating: important References: * bsc#1264097 * bsc#1264145 * bsc#1265421 * bsc#1267531 * bsc#1267567 * bsc#1267635 * bsc#1267684 * bsc#1267722 * bsc#1267918 * bsc#1267993 * bsc#1268022 * bsc#1268660 * bsc#1269022 * bsc#1269033 * bsc#1269036 * bsc#1269090 * bsc#1269100 * bsc#1269159 * bsc#1269184 * bsc#1269193 * bsc#1269195 * bsc#1269310 * bsc#1269398 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269821 * bsc#1270059 Cross-References: * CVE-2026-31771 * CVE-2026-43038 * CVE-2026-46090 * CVE-2026-46173 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46331 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52943 * CVE-2026-52955 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-52993 * CVE-2026-53016 * CVE-2026-53041 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53133 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 28 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3044=1 * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-3044=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3044=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3044=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3044=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3044=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3044=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3044=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3044=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3044=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3044=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64) * kernel-64kb-devel-5.14.21-150400.24.228.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (s390x) * kernel-zfcpdump-debuginfo-5.14.21-150400.24.228.1 * kernel-zfcpdump-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64) * kernel-64kb-devel-5.14.21-150400.24.228.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (nosrc s390x) * kernel-zfcpdump-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64) * kernel-64kb-devel-5.14.21-150400.24.228.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * cluster-md-kmp-default-5.14.21-150400.24.228.1 * ocfs2-kmp-default-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-default-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-default-5.14.21-150400.24.228.1 * cluster-md-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * dlm-kmp-default-debuginfo-5.14.21-150400.24.228.1 * ocfs2-kmp-default-5.14.21-150400.24.228.1 * dlm-kmp-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (nosrc) * kernel-default-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64) * dtb-rockchip-5.14.21-150400.24.228.1 * kselftests-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * cluster-md-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * dtb-amazon-5.14.21-150400.24.228.1 * kselftests-kmp-64kb-5.14.21-150400.24.228.1 * dtb-socionext-5.14.21-150400.24.228.1 * dtb-arm-5.14.21-150400.24.228.1 * ocfs2-kmp-64kb-5.14.21-150400.24.228.1 * kernel-64kb-optional-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-devel-5.14.21-150400.24.228.1 * dlm-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-64kb-5.14.21-150400.24.228.1 * dtb-exynos-5.14.21-150400.24.228.1 * dtb-broadcom-5.14.21-150400.24.228.1 * dtb-cavium-5.14.21-150400.24.228.1 * dtb-nvidia-5.14.21-150400.24.228.1 * dtb-hisilicon-5.14.21-150400.24.228.1 * dtb-xilinx-5.14.21-150400.24.228.1 * kernel-64kb-optional-5.14.21-150400.24.228.1 * dtb-renesas-5.14.21-150400.24.228.1 * dtb-amd-5.14.21-150400.24.228.1 * dtb-allwinner-5.14.21-150400.24.228.1 * dtb-sprd-5.14.21-150400.24.228.1 * kernel-64kb-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-extra-5.14.21-150400.24.228.1 * dtb-lg-5.14.21-150400.24.228.1 * reiserfs-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * dtb-altera-5.14.21-150400.24.228.1 * dlm-kmp-64kb-5.14.21-150400.24.228.1 * kernel-64kb-debugsource-5.14.21-150400.24.228.1 * gfs2-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * dtb-freescale-5.14.21-150400.24.228.1 * dtb-qcom-5.14.21-150400.24.228.1 * dtb-amlogic-5.14.21-150400.24.228.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.228.1 * dtb-marvell-5.14.21-150400.24.228.1 * reiserfs-kmp-64kb-5.14.21-150400.24.228.1 * ocfs2-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * cluster-md-kmp-64kb-5.14.21-150400.24.228.1 * dtb-apple-5.14.21-150400.24.228.1 * kernel-64kb-extra-debuginfo-5.14.21-150400.24.228.1 * dtb-mediatek-5.14.21-150400.24.228.1 * dtb-apm-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * cluster-md-kmp-default-5.14.21-150400.24.228.1 * kernel-default-extra-5.14.21-150400.24.228.1 * cluster-md-kmp-default-debuginfo-5.14.21-150400.24.228.1 * ocfs2-kmp-default-5.14.21-150400.24.228.1 * dlm-kmp-default-5.14.21-150400.24.228.1 * ocfs2-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-optional-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-default-extra-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-qa-5.14.21-150400.24.228.1 * kselftests-kmp-default-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * dlm-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kselftests-kmp-default-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-default-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * kernel-default-livepatch-5.14.21-150400.24.228.1 * kernel-default-optional-5.14.21-150400.24.228.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * kernel-docs-html-5.14.21-150400.24.228.1 * kernel-source-vanilla-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64) * kernel-kvmsmall-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-kvmsmall-debuginfo-5.14.21-150400.24.228.1 * kernel-kvmsmall-devel-5.14.21-150400.24.228.1 * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * kernel-default-base-rebuild-5.14.21-150400.24.228.1.150400.24.116.1 * kernel-kvmsmall-debugsource-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (nosrc s390x) * kernel-zfcpdump-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-default-livepatch-devel-5.14.21-150400.24.228.1 * kernel-livepatch-5_14_21-150400_24_228-default-1-150400.9.3.1 * kernel-livepatch-5_14_21-150400_24_228-default-debuginfo-1-150400.9.3.1 * kernel-livepatch-SLE15-SP4_Update_57-debugsource-1-150400.9.3.1 * openSUSE Leap 15.4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (nosrc) * dtb-aarch64-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64 nosrc ppc64le x86_64) * kernel-kvmsmall-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (s390x) * kernel-zfcpdump-debugsource-5.14.21-150400.24.228.1 * kernel-zfcpdump-debuginfo-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-default-livepatch-5.14.21-150400.24.228.1 * kernel-livepatch-5_14_21-150400_24_228-default-debuginfo-1-150400.9.3.1 * kernel-default-livepatch-devel-5.14.21-150400.24.228.1 * kernel-livepatch-5_14_21-150400_24_228-default-1-150400.9.3.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-livepatch-SLE15-SP4_Update_57-debugsource-1-150400.9.3.1 * SUSE Linux Enterprise Live Patching 15-SP4 (nosrc) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1264097 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:35:02 -0000 Subject: SUSE-SU-2026:3043-1: important: Security update for curl Message-ID: <178413330234.13854.8126997722594036502@fcb35a5fe5ab> # Security update for curl Announcement ID: SUSE-SU-2026:3043-1 Release Date: 2026-07-15T11:51:45Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3043=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3043=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3043=1 * SUSE Linux Enterprise Server 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3043=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3043=1 SUSE-SLE-Product- SLES_SAP-15-SP5-2026-3043=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3043=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3043=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3043=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3043=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3043=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3043=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3043=1 * SUSE Linux Enterprise High Performance Computing 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Linux Enterprise Server 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 SUSE-SLE-Product- SLES_SAP-15-SP4-2026-3043=1 * SUSE Linux Enterprise Desktop 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3043=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3043=1 * SUSE Linux Enterprise High Performance Computing 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3043=1 * SUSE Linux Enterprise Desktop 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3043=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * curl-mini-debugsource-8.14.1-150400.5.86.1 * libcurl-mini4-8.14.1-150400.5.86.1 * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-mini4-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * openSUSE Leap 15.4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-32bit-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * openSUSE Leap 15.4 (noarch) * curl-zsh-completion-8.14.1-150400.5.86.1 * libcurl-devel-doc-8.14.1-150400.5.86.1 * curl-fish-completion-8.14.1-150400.5.86.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libcurl4-64bit-8.14.1-150400.5.86.1 * libcurl-devel-64bit-8.14.1-150400.5.86.1 * libcurl4-64bit-debuginfo-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP4 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing 15 SP5 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Desktop 15 SP5 (x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP5 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing 15 SP4 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Desktop 15 SP4 (x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Manager Proxy 4.3 (x86_64) * libcurl4-8.14.1-150400.5.86.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:08 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:35:08 -0000 Subject: SUSE-SU-2026:3042-1: important: Security update for gnutls Message-ID: <178413330848.13854.7059017420286490879@fcb35a5fe5ab> # Security update for gnutls Announcement ID: SUSE-SU-2026:3042-1 Release Date: 2026-07-15T11:50:16Z Rating: important References: * bsc#1263713 Cross-References: * CVE-2026-42014 CVSS scores: * CVE-2026-42014 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42014 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42014 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gnutls fixes the following issue * Rebase the CVE-2026-42014 patch to include a missing call to `p11_kit_uri_free()` in `gnutls_pkcs11_token_set_pin()` (bsc#1263713). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3042=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3042=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3042=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3042=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3042=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3042=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3042=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3042=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3042=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3042=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3042=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3042=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgnutls-devel-64bit-3.7.3-150400.4.62.1 * libgnutls30-64bit-debuginfo-3.7.3-150400.4.62.1 * libgnutls30-hmac-64bit-3.7.3-150400.4.62.1 * libgnutls30-64bit-3.7.3-150400.4.62.1 * openSUSE Leap 15.4 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls-devel-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42014.html * https://bugzilla.suse.com/show_bug.cgi?id=1263713 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:15 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:35:15 -0000 Subject: SUSE-SU-2026:3041-1: important: Security update for sssd Message-ID: <178413331552.13854.4840687361542356899@fcb35a5fe5ab> # Security update for sssd Announcement ID: SUSE-SU-2026:3041-1 Release Date: 2026-07-15T11:49:01Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3041=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsss_nss_idmap0-debuginfo-2.10.2-150700.9.34.1 * libsss_simpleifp-devel-2.10.2-150700.9.34.1 * sssd-tools-debuginfo-2.10.2-150700.9.34.1 * sssd-ldap-2.10.2-150700.9.34.1 * sssd-ad-2.10.2-150700.9.34.1 * sssd-krb5-common-2.10.2-150700.9.34.1 * sssd-kcm-debuginfo-2.10.2-150700.9.34.1 * sssd-proxy-2.10.2-150700.9.34.1 * libsss_simpleifp0-debuginfo-2.10.2-150700.9.34.1 * libsss_idmap0-debuginfo-2.10.2-150700.9.34.1 * libsss_nss_idmap0-2.10.2-150700.9.34.1 * libsss_idmap-devel-2.10.2-150700.9.34.1 * sssd-ad-debuginfo-2.10.2-150700.9.34.1 * libsss_certmap-devel-2.10.2-150700.9.34.1 * sssd-winbind-idmap-2.10.2-150700.9.34.1 * libsss_certmap0-debuginfo-2.10.2-150700.9.34.1 * libsss_nss_idmap-devel-2.10.2-150700.9.34.1 * sssd-dbus-debuginfo-2.10.2-150700.9.34.1 * sssd-krb5-debuginfo-2.10.2-150700.9.34.1 * sssd-2.10.2-150700.9.34.1 * libipa_hbac-devel-2.10.2-150700.9.34.1 * sssd-debuginfo-2.10.2-150700.9.34.1 * libipa_hbac0-2.10.2-150700.9.34.1 * sssd-tools-2.10.2-150700.9.34.1 * sssd-proxy-debuginfo-2.10.2-150700.9.34.1 * libsss_idmap0-2.10.2-150700.9.34.1 * sssd-winbind-idmap-debuginfo-2.10.2-150700.9.34.1 * sssd-ipa-2.10.2-150700.9.34.1 * python3-sssd-config-debuginfo-2.10.2-150700.9.34.1 * sssd-debugsource-2.10.2-150700.9.34.1 * sssd-ldap-debuginfo-2.10.2-150700.9.34.1 * sssd-krb5-common-debuginfo-2.10.2-150700.9.34.1 * python3-sssd-config-2.10.2-150700.9.34.1 * sssd-kcm-2.10.2-150700.9.34.1 * libsss_simpleifp0-2.10.2-150700.9.34.1 * libsss_certmap0-2.10.2-150700.9.34.1 * sssd-krb5-2.10.2-150700.9.34.1 * libipa_hbac0-debuginfo-2.10.2-150700.9.34.1 * sssd-ipa-debuginfo-2.10.2-150700.9.34.1 * sssd-dbus-2.10.2-150700.9.34.1 * Basesystem Module 15-SP7 (x86_64) * sssd-32bit-2.10.2-150700.9.34.1 * sssd-32bit-debuginfo-2.10.2-150700.9.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:32 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:35:32 -0000 Subject: SUSE-SU-2026:3040-1: important: Security update for python-cryptography Message-ID: <178413333280.13854.15578616913387019537@fcb35a5fe5ab> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:3040-1 Release Date: 2026-07-15T11:48:45Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3040=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3040=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3040=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3040=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3040=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3040=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3040=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3040=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3040=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3040=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-cryptography-41.0.3-150400.16.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:39 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:35:39 -0000 Subject: SUSE-SU-2026:3039-1: important: Security update for libpng12 Message-ID: <178413333997.13854.1880786431539237633@fcb35a5fe5ab> # Security update for libpng12 Announcement ID: SUSE-SU-2026:3039-1 Release Date: 2026-07-15T11:45:44Z Rating: important References: * bsc#1258020 Cross-References: * CVE-2026-25646 CVSS scores: * CVE-2026-25646 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-25646 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-25646 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25646 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-25646 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libpng12 fixes the following issue * CVE-2026-25646: Heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3039=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3039=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpng12-debugsource-1.2.59-20.17.1 * libpng12-0-1.2.59-20.17.1 * libpng12-compat-devel-1.2.59-20.17.1 * libpng12-devel-1.2.59-20.17.1 * libpng12-0-32bit-1.2.59-20.17.1 * libpng12-0-debuginfo-1.2.59-20.17.1 * libpng12-0-debuginfo-32bit-1.2.59-20.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpng12-debugsource-1.2.59-20.17.1 * libpng12-0-1.2.59-20.17.1 * libpng12-compat-devel-1.2.59-20.17.1 * libpng12-devel-1.2.59-20.17.1 * libpng12-0-debuginfo-1.2.59-20.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libpng12-0-32bit-1.2.59-20.17.1 * libpng12-0-debuginfo-32bit-1.2.59-20.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25646.html * https://bugzilla.suse.com/show_bug.cgi?id=1258020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:49 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:35:49 -0000 Subject: SUSE-SU-2026:3038-1: important: Security update for qemu Message-ID: <178413334937.13854.13928699902821095335@fcb35a5fe5ab> # Security update for qemu Announcement ID: SUSE-SU-2026:3038-1 Release Date: 2026-07-15T11:45:32Z Rating: important References: * bsc#1268061 * bsc#1268794 * bsc#1270133 * jsc#PED-14242 * jsc#PED-14279 Cross-References: * CVE-2026-3886 * CVE-2026-48004 * CVE-2026-48914 CVSS scores: * CVE-2026-3886 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-48004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48914 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H * CVE-2026-48914 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities and contains two features can now be installed. ## Description: This update for qemu fixes the following issues * CVE-2026-3886: QEMU calc_image_hostmem Integer Overflow Local Privilege Escalation Vulnerability (bsc#1268061). * CVE-2026-48004: heap use-after-free race condition allows a DoS by an unprivileged guest user (bsc#1270133). * CVE-2026-48914: qemu-kvm: Heap Buffer Overflow in virtio-blk SCSI Request Handling (bsc#1268794). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3038=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3038=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3038=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * qemu-ui-dbus-9.2.4-150700.3.23.1 * qemu-chardev-spice-9.2.4-150700.3.23.1 * qemu-ui-opengl-debuginfo-9.2.4-150700.3.23.1 * qemu-ui-curses-9.2.4-150700.3.23.1 * qemu-audio-spice-9.2.4-150700.3.23.1 * qemu-hw-display-qxl-debuginfo-9.2.4-150700.3.23.1 * qemu-ui-dbus-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-pipewire-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-usb-host-9.2.4-150700.3.23.1 * qemu-audio-spice-debuginfo-9.2.4-150700.3.23.1 * qemu-block-nfs-debuginfo-9.2.4-150700.3.23.1 * qemu-block-iscsi-debuginfo-9.2.4-150700.3.23.1 * qemu-ui-opengl-9.2.4-150700.3.23.1 * qemu-ui-curses-debuginfo-9.2.4-150700.3.23.1 * qemu-block-curl-debuginfo-9.2.4-150700.3.23.1 * qemu-guest-agent-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-dbus-9.2.4-150700.3.23.1 * qemu-hw-usb-redirect-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-vga-debuginfo-9.2.4-150700.3.23.1 * qemu-9.2.4-150700.3.23.1 * qemu-debugsource-9.2.4-150700.3.23.1 * qemu-chardev-baum-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-usb-redirect-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-vga-9.2.4-150700.3.23.1 * qemu-block-nfs-9.2.4-150700.3.23.1 * qemu-ksm-9.2.4-150700.3.23.1 * qemu-block-rbd-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-usb-host-debuginfo-9.2.4-150700.3.23.1 * qemu-block-iscsi-9.2.4-150700.3.23.1 * qemu-debuginfo-9.2.4-150700.3.23.1 * qemu-headless-9.2.4-150700.3.23.1 * qemu-chardev-baum-9.2.4-150700.3.23.1 * qemu-ui-spice-core-9.2.4-150700.3.23.1 * qemu-block-rbd-9.2.4-150700.3.23.1 * qemu-block-curl-9.2.4-150700.3.23.1 * qemu-guest-agent-9.2.4-150700.3.23.1 * qemu-ui-spice-core-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-display-qxl-9.2.4-150700.3.23.1 * qemu-chardev-spice-debuginfo-9.2.4-150700.3.23.1 * qemu-block-ssh-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-pipewire-9.2.4-150700.3.23.1 * qemu-spice-9.2.4-150700.3.23.1 * qemu-block-ssh-9.2.4-150700.3.23.1 * qemu-audio-dbus-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (s390x) * qemu-hw-s390x-virtio-gpu-ccw-9.2.4-150700.3.23.1 * qemu-s390x-9.2.4-150700.3.23.1 * qemu-s390x-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (aarch64 ppc64le x86_64) * qemu-ui-spice-app-debuginfo-9.2.4-150700.3.23.1 * qemu-ui-spice-app-9.2.4-150700.3.23.1 * qemu-ui-gtk-9.2.4-150700.3.23.1 * qemu-ui-gtk-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (aarch64 s390x x86_64) * qemu-hw-display-virtio-gpu-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-pci-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (noarch) * qemu-vgabios-9.2.41.16.3_3_g3d33c746-150700.3.23.1 * qemu-seabios-9.2.41.16.3_3_g3d33c746-150700.3.23.1 * qemu-ipxe-9.2.4-150700.3.23.1 * qemu-skiboot-9.2.4-150700.3.23.1 * qemu-lang-9.2.4-150700.3.23.1 * qemu-SLOF-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (x86_64) * qemu-x86-9.2.4-150700.3.23.1 * qemu-audio-alsa-9.2.4-150700.3.23.1 * qemu-audio-alsa-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-pa-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-pa-9.2.4-150700.3.23.1 * qemu-x86-debuginfo-9.2.4-150700.3.23.1 * qemu-accel-tcg-x86-debuginfo-9.2.4-150700.3.23.1 * qemu-accel-tcg-x86-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (aarch64) * qemu-arm-9.2.4-150700.3.23.1 * qemu-arm-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (ppc64le) * qemu-ppc-debuginfo-9.2.4-150700.3.23.1 * qemu-ppc-9.2.4-150700.3.23.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * qemu-audio-jack-9.2.4-150700.3.23.1 * qemu-vhost-user-gpu-9.2.4-150700.3.23.1 * qemu-vhost-user-gpu-debuginfo-9.2.4-150700.3.23.1 * qemu-s390x-9.2.4-150700.3.23.1 * qemu-linux-user-9.2.4-150700.3.23.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-9.2.4-150700.3.23.1 * qemu-ivshmem-tools-9.2.4-150700.3.23.1 * qemu-linux-user-debugsource-9.2.4-150700.3.23.1 * qemu-block-dmg-debuginfo-9.2.4-150700.3.23.1 * qemu-extra-9.2.4-150700.3.23.1 * qemu-accel-qtest-debuginfo-9.2.4-150700.3.23.1 * qemu-linux-user-debuginfo-9.2.4-150700.3.23.1 * qemu-ivshmem-tools-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-usb-smartcard-9.2.4-150700.3.23.1 * qemu-debugsource-9.2.4-150700.3.23.1 * qemu-hw-s390x-virtio-gpu-ccw-9.2.4-150700.3.23.1 * qemu-arm-debuginfo-9.2.4-150700.3.23.1 * qemu-extra-debuginfo-9.2.4-150700.3.23.1 * qemu-block-dmg-9.2.4-150700.3.23.1 * qemu-s390x-debuginfo-9.2.4-150700.3.23.1 * qemu-ppc-debuginfo-9.2.4-150700.3.23.1 * qemu-accel-qtest-9.2.4-150700.3.23.1 * qemu-arm-9.2.4-150700.3.23.1 * qemu-hw-usb-smartcard-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-jack-debuginfo-9.2.4-150700.3.23.1 * qemu-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-oss-9.2.4-150700.3.23.1 * qemu-ppc-9.2.4-150700.3.23.1 * qemu-audio-oss-debuginfo-9.2.4-150700.3.23.1 * SUSE Package Hub 15 15-SP7 (noarch) * qemu-microvm-9.2.4-150700.3.23.1 * qemu-SLOF-9.2.4-150700.3.23.1 * qemu-skiboot-9.2.4-150700.3.23.1 * SUSE Package Hub 15 15-SP7 (ppc64le) * qemu-hw-display-virtio-gpu-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-pci-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-debuginfo-9.2.4-150700.3.23.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * qemu-pr-helper-9.2.4-150700.3.23.1 * qemu-img-9.2.4-150700.3.23.1 * qemu-img-debuginfo-9.2.4-150700.3.23.1 * qemu-debuginfo-9.2.4-150700.3.23.1 * qemu-debugsource-9.2.4-150700.3.23.1 * qemu-tools-debuginfo-9.2.4-150700.3.23.1 * qemu-tools-9.2.4-150700.3.23.1 * qemu-pr-helper-debuginfo-9.2.4-150700.3.23.1 * Basesystem Module 15-SP7 (x86_64) * qemu-vmsr-helper-9.2.4-150700.3.23.1 * qemu-vmsr-helper-debuginfo-9.2.4-150700.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3886.html * https://www.suse.com/security/cve/CVE-2026-48004.html * https://www.suse.com/security/cve/CVE-2026-48914.html * https://bugzilla.suse.com/show_bug.cgi?id=1268061 * https://bugzilla.suse.com/show_bug.cgi?id=1268794 * https://bugzilla.suse.com/show_bug.cgi?id=1270133 * https://jira.suse.com/browse/PED-14242 * https://jira.suse.com/browse/PED-14279 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:55 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:35:55 -0000 Subject: SUSE-SU-2026:3037-1: important: Security update for yelp Message-ID: <178413335510.13854.6721727078868584201@fcb35a5fe5ab> # Security update for yelp Announcement ID: SUSE-SU-2026:3037-1 Release Date: 2026-07-15T11:45:09Z Rating: important References: * bsc#1269625 Cross-References: * CVE-2026-13601 CVSS scores: * CVE-2026-13601 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-13601 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issue * CVE-2026-13601: overly permissive Content Security Policy allows host file disclosure via Flatpak applications (bsc#1269625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3037=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3037=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3037=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3037=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3037=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3037=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3037=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3037=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3037=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * yelp-debugsource-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * yelp-debugsource-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * yelp-debugsource-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * yelp-lang-41.2-150400.3.6.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * openSUSE Leap 15.4 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * yelp-debugsource-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * yelp-lang-41.2-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13601.html * https://bugzilla.suse.com/show_bug.cgi?id=1269625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:00 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:00 -0000 Subject: SUSE-SU-2026:3036-1: important: Security update for yelp Message-ID: <178413336099.13854.4240369283746369669@fcb35a5fe5ab> # Security update for yelp Announcement ID: SUSE-SU-2026:3036-1 Release Date: 2026-07-15T11:44:33Z Rating: important References: * bsc#1269625 Cross-References: * CVE-2026-13601 CVSS scores: * CVE-2026-13601 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-13601 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issue * CVE-2026-13601: overly permissive Content Security Policy allows host file disclosure via Flatpak applications (bsc#1269625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3036=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3036=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3036=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3036=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * yelp-debugsource-42.2-150600.3.6.1 * libyelp0-42.2-150600.3.6.1 * yelp-devel-42.2-150600.3.6.1 * libyelp0-debuginfo-42.2-150600.3.6.1 * yelp-debuginfo-42.2-150600.3.6.1 * yelp-42.2-150600.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * yelp-lang-42.2-150600.3.6.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * yelp-debugsource-42.2-150600.3.6.1 * libyelp0-42.2-150600.3.6.1 * yelp-devel-42.2-150600.3.6.1 * libyelp0-debuginfo-42.2-150600.3.6.1 * yelp-debuginfo-42.2-150600.3.6.1 * yelp-42.2-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * yelp-lang-42.2-150600.3.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * yelp-debugsource-42.2-150600.3.6.1 * libyelp0-42.2-150600.3.6.1 * yelp-devel-42.2-150600.3.6.1 * libyelp0-debuginfo-42.2-150600.3.6.1 * yelp-debuginfo-42.2-150600.3.6.1 * yelp-42.2-150600.3.6.1 * Desktop Applications Module 15-SP7 (noarch) * yelp-lang-42.2-150600.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * yelp-debugsource-42.2-150600.3.6.1 * libyelp0-42.2-150600.3.6.1 * yelp-devel-42.2-150600.3.6.1 * libyelp0-debuginfo-42.2-150600.3.6.1 * yelp-debuginfo-42.2-150600.3.6.1 * yelp-42.2-150600.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * yelp-lang-42.2-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13601.html * https://bugzilla.suse.com/show_bug.cgi?id=1269625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:06 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:06 -0000 Subject: SUSE-SU-2026:3035-1: important: Security update for yelp Message-ID: <178413336660.13854.15941970603428443900@fcb35a5fe5ab> # Security update for yelp Announcement ID: SUSE-SU-2026:3035-1 Release Date: 2026-07-15T11:44:17Z Rating: important References: * bsc#1269625 Cross-References: * CVE-2026-13601 CVSS scores: * CVE-2026-13601 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-13601 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issue * CVE-2026-13601: overly permissive Content Security Policy allows host file disclosure via Flatpak applications (bsc#1269625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3035=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3035=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * yelp-debuginfo-3.20.1-7.6.1 * yelp-devel-3.20.1-7.6.1 * yelp-debugsource-3.20.1-7.6.1 * yelp-3.20.1-7.6.1 * libyelp0-3.20.1-7.6.1 * libyelp0-debuginfo-3.20.1-7.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * yelp-lang-3.20.1-7.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * yelp-debuginfo-3.20.1-7.6.1 * yelp-debugsource-3.20.1-7.6.1 * yelp-devel-3.20.1-7.6.1 * yelp-3.20.1-7.6.1 * libyelp0-3.20.1-7.6.1 * libyelp0-debuginfo-3.20.1-7.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * yelp-lang-3.20.1-7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13601.html * https://bugzilla.suse.com/show_bug.cgi?id=1269625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:11 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:11 -0000 Subject: SUSE-RU-2026:3034-1: moderate: Recommended update for scap-security-guide Message-ID: <178413337193.13854.4275743555164609731@fcb35a5fe5ab> # Recommended update for scap-security-guide Announcement ID: SUSE-RU-2026:3034-1 Release Date: 2026-07-15T09:56:32Z Rating: moderate References: * jsc#ECO-3319 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Client Tools for SLE Micro 5 An update that contains one feature can now be installed. ## Description: This update for scap-security-guide fixes the following issues: * Add Hummingbird product support * updated to 0.1.81 (jsc#ECO-3319): * Create SLE16 ANSSI profiles * Update SLE15 STIG version to V2R7 * Update SLE12 STIG version to V3R5 * Update SLEM5 STIG version to V1R3 * Add Claude Code skills for content development workflows * Create Claude Skill for creating new products * Various updates for SLE 12/15 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3034=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3034=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3034=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3034=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3034=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3034=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3034=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3034=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3034=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3034=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3034=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3034=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3034=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3034=1 * SUSE Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2026-3034=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3034=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3034=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * Basesystem Module 15-SP7 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Manager Client Tools for SLE Micro 5 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * scap-security-guide-0.1.81-150000.1.109.1 * scap-security-guide-ubuntu-0.1.81-150000.1.109.1 * scap-security-guide-debian-0.1.81-150000.1.109.1 * scap-security-guide-redhat-0.1.81-150000.1.109.1 ## References: * https://jira.suse.com/browse/ECO-3319 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:17 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:17 -0000 Subject: SUSE-SU-2026:3033-1: moderate: Security update for perl-libwww-perl Message-ID: <178413337784.13854.16588747321175736408@fcb35a5fe5ab> # Security update for perl-libwww-perl Announcement ID: SUSE-SU-2026:3033-1 Release Date: 2026-07-15T09:54:09Z Rating: moderate References: * bsc#1265156 Cross-References: * CVE-2026-8368 CVSS scores: * CVE-2026-8368 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-8368 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-libwww-perl fixes the following issue * CVE-2026-8368: LWP: UserAgent: Authorization and Proxy-Authorization headers are leaked on cross-origin redirects (bsc#1265156). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3033=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * perl-libwww-perl-6.05-6.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8368.html * https://bugzilla.suse.com/show_bug.cgi?id=1265156 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:22 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:22 -0000 Subject: SUSE-SU-2026:3032-1: moderate: Security update for glib-networking Message-ID: <178413338299.13854.10351118792613691689@fcb35a5fe5ab> # Security update for glib-networking Announcement ID: SUSE-SU-2026:3032-1 Release Date: 2026-07-15T09:53:56Z Rating: moderate References: * bsc#1267979 Cross-References: * CVE-2026-10028 CVSS scores: * CVE-2026-10028 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-10028 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-10028 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for glib-networking fixes the following issue * CVE-2026-10028: two certificates which are each signed by the other can lead to an infinite loop (bsc#1267979). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3032=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3032=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * glib-networking-debugsource-2.78.0-150600.3.3.1 * glib-networking-2.78.0-150600.3.3.1 * glib-networking-debuginfo-2.78.0-150600.3.3.1 * openSUSE Leap 15.6 (x86_64) * glib-networking-32bit-debuginfo-2.78.0-150600.3.3.1 * glib-networking-32bit-2.78.0-150600.3.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * glib-networking-64bit-debuginfo-2.78.0-150600.3.3.1 * glib-networking-64bit-2.78.0-150600.3.3.1 * openSUSE Leap 15.6 (noarch) * glib-networking-lang-2.78.0-150600.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glib-networking-debugsource-2.78.0-150600.3.3.1 * glib-networking-2.78.0-150600.3.3.1 * glib-networking-debuginfo-2.78.0-150600.3.3.1 * Basesystem Module 15-SP7 (noarch) * glib-networking-lang-2.78.0-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10028.html * https://bugzilla.suse.com/show_bug.cgi?id=1267979 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:28 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:28 -0000 Subject: SUSE-SU-2026:3031-1: moderate: Security update for python-paramiko Message-ID: <178413338854.13854.4235576418712015473@fcb35a5fe5ab> # Security update for python-paramiko Announcement ID: SUSE-SU-2026:3031-1 Release Date: 2026-07-15T09:53:45Z Rating: moderate References: * bsc#1264225 Cross-References: * CVE-2026-44405 CVSS scores: * CVE-2026-44405 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-44405 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44405 ( NVD ): 3.4 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-paramiko fixes the following issues: * CVE-2026-44405: data integrity compromise due to allowed SHA-1 algorithm use (bsc#1264225). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3031=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-paramiko-3.5.1-150700.20.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44405.html * https://bugzilla.suse.com/show_bug.cgi?id=1264225 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:35 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:35 -0000 Subject: SUSE-SU-2026:3030-1: moderate: Security update for glibc Message-ID: <178413339541.13854.10896990736088817305@fcb35a5fe5ab> # Security update for glibc Announcement ID: SUSE-SU-2026:3030-1 Release Date: 2026-07-15T09:53:19Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3030=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3030=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3030=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3030=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3030=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libnsl1-32bit-2.38-150600.14.52.1 * glibc-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-2.38-150600.14.52.1 * libnsl1-32bit-debuginfo-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.52.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * glibc-extra-2.38-150600.14.52.1 * glibc-locale-base-debuginfo-2.38-150600.14.52.1 * glibc-utils-2.38-150600.14.52.1 * libnsl1-2.38-150600.14.52.1 * glibc-extra-debuginfo-2.38-150600.14.52.1 * nscd-2.38-150600.14.52.1 * glibc-devel-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * glibc-2.38-150600.14.52.1 * glibc-devel-static-2.38-150600.14.52.1 * glibc-locale-base-2.38-150600.14.52.1 * glibc-devel-2.38-150600.14.52.1 * glibc-profile-2.38-150600.14.52.1 * glibc-locale-2.38-150600.14.52.1 * libnsl1-debuginfo-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * nscd-debuginfo-2.38-150600.14.52.1 * glibc-utils-src-debugsource-2.38-150600.14.52.1 * glibc-utils-debuginfo-2.38-150600.14.52.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * glibc-lang-2.38-150600.14.52.1 * glibc-i18ndata-2.38-150600.14.52.1 * glibc-info-2.38-150600.14.52.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glibc-devel-2.38-150600.14.52.1 * glibc-profile-2.38-150600.14.52.1 * nscd-2.38-150600.14.52.1 * glibc-extra-2.38-150600.14.52.1 * glibc-locale-2.38-150600.14.52.1 * glibc-devel-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * libnsl1-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-debuginfo-2.38-150600.14.52.1 * glibc-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-2.38-150600.14.52.1 * libnsl1-2.38-150600.14.52.1 * glibc-extra-debuginfo-2.38-150600.14.52.1 * nscd-debuginfo-2.38-150600.14.52.1 * Basesystem Module 15-SP7 (noarch) * glibc-lang-2.38-150600.14.52.1 * glibc-i18ndata-2.38-150600.14.52.1 * glibc-info-2.38-150600.14.52.1 * Basesystem Module 15-SP7 (x86_64) * libnsl1-32bit-2.38-150600.14.52.1 * glibc-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-2.38-150600.14.52.1 * libnsl1-32bit-debuginfo-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.52.1 * openSUSE Leap 15.6 (aarch64 i586 i686 ppc64le s390x x86_64) * glibc-devel-2.38-150600.14.52.1 * glibc-profile-2.38-150600.14.52.1 * glibc-locale-2.38-150600.14.52.1 * glibc-devel-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * libnsl1-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-debuginfo-2.38-150600.14.52.1 * glibc-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * glibc-devel-static-2.38-150600.14.52.1 * glibc-locale-base-2.38-150600.14.52.1 * libnsl1-2.38-150600.14.52.1 * openSUSE Leap 15.6 (x86_64) * libnsl1-32bit-2.38-150600.14.52.1 * glibc-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-2.38-150600.14.52.1 * libnsl1-32bit-debuginfo-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-utils-32bit-2.38-150600.14.52.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.52.1 * glibc-profile-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-2.38-150600.14.52.1 * glibc-devel-static-32bit-2.38-150600.14.52.1 * glibc-utils-32bit-debuginfo-2.38-150600.14.52.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.38-150600.14.52.1 * nscd-2.38-150600.14.52.1 * glibc-extra-2.38-150600.14.52.1 * glibc-utils-debuginfo-2.38-150600.14.52.1 * glibc-utils-2.38-150600.14.52.1 * glibc-extra-debuginfo-2.38-150600.14.52.1 * nscd-debuginfo-2.38-150600.14.52.1 * openSUSE Leap 15.6 (aarch64_ilp32) * glibc-locale-base-64bit-debuginfo-2.38-150600.14.52.1 * glibc-utils-64bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-static-64bit-2.38-150600.14.52.1 * glibc-64bit-debuginfo-2.38-150600.14.52.1 * libnsl1-64bit-2.38-150600.14.52.1 * glibc-devel-64bit-2.38-150600.14.52.1 * glibc-64bit-2.38-150600.14.52.1 * glibc-profile-64bit-2.38-150600.14.52.1 * glibc-utils-64bit-2.38-150600.14.52.1 * glibc-locale-base-64bit-2.38-150600.14.52.1 * glibc-devel-64bit-debuginfo-2.38-150600.14.52.1 * libnsl1-64bit-debuginfo-2.38-150600.14.52.1 * openSUSE Leap 15.6 (noarch) * glibc-lang-2.38-150600.14.52.1 * glibc-i18ndata-2.38-150600.14.52.1 * glibc-info-2.38-150600.14.52.1 * glibc-html-2.38-150600.14.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libnsl1-32bit-2.38-150600.14.52.1 * glibc-32bit-2.38-150600.14.52.1 * libnsl1-32bit-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-32bit-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-2.38-150600.14.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * glibc-extra-2.38-150600.14.52.1 * glibc-locale-base-debuginfo-2.38-150600.14.52.1 * glibc-utils-2.38-150600.14.52.1 * libnsl1-2.38-150600.14.52.1 * glibc-extra-debuginfo-2.38-150600.14.52.1 * nscd-2.38-150600.14.52.1 * glibc-devel-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * glibc-2.38-150600.14.52.1 * glibc-devel-static-2.38-150600.14.52.1 * glibc-locale-base-2.38-150600.14.52.1 * glibc-devel-2.38-150600.14.52.1 * glibc-profile-2.38-150600.14.52.1 * glibc-locale-2.38-150600.14.52.1 * libnsl1-debuginfo-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * nscd-debuginfo-2.38-150600.14.52.1 * glibc-utils-src-debugsource-2.38-150600.14.52.1 * glibc-utils-debuginfo-2.38-150600.14.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * glibc-lang-2.38-150600.14.52.1 * glibc-i18ndata-2.38-150600.14.52.1 * glibc-info-2.38-150600.14.52.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.38-150600.14.52.1 * glibc-utils-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * glibc-utils-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * glibc-devel-static-2.38-150600.14.52.1 * Development Tools Module 15-SP7 (x86_64) * glibc-devel-32bit-debuginfo-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-2.38-150600.14.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:42 -0000 Subject: SUSE-SU-2026:3029-1: moderate: Security update for glibc Message-ID: <178413340280.13854.12871803093121426699@fcb35a5fe5ab> # Security update for glibc Announcement ID: SUSE-SU-2026:3029-1 Release Date: 2026-07-15T09:52:53Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3029=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3029=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3029=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3029=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3029=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3029=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3029=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3029=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3029=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3029=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3029=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3029=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3029=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3029=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * openSUSE Leap 15.3 (aarch64 i586 i686 ppc64le s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * openSUSE Leap 15.3 (x86_64) * glibc-profile-32bit-2.31-150300.104.1 * glibc-utils-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-utils-32bit-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-devel-static-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * openSUSE Leap 15.3 (noarch) * glibc-html-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * openSUSE Leap 15.3 (aarch64_ilp32) * glibc-locale-base-64bit-debuginfo-2.31-150300.104.1 * glibc-64bit-2.31-150300.104.1 * glibc-profile-64bit-2.31-150300.104.1 * glibc-devel-64bit-2.31-150300.104.1 * glibc-64bit-debuginfo-2.31-150300.104.1 * glibc-devel-static-64bit-2.31-150300.104.1 * glibc-devel-64bit-debuginfo-2.31-150300.104.1 * glibc-utils-64bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-64bit-2.31-150300.104.1 * glibc-utils-64bit-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * glibc-i18ndata-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * glibc-i18ndata-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * glibc-i18ndata-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * glibc-i18ndata-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:51 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:51 -0000 Subject: SUSE-SU-2026:3028-1: important: Security update for dnsmasq Message-ID: <178413341104.13854.2002906999327646700@fcb35a5fe5ab> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:3028-1 Release Date: 2026-07-15T09:51:44Z Rating: important References: * bsc#1268764 * bsc#1268882 Cross-References: * CVE-2026-12725 * CVE-2026-12969 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12969 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). * CVE-2026-12969: out-of-bounds read in `find_soa()` due to missing extrabytes validation (bsc#1268882). Changes for dnsmasq: * Update to 2.93: * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3028=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3028=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3028=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3028=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3028=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3028=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3028=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3028=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3028=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3028=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3028=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3028=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3028=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3028=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-utils-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * dnsmasq-utils-2.93-150400.16.17.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-12969.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 * https://bugzilla.suse.com/show_bug.cgi?id=1268882 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:57 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:36:57 -0000 Subject: SUSE-SU-2026:3027-1: important: Security update for tiff Message-ID: <178413341780.13854.14425737637565074989@fcb35a5fe5ab> # Security update for tiff Announcement ID: SUSE-SU-2026:3027-1 Release Date: 2026-07-15T09:49:58Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3027=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3027=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * tiff-debuginfo-4.0.9-44.115.1 * libtiff-devel-4.0.9-44.115.1 * tiff-debugsource-4.0.9-44.115.1 * libtiff5-debuginfo-4.0.9-44.115.1 * libtiff5-4.0.9-44.115.1 * tiff-4.0.9-44.115.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libtiff5-32bit-4.0.9-44.115.1 * libtiff5-debuginfo-32bit-4.0.9-44.115.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * tiff-debuginfo-4.0.9-44.115.1 * libtiff-devel-4.0.9-44.115.1 * libtiff5-debuginfo-32bit-4.0.9-44.115.1 * libtiff5-32bit-4.0.9-44.115.1 * tiff-debugsource-4.0.9-44.115.1 * libtiff5-debuginfo-4.0.9-44.115.1 * libtiff5-4.0.9-44.115.1 * tiff-4.0.9-44.115.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:37:14 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:37:14 -0000 Subject: SUSE-SU-2026:3026-1: important: Security update for python-cryptography Message-ID: <178413343433.13854.10549040309951830510@fcb35a5fe5ab> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:3026-1 Release Date: 2026-07-15T09:49:44Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270620). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270706). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270801). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3026=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3026=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3026=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3026=1 ## Package List: * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150600.23.9.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150600.23.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-cryptography-41.0.3-150600.23.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150600.23.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:37:21 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:37:21 -0000 Subject: SUSE-SU-2026:3025-1: important: Security update for sssd Message-ID: <178413344115.13854.16175143359769712524@fcb35a5fe5ab> # Security update for sssd Announcement ID: SUSE-SU-2026:3025-1 Release Date: 2026-07-15T09:49:27Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3025=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3025=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3025=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * sssd-dbus-2.10.2-150600.3.53.1 * libsss_simpleifp0-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-debuginfo-2.10.2-150600.3.53.1 * python3-sss_nss_idmap-2.10.2-150600.3.53.1 * sssd-krb5-2.10.2-150600.3.53.1 * libsss_certmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_simpleifp-devel-2.10.2-150600.3.53.1 * libnfsidmap-sss-debuginfo-2.10.2-150600.3.53.1 * python3-sss_nss_idmap-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-2.10.2-150600.3.53.1 * sssd-krb5-common-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-debuginfo-2.10.2-150600.3.53.1 * sssd-debugsource-2.10.2-150600.3.53.1 * sssd-proxy-2.10.2-150600.3.53.1 * sssd-ad-2.10.2-150600.3.53.1 * python3-ipa_hbac-debuginfo-2.10.2-150600.3.53.1 * sssd-ldap-debuginfo-2.10.2-150600.3.53.1 * libsss_idmap0-2.10.2-150600.3.53.1 * python3-ipa_hbac-2.10.2-150600.3.53.1 * libsss_nss_idmap0-2.10.2-150600.3.53.1 * sssd-ad-debuginfo-2.10.2-150600.3.53.1 * sssd-winbind-idmap-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-debuginfo-2.10.2-150600.3.53.1 * libipa_hbac0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap-devel-2.10.2-150600.3.53.1 * sssd-winbind-idmap-2.10.2-150600.3.53.1 * sssd-proxy-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-2.10.2-150600.3.53.1 * sssd-2.10.2-150600.3.53.1 * libsss_idmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-debuginfo-2.10.2-150600.3.53.1 * libnfsidmap-sss-2.10.2-150600.3.53.1 * sssd-ldap-2.10.2-150600.3.53.1 * sssd-kcm-debuginfo-2.10.2-150600.3.53.1 * sssd-kcm-2.10.2-150600.3.53.1 * libsss_simpleifp0-2.10.2-150600.3.53.1 * sssd-krb5-common-2.10.2-150600.3.53.1 * libipa_hbac0-2.10.2-150600.3.53.1 * python3-sss-murmur-debuginfo-2.10.2-150600.3.53.1 * libsss_certmap0-2.10.2-150600.3.53.1 * libsss_certmap-devel-2.10.2-150600.3.53.1 * sssd-dbus-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-2.10.2-150600.3.53.1 * python3-sss-murmur-2.10.2-150600.3.53.1 * libipa_hbac-devel-2.10.2-150600.3.53.1 * libsss_idmap-devel-2.10.2-150600.3.53.1 * openSUSE Leap 15.6 (x86_64) * sssd-32bit-2.10.2-150600.3.53.1 * sssd-32bit-debuginfo-2.10.2-150600.3.53.1 * openSUSE Leap 15.6 (aarch64_ilp32) * sssd-64bit-2.10.2-150600.3.53.1 * sssd-64bit-debuginfo-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * sssd-dbus-2.10.2-150600.3.53.1 * libsss_certmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-debuginfo-2.10.2-150600.3.53.1 * libsss_simpleifp0-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-2.10.2-150600.3.53.1 * libsss_simpleifp-devel-2.10.2-150600.3.53.1 * python3-sssd-config-2.10.2-150600.3.53.1 * sssd-krb5-common-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-debuginfo-2.10.2-150600.3.53.1 * sssd-debugsource-2.10.2-150600.3.53.1 * sssd-proxy-2.10.2-150600.3.53.1 * sssd-ad-2.10.2-150600.3.53.1 * sssd-ldap-debuginfo-2.10.2-150600.3.53.1 * libsss_idmap0-2.10.2-150600.3.53.1 * libsss_nss_idmap0-2.10.2-150600.3.53.1 * sssd-ad-debuginfo-2.10.2-150600.3.53.1 * sssd-winbind-idmap-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-debuginfo-2.10.2-150600.3.53.1 * libipa_hbac0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap-devel-2.10.2-150600.3.53.1 * sssd-winbind-idmap-2.10.2-150600.3.53.1 * sssd-proxy-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-2.10.2-150600.3.53.1 * sssd-2.10.2-150600.3.53.1 * libsss_idmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-debuginfo-2.10.2-150600.3.53.1 * sssd-kcm-debuginfo-2.10.2-150600.3.53.1 * sssd-ldap-2.10.2-150600.3.53.1 * libipa_hbac0-2.10.2-150600.3.53.1 * libsss_simpleifp0-2.10.2-150600.3.53.1 * sssd-kcm-2.10.2-150600.3.53.1 * sssd-krb5-common-2.10.2-150600.3.53.1 * libsss_certmap0-2.10.2-150600.3.53.1 * libsss_certmap-devel-2.10.2-150600.3.53.1 * sssd-dbus-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-2.10.2-150600.3.53.1 * libipa_hbac-devel-2.10.2-150600.3.53.1 * libsss_idmap-devel-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * sssd-32bit-2.10.2-150600.3.53.1 * sssd-32bit-debuginfo-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * sssd-dbus-2.10.2-150600.3.53.1 * libsss_certmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-debuginfo-2.10.2-150600.3.53.1 * libsss_simpleifp0-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-2.10.2-150600.3.53.1 * libsss_simpleifp-devel-2.10.2-150600.3.53.1 * python3-sssd-config-2.10.2-150600.3.53.1 * sssd-krb5-common-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-debuginfo-2.10.2-150600.3.53.1 * sssd-debugsource-2.10.2-150600.3.53.1 * sssd-proxy-2.10.2-150600.3.53.1 * sssd-ad-2.10.2-150600.3.53.1 * sssd-ldap-debuginfo-2.10.2-150600.3.53.1 * libsss_idmap0-2.10.2-150600.3.53.1 * libsss_nss_idmap0-2.10.2-150600.3.53.1 * sssd-ad-debuginfo-2.10.2-150600.3.53.1 * sssd-winbind-idmap-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-debuginfo-2.10.2-150600.3.53.1 * libipa_hbac0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap-devel-2.10.2-150600.3.53.1 * sssd-winbind-idmap-2.10.2-150600.3.53.1 * sssd-proxy-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-2.10.2-150600.3.53.1 * sssd-2.10.2-150600.3.53.1 * libsss_idmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-common-2.10.2-150600.3.53.1 * sssd-kcm-debuginfo-2.10.2-150600.3.53.1 * sssd-ldap-2.10.2-150600.3.53.1 * libipa_hbac0-2.10.2-150600.3.53.1 * sssd-debuginfo-2.10.2-150600.3.53.1 * sssd-kcm-2.10.2-150600.3.53.1 * libsss_simpleifp0-2.10.2-150600.3.53.1 * libsss_certmap0-2.10.2-150600.3.53.1 * libsss_certmap-devel-2.10.2-150600.3.53.1 * sssd-dbus-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-2.10.2-150600.3.53.1 * libipa_hbac-devel-2.10.2-150600.3.53.1 * libsss_idmap-devel-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * sssd-32bit-2.10.2-150600.3.53.1 * sssd-32bit-debuginfo-2.10.2-150600.3.53.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:38:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:38:02 -0000 Subject: SUSE-SU-2026:3024-1: important: Security update for ImageMagick Message-ID: <178413348208.13854.16571465399902499434@fcb35a5fe5ab> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3024-1 Release Date: 2026-07-15T09:49:13Z Rating: important References: * bsc#1265048 * bsc#1268092 * bsc#1268094 * bsc#1268096 * bsc#1268101 * bsc#1268102 * bsc#1268105 * bsc#1268108 * bsc#1268110 * bsc#1268111 * bsc#1268112 * bsc#1268113 * bsc#1268114 * bsc#1268117 * bsc#1268120 * bsc#1268124 * bsc#1268125 * bsc#1268126 * bsc#1268640 * bsc#1268645 * bsc#1268878 * bsc#1268879 * bsc#1269064 * bsc#1270001 * bsc#1270002 * bsc#1270004 * bsc#1270073 * bsc#1270074 Cross-References: * CVE-2026-42050 * CVE-2026-42326 * CVE-2026-45031 * CVE-2026-45358 * CVE-2026-45624 * CVE-2026-45664 * CVE-2026-46520 * CVE-2026-46521 * CVE-2026-46522 * CVE-2026-46523 * CVE-2026-46692 * CVE-2026-46693 * CVE-2026-47165 * CVE-2026-47166 * CVE-2026-48994 * CVE-2026-49218 * CVE-2026-53460 * CVE-2026-53463 * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56365 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56371 * CVE-2026-56379 CVSS scores: * CVE-2026-42050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42326 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42326 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-42326 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45031 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45358 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45358 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-45358 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45624 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45664 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45664 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46520 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46521 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46692 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46693 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46693 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46693 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-47165 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-47166 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-48994 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48994 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-49218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53460 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53463 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53463 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56365 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56365 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 27 vulnerabilities and has one security fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-42050: stack buffer overflow in XTileImage (bsc#1265048). * CVE-2026-42326: information disclosure via malicious IPTC input file (bsc#1268092). * CVE-2026-45031: denial of Service due to resource policy bypass in PSD decoder (bsc#1268094). * CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102). * CVE-2026-45624: data exposure due to image processing vulnerability (bsc#1268096). * CVE-2026-45664: denial of Service due to excessive resource use in MNG coder (bsc#1268101). * CVE-2026-46520: denial of Service via out-of-bounds write when processing multiple images (bsc#1268112). * CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124). * CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126). * CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125). * CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). * CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute- cache service (bsc#1268117). * CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114). * CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). * CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111). * CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110). * CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108). * CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105). * CVE-2026-53466: heap Buffer Over-Read in XCF decoder due to integer conversion overflow (bsc#1270073). * CVE-2026-53467: information Disclosure in MNG decoder because allocated memory is left unchanged (bsc#1270074). * CVE-2026-56361: off-by-one origin validation in allows out-of-bounds read in morphology processing (bsc#1270001). * CVE-2026-56363: division by Zero in binomial kernel (bsc#1270002). * CVE-2026-56365: memory leak in PNG encoder when writing a MNG image (bsc#1270004). * CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out-of-bounds read (bsc#1268645). * CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3024=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3024=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.259.1 * libMagickCore-6_Q16-1-6.8.8.1-71.259.1 * libMagick++-devel-6.8.8.1-71.259.1 * ImageMagick-devel-6.8.8.1-71.259.1 * ImageMagick-config-6-upstream-6.8.8.1-71.259.1 * ImageMagick-debugsource-6.8.8.1-71.259.1 * libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.259.1 * ImageMagick-debuginfo-6.8.8.1-71.259.1 * libMagickWand-6_Q16-1-6.8.8.1-71.259.1 * ImageMagick-config-6-SUSE-6.8.8.1-71.259.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.259.1 * ImageMagick-devel-6.8.8.1-71.259.1 * libMagick++-devel-6.8.8.1-71.259.1 * libMagickCore-6_Q16-1-6.8.8.1-71.259.1 * ImageMagick-config-6-upstream-6.8.8.1-71.259.1 * ImageMagick-debugsource-6.8.8.1-71.259.1 * libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.259.1 * ImageMagick-debuginfo-6.8.8.1-71.259.1 * libMagickWand-6_Q16-1-6.8.8.1-71.259.1 * ImageMagick-config-6-SUSE-6.8.8.1-71.259.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42050.html * https://www.suse.com/security/cve/CVE-2026-42326.html * https://www.suse.com/security/cve/CVE-2026-45031.html * https://www.suse.com/security/cve/CVE-2026-45358.html * https://www.suse.com/security/cve/CVE-2026-45624.html * https://www.suse.com/security/cve/CVE-2026-45664.html * https://www.suse.com/security/cve/CVE-2026-46520.html * https://www.suse.com/security/cve/CVE-2026-46521.html * https://www.suse.com/security/cve/CVE-2026-46522.html * https://www.suse.com/security/cve/CVE-2026-46523.html * https://www.suse.com/security/cve/CVE-2026-46692.html * https://www.suse.com/security/cve/CVE-2026-46693.html * https://www.suse.com/security/cve/CVE-2026-47165.html * https://www.suse.com/security/cve/CVE-2026-47166.html * https://www.suse.com/security/cve/CVE-2026-48994.html * https://www.suse.com/security/cve/CVE-2026-49218.html * https://www.suse.com/security/cve/CVE-2026-53460.html * https://www.suse.com/security/cve/CVE-2026-53463.html * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56365.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1265048 * https://bugzilla.suse.com/show_bug.cgi?id=1268092 * https://bugzilla.suse.com/show_bug.cgi?id=1268094 * https://bugzilla.suse.com/show_bug.cgi?id=1268096 * https://bugzilla.suse.com/show_bug.cgi?id=1268101 * https://bugzilla.suse.com/show_bug.cgi?id=1268102 * https://bugzilla.suse.com/show_bug.cgi?id=1268105 * https://bugzilla.suse.com/show_bug.cgi?id=1268108 * https://bugzilla.suse.com/show_bug.cgi?id=1268110 * https://bugzilla.suse.com/show_bug.cgi?id=1268111 * https://bugzilla.suse.com/show_bug.cgi?id=1268112 * https://bugzilla.suse.com/show_bug.cgi?id=1268113 * https://bugzilla.suse.com/show_bug.cgi?id=1268114 * https://bugzilla.suse.com/show_bug.cgi?id=1268117 * https://bugzilla.suse.com/show_bug.cgi?id=1268120 * https://bugzilla.suse.com/show_bug.cgi?id=1268124 * https://bugzilla.suse.com/show_bug.cgi?id=1268125 * https://bugzilla.suse.com/show_bug.cgi?id=1268126 * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270004 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:38:59 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:38:59 -0000 Subject: SUSE-SU-2026:3023-1: important: Security update for ImageMagick Message-ID: <178413353938.13854.9903760572421988413@fcb35a5fe5ab> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3023-1 Release Date: 2026-07-15T09:48:59Z Rating: important References: * bsc#1265048 * bsc#1268092 * bsc#1268094 * bsc#1268095 * bsc#1268096 * bsc#1268101 * bsc#1268102 * bsc#1268103 * bsc#1268105 * bsc#1268107 * bsc#1268108 * bsc#1268110 * bsc#1268111 * bsc#1268112 * bsc#1268113 * bsc#1268114 * bsc#1268117 * bsc#1268120 * bsc#1268121 * bsc#1268122 * bsc#1268123 * bsc#1268124 * bsc#1268125 * bsc#1268126 * bsc#1268640 * bsc#1268645 * bsc#1268878 * bsc#1268879 * bsc#1268880 * bsc#1269063 * bsc#1269064 * bsc#1270001 * bsc#1270002 * bsc#1270003 * bsc#1270004 * bsc#1270073 * bsc#1270074 * bsc#1270077 * bsc#1270079 * bsc#1270080 * bsc#1271099 Cross-References: * CVE-2026-40169 * CVE-2026-42050 * CVE-2026-42326 * CVE-2026-45031 * CVE-2026-45358 * CVE-2026-45359 * CVE-2026-45624 * CVE-2026-45664 * CVE-2026-46520 * CVE-2026-46521 * CVE-2026-46522 * CVE-2026-46523 * CVE-2026-46557 * CVE-2026-46559 * CVE-2026-46692 * CVE-2026-46693 * CVE-2026-47165 * CVE-2026-47166 * CVE-2026-48734 * CVE-2026-48994 * CVE-2026-49218 * CVE-2026-53460 * CVE-2026-53461 * CVE-2026-53463 * CVE-2026-53464 * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-55594 * CVE-2026-55595 * CVE-2026-55597 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56364 * CVE-2026-56365 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56370 * CVE-2026-56371 * CVE-2026-56374 * CVE-2026-56376 * CVE-2026-56379 CVSS scores: * CVE-2026-40169 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40169 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42326 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42326 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-42326 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45031 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45031 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45358 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45358 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-45358 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45359 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45359 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45624 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45624 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45664 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45664 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45664 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46520 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46520 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46521 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46557 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46559 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46559 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-46559 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46692 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46692 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46693 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46693 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46693 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-47165 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-47166 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-48734 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48734 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48994 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-49218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53460 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53461 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53463 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53463 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-53464 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53464 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53464 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55595 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56364 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56365 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56370 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56370 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56370 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56370 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56374 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56374 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56374 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56376 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56376 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56376 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 41 vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-42050: stack buffer overflow in XTileImage (bsc#1265048). * CVE-2026-42326: information disclosure via malicious IPTC input file (bsc#1268092). * CVE-2026-45031: denial of Service due to resource policy bypass in PSD decoder (bsc#1268094). * CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102). * CVE-2026-45359: information Disclosure via Invalid Connected-Components Value (bsc#1268095). * CVE-2026-45624: data exposure due to image processing vulnerability (bsc#1268096). * CVE-2026-45664: denial of Service due to excessive resource use in MNG coder (bsc#1268101). * CVE-2026-46520: denial of Service via out-of-bounds write when processing multiple images (bsc#1268112). * CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124). * CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126). * CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125). * CVE-2026-46557: stack overflow can occur in the fx operation by passing a crafted argument due to a missing depth check (bsc#1268123). * CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 (bsc#1268121). * CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). * CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute- cache service (bsc#1268117). * CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114). * CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). * CVE-2026-48734: Stack Overflow in MVG decoder (bsc#1268122). * CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111). * CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110). * CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108). * CVE-2026-53461: out of bounds heap write due to an incorrect loop in the ICON decoder (bsc#1268107). * CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105). * CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser (bsc#1268103). * CVE-2026-53466: heap Buffer Over-Read in XCF decoder due to integer conversion overflow (bsc#1270073). * CVE-2026-53467: information Disclosure in MNG decoder because allocated memory is left unchanged (bsc#1270074). * CVE-2026-55594: stack Overflow in MVG decoder due to missing depth check (bsc#1270077). * CVE-2026-55595: infinite Loop in connected-components when providing invalid arguments (bsc#1270079). * CVE-2026-55597: heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments (bsc#1270080). * CVE-2026-56361: off-by-one origin validation in allows out-of-bounds read in morphology processing (bsc#1270001). * CVE-2026-56363: division by Zero in binomial kernel (bsc#1270002). * CVE-2026-56364: memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML (bsc#1270003). * CVE-2026-56365: memory leak in PNG encoder when writing a MNG image (bsc#1270004). * CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out-of-bounds read (bsc#1268645). * CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing connected-components:* artifacts with invalid indices (bsc#1269063). * CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56374: heap-buffer-overflow in FTXT encoder (bsc#1271099). * CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3023=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3023=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3023=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * perl-PerlMagick-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.73.1 * libMagick++-devel-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-7.1.1.21-150600.3.73.1 * ImageMagick-debugsource-7.1.1.21-150600.3.73.1 * perl-PerlMagick-debuginfo-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.73.1 * ImageMagick-devel-7.1.1.21-150600.3.73.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1 * perl-PerlMagick-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-debugsource-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1 * ImageMagick-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-debuginfo-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-devel-7.1.1.21-150600.3.73.1 * perl-PerlMagick-7.1.1.21-150600.3.73.1 * libMagick++-devel-7.1.1.21-150600.3.73.1 * ImageMagick-extra-7.1.1.21-150600.3.73.1 * ImageMagick-extra-debuginfo-7.1.1.21-150600.3.73.1 * openSUSE Leap 15.6 (x86_64) * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-32bit-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-32bit-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-32bit-7.1.1.21-150600.3.73.1 * ImageMagick-devel-32bit-7.1.1.21-150600.3.73.1 * libMagick++-devel-32bit-7.1.1.21-150600.3.73.1 * openSUSE Leap 15.6 (noarch) * ImageMagick-doc-7.1.1.21-150600.3.73.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libMagickCore-7_Q16HDRI10-64bit-7.1.1.21-150600.3.73.1 * ImageMagick-devel-64bit-7.1.1.21-150600.3.73.1 * libMagick++-devel-64bit-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-64bit-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-64bit-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.73.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.73.1 * perl-PerlMagick-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.73.1 * libMagick++-devel-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1 * ImageMagick-7.1.1.21-150600.3.73.1 * ImageMagick-debugsource-7.1.1.21-150600.3.73.1 * perl-PerlMagick-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-devel-7.1.1.21-150600.3.73.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40169.html * https://www.suse.com/security/cve/CVE-2026-42050.html * https://www.suse.com/security/cve/CVE-2026-42326.html * https://www.suse.com/security/cve/CVE-2026-45031.html * https://www.suse.com/security/cve/CVE-2026-45358.html * https://www.suse.com/security/cve/CVE-2026-45359.html * https://www.suse.com/security/cve/CVE-2026-45624.html * https://www.suse.com/security/cve/CVE-2026-45664.html * https://www.suse.com/security/cve/CVE-2026-46520.html * https://www.suse.com/security/cve/CVE-2026-46521.html * https://www.suse.com/security/cve/CVE-2026-46522.html * https://www.suse.com/security/cve/CVE-2026-46523.html * https://www.suse.com/security/cve/CVE-2026-46557.html * https://www.suse.com/security/cve/CVE-2026-46559.html * https://www.suse.com/security/cve/CVE-2026-46692.html * https://www.suse.com/security/cve/CVE-2026-46693.html * https://www.suse.com/security/cve/CVE-2026-47165.html * https://www.suse.com/security/cve/CVE-2026-47166.html * https://www.suse.com/security/cve/CVE-2026-48734.html * https://www.suse.com/security/cve/CVE-2026-48994.html * https://www.suse.com/security/cve/CVE-2026-49218.html * https://www.suse.com/security/cve/CVE-2026-53460.html * https://www.suse.com/security/cve/CVE-2026-53461.html * https://www.suse.com/security/cve/CVE-2026-53463.html * https://www.suse.com/security/cve/CVE-2026-53464.html * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-55594.html * https://www.suse.com/security/cve/CVE-2026-55595.html * https://www.suse.com/security/cve/CVE-2026-55597.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56364.html * https://www.suse.com/security/cve/CVE-2026-56365.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56370.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56374.html * https://www.suse.com/security/cve/CVE-2026-56376.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1265048 * https://bugzilla.suse.com/show_bug.cgi?id=1268092 * https://bugzilla.suse.com/show_bug.cgi?id=1268094 * https://bugzilla.suse.com/show_bug.cgi?id=1268095 * https://bugzilla.suse.com/show_bug.cgi?id=1268096 * https://bugzilla.suse.com/show_bug.cgi?id=1268101 * https://bugzilla.suse.com/show_bug.cgi?id=1268102 * https://bugzilla.suse.com/show_bug.cgi?id=1268103 * https://bugzilla.suse.com/show_bug.cgi?id=1268105 * https://bugzilla.suse.com/show_bug.cgi?id=1268107 * https://bugzilla.suse.com/show_bug.cgi?id=1268108 * https://bugzilla.suse.com/show_bug.cgi?id=1268110 * https://bugzilla.suse.com/show_bug.cgi?id=1268111 * https://bugzilla.suse.com/show_bug.cgi?id=1268112 * https://bugzilla.suse.com/show_bug.cgi?id=1268113 * https://bugzilla.suse.com/show_bug.cgi?id=1268114 * https://bugzilla.suse.com/show_bug.cgi?id=1268117 * https://bugzilla.suse.com/show_bug.cgi?id=1268120 * https://bugzilla.suse.com/show_bug.cgi?id=1268121 * https://bugzilla.suse.com/show_bug.cgi?id=1268122 * https://bugzilla.suse.com/show_bug.cgi?id=1268123 * https://bugzilla.suse.com/show_bug.cgi?id=1268124 * https://bugzilla.suse.com/show_bug.cgi?id=1268125 * https://bugzilla.suse.com/show_bug.cgi?id=1268126 * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1268880 * https://bugzilla.suse.com/show_bug.cgi?id=1269063 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270003 * https://bugzilla.suse.com/show_bug.cgi?id=1270004 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 * https://bugzilla.suse.com/show_bug.cgi?id=1270077 * https://bugzilla.suse.com/show_bug.cgi?id=1270079 * https://bugzilla.suse.com/show_bug.cgi?id=1270080 * https://bugzilla.suse.com/show_bug.cgi?id=1271099 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:39:22 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:39:22 -0000 Subject: SUSE-SU-2026:3022-1: important: Security update for sccache Message-ID: <178413356237.13854.8955854586866263234@fcb35a5fe5ab> # Security update for sccache Announcement ID: SUSE-SU-2026:3022-1 Release Date: 2026-07-15T09:48:48Z Rating: important References: * bsc#1210346 * bsc#1223238 * bsc#1229955 * bsc#1242611 * bsc#1243868 * bsc#1257923 * bsc#1270206 * bsc#1270512 * bsc#1270559 * bsc#1270693 * bsc#1270736 * bsc#1270869 * bsc#1270938 * bsc#1270948 Cross-References: * CVE-2023-26964 * CVE-2024-12224 * CVE-2024-32650 * CVE-2024-43806 * CVE-2025-3416 * CVE-2026-25727 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2023-26964 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-26964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-26964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-32650 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-43806 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 14 vulnerabilities can now be installed. ## Description: This update for sccache fixes the following issues: Update to version 0.15.0~17. * CVE-2023-26964: hyper,h2: high resource consumption due to stream stacking when H2 component processes `HTTP2 RST_STREAM` frames (bsc#1210346). * CVE-2024-32650: rust-rustls: infinite loop in `rustls::conn::ConnectionCommon:complete_io()` when processing client input network input (bsc#1223238). * CVE-2025-3416: openssl: use-after-free in `Md::fetch` and `Cipher::fetch` (bsc#1242611). * CVE-2026-25727: time: stack exhaustion in the RFC 2822 date parser when processing certain user provided input (bsc#1257923). * CVE-2026-41676: openssl: short buffer overflow via `Deriver:derive` and `PkeyCtxRef:derive` when using OpenSSL 1.1.1 (bsc#1270206). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270559). * CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270693). * CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()` writing past caller buffer with no length check (bsc#1270736). * CVE-2026-41898: openssl: information leak to network peers due to unchecked callback-returned length in PSK and cookie generate trampolines (bsc#1270869). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270512). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270938). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270948). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3022=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3022=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3022=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3022=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * sccache-debuginfo-0.16.0~0-150600.10.11.1 * sccache-0.16.0~0-150600.10.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * sccache-debuginfo-0.16.0~0-150600.10.11.1 * sccache-0.16.0~0-150600.10.11.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * sccache-debuginfo-0.16.0~0-150600.10.11.1 * sccache-debugsource-0.16.0~0-150600.10.11.1 * sccache-0.16.0~0-150600.10.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * sccache-debuginfo-0.16.0~0-150600.10.11.1 * sccache-0.16.0~0-150600.10.11.1 ## References: * https://www.suse.com/security/cve/CVE-2023-26964.html * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2024-32650.html * https://www.suse.com/security/cve/CVE-2024-43806.html * https://www.suse.com/security/cve/CVE-2025-3416.html * https://www.suse.com/security/cve/CVE-2026-25727.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1210346 * https://bugzilla.suse.com/show_bug.cgi?id=1223238 * https://bugzilla.suse.com/show_bug.cgi?id=1229955 * https://bugzilla.suse.com/show_bug.cgi?id=1242611 * https://bugzilla.suse.com/show_bug.cgi?id=1243868 * https://bugzilla.suse.com/show_bug.cgi?id=1257923 * https://bugzilla.suse.com/show_bug.cgi?id=1270206 * https://bugzilla.suse.com/show_bug.cgi?id=1270512 * https://bugzilla.suse.com/show_bug.cgi?id=1270559 * https://bugzilla.suse.com/show_bug.cgi?id=1270693 * https://bugzilla.suse.com/show_bug.cgi?id=1270736 * https://bugzilla.suse.com/show_bug.cgi?id=1270869 * https://bugzilla.suse.com/show_bug.cgi?id=1270938 * https://bugzilla.suse.com/show_bug.cgi?id=1270948 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:39:30 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:39:30 -0000 Subject: SUSE-SU-2026:3021-1: important: Security update for uriparser Message-ID: <178413357075.13854.1215589732529195323@fcb35a5fe5ab> # Security update for uriparser Announcement ID: SUSE-SU-2026:3021-1 Release Date: 2026-07-15T09:48:32Z Rating: important References: * bsc#1262999 * bsc#1264578 * bsc#1264579 Cross-References: * CVE-2026-42371 * CVE-2026-44927 * CVE-2026-44928 CVSS scores: * CVE-2026-42371 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42371 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42371 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42371 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44927 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-44927 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-44927 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44927 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-44928 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for uriparser fixes the following issues * CVE-2026-42371: numeric truncation in text range comparison when an application accepts URIs with a length in gigabytes (bsc#1262999). * CVE-2026-44927: truncation of `ptrdiff_t` to `int` in various places (bsc#1264578). * CVE-2026-44928: function family `EqualsUri` can misclassify two unequal URIs as equal (bsc#1264579). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3021=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * liburiparser1-0.8.5-150000.3.14.1 * uriparser-0.8.5-150000.3.14.1 * uriparser-devel-0.8.5-150000.3.14.1 * liburiparser1-debuginfo-0.8.5-150000.3.14.1 * uriparser-debugsource-0.8.5-150000.3.14.1 * uriparser-debuginfo-0.8.5-150000.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42371.html * https://www.suse.com/security/cve/CVE-2026-44927.html * https://www.suse.com/security/cve/CVE-2026-44928.html * https://bugzilla.suse.com/show_bug.cgi?id=1262999 * https://bugzilla.suse.com/show_bug.cgi?id=1264578 * https://bugzilla.suse.com/show_bug.cgi?id=1264579 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:39:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:39:36 -0000 Subject: SUSE-RU-2026:3020-1: moderate: Recommended update for go Message-ID: <178413357688.13854.6890949548103894910@fcb35a5fe5ab> # Recommended update for go Announcement ID: SUSE-RU-2026:3020-1 Release Date: 2026-07-15T09:35:59Z Rating: moderate References: * bsc#1255111 Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for go fixes the following issues: * Update default go to current stable go1.26 (bsc#1255111) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3020=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3020=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3020=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3020=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3020=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3020=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3020=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3020=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3020=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3020=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3020=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * go-race-1.26-150000.3.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go-1.26-150000.3.49.1 * go-doc-1.26-150000.3.49.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go-1.26-150000.3.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go-1.26-150000.3.49.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * go-race-1.26-150000.3.49.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go-1.26-150000.3.49.1 * go-doc-1.26-150000.3.49.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * go-race-1.26-150000.3.49.1 * go-1.26-150000.3.49.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * go-race-1.26-150000.3.49.1 * go-1.26-150000.3.49.1 * go-doc-1.26-150000.3.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go-race-1.26-150000.3.49.1 * go-1.26-150000.3.49.1 * go-doc-1.26-150000.3.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go-1.26-150000.3.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go-1.26-150000.3.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * go-race-1.26-150000.3.49.1 * go-1.26-150000.3.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go-race-1.26-150000.3.49.1 * go-1.26-150000.3.49.1 * go-doc-1.26-150000.3.49.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1255111 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:39:40 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:39:40 -0000 Subject: SUSE-RU-2026:3019-1: moderate: Recommended update for hplip Message-ID: <178413358099.13854.10960926960323954581@fcb35a5fe5ab> # Recommended update for hplip Announcement ID: SUSE-RU-2026:3019-1 Release Date: 2026-07-15T09:19:16Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that can now be installed. ## Description: This update for hplip fixes the following issues: * hp-plugin: fix plugin installation from local file ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3019=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3019=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * hplip-hpijs-debuginfo-3.26.4-3.11.1 * hplip-debuginfo-3.26.4-3.11.1 * hplip-hpijs-3.26.4-3.11.1 * hplip-debugsource-3.26.4-3.11.1 * hplip-udev-rules-3.26.4-3.11.1 * hplip-devel-3.26.4-3.11.1 * hplip-3.26.4-3.11.1 * hplip-sane-3.26.4-3.11.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * hplip-sane-debuginfo-3.26.4-3.11.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * hplip-hpijs-3.26.4-3.11.1 * hplip-debuginfo-3.26.4-3.11.1 * hplip-hpijs-debuginfo-3.26.4-3.11.1 * hplip-debugsource-3.26.4-3.11.1 * hplip-udev-rules-3.26.4-3.11.1 * hplip-devel-3.26.4-3.11.1 * hplip-3.26.4-3.11.1 * hplip-sane-debuginfo-3.26.4-3.11.1 * hplip-sane-3.26.4-3.11.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:39:44 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:39:44 -0000 Subject: SUSE-RU-2026:3018-1: moderate: Recommended update for hplip Message-ID: <178413358475.13854.3067663522720308737@fcb35a5fe5ab> # Recommended update for hplip Announcement ID: SUSE-RU-2026:3018-1 Release Date: 2026-07-15T09:18:48Z Rating: moderate References: Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that can now be installed. ## Description: This update for hplip fixes the following issues: * hp-plugin: fix plugin installation from local file * fix errors with python2-incompatible syntax * Spec file: fix python-gobject2 dependency under SLE12 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3018=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3018=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3018=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * hplip-udev-rules-3.26.4-150600.4.12.1 * hplip-3.26.4-150600.4.12.1 * hplip-hpijs-debuginfo-3.26.4-150600.4.12.1 * hplip-sane-3.26.4-150600.4.12.1 * hplip-debuginfo-3.26.4-150600.4.12.1 * hplip-hpijs-3.26.4-150600.4.12.1 * hplip-debugsource-3.26.4-150600.4.12.1 * hplip-scan-utils-3.26.4-150600.4.12.1 * hplip-scan-utils-debuginfo-3.26.4-150600.4.12.1 * hplip-sane-debuginfo-3.26.4-150600.4.12.1 * hplip-devel-3.26.4-150600.4.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * hplip-udev-rules-3.26.4-150600.4.12.1 * hplip-3.26.4-150600.4.12.1 * hplip-hpijs-debuginfo-3.26.4-150600.4.12.1 * hplip-sane-3.26.4-150600.4.12.1 * hplip-debuginfo-3.26.4-150600.4.12.1 * hplip-hpijs-3.26.4-150600.4.12.1 * hplip-debugsource-3.26.4-150600.4.12.1 * hplip-sane-debuginfo-3.26.4-150600.4.12.1 * hplip-devel-3.26.4-150600.4.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * hplip-udev-rules-3.26.4-150600.4.12.1 * hplip-3.26.4-150600.4.12.1 * hplip-hpijs-debuginfo-3.26.4-150600.4.12.1 * hplip-sane-3.26.4-150600.4.12.1 * hplip-debuginfo-3.26.4-150600.4.12.1 * hplip-hpijs-3.26.4-150600.4.12.1 * hplip-debugsource-3.26.4-150600.4.12.1 * hplip-sane-debuginfo-3.26.4-150600.4.12.1 * hplip-devel-3.26.4-150600.4.12.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:39:51 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:39:51 -0000 Subject: SUSE-RU-2026:3017-1: important: Recommended update for nodejs22 Message-ID: <178413359170.13854.11740138731014066864@fcb35a5fe5ab> # Recommended update for nodejs22 Announcement ID: SUSE-RU-2026:3017-1 Release Date: 2026-07-15T09:17:20Z Rating: important References: * bsc#1269825 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one fix can now be installed. ## Description: This update for nodejs22 fixes the following issues: * Update to version 22.23.1: * http: avoid stream listeners on idle agent sockets (bsc#1269825) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3017=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3017=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3017=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * nodejs22-debuginfo-22.23.1-150600.13.21.1 * npm22-22.23.1-150600.13.21.1 * nodejs22-22.23.1-150600.13.21.1 * nodejs22-devel-22.23.1-150600.13.21.1 * nodejs22-debugsource-22.23.1-150600.13.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * nodejs22-docs-22.23.1-150600.13.21.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * nodejs22-docs-22.23.1-150600.13.21.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * nodejs22-debuginfo-22.23.1-150600.13.21.1 * npm22-22.23.1-150600.13.21.1 * nodejs22-22.23.1-150600.13.21.1 * nodejs22-devel-22.23.1-150600.13.21.1 * nodejs22-debugsource-22.23.1-150600.13.21.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * nodejs22-debuginfo-22.23.1-150600.13.21.1 * corepack22-22.23.1-150600.13.21.1 * npm22-22.23.1-150600.13.21.1 * nodejs22-22.23.1-150600.13.21.1 * nodejs22-devel-22.23.1-150600.13.21.1 * nodejs22-debugsource-22.23.1-150600.13.21.1 * openSUSE Leap 15.6 (noarch) * nodejs22-docs-22.23.1-150600.13.21.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269825 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:39:57 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:39:57 -0000 Subject: SUSE-RU-2026:3016-1: important: Recommended update for nodejs22 Message-ID: <178413359733.13854.14902153535923106628@fcb35a5fe5ab> # Recommended update for nodejs22 Announcement ID: SUSE-RU-2026:3016-1 Release Date: 2026-07-15T09:15:41Z Rating: important References: * bsc#1269825 Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that has one fix can now be installed. ## Description: This update for nodejs22 fixes the following issues: * Update to version 22.23.1: * http: avoid stream listeners on idle agent sockets (bsc#1269825) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3016=1 ## Package List: * Web and Scripting Module 15-SP7 (noarch) * nodejs22-docs-22.23.1-150700.3.15.1 * Web and Scripting Module 15-SP7 (aarch64 ppc64le s390x x86_64) * nodejs22-devel-22.23.1-150700.3.15.1 * nodejs22-debuginfo-22.23.1-150700.3.15.1 * nodejs22-22.23.1-150700.3.15.1 * nodejs22-debugsource-22.23.1-150700.3.15.1 * npm22-22.23.1-150700.3.15.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269825 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:40:08 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:40:08 -0000 Subject: SUSE-RU-2026:3015-1: moderate: Recommended update for suseconnect-ng Message-ID: <178413360869.13854.16612597718407468003@fcb35a5fe5ab> # Recommended update for suseconnect-ng Announcement ID: SUSE-RU-2026:3015-1 Release Date: 2026-07-15T09:08:04Z Rating: moderate References: * bsc#1197231 * bsc#1263772 * bsc#1265410 * bsc#1268017 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has four fixes can now be installed. ## Description: This update for suseconnect-ng fixes the following issues: * Update version to 1.22.1: * Allow clients to disable the token handling mechanism * Ensure updated system certs are included when creating HTTP client connections (bsc#1268017, jsc#SCC-804) * Update version to 1.22: * Fix keepalive service failing on unregistered system (bsc#1263772) * Add collector support for gathering RKE2 & K3s kubernetes provider info if enabled on a system * Add email address validation to SUSEConnect -e/--email option. (bsc#1197231) * Add collector support for detecting if system is running pacemaker * Avoid double slash at start of request URL path component * Use product identifier when finding product packages during migrations (bsc#1265410) * Add opt in/out support for collectors * Update config parser for suseconnect to be YAML based ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3015=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3015=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3015=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3015=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libsuseconnect-1.22.1-150600.3.21.1 * suseconnect-ng-1.22.1-150600.3.21.1 * suseconnect-ruby-bindings-1.22.1-150600.3.21.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * suseconnect-ruby-bindings-1.22.1-150600.3.21.1 * suseconnect-ng-1.22.1-150600.3.21.1 * libsuseconnect-1.22.1-150600.3.21.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libsuseconnect-1.22.1-150600.3.21.1 * suseconnect-ng-1.22.1-150600.3.21.1 * mcp-server-suseconnect-1.22.1-150600.3.21.1 * suseconnect-ruby-bindings-1.22.1-150600.3.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * suseconnect-ruby-bindings-1.22.1-150600.3.21.1 * suseconnect-ng-1.22.1-150600.3.21.1 * libsuseconnect-1.22.1-150600.3.21.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1197231 * https://bugzilla.suse.com/show_bug.cgi?id=1263772 * https://bugzilla.suse.com/show_bug.cgi?id=1265410 * https://bugzilla.suse.com/show_bug.cgi?id=1268017 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:40:19 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:40:19 -0000 Subject: SUSE-RU-2026:3014-1: moderate: Recommended update for suseconnect-ng Message-ID: <178413361936.13854.6926767065660153531@fcb35a5fe5ab> # Recommended update for suseconnect-ng Announcement ID: SUSE-RU-2026:3014-1 Release Date: 2026-07-15T09:07:46Z Rating: moderate References: * bsc#1197231 * bsc#1263772 * bsc#1265410 * bsc#1268017 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has four fixes can now be installed. ## Description: This update for suseconnect-ng fixes the following issues: * Update version to 1.22.1: * Allow clients to disable the token handling mechanism * Ensure updated system certs are included when creating HTTP client connections (bsc#1268017, jsc#SCC-804) * Update version to 1.22: * Fix keepalive service failing on unregistered system (bsc#1263772) * Add collector support for gathering RKE2 & K3s kubernetes provider info if enabled on a system * Add email address validation to SUSEConnect -e/--email option. (bsc#1197231) * Add collector support for detecting if system is running pacemaker * Avoid double slash at start of request URL path component * Use product identifier when finding product packages during migrations (bsc#1265410) * Add opt in/out support for collectors * Update config parser for suseconnect to be YAML based ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3014=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3014=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * suseconnect-ng-1.22.1-3.38.2 * suseconnect-ruby-bindings-1.22.1-3.38.2 * libsuseconnect-1.22.1-3.38.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * suseconnect-ng-1.22.1-3.38.2 * suseconnect-ruby-bindings-1.22.1-3.38.2 * libsuseconnect-1.22.1-3.38.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1197231 * https://bugzilla.suse.com/show_bug.cgi?id=1263772 * https://bugzilla.suse.com/show_bug.cgi?id=1265410 * https://bugzilla.suse.com/show_bug.cgi?id=1268017 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:40:29 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:40:29 -0000 Subject: SUSE-RU-2026:3013-1: moderate: Recommended update for suseconnect-ng Message-ID: <178413362919.13854.2667683326340390437@fcb35a5fe5ab> # Recommended update for suseconnect-ng Announcement ID: SUSE-RU-2026:3013-1 Release Date: 2026-07-15T09:07:33Z Rating: moderate References: * bsc#1197231 * bsc#1263772 * bsc#1265410 * bsc#1268017 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that has four fixes can now be installed. ## Description: This update for suseconnect-ng fixes the following issues: * Update version to 1.22.1: * Allow clients to disable the token handling mechanism * Ensure updated system certs are included when creating HTTP client connections (bsc#1268017, jsc#SCC-804) * Update version to 1.22: * Fix keepalive service failing on unregistered system (bsc#1263772) * Add collector support for gathering RKE2 & K3s kubernetes provider info if enabled on a system * Add email address validation to SUSEConnect -e/--email option. (bsc#1197231) * Add collector support for detecting if system is running pacemaker * Avoid double slash at start of request URL path component * Use product identifier when finding product packages during migrations (bsc#1265410) * Add opt in/out support for collectors * Update config parser for suseconnect to be YAML based ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3013=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3013=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3013=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3013=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3013=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3013=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3013=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3013=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3013=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * suseconnect-ruby-bindings-1.22.1-150400.3.52.1 * libsuseconnect-1.22.1-150400.3.52.1 * suseconnect-ng-1.22.1-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * suseconnect-ruby-bindings-1.22.1-150400.3.52.1 * libsuseconnect-1.22.1-150400.3.52.1 * suseconnect-ng-1.22.1-150400.3.52.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * suseconnect-ruby-bindings-1.22.1-150400.3.52.1 * mcp-server-suseconnect-1.22.1-150400.3.52.1 * libsuseconnect-1.22.1-150400.3.52.1 * suseconnect-ng-1.22.1-150400.3.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * suseconnect-ruby-bindings-1.22.1-150400.3.52.1 * libsuseconnect-1.22.1-150400.3.52.1 * suseconnect-ng-1.22.1-150400.3.52.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * suseconnect-ng-1.22.1-150400.3.52.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * suseconnect-ng-1.22.1-150400.3.52.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * suseconnect-ng-1.22.1-150400.3.52.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * suseconnect-ng-1.22.1-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * suseconnect-ruby-bindings-1.22.1-150400.3.52.1 * libsuseconnect-1.22.1-150400.3.52.1 * suseconnect-ng-1.22.1-150400.3.52.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1197231 * https://bugzilla.suse.com/show_bug.cgi?id=1263772 * https://bugzilla.suse.com/show_bug.cgi?id=1265410 * https://bugzilla.suse.com/show_bug.cgi?id=1268017 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:40:39 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 16:40:39 -0000 Subject: SUSE-RU-2026:3012-1: moderate: Recommended update for suseconnect-ng Message-ID: <178413363979.13854.8581922345573977553@fcb35a5fe5ab> # Recommended update for suseconnect-ng Announcement ID: SUSE-RU-2026:3012-1 Release Date: 2026-07-15T09:06:42Z Rating: moderate References: * bsc#1197231 * bsc#1263772 * bsc#1265410 * bsc#1268017 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has four fixes can now be installed. ## Description: This update for suseconnect-ng fixes the following issues: * Update version to 1.22.1: * Allow clients to disable the token handling mechanism * Ensure updated system certs are included when creating HTTP client connections (bsc#1268017, jsc#SCC-804) * Update version to 1.22: * Fix keepalive service failing on unregistered system (bsc#1263772) * Add collector support for gathering RKE2 & K3s kubernetes provider info if enabled on a system * Add email address validation to SUSEConnect -e/--email option. (bsc#1197231) * Add collector support for detecting if system is running pacemaker * Avoid double slash at start of request URL path component * Use product identifier when finding product packages during migrations (bsc#1265410) * Add opt in/out support for collectors * Update config parser for suseconnect to be YAML based ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3012=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3012=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3012=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3012=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3012=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3012=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libsuseconnect-1.22.1-150500.3.45.1 * suseconnect-ng-1.22.1-150500.3.45.1 * suseconnect-ruby-bindings-1.22.1-150500.3.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libsuseconnect-1.22.1-150500.3.45.1 * suseconnect-ng-1.22.1-150500.3.45.1 * suseconnect-ruby-bindings-1.22.1-150500.3.45.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libsuseconnect-1.22.1-150500.3.45.1 * suseconnect-ng-1.22.1-150500.3.45.1 * mcp-server-suseconnect-1.22.1-150500.3.45.1 * suseconnect-ruby-bindings-1.22.1-150500.3.45.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * suseconnect-ruby-bindings-1.22.1-150500.3.45.1 * suseconnect-ng-1.22.1-150500.3.45.1 * libsuseconnect-1.22.1-150500.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libsuseconnect-1.22.1-150500.3.45.1 * suseconnect-ng-1.22.1-150500.3.45.1 * suseconnect-ruby-bindings-1.22.1-150500.3.45.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * suseconnect-ng-1.22.1-150500.3.45.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1197231 * https://bugzilla.suse.com/show_bug.cgi?id=1263772 * https://bugzilla.suse.com/show_bug.cgi?id=1265410 * https://bugzilla.suse.com/show_bug.cgi?id=1268017 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:30:04 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:30:04 -0000 Subject: SUSE-SU-2026:3064-1: important: Security update for docker Message-ID: <178414740444.406.3211712304225232473@1437f03ce14a> # Security update for docker Announcement ID: SUSE-SU-2026:3064-1 Release Date: 2026-07-15T15:02:51Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for docker rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3064=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3064=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3064=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3064=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3064=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3064=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3064=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3064=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3064=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3064=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3064=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3064=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3064=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3064=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3064=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3064=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3064=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * docker-zsh-completion-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * Containers Module 15-SP7 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * docker-zsh-completion-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * docker-zsh-completion-29.4.0_ce-150000.255.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:30:08 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:30:08 -0000 Subject: SUSE-SU-2026:3063-1: important: Security update for buildah Message-ID: <178414740863.406.6271674319816335204@1437f03ce14a> # Security update for buildah Announcement ID: SUSE-SU-2026:3063-1 Release Date: 2026-07-15T15:01:02Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for buildah rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3063=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3063=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3063=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3063=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3063=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3063=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3063=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3063=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.64.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * buildah-1.35.5-150500.3.64.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * buildah-1.35.5-150500.3.64.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:30:12 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:30:12 -0000 Subject: SUSE-RU-2026:3062-1: moderate: Recommended update for rust, rust1.96 Message-ID: <178414741285.406.6303528027753415244@1437f03ce14a> # Recommended update for rust, rust1.96 Announcement ID: SUSE-RU-2026:3062-1 Release Date: 2026-07-15T14:59:23Z Rating: moderate References: Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for rust, rust1.96 fixes the following issues: Changes in rust1.96: * Release notes can be found externally: https://github.com/rust- lang/rust/releases/tag/1.96.1 Changes in rust: * Update to version 1.96.1 - for details see the rust1.96 package ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3062=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3062=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3062=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3062=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3062=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3062=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3062=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3062=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3062=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3062=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3062=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3062=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc ppc64le s390x x86_64) * rust1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le x86_64) * rust1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc x86_64) * rust1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (nosrc ppc64le x86_64) * rust1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 nosrc ppc64le s390x x86_64) * rust1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * openSUSE Leap 15.3 (aarch64 i586 nosrc ppc64le s390x x86_64) * rust1.96-1.96.1-150300.7.6.1 * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * rust-src-1.96.1-150300.21.93.1 * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * cargo-1.96.1-150300.21.93.1 * rust-1.96.1-150300.21.93.1 * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * openSUSE Leap 15.3 (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * openSUSE Leap 15.3 (nosrc) * rust1.96-test-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 nosrc ppc64le s390x x86_64) * rust1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 nosrc x86_64) * rust1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (nosrc ppc64le x86_64) * rust1.96-1.96.1-150300.7.6.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * Development Tools Module 15-SP7 (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * Development Tools Module 15-SP7 (aarch64 nosrc ppc64le s390x x86_64) * rust1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 nosrc x86_64) * rust1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rust1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-debuginfo-1.96.1-150300.7.6.1 * cargo1.96-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * rust1.96-src-1.96.1-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc x86_64) * rust1.96-1.96.1-150300.7.6.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:30:41 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:30:41 -0000 Subject: SUSE-RU-2026:3061-1: moderate: Recommended update for cloud-regionsrv-client, python-instance-billing-flavor-check Message-ID: <178414744130.406.12043377960842752488@1437f03ce14a> # Recommended update for cloud-regionsrv-client, python-instance-billing-flavor- check Announcement ID: SUSE-RU-2026:3061-1 Release Date: 2026-07-15T14:09:35Z Rating: moderate References: * bsc#1247539 * bsc#1250110 * bsc#1253777 * bsc#1254702 * bsc#1254960 * bsc#1254982 * bsc#1254984 * bsc#1260421 * bsc#1265930 * bsc#1267739 * jsc#PED-14732 * jsc#PED-8945 Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that contains two features and has 10 fixes can now be installed. ## Description: This update for cloud-regionsrv-client, python-instance-billing-flavor-check contains the following fixes: cloud-regionsrv-client: * Update to version 11.0.3 * Write instance data cache file after cleaning the cache when the update server fails. (bsc#1265930) * Create the cache directory when populating the cache. (bsc#1267739) * Update to version 11.0.2: (bsc#1260421) * Add iputils as a dependency to make automatic NVIDIA repo enablement work * Update to version 11.0.1: * Fix attempt to read a deleted file resulting in an error. Refresh the file list for repos and services for each pass over the server domains we are looking to clean up the registration. * Update user visible messages only showing messages for the application configuration file. * Update to version 11.0.0: (bsc#1254960, bsc#1254982, bsc#1253777) * Major version bump for main package and plugin sub-packages due to interpreter change in SLE 15 SP4+ from Python 3.6 to Python 3.11 * Create cache directory in code and drop from package (jsc#PED-14732) * Fix race condition between license watcher timer and registration (bsc#1254984) * Fix cleanup issue in hosts (bsc#1254702) * Fix cache clean up * Fix exit condition from container registry setup * Lock the registration process to ensure single execution (bsc#1254984) * Fix traceback on FP and cert mismatch * Switch remaining code to updated logging implementation * Increase loggin information in log to help with issue debugging * Fix exit code on partial registration success * Remove obsolete switchcloudguestservices * Update to version 10.5.3: * Move project setup to poetry and apply python standards * Fix use of logging facility Use logging facility in the desired way throughout the entire code base. This includes the following changes and refactor * Add handler and formatter for the logfile containing more information about function and position in code for the message * Add handler for stdout (INFO and WARNING) * Add handler for stderr (ERROR). * Implement Logger class providing the logging setup and methods * Drop the start_logging() method. * Fix and refactor all unit tests around the use of logging with a proper fixture and place all tests for registerutils into its own class TestRegisterUtils. * Add --debug switch for registercloudguest. Allow to increase logfile information. All messages produced via log.debug(...) in code will be part of the logfile. Debug messages will not be shown on the console * Update SLE12 patches due to logging refactor * Use --debug flag in guestregister service python-instance-billing-flavor-check: * Build fix for SLE 16 and later: (bsc#1250110) * Switch SLE 15 SP4 - SP7 to Python 3.11 (jsc#PED-8945) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3061=1 ## Package List: * Public Cloud Module 12 (noarch) * cloud-regionsrv-client-plugin-ec2-2.0.0-52.137.1 * cloud-regionsrv-client-license-watcher-1.0.0-52.137.1 * cloud-regionsrv-client-plugin-gce-2.0.0-52.137.1 * cloud-regionsrv-client-plugin-azure-3.0.0-52.137.1 * cloud-regionsrv-client-generic-config-1.0.0-52.137.1 * cloud-regionsrv-client-11.0.3-52.137.1 * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * python-instance-billing-flavor-check-1.0.1-1.26.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1247539 * https://bugzilla.suse.com/show_bug.cgi?id=1250110 * https://bugzilla.suse.com/show_bug.cgi?id=1253777 * https://bugzilla.suse.com/show_bug.cgi?id=1254702 * https://bugzilla.suse.com/show_bug.cgi?id=1254960 * https://bugzilla.suse.com/show_bug.cgi?id=1254982 * https://bugzilla.suse.com/show_bug.cgi?id=1254984 * https://bugzilla.suse.com/show_bug.cgi?id=1260421 * https://bugzilla.suse.com/show_bug.cgi?id=1265930 * https://bugzilla.suse.com/show_bug.cgi?id=1267739 * https://jira.suse.com/browse/PED-14732 * https://jira.suse.com/browse/PED-8945 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:30:59 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:30:59 -0000 Subject: SUSE-RU-2026:3060-1: moderate: Recommended update for cloud-regionsrv-client, python-instance-billing-flavor-check Message-ID: <178414745916.406.17649394037584074224@1437f03ce14a> # Recommended update for cloud-regionsrv-client, python-instance-billing-flavor- check Announcement ID: SUSE-RU-2026:3060-1 Release Date: 2026-07-15T14:09:03Z Rating: moderate References: * bsc#1247539 * bsc#1250110 * bsc#1253777 * bsc#1254702 * bsc#1254960 * bsc#1254982 * bsc#1254984 * bsc#1260421 * bsc#1265930 * bsc#1267739 * jsc#PED-14732 * jsc#PED-8944 * jsc#PED-8945 Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that contains three features and has 10 fixes can now be installed. ## Description: This update for cloud-regionsrv-client, python-instance-billing-flavor-check contains the following fixes: cloud-regionsrv-client: * Update to version 11.0.3 * Write instance data cache file after cleaning the cache when the update server fails. (bsc#1265930) * Create the cache directory when populating the cache. (bsc#1267739) * Update to version 11.0.2: * Add iputils as a dependency to make automatic NVIDIA repo enablement work. (bsc#1260421) * Update to version 11.0.1: * Fix attempt to read a deleted file resulting in an error. Refresh the file list for repos and services for each pass over the server domains we are looking to clean up the registration. * Update user visible messages only showing messages for the application configuration file. * Update to version 11.0.0: (bsc#1254960, bsc#1254982, bsc#1253777) * Major version bump for main package and plugin sub-packages due to interpreter change in SLE 15 SP4+ from Python 3.6 to Python 3.11 * Create cache directory in code and drop from package (jsc#PED-14732) * Fix race condition between license watcher timer and registration (bsc#1254984) * Fix cleanup issue in hosts (bsc#1254702) * Fix cache clean up * Fix exit condition from container registry setup * Lock the registration process to ensure single execution (bsc#1254984) * Fix traceback on FP and cert mismatch * Switch remaining code to updated logging implementation * Increase loggin information in log to help with issue debugging * Fix exit code on partial registration success * Remove obsolete switchcloudguestservices * Update to version 10.5.3: * Move project setup to poetry and apply python standards * Fix use of logging facility Use logging facility in the desired way throughout the entire code base. This includes the following changes and refactor * Add handler and formatter for the logfile containing more information about function and position in code for the message * Add handler for stdout (INFO and WARNING) * Add handler for stderr (ERROR). * Implement Logger class providing the logging setup and methods * Drop the start_logging() method. * Fix and refactor all unit tests around the use of logging with a proper fixture and place all tests for registerutils into its own class TestRegisterUtils. * Add --debug switch for registercloudguest. Allow to increase logfile information. All messages produced via log.debug(...) in code will be part of the logfile. Debug messages will not be shown on the console * Update SLE12 patches due to logging refactor * Use --debug flag in guestregister service python-instance-billing-flavor-check: * Build fix for SLE 16 and later. (bsc#1250110) * Switch SLE 15 SP4 - SP7 to Python 3.11 (jsc#PED-8944)a ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3060=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3060=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3060=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3060=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3060=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3060=1 ## Package List: * Public Cloud Module 15-SP7 (noarch) * cloud-regionsrv-client-plugin-ec2-2.0.0-150400.16.5.1 * cloud-regionsrv-client-11.0.3-150400.16.5.1 * cloud-regionsrv-client-license-watcher-1.0.0-150400.16.5.1 * cloud-regionsrv-client-generic-config-1.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-azure-3.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-gce-2.0.0-150400.16.5.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-instance-billing-flavor-check-1.0.1-150400.10.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python-instance-billing-flavor-check-1.0.1-150400.10.3.1 * openSUSE Leap 15.4 (noarch) * cloud-regionsrv-client-plugin-ec2-2.0.0-150400.16.5.1 * python311-toml-0.10.2-150400.5.5.1 * cloud-regionsrv-client-11.0.3-150400.16.5.1 * cloud-regionsrv-client-license-watcher-1.0.0-150400.16.5.1 * cloud-regionsrv-client-generic-config-1.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-azure-3.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-gce-2.0.0-150400.16.5.1 * Public Cloud Module 15-SP5 (noarch) * cloud-regionsrv-client-plugin-ec2-2.0.0-150400.16.5.1 * cloud-regionsrv-client-11.0.3-150400.16.5.1 * cloud-regionsrv-client-license-watcher-1.0.0-150400.16.5.1 * cloud-regionsrv-client-generic-config-1.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-azure-3.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-gce-2.0.0-150400.16.5.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python-instance-billing-flavor-check-1.0.1-150400.10.3.1 * Public Cloud Module 15-SP4 (noarch) * cloud-regionsrv-client-plugin-ec2-2.0.0-150400.16.5.1 * cloud-regionsrv-client-11.0.3-150400.16.5.1 * cloud-regionsrv-client-license-watcher-1.0.0-150400.16.5.1 * cloud-regionsrv-client-generic-config-1.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-azure-3.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-gce-2.0.0-150400.16.5.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python-instance-billing-flavor-check-1.0.1-150400.10.3.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python-instance-billing-flavor-check-1.0.1-150400.10.3.1 * Public Cloud Module 15-SP6 (noarch) * cloud-regionsrv-client-plugin-ec2-2.0.0-150400.16.5.1 * cloud-regionsrv-client-11.0.3-150400.16.5.1 * cloud-regionsrv-client-license-watcher-1.0.0-150400.16.5.1 * cloud-regionsrv-client-generic-config-1.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-azure-3.0.0-150400.16.5.1 * cloud-regionsrv-client-plugin-gce-2.0.0-150400.16.5.1 * Python 3 Module 15-SP7 (noarch) * python311-toml-0.10.2-150400.5.5.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1247539 * https://bugzilla.suse.com/show_bug.cgi?id=1250110 * https://bugzilla.suse.com/show_bug.cgi?id=1253777 * https://bugzilla.suse.com/show_bug.cgi?id=1254702 * https://bugzilla.suse.com/show_bug.cgi?id=1254960 * https://bugzilla.suse.com/show_bug.cgi?id=1254982 * https://bugzilla.suse.com/show_bug.cgi?id=1254984 * https://bugzilla.suse.com/show_bug.cgi?id=1260421 * https://bugzilla.suse.com/show_bug.cgi?id=1265930 * https://bugzilla.suse.com/show_bug.cgi?id=1267739 * https://jira.suse.com/browse/PED-14732 * https://jira.suse.com/browse/PED-8944 * https://jira.suse.com/browse/PED-8945 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:31:19 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:31:19 -0000 Subject: SUSE-SU-2026:3059-1: important: Security update for python-aiohttp Message-ID: <178414747910.406.7571708348215578198@1437f03ce14a> # Security update for python-aiohttp Announcement ID: SUSE-SU-2026:3059-1 Release Date: 2026-07-15T13:34:43Z Rating: important References: * bsc#1261320 * bsc#1261321 * bsc#1261322 * bsc#1261329 * bsc#1261331 * bsc#1261332 * bsc#1261334 * bsc#1261335 * bsc#1261343 * bsc#1267471 * bsc#1267561 Cross-References: * CVE-2026-22815 * CVE-2026-34513 * CVE-2026-34514 * CVE-2026-34516 * CVE-2026-34517 * CVE-2026-34518 * CVE-2026-34519 * CVE-2026-34520 * CVE-2026-34525 * CVE-2026-34993 * CVE-2026-47265 CVSS scores: * CVE-2026-22815 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22815 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22815 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-22815 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34513 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34513 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34513 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34513 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34514 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-34514 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34514 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34514 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34516 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34516 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34516 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34516 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34517 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34517 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-34517 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34517 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34518 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34518 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34518 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34518 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34519 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34519 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34519 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34519 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34520 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34520 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34520 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34520 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-34525 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-34525 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-34525 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34525 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34993 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-34993 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L * CVE-2026-34993 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-34993 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2026-47265 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-47265 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47265 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for python-aiohttp fixes the following issues * CVE-2026-22815: insufficient header/trailer handling can cause a denial of service (bsc#1261320). * CVE-2026-34513: unbounded DNS cache can cause a denial of service (bsc#1261321). * CVE-2026-34514: content_type parameter manipulation can lead to header Injection (bsc#1261322). * CVE-2026-34516: excessive multipart headers can cause a denial of service (bsc#1261329). * CVE-2026-34517: large multipart form fields can cause a denial of service (bsc#1261331). * CVE-2026-34518: retained Cookie and Proxy-Authorization headers during redirects can lead to information disclosure (bsc#1261332). * CVE-2026-34519: reason parameter can be use to perform header injection (bsc#1261334). * CVE-2026-34520: improper character handling can lead to header injection (bsc#1261335). * CVE-2026-34525: multiple Host headers can potentially lead to security bypass (bsc#1261343). * CVE-2026-34993: arbitrary code execution via loading untrusted input in CookieJar.load() (bsc#1267471). * CVE-2026-47265: cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect (bsc#1267561). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3059=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3059=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3059=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3059=1 ## Package List: * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-3.6.0-150100.3.35.1 * python-aiohttp-debugsource-3.6.0-150100.3.35.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.35.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-3.6.0-150100.3.35.1 * python-aiohttp-debugsource-3.6.0-150100.3.35.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.35.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-3.6.0-150100.3.35.1 * python-aiohttp-debugsource-3.6.0-150100.3.35.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.35.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-3.6.0-150100.3.35.1 * python-aiohttp-debugsource-3.6.0-150100.3.35.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.35.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22815.html * https://www.suse.com/security/cve/CVE-2026-34513.html * https://www.suse.com/security/cve/CVE-2026-34514.html * https://www.suse.com/security/cve/CVE-2026-34516.html * https://www.suse.com/security/cve/CVE-2026-34517.html * https://www.suse.com/security/cve/CVE-2026-34518.html * https://www.suse.com/security/cve/CVE-2026-34519.html * https://www.suse.com/security/cve/CVE-2026-34520.html * https://www.suse.com/security/cve/CVE-2026-34525.html * https://www.suse.com/security/cve/CVE-2026-34993.html * https://www.suse.com/security/cve/CVE-2026-47265.html * https://bugzilla.suse.com/show_bug.cgi?id=1261320 * https://bugzilla.suse.com/show_bug.cgi?id=1261321 * https://bugzilla.suse.com/show_bug.cgi?id=1261322 * https://bugzilla.suse.com/show_bug.cgi?id=1261329 * https://bugzilla.suse.com/show_bug.cgi?id=1261331 * https://bugzilla.suse.com/show_bug.cgi?id=1261332 * https://bugzilla.suse.com/show_bug.cgi?id=1261334 * https://bugzilla.suse.com/show_bug.cgi?id=1261335 * https://bugzilla.suse.com/show_bug.cgi?id=1261343 * https://bugzilla.suse.com/show_bug.cgi?id=1267471 * https://bugzilla.suse.com/show_bug.cgi?id=1267561 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:31:32 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:31:32 -0000 Subject: SUSE-SU-2026:3058-1: important: Security update for gstreamer-plugins-bad Message-ID: <178414749286.406.11505670658796409444@1437f03ce14a> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:3058-1 Release Date: 2026-07-15T13:32:28Z Rating: important References: * bsc#1268168 * bsc#1268406 * bsc#1268408 * bsc#1268410 * bsc#1268971 * bsc#1271051 * bsc#1271168 Cross-References: * CVE-2026-12892 * CVE-2026-14935 * CVE-2026-52720 * CVE-2026-52721 * CVE-2026-52722 * CVE-2026-53702 * CVE-2026-59692 CVSS scores: * CVE-2026-12892 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12892 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12892 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-14935 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-14935 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-14935 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-52720 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52721 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-52721 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53702 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53702 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59692 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issues * CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser (bsc#1268971). * CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check (bsc#1271051). * CVE-2026-52720: invalid check of total area instead of individual dimensions could trigger a heap out-of-bounds write (bsc#1268406). * CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could cause an out-of-bounds read (bsc#1268408). * CVE-2026-52722: crafted VMnc stream with large cursor dimensions can overflow signed integer (bsc#1268410). * CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could result in a stack buffer overflow (bsc#1268168). * CVE-2026-59692: unvalidated peer certificate Subject DN printed during a DTLS handshake could cause a stack buffer overflow (bsc#1271168). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3058=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3058=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3058=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3058=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3058=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3058=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.9.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-1.24.0-150600.4.9.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-1.24.0-150600.4.9.1 * libgstmse-1_0-0-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-1.24.0-150600.4.9.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.9.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstva-1_0-0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.9.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.9.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-transcoder-1.24.0-150600.4.9.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-1.24.0-150600.4.9.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstVulkanXCB-1_0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-1.24.0-150600.4.9.1 * libgstmse-1_0-0-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstTranscoder-1_0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-transcoder-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-1.24.0-150600.4.9.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.24.0-150600.4.9.1 * gstreamer-transcoder-devel-1.24.0-150600.4.9.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstva-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstVulkanWayland-1_0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstVulkan-1_0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.9.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libgstwayland-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-64bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-64bit-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-64bit-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstva-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstmse-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstplay-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-64bit-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstva-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstplay-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-64bit-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-64bit-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstmse-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-64bit-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * openSUSE Leap 15.6 (x86_64) * libgstwayland-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-32bit-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstmse-1_0-0-32bit-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-32bit-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-32bit-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstva-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstplay-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-32bit-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstmse-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-32bit-1.24.0-150600.4.9.1 * libgstva-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * openSUSE Leap 15.6 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.9.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-1.24.0-150600.4.9.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.9.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-1.24.0-150600.4.9.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-1.24.0-150600.4.9.1 * libgstmse-1_0-0-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-1.24.0-150600.4.9.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.9.1 * libgstva-1_0-0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.9.1 * Desktop Applications Module 15-SP7 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.9.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-1.24.0-150600.4.9.1 * libgstmse-1_0-0-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.9.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.9.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstva-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.9.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12892.html * https://www.suse.com/security/cve/CVE-2026-14935.html * https://www.suse.com/security/cve/CVE-2026-52720.html * https://www.suse.com/security/cve/CVE-2026-52721.html * https://www.suse.com/security/cve/CVE-2026-52722.html * https://www.suse.com/security/cve/CVE-2026-53702.html * https://www.suse.com/security/cve/CVE-2026-59692.html * https://bugzilla.suse.com/show_bug.cgi?id=1268168 * https://bugzilla.suse.com/show_bug.cgi?id=1268406 * https://bugzilla.suse.com/show_bug.cgi?id=1268408 * https://bugzilla.suse.com/show_bug.cgi?id=1268410 * https://bugzilla.suse.com/show_bug.cgi?id=1268971 * https://bugzilla.suse.com/show_bug.cgi?id=1271051 * https://bugzilla.suse.com/show_bug.cgi?id=1271168 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:31:50 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:31:50 -0000 Subject: SUSE-SU-2026:3057-1: important: Security update for terraform-provider-susepubliccloud Message-ID: <178414751097.406.12518522277990065621@1437f03ce14a> # Security update for terraform-provider-susepubliccloud Announcement ID: SUSE-SU-2026:3057-1 Release Date: 2026-07-15T13:30:14Z Rating: important References: * bsc#1208300 * bsc#1260180 * bsc#1263247 * bsc#1263316 * bsc#1263357 * bsc#1263411 * bsc#1263445 * bsc#1263515 * bsc#1263606 * bsc#1266477 Cross-References: * CVE-2022-41723 * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-41602 * CVE-2026-41603 * CVE-2026-41604 * CVE-2026-41605 * CVE-2026-41606 * CVE-2026-41607 * CVE-2026-41636 CVSS scores: * CVE-2022-41723 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41603 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41603 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-41603 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-41603 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-41604 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41604 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41604 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41604 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41605 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-41605 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-41605 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-41605 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-41606 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41607 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41607 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41636 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41636 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41636 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41636 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for terraform-provider-susepubliccloud fixes the following issues * CVE-2022-41723: go1.19,go1.20: net/http2: quadratic complexity in HPACK decoding (bsc#1208300). * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 `:path` pseudo-header (bsc#1260180). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266477). * CVE-2026-41602: github.com/apache/thrift: `TFramedTransport` frame size headers can lead to a `uint32` integer overflow (bsc#1263515). * CVE-2026-41603: github.com/apache/thrift: improper hostname verification in `TSSLTransportFactory` can lead to host mismatch (bsc#1263606). * CVE-2026-41604: github.com/apache/thrift: swift input with an invalid field range can lead to an out-of-bounds read and application crash (bsc#1263445). * CVE-2026-41605: github.com/apache/thrift: compact protocol messages with large integer values can lead to integer overflow (bsc#1263411). * CVE-2026-41606: github.com/apache/thrift: crafted nested messages in `c_glib` dispatch can lead to uncontrolled recursion and denial of service (bsc#1263357). * CVE-2026-41607: github.com/apache/thrift: crafted message with improper length validation can lead to an out-of-bounds read and potential information disclosure (bsc#1263316). * CVE-2026-41636: github.com/apache/thrift: uncontrolled recursion in Node.js bindings can lead to denial of service via stack exhaustion (bsc#1263247). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3057=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3057=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-susepubliccloud-0.0.1-150100.3.14.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-susepubliccloud-0.0.1-150100.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2022-41723.html * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-41603.html * https://www.suse.com/security/cve/CVE-2026-41604.html * https://www.suse.com/security/cve/CVE-2026-41605.html * https://www.suse.com/security/cve/CVE-2026-41606.html * https://www.suse.com/security/cve/CVE-2026-41607.html * https://www.suse.com/security/cve/CVE-2026-41636.html * https://bugzilla.suse.com/show_bug.cgi?id=1208300 * https://bugzilla.suse.com/show_bug.cgi?id=1260180 * https://bugzilla.suse.com/show_bug.cgi?id=1263247 * https://bugzilla.suse.com/show_bug.cgi?id=1263316 * https://bugzilla.suse.com/show_bug.cgi?id=1263357 * https://bugzilla.suse.com/show_bug.cgi?id=1263411 * https://bugzilla.suse.com/show_bug.cgi?id=1263445 * https://bugzilla.suse.com/show_bug.cgi?id=1263515 * https://bugzilla.suse.com/show_bug.cgi?id=1263606 * https://bugzilla.suse.com/show_bug.cgi?id=1266477 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:32:52 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:32:52 -0000 Subject: SUSE-SU-2026:3056-1: important: Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Message-ID: <178414757291.406.4165304088467174331@1437f03ce14a> # Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Announcement ID: SUSE-SU-2026:3056-1 Release Date: 2026-07-15T13:28:53Z Rating: important References: * bsc#1208300 * bsc#1241030 * bsc#1241033 * bsc#1241728 * bsc#1251365 * bsc#1251559 * bsc#1253508 * bsc#1253517 * bsc#1253797 * bsc#1253799 * bsc#1253980 * bsc#1253983 * bsc#1258096 * bsc#1260139 * bsc#1260149 * bsc#1260180 * bsc#1263247 * bsc#1263313 * bsc#1263357 * bsc#1263411 * bsc#1263445 * bsc#1263515 * bsc#1263606 * bsc#1264862 * bsc#1264888 * bsc#1264938 * bsc#1266051 * bsc#1266057 * bsc#1266086 * bsc#1266112 * bsc#1266122 * bsc#1266127 * bsc#1266132 * bsc#1266150 * bsc#1266160 * bsc#1266477 * bsc#1266482 * bsc#1266541 * bsc#1266547 * bsc#1267058 * bsc#1267271 * bsc#1267273 * bsc#1267276 Cross-References: * CVE-2022-41723 * CVE-2025-22872 * CVE-2025-32386 * CVE-2025-32387 * CVE-2025-47911 * CVE-2025-47913 * CVE-2025-47914 * CVE-2025-58181 * CVE-2025-58190 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-25934 * CVE-2026-27136 * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41506 * CVE-2026-41602 * CVE-2026-41603 * CVE-2026-41604 * CVE-2026-41605 * CVE-2026-41606 * CVE-2026-41607 * CVE-2026-41636 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-44740 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2022-41723 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2025-22872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2025-32386 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32386 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32386 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32387 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32387 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32387 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47914 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47914 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47914 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58181 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58181 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58181 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25934 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25934 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25934 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25934 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41506 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41506 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-41506 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-41506 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41603 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41603 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-41603 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-41603 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-41604 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41604 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41604 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41604 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41605 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-41605 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-41605 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-41605 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-41606 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41606 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41607 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41607 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41636 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41636 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41636 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41636 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44740 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 39 vulnerabilities and has four security fixes can now be installed. ## Description: This update for terraform-provider-aws, terraform-provider-azurerm, terraform- provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider- null, terraform-provider-random, terraform-provider-tls fixes the following issues * CVE-2022-41723: go1.19,go1.20: net/http2: quadratic complexity in HPACK decoding (bsc#1208300). * CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241728). * CVE-2025-32386: helm: specially crafted chart archive can cause OOM termination (bsc#1241030). * CVE-2025-32387: helm: specially crafted JSON schema can cause a stack overflow (bsc#1241033). * CVE-2025-47911: golang.org/x/net/html: various algorithms have quadratic complexity when parsing HTML documents (bsc#1251365). * CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253508 bsc#1253517). * CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1253980 bsc#1253983). * CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253797 bsc#1253799). * CVE-2025-58190: golang.org/x/net/html: specially crafted input can cause excessive memory consumption by `html.ParseFragment` (bsc#1251559). * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267058). * CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for `.pack` and `.idx` files can lead to the consumption of corrupted files (bsc#1258096). * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 `:path` pseudo-header (bsc#1260139 bsc#1260149 bsc#1260180). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266477 bsc#1266482 bsc#1266541 bsc#1266547). * CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues in the crypto/ssh library (bsc#1266051 bsc#1266057 bsc#1266086 bsc#1266112 bsc#1266122 bsc#1266127 bsc#1266132 bsc#1266150 bsc#1266160). * CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264862 bsc#1264888 bsc#1264938). * CVE-2026-41602: github.com/apache/thrift: `TFramedTransport` frame size headers can lead to a `uint32` integer overflow (bsc#1263515). * CVE-2026-41603: github.com/apache/thrift: improper hostname verification in `TSSLTransportFactory` can lead to host mismatch (bsc#1263606). * CVE-2026-41604: github.com/apache/thrift: swift input with an invalid field range can lead to an out-of-bounds read and application crash (bsc#1263445). * CVE-2026-41605: github.com/apache/thrift: compact protocol messages with large integer values can lead to integer overflow (bsc#1263411). * CVE-2026-41606: github.com/apache/thrift: crafted nested messages in `c_glib` dispatch can lead to uncontrolled recursion and denial of service (bsc#1263357). * CVE-2026-41607: github.com/apache/thrift: crafted message with improper length validation can lead to an out-of-bounds read and potential information disclosure (bsc#1263313). * CVE-2026-41636: github.com/apache/thrift: uncontrolled recursion in Node.js bindings can lead to denial of service via stack exhaustion (bsc#1263247). * CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267271 bsc#1267273 bsc#1267276). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3056=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3056=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.18.1 * terraform-provider-external-2.0.0-150200.6.12.1 * terraform-provider-random-3.0.0-150200.6.15.1 * terraform-provider-tls-3.0.0-150200.5.15.1 * terraform-provider-local-2.0.0-150200.6.17.1 * terraform-provider-helm-2.9.0-150200.6.23.1 * terraform-provider-google-3.43.0-150200.6.12.1 * terraform-provider-null-3.0.0-150200.6.18.1 * terraform-provider-azurerm-2.32.0-150200.6.12.1 * terraform-provider-kubernetes-1.13.2-150200.6.12.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.18.1 * terraform-provider-external-2.0.0-150200.6.12.1 * terraform-provider-tls-3.0.0-150200.5.15.1 * terraform-provider-random-3.0.0-150200.6.15.1 * terraform-provider-helm-2.9.0-150200.6.23.1 * terraform-provider-local-2.0.0-150200.6.17.1 * terraform-provider-google-3.43.0-150200.6.12.1 * terraform-provider-null-3.0.0-150200.6.18.1 * terraform-provider-azurerm-2.32.0-150200.6.12.1 * terraform-provider-kubernetes-1.13.2-150200.6.12.1 ## References: * https://www.suse.com/security/cve/CVE-2022-41723.html * https://www.suse.com/security/cve/CVE-2025-22872.html * https://www.suse.com/security/cve/CVE-2025-32386.html * https://www.suse.com/security/cve/CVE-2025-32387.html * https://www.suse.com/security/cve/CVE-2025-47911.html * https://www.suse.com/security/cve/CVE-2025-47913.html * https://www.suse.com/security/cve/CVE-2025-47914.html * https://www.suse.com/security/cve/CVE-2025-58181.html * https://www.suse.com/security/cve/CVE-2025-58190.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-25934.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41506.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-41603.html * https://www.suse.com/security/cve/CVE-2026-41604.html * https://www.suse.com/security/cve/CVE-2026-41605.html * https://www.suse.com/security/cve/CVE-2026-41606.html * https://www.suse.com/security/cve/CVE-2026-41607.html * https://www.suse.com/security/cve/CVE-2026-41636.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-44740.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1208300 * https://bugzilla.suse.com/show_bug.cgi?id=1241030 * https://bugzilla.suse.com/show_bug.cgi?id=1241033 * https://bugzilla.suse.com/show_bug.cgi?id=1241728 * https://bugzilla.suse.com/show_bug.cgi?id=1251365 * https://bugzilla.suse.com/show_bug.cgi?id=1251559 * https://bugzilla.suse.com/show_bug.cgi?id=1253508 * https://bugzilla.suse.com/show_bug.cgi?id=1253517 * https://bugzilla.suse.com/show_bug.cgi?id=1253797 * https://bugzilla.suse.com/show_bug.cgi?id=1253799 * https://bugzilla.suse.com/show_bug.cgi?id=1253980 * https://bugzilla.suse.com/show_bug.cgi?id=1253983 * https://bugzilla.suse.com/show_bug.cgi?id=1258096 * https://bugzilla.suse.com/show_bug.cgi?id=1260139 * https://bugzilla.suse.com/show_bug.cgi?id=1260149 * https://bugzilla.suse.com/show_bug.cgi?id=1260180 * https://bugzilla.suse.com/show_bug.cgi?id=1263247 * https://bugzilla.suse.com/show_bug.cgi?id=1263313 * https://bugzilla.suse.com/show_bug.cgi?id=1263357 * https://bugzilla.suse.com/show_bug.cgi?id=1263411 * https://bugzilla.suse.com/show_bug.cgi?id=1263445 * https://bugzilla.suse.com/show_bug.cgi?id=1263515 * https://bugzilla.suse.com/show_bug.cgi?id=1263606 * https://bugzilla.suse.com/show_bug.cgi?id=1264862 * https://bugzilla.suse.com/show_bug.cgi?id=1264888 * https://bugzilla.suse.com/show_bug.cgi?id=1264938 * https://bugzilla.suse.com/show_bug.cgi?id=1266051 * https://bugzilla.suse.com/show_bug.cgi?id=1266057 * https://bugzilla.suse.com/show_bug.cgi?id=1266086 * https://bugzilla.suse.com/show_bug.cgi?id=1266112 * https://bugzilla.suse.com/show_bug.cgi?id=1266122 * https://bugzilla.suse.com/show_bug.cgi?id=1266127 * https://bugzilla.suse.com/show_bug.cgi?id=1266132 * https://bugzilla.suse.com/show_bug.cgi?id=1266150 * https://bugzilla.suse.com/show_bug.cgi?id=1266160 * https://bugzilla.suse.com/show_bug.cgi?id=1266477 * https://bugzilla.suse.com/show_bug.cgi?id=1266482 * https://bugzilla.suse.com/show_bug.cgi?id=1266541 * https://bugzilla.suse.com/show_bug.cgi?id=1266547 * https://bugzilla.suse.com/show_bug.cgi?id=1267058 * https://bugzilla.suse.com/show_bug.cgi?id=1267271 * https://bugzilla.suse.com/show_bug.cgi?id=1267273 * https://bugzilla.suse.com/show_bug.cgi?id=1267276 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:32:58 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:32:58 -0000 Subject: SUSE-SU-2026:3055-1: important: Security update for radvd Message-ID: <178414757883.406.16510958061657723275@1437f03ce14a> # Security update for radvd Announcement ID: SUSE-SU-2026:3055-1 Release Date: 2026-07-15T13:23:58Z Rating: important References: * bsc#1268641 Cross-References: * CVE-2026-48715 CVSS scores: * CVE-2026-48715 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48715 ( NVD ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48715 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for radvd fixes the following issue * CVE-2026-48715: stack-based buffer overflow in the `radvdump` Route Information option parser when processing crafted ICMPv6 Router Advertisements (bsc#1268641). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3055=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3055=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3055=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3055=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3055=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3055=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3055=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3055=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3055=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3055=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3055=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48715.html * https://bugzilla.suse.com/show_bug.cgi?id=1268641 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:05 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:33:05 -0000 Subject: SUSE-SU-2026:3054-1: important: Security update for tiff Message-ID: <178414758591.406.5071117417382525632@1437f03ce14a> # Security update for tiff Announcement ID: SUSE-SU-2026:3054-1 Release Date: 2026-07-15T13:21:52Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3054=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3054=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3054=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3054=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3054=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3054=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3054=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3054=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3054=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3054=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3054=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3054=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3054=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3054=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3054=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3054=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libtiff5-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libtiff5-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libtiff5-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * Basesystem Module 15-SP7 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:32 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:33:32 -0000 Subject: SUSE-SU-2026:3053-1: important: Security update for ImageMagick Message-ID: <178414761259.406.10222862998673142310@1437f03ce14a> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3053-1 Release Date: 2026-07-15T13:18:11Z Rating: important References: * bsc#1268640 * bsc#1268645 * bsc#1268878 * bsc#1268879 * bsc#1268880 * bsc#1269063 * bsc#1269064 * bsc#1270001 * bsc#1270002 * bsc#1270003 * bsc#1270004 * bsc#1270073 * bsc#1270074 * bsc#1270077 * bsc#1270079 * bsc#1270080 Cross-References: * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-55594 * CVE-2026-55595 * CVE-2026-55597 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56364 * CVE-2026-56365 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56370 * CVE-2026-56371 * CVE-2026-56376 * CVE-2026-56379 CVSS scores: * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55595 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56364 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56365 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56370 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56370 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56370 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56370 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56376 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56376 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 15 vulnerabilities and has one security fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of- bounds read when a crafted image is read (bsc#1270073). * CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). * CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). * CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). * CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). * CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001). * CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002). * CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). * CVE-2026-56365: memory leak in PNG encoder when writing a MNG image (bsc#1270004). * CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path can lead to an heap out-of-bounds read (bsc#1268645). * CVE-2026-56368: improper memory management can lead to memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing `connected-components:*` artifacts with invalid indices (bsc#1269063). * CVE-2026-56371: memory leak in `coders/txt.c` when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3053=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3053=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3053=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3053=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3053=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3053=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3053=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3053=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3053=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3053=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3053=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3053=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-extra-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-extra-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.96.1 * ImageMagick-devel-64bit-7.1.0.9-150400.6.96.1 * libMagick++-devel-64bit-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.96.1 * openSUSE Leap 15.4 (x86_64) * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagick++-devel-32bit-7.1.0.9-150400.6.96.1 * ImageMagick-devel-32bit-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.96.1 * openSUSE Leap 15.4 (noarch) * ImageMagick-doc-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-55594.html * https://www.suse.com/security/cve/CVE-2026-55595.html * https://www.suse.com/security/cve/CVE-2026-55597.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56364.html * https://www.suse.com/security/cve/CVE-2026-56365.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56370.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56376.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1268880 * https://bugzilla.suse.com/show_bug.cgi?id=1269063 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270003 * https://bugzilla.suse.com/show_bug.cgi?id=1270004 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 * https://bugzilla.suse.com/show_bug.cgi?id=1270077 * https://bugzilla.suse.com/show_bug.cgi?id=1270079 * https://bugzilla.suse.com/show_bug.cgi?id=1270080 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:37 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:33:37 -0000 Subject: SUSE-SU-2026:3052-1: important: Security update for containerd Message-ID: <178414761751.406.12738916048265347134@1437f03ce14a> # Security update for containerd Announcement ID: SUSE-SU-2026:3052-1 Release Date: 2026-07-15T13:12:40Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for containerd rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3052=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3052=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3052=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3052=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3052=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3052=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3052=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3052=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3052=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3052=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3052=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3052=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3052=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3052=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3052=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3052=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3052=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * containerd-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * containerd-1.7.29-150000.139.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * containerd-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * containerd-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:41 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:33:41 -0000 Subject: SUSE-SU-2026:3051-1: important: Security update for runc Message-ID: <178414762153.406.4475883162505849117@1437f03ce14a> # Security update for runc Announcement ID: SUSE-SU-2026:3051-1 Release Date: 2026-07-15T13:11:12Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for runc rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3051=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3051=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3051=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3051=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3051=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3051=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2026-3051=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3051=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3051=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3051=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3051=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3051=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3051=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3051=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3051=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3051=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3051=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:46 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:33:46 -0000 Subject: SUSE-SU-2026:3050-1: important: Security update for helm Message-ID: <178414762675.406.1074180048344338881@1437f03ce14a> # Security update for helm Announcement ID: SUSE-SU-2026:3050-1 Release Date: 2026-07-15T13:09:46Z Rating: important References: Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that can now be installed. ## Description: This update for helm rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3050=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3050=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3050=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3050=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3050=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3050=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3050=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3050=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3050=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3050=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3050=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3050=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3050=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * Containers Module 15-SP7 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:50 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:33:50 -0000 Subject: SUSE-SU-2026:3049-1: important: Security update for distribution Message-ID: <178414763078.406.1391770343300052087@1437f03ce14a> # Security update for distribution Announcement ID: SUSE-SU-2026:3049-1 Release Date: 2026-07-15T13:08:15Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for distribution rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3049=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3049=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3049=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3049=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3049=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3049=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3049=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3049=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3049=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3049=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3049=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3049=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * distribution-registry-2.8.3-150400.9.36.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * distribution-registry-2.8.3-150400.9.36.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:55 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:33:55 -0000 Subject: SUSE-SU-2026:3048-1: important: Security update for container-suseconnect Message-ID: <178414763545.406.8645679398133147775@1437f03ce14a> # Security update for container-suseconnect Announcement ID: SUSE-SU-2026:3048-1 Release Date: 2026-07-15T13:07:18Z Rating: important References: Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for container-suseconnect rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3048=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3048=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3048=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3048=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3048=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3048=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3048=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3048=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3048=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3048=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3048=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * container-suseconnect-2.5.6-150000.4.90.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:34:11 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:34:11 -0000 Subject: SUSE-SU-2026:3047-1: important: Security update for go1.26-openssl Message-ID: <178414765147.406.14426882400798856629@1437f03ce14a> # Security update for go1.26-openssl Announcement ID: SUSE-SU-2026:3047-1 Release Date: 2026-07-15T13:06:11Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1267442 * bsc#1267444 * bsc#1267450 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-27145 * CVE-2026-39822 * CVE-2026-42504 * CVE-2026-42505 * CVE-2026-42507 CVSS scores: * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities, contains two features and has three security fixes can now be installed. ## Description: This update for go1.26-openssl fixes the following issues * Update to version go1.26.5 (bsc#1255111). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). * CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3047=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3047=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3047=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3047=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3047=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3047=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3047=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3047=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.26-openssl-doc-1.26.5-150000.1.12.1 * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.26-openssl-doc-1.26.5-150000.1.12.1 * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * go1.26-openssl-doc-1.26.5-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * go1.26-openssl-doc-1.26.5-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-openssl-doc-1.26.5-150000.1.12.1 * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * go1.26-openssl-doc-1.26.5-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go1.26-openssl-doc-1.26.5-150000.1.12.1 * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * go1.26-openssl-doc-1.26.5-150000.1.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:34:30 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:34:30 -0000 Subject: SUSE-SU-2026:3046-1: important: Security update for go1.25-openssl Message-ID: <178414767068.406.14225473167591501592@1437f03ce14a> # Security update for go1.25-openssl Announcement ID: SUSE-SU-2026:3046-1 Release Date: 2026-07-15T13:05:24Z Rating: important References: * bsc#1244485 * bsc#1245878 * bsc#1259264 * bsc#1259265 * bsc#1259268 * bsc#1264394 * bsc#1267442 * bsc#1267444 * bsc#1267450 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-25679 * CVE-2026-27139 * CVE-2026-27142 * CVE-2026-27145 * CVE-2026-39822 * CVE-2026-42504 * CVE-2026-42505 * CVE-2026-42507 CVSS scores: * CVE-2026-25679 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27139 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27142 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities, contains two features and has three security fixes can now be installed. ## Description: This update for go1.25-openssl fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). * CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3046=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3046=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3046=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3046=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3046=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3046=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3046=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3046=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25679.html * https://www.suse.com/security/cve/CVE-2026-27139.html * https://www.suse.com/security/cve/CVE-2026-27142.html * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1259264 * https://bugzilla.suse.com/show_bug.cgi?id=1259265 * https://bugzilla.suse.com/show_bug.cgi?id=1259268 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:34:35 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 15 Jul 2026 20:34:35 -0000 Subject: SUSE-SU-2026:3045-1: important: Security update for rootlesskit Message-ID: <178414767537.406.10732011356981404458@1437f03ce14a> # Security update for rootlesskit Announcement ID: SUSE-SU-2026:3045-1 Release Date: 2026-07-15T13:04:39Z Rating: important References: Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that can now be installed. ## Description: This update for rootlesskit rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3045=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3045=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3045=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3045=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3045=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3045=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3045=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3045=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 08:30:23 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 08:30:23 -0000 Subject: SUSE-SU-2026:3065-1: important: Security update for the Linux Kernel (Live Patch 74 for SUSE Linux Enterprise 12 SP5) Message-ID: <178419062301.503.6889425970354496939@178315a69387> # Security update for the Linux Kernel (Live Patch 74 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3065-1 Release Date: 2026-07-15T19:04:03Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.280 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3065=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_280-default-10-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:16 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 12:30:16 -0000 Subject: SUSE-SU-2026:3067-1: important: Security update for the Linux Kernel (Live Patch 83 for SUSE Linux Enterprise 12 SP5) Message-ID: <178420501657.569.9204077307171667868@ddd703581f31> # Security update for the Linux Kernel (Live Patch 83 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3067-1 Release Date: 2026-07-16T02:04:19Z Rating: important References: * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-43037 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.310 fixes various security issues The following security issues were fixed: * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3067=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_310-default-3-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:34 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 12:30:34 -0000 Subject: SUSE-SU-2026:3066-1: important: Security update for the Linux Kernel (Live Patch 78 for SUSE Linux Enterprise 12 SP5) Message-ID: <178420503423.569.10618636443165612551@ddd703581f31> # Security update for the Linux Kernel (Live Patch 78 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3066-1 Release Date: 2026-07-15T22:33:29Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.296 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3066=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_296-default-6-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:40 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 12:30:40 -0000 Subject: SUSE-FU-2026:3072-1: low: Feature update for kio Message-ID: <178420504059.569.12465341498485275942@ddd703581f31> # Feature update for kio Announcement ID: SUSE-FU-2026:3072-1 Release Date: 2026-07-16T07:38:43Z Rating: low References: * bsc#1269569 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that has one fix can now be installed. ## Description: This update for kio fixes the following issues: * Add kio-lang to Package Hub (bsc#1269569) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3072=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3072=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * kio-lang-5.115.0-150600.3.2.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * kio-devel-debuginfo-5.115.0-150600.3.2.1 * kio-core-5.115.0-150600.3.2.1 * kio-5.115.0-150600.3.2.1 * kio-debugsource-5.115.0-150600.3.2.1 * kio-core-debuginfo-5.115.0-150600.3.2.1 * kio-debuginfo-5.115.0-150600.3.2.1 * kio-devel-5.115.0-150600.3.2.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * kio-devel-debuginfo-5.115.0-150600.3.2.1 * kio-core-5.115.0-150600.3.2.1 * kio-5.115.0-150600.3.2.1 * kio-debugsource-5.115.0-150600.3.2.1 * kio-core-debuginfo-5.115.0-150600.3.2.1 * kio-debuginfo-5.115.0-150600.3.2.1 * kio-devel-5.115.0-150600.3.2.1 * openSUSE Leap 15.6 (noarch) * kio-lang-5.115.0-150600.3.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269569 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:44 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 12:30:44 -0000 Subject: SUSE-SU-2026:3071-1: important: Security update for podman Message-ID: <178420504449.569.4077385172834998126@ddd703581f31> # Security update for podman Announcement ID: SUSE-SU-2026:3071-1 Release Date: 2026-07-16T07:23:26Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for podman rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3071=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3071=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3071=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3071=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3071=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3071=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3071=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3071=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3071=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * openSUSE Leap 15.5 (noarch) * podman-docker-4.9.5-150500.3.75.1 * Containers Module 15-SP7 (noarch) * podman-docker-4.9.5-150500.3.75.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * podman-docker-4.9.5-150500.3.75.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:48 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 12:30:48 -0000 Subject: SUSE-SU-2026:3070-1: important: Security update for podman Message-ID: <178420504878.569.9449627345372414516@ddd703581f31> # Security update for podman Announcement ID: SUSE-SU-2026:3070-1 Release Date: 2026-07-16T02:34:18Z Rating: important References: Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Server 15 SP3 An update that can now be installed. ## Description: This update for podman rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2026-3070=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3070=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * podman-4.9.5-150300.9.80.1 * podmansh-4.9.5-150300.9.80.1 * podman-debuginfo-4.9.5-150300.9.80.1 * podman-remote-4.9.5-150300.9.80.1 * podman-remote-debuginfo-4.9.5-150300.9.80.1 * openSUSE Leap 15.3 (noarch) * podman-docker-4.9.5-150300.9.80.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * podman-debuginfo-4.9.5-150300.9.80.1 * podman-4.9.5-150300.9.80.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:53 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 12:30:53 -0000 Subject: SUSE-SU-2026:3069-1: important: Security update for rekor Message-ID: <178420505304.569.11516907170949281026@ddd703581f31> # Security update for rekor Announcement ID: SUSE-SU-2026:3069-1 Release Date: 2026-07-16T02:34:04Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for rekor rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3069=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3069=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3069=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3069=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3069=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3069=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3069=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3069=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3069=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3069=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3069=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3069=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * rekor-debuginfo-1.4.3-150400.4.36.1 * rekor-1.4.3-150400.4.36.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rekor-debuginfo-1.4.3-150400.4.36.1 * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rekor-debuginfo-1.4.3-150400.4.36.1 * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rekor-debuginfo-1.4.3-150400.4.36.1 * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rekor-1.4.3-150400.4.36.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:57 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 12:30:57 -0000 Subject: SUSE-SU-2026:3068-1: important: Security update for cosign Message-ID: <178420505715.569.3278316776737257688@ddd703581f31> # Security update for cosign Announcement ID: SUSE-SU-2026:3068-1 Release Date: 2026-07-16T02:32:56Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for cosign rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3068=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3068=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3068=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3068=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3068=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3068=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3068=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3068=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3068=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3068=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3068=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3068=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * cosign-debuginfo-3.1.1-150400.3.47.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * cosign-3.1.1-150400.3.47.1 * openSUSE Leap 15.4 (noarch) * cosign-zsh-completion-3.1.1-150400.3.47.1 * cosign-bash-completion-3.1.1-150400.3.47.1 * cosign-fish-completion-3.1.1-150400.3.47.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * cosign-debuginfo-3.1.1-150400.3.47.1 * Basesystem Module 15-SP7 (noarch) * cosign-zsh-completion-3.1.1-150400.3.47.1 * cosign-bash-completion-3.1.1-150400.3.47.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * cosign-debuginfo-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * cosign-3.1.1-150400.3.47.1 * cosign-debuginfo-3.1.1-150400.3.47.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * cosign-3.1.1-150400.3.47.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:31:04 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 12:31:04 -0000 Subject: SUSE-SU-2026:2854-2: moderate: Security update for python-urllib3 Message-ID: <178420506451.569.9145931669485890395@ddd703581f31> # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:2854-2 Release Date: 2026-07-16T02:26:06Z Rating: moderate References: * bsc#1254867 * bsc#1270365 Cross-References: * CVE-2025-66471 CVSS scores: * CVE-2025-66471 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66471 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66471 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66471 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python-urllib3 fixes the following issue * Regression introduced by CVE-2025-66471 fix during file download with pySSL (bsc#1270365). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2854=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2854=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2854=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2854=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2854=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2854=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2854=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2854=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2854=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2854=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-66471.html * https://bugzilla.suse.com/show_bug.cgi?id=1254867 * https://bugzilla.suse.com/show_bug.cgi?id=1270365 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:30:08 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:30:08 -0000 Subject: SUSE-RU-2026:22662-1: moderate: Recommended update for libica Message-ID: <178421940872.660.7247378087139980730@1437f03ce14a> # Recommended update for libica Announcement ID: SUSE-RU-2026:22662-1 Release Date: 2026-07-14T10:05:33Z Rating: moderate References: * bsc#1265602 Affected Products: * SUSE Linux Enterprise Server 16.0 An update that has one fix can now be installed. ## Description: This update for libica fixes the following issues: Changes in libica: * FIPS: Extend RSA KAT coverage to 3072 and 4096 bits (bsc#1265602) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1242=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (s390x) * libica4-debuginfo-4.4.2-160000.2.1 * libica-tools-4.4.2-160000.2.1 * libica-debugsource-4.4.2-160000.2.1 * libica-devel-4.4.2-160000.2.1 * libica4-4.4.2-160000.2.1 * libica-debuginfo-4.4.2-160000.2.1 * libica-tools-debuginfo-4.4.2-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265602 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:30:17 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:30:17 -0000 Subject: SUSE-RU-2026:22661-1: moderate: Recommended update for python-matplotlib, python-tabulate Message-ID: <178421941772.660.8628724786776207513@1437f03ce14a> # Recommended update for python-matplotlib, python-tabulate Announcement ID: SUSE-RU-2026:22661-1 Release Date: 2026-07-11T20:42:58Z Rating: moderate References: * bsc#1256318 * bsc#1268243 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for python-matplotlib, python-tabulate fixes the following issues: Changes in python-matplotlib: * Skip failing tests, sync test section with slfo-main branch * TST: Use correct method of clearing mock objects * Fix: various rebuild issues with python (bsc#1268243) Changes in python-tabulate: * Skip tests failing on recent python interpreters (bsc#1256318) * Fix: various rebuild issues with python (bsc#1268243) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1217=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1217=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-tabulate-0.9.0-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-tabulate-0.9.0-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1256318 * https://bugzilla.suse.com/show_bug.cgi?id=1268243 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:30:25 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:30:25 -0000 Subject: SUSE-SU-2026:22660-1: important: Security update for python-soupsieve Message-ID: <178421942596.660.1833399553823977521@1437f03ce14a> # Security update for python-soupsieve Announcement ID: SUSE-SU-2026:22660-1 Release Date: 2026-07-14T10:43:25Z Rating: important References: * bsc#1271187 * bsc#1271188 Cross-References: * CVE-2026-49476 * CVE-2026-49477 CVSS scores: * CVE-2026-49476 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49476 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-soupsieve fixes the following issues * CVE-2026-49476: Memory Exhaustion via Large Comma-Separated Selector Lists (bsc#1271187). * CVE-2026-49477: Regular Expression Denial of Service (ReDoS) via Selector Parser (bsc#1271188). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1246=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1246=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-soupsieve-2.6-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-soupsieve-2.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49476.html * https://www.suse.com/security/cve/CVE-2026-49477.html * https://bugzilla.suse.com/show_bug.cgi?id=1271187 * https://bugzilla.suse.com/show_bug.cgi?id=1271188 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:30:39 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:30:39 -0000 Subject: SUSE-RU-2026:22659-1: important: Recommended update for suse-lifecycle Message-ID: <178421943937.660.13265770010014218920@1437f03ce14a> # Recommended update for suse-lifecycle Announcement ID: SUSE-RU-2026:22659-1 Release Date: 2026-07-14T10:41:18Z Rating: important References: * bsc#1249253 * bsc#1252470 * bsc#1252471 * bsc#1254117 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has four fixes can now be installed. ## Description: This update for suse-lifecycle fixes the following issues: * No longer use setup.py but install the script directly (bsc#1252470, bsc#1254117, bsc#1249253) * Update to version 0.9+git20260324.4c04127: * implement the check action (bsc#1252471) * When reading lifecycle data, ignore new keywords display_* * Removed project files no longer used * Add a --product switch * When loading produce definitions, always check for known life cycles * Add -d/--debug option * When a life cycle id, hide "lifecycle:" prefix if it exists ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1249=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1249=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * suse-lifecycle-0.9+git20260324.4c04127-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * suse-lifecycle-0.9+git20260324.4c04127-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1249253 * https://bugzilla.suse.com/show_bug.cgi?id=1252470 * https://bugzilla.suse.com/show_bug.cgi?id=1252471 * https://bugzilla.suse.com/show_bug.cgi?id=1254117 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:30:43 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:30:43 -0000 Subject: SUSE-RU-2026:22658-1: moderate: Recommended update for python-knack Message-ID: <178421944310.660.11390535824786622711@1437f03ce14a> # Recommended update for python-knack Announcement ID: SUSE-RU-2026:22658-1 Release Date: 2026-07-14T10:41:18Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for python-knack fixes the following issues: Changes in python-knack: * update to 0.14.0: * Declare support for Python 3.14 and drop support for Python 3.9 * Fix help text rendering for Python 3.14 argparse strict validation * Update to version 0.13.0 * Declare support for Python 3.13 (#290) * Drop Python 3.8 support (#289) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1248=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1248=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-knack-0.14.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-knack-0.14.0-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:30:48 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:30:48 -0000 Subject: SUSE-SU-2026:22657-1: moderate: Security update for python-sqlparse Message-ID: <178421944874.660.14624879766037353720@1437f03ce14a> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:22657-1 Release Date: 2026-07-14T10:41:18Z Rating: moderate References: * bsc#1268597 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for python-sqlparse fixes the following issues: Changes in python-sqlparse: * GHSA-27jp-wm6q-gp25: Limit recursion during parsing of tuples. (bsc#1268597) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1247=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1247=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-sqlparse-0.5.3-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-sqlparse-0.5.3-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:01 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:31:01 -0000 Subject: SUSE-SU-2026:22656-1: important: Security update for go1.26 Message-ID: <178421946123.660.12720520399446630755@1437f03ce14a> # Security update for go1.26 Announcement ID: SUSE-SU-2026:22656-1 Release Date: 2026-07-14T10:41:18Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 Cross-References: * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed. ## Description: This update for go1.26 fixes the following issues * Update to version go1.26.5 (bsc#1255111). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1245=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1245=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.26-race-1.26.5-160000.1.1 * go1.26-doc-1.26.5-160000.1.1 * go1.26-1.26.5-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.26-doc-1.26.5-160000.1.1 * go1.26-race-1.26.5-160000.1.1 * go1.26-1.26.5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:17 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:31:17 -0000 Subject: SUSE-SU-2026:22655-1: moderate: Security update for python-mistune Message-ID: <178421947787.660.1185882395194963479@1437f03ce14a> # Security update for python-mistune Announcement ID: SUSE-SU-2026:22655-1 Release Date: 2026-07-14T10:41:18Z Rating: moderate References: * bsc#1271082 * bsc#1271117 * bsc#1271119 * bsc#1271121 * bsc#1271125 * bsc#1271127 * bsc#1271128 * bsc#1271131 * bsc#1271132 Cross-References: * CVE-2026-44896 * CVE-2026-59922 * CVE-2026-59923 * CVE-2026-59924 * CVE-2026-59925 * CVE-2026-59926 * CVE-2026-59927 * CVE-2026-59928 * CVE-2026-59929 * CVE-2026-59930 CVSS scores: * CVE-2026-44896 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-44896 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44896 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44896 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-59922 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59922 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59922 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59923 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59923 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59923 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-59924 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59924 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59924 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59925 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59925 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59925 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59926 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59926 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59926 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59926 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-59927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59927 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59928 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59928 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59928 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59929 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59929 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-59930 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-59930 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for python-mistune fixes the following issues * CVE-2026-59922: quadratic-time parsing on long runs of some markers in `formatting.py` can lead to DoS (bsc#1271117). * CVE-2026-59923: `HTMLRenderer.safe_url()` does not block percent-encoded javascript URIs and allows for XSS (bsc#1271119). * CVE-2026-59924: improper processing of user-supplied include paths in `Include.parse()` can lead to path traversal and arbitrary file reads (bsc#1271121). * CVE-2026-59925: quadratic-time parsing on long runs of some emphasis pairs in `inline_parser` can lead to DoS (bsc#1271125). * CVE-2026-59926: improper escaping in `render_admonition()` can lead to atribute injection and XSS (bsc#1271127). * CVE-2026-59927: uncontrolled recursion when processing two markdown files that include each other can lead to a DoS (bsc#1271128). * CVE-2026-59928: quadratic-time parsing on long lists of repeated reference- link definitions in `block_parser` can lead to DoS (bsc#1271131). * CVE-2026-59929: HARMFUL_PROTOCOLS list misses legacy and chained schemes and allow arbitrary script execution in user agents (bsc#1271132). * CVE-2026-59930: the `toc` plugin and `TableOfContents` directive generate heading IDs with predictable values and allow for collisions with attacker- controlled `id="toc_N"` content (bsc#1271082). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1243=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1243=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-mistune-3.1.3-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-mistune-3.1.3-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44896.html * https://www.suse.com/security/cve/CVE-2026-59922.html * https://www.suse.com/security/cve/CVE-2026-59923.html * https://www.suse.com/security/cve/CVE-2026-59924.html * https://www.suse.com/security/cve/CVE-2026-59925.html * https://www.suse.com/security/cve/CVE-2026-59926.html * https://www.suse.com/security/cve/CVE-2026-59927.html * https://www.suse.com/security/cve/CVE-2026-59928.html * https://www.suse.com/security/cve/CVE-2026-59929.html * https://www.suse.com/security/cve/CVE-2026-59930.html * https://bugzilla.suse.com/show_bug.cgi?id=1271082 * https://bugzilla.suse.com/show_bug.cgi?id=1271117 * https://bugzilla.suse.com/show_bug.cgi?id=1271119 * https://bugzilla.suse.com/show_bug.cgi?id=1271121 * https://bugzilla.suse.com/show_bug.cgi?id=1271125 * https://bugzilla.suse.com/show_bug.cgi?id=1271127 * https://bugzilla.suse.com/show_bug.cgi?id=1271128 * https://bugzilla.suse.com/show_bug.cgi?id=1271131 * https://bugzilla.suse.com/show_bug.cgi?id=1271132 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:23 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:31:23 -0000 Subject: SUSE-RU-2026:22654-1: moderate: Recommended update for policycoreutils Message-ID: <178421948327.660.12797827944478143494@1437f03ce14a> # Recommended update for policycoreutils Announcement ID: SUSE-RU-2026:22654-1 Release Date: 2026-07-14T10:32:29Z Rating: moderate References: * bsc#1270534 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for policycoreutils fixes the following issues: Changes in policycoreutils: * Remove sandbox package as it will be provided as a separate package: selinux-sandbox (bsc#1270534) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1241=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1241=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * policycoreutils-python-utils-3.8.1-160000.4.1 * python313-policycoreutils-3.8.1-160000.4.1 * policycoreutils-lang-3.8.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * policycoreutils-newrole-3.8.1-160000.4.1 * policycoreutils-newrole-debuginfo-3.8.1-160000.4.1 * policycoreutils-3.8.1-160000.4.1 * policycoreutils-devel-3.8.1-160000.4.1 * policycoreutils-devel-debuginfo-3.8.1-160000.4.1 * policycoreutils-debuginfo-3.8.1-160000.4.1 * policycoreutils-debugsource-3.8.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * policycoreutils-newrole-3.8.1-160000.4.1 * policycoreutils-newrole-debuginfo-3.8.1-160000.4.1 * policycoreutils-3.8.1-160000.4.1 * policycoreutils-devel-3.8.1-160000.4.1 * policycoreutils-devel-debuginfo-3.8.1-160000.4.1 * policycoreutils-debuginfo-3.8.1-160000.4.1 * policycoreutils-debugsource-3.8.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * policycoreutils-python-utils-3.8.1-160000.4.1 * python313-policycoreutils-3.8.1-160000.4.1 * policycoreutils-lang-3.8.1-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270534 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:34 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:31:34 -0000 Subject: SUSE-SU-2026:22653-1: moderate: Security update for openexr Message-ID: <178421949401.660.4029822043301945628@1437f03ce14a> # Security update for openexr Announcement ID: SUSE-SU-2026:22653-1 Release Date: 2026-07-14T08:46:15Z Rating: moderate References: * bsc#1269701 * bsc#1269702 * bsc#1269703 Cross-References: * CVE-2026-54920 * CVE-2026-55059 * CVE-2026-55373 CVSS scores: * CVE-2026-54920 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55059 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-55373 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for openexr fixes the following issues * CVE-2026-54920: unchecked integer overflows in Image::resize() followed by an exception can lead to an invalid delete via uninitialized pointers (bsc#1269703). * CVE-2026-55059: row setter utilizing dataWindow.min.x instead of min.y can lead to a heap out-of-bounds write (bsc#1269702). * CVE-2026-55373: integer overflow in roundListSizeUp() wrapping a 32-bit unsigned value to zero can lead to an infinite loop (bsc#1269701). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1240=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1240=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * openexr-doc-3.2.2-160000.9.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libOpenEXR-3_2-31-3.2.2-160000.9.1 * libIex-3_2-31-debuginfo-3.2.2-160000.9.1 * libIex-3_2-31-3.2.2-160000.9.1 * openexr-3.2.2-160000.9.1 * libIlmThread-3_2-31-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-3.2.2-160000.9.1 * libOpenEXR-3_2-31-debuginfo-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-debuginfo-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-debuginfo-3.2.2-160000.9.1 * openexr-debuginfo-3.2.2-160000.9.1 * libIlmThread-3_2-31-debuginfo-3.2.2-160000.9.1 * openexr-debugsource-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-3.2.2-160000.9.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXR-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXR-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libIlmThread-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libIex-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libIex-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libOpenEXR-3_2-31-3.2.2-160000.9.1 * libIex-3_2-31-debuginfo-3.2.2-160000.9.1 * libIex-3_2-31-3.2.2-160000.9.1 * openexr-3.2.2-160000.9.1 * libIlmThread-3_2-31-3.2.2-160000.9.1 * libOpenEXR-3_2-31-debuginfo-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-debuginfo-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-debuginfo-3.2.2-160000.9.1 * openexr-debuginfo-3.2.2-160000.9.1 * libIlmThread-3_2-31-debuginfo-3.2.2-160000.9.1 * openexr-debugsource-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-3.2.2-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXR-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libIlmThread-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXR-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libIex-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libIex-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * openexr-doc-3.2.2-160000.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54920.html * https://www.suse.com/security/cve/CVE-2026-55059.html * https://www.suse.com/security/cve/CVE-2026-55373.html * https://bugzilla.suse.com/show_bug.cgi?id=1269701 * https://bugzilla.suse.com/show_bug.cgi?id=1269702 * https://bugzilla.suse.com/show_bug.cgi?id=1269703 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:38 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:31:38 -0000 Subject: SUSE-RU-2026:22652-1: moderate: Recommended update for protobuf Message-ID: <178421949807.660.3164823700255411962@1437f03ce14a> # Recommended update for protobuf Announcement ID: SUSE-RU-2026:22652-1 Release Date: 2026-07-14T08:20:34Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for protobuf fixes the following issues: * Add missing python-rpm-macros BR ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1239=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1239=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libprotoc28_3_0-debuginfo-28.3-160000.5.1 * libprotoc28_3_0-28.3-160000.5.1 * libutf8_range-28_3_0-debuginfo-28.3-160000.5.1 * libprotobuf28_3_0-debuginfo-28.3-160000.5.1 * libutf8_range-28_3_0-28.3-160000.5.1 * libprotobuf28_3_0-28.3-160000.5.1 * python313-protobuf-debuginfo-5.28.3-160000.5.1 * libprotobuf-lite28_3_0-28.3-160000.5.1 * python-protobuf-debugsource-5.28.3-160000.5.1 * python313-protobuf-5.28.3-160000.5.1 * protobuf-devel-28.3-160000.5.1 * libprotobuf-lite28_3_0-debuginfo-28.3-160000.5.1 * protobuf-debugsource-28.3-160000.5.1 * protobuf-devel-debuginfo-28.3-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * protobuf-java-28.3-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libutf8_range-28_3_0-debuginfo-28.3-160000.5.1 * libprotoc28_3_0-debuginfo-28.3-160000.5.1 * libutf8_range-28_3_0-28.3-160000.5.1 * libprotobuf28_3_0-debuginfo-28.3-160000.5.1 * libprotobuf28_3_0-28.3-160000.5.1 * libprotobuf-lite28_3_0-28.3-160000.5.1 * python-protobuf-debugsource-5.28.3-160000.5.1 * python313-protobuf-debuginfo-5.28.3-160000.5.1 * protobuf-devel-debuginfo-28.3-160000.5.1 * python313-protobuf-5.28.3-160000.5.1 * protobuf-devel-28.3-160000.5.1 * libprotobuf-lite28_3_0-debuginfo-28.3-160000.5.1 * protobuf-debugsource-28.3-160000.5.1 * libprotoc28_3_0-28.3-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * protobuf-java-28.3-160000.5.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:44 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:31:44 -0000 Subject: SUSE-SU-2026:22651-1: low: Security update for patch Message-ID: <178421950493.660.4360887217159692298@1437f03ce14a> # Security update for patch Announcement ID: SUSE-SU-2026:22651-1 Release Date: 2026-07-13T19:29:50Z Rating: low References: * bsc#1271166 * bsc#1271167 Cross-References: * CVE-2026-56288 * CVE-2026-56289 CVSS scores: * CVE-2026-56288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56288 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56288 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56289 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2026-56289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56289 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56289 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for patch fixes the following issues * CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167). * CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1236=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1236=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * patch-debuginfo-2.7.6-160000.4.1 * patch-2.7.6-160000.4.1 * patch-debugsource-2.7.6-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * patch-debuginfo-2.7.6-160000.4.1 * patch-2.7.6-160000.4.1 * patch-debugsource-2.7.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56288.html * https://www.suse.com/security/cve/CVE-2026-56289.html * https://bugzilla.suse.com/show_bug.cgi?id=1271166 * https://bugzilla.suse.com/show_bug.cgi?id=1271167 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:50 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:31:50 -0000 Subject: SUSE-SU-2026:22650-1: low: Security update for helm Message-ID: <178421951032.660.1908692588363424569@1437f03ce14a> # Security update for helm Announcement ID: SUSE-SU-2026:22650-1 Release Date: 2026-07-13T19:24:02Z Rating: low References: * bsc#1270127 Cross-References: * CVE-2026-48978 CVSS scores: * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). Changes for helm: * Update to version 3.21.2. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1235=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1235=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 s390x x86_64) * helm-debuginfo-3.21.2-160000.2.1 * helm-3.21.2-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * helm-zsh-completion-3.21.2-160000.2.1 * helm-fish-completion-3.21.2-160000.2.1 * helm-bash-completion-3.21.2-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * helm-zsh-completion-3.21.2-160000.2.1 * helm-fish-completion-3.21.2-160000.2.1 * helm-bash-completion-3.21.2-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * helm-debuginfo-3.21.2-160000.2.1 * helm-3.21.2-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48978.html * https://bugzilla.suse.com/show_bug.cgi?id=1270127 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:55 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:31:55 -0000 Subject: SUSE-RU-2026:22649-1: moderate: Recommended update for gnome-remote-desktop Message-ID: <178421951582.660.8183685950857846575@1437f03ce14a> # Recommended update for gnome-remote-desktop Announcement ID: SUSE-RU-2026:22649-1 Release Date: 2026-07-13T19:24:02Z Rating: moderate References: * bsc#1270348 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for gnome-remote-desktop fixes the following issues: * Fix strlen crash in FreeRDP caused by NULL pointer. (bsc#1270348) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1234=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1234=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gnome-remote-desktop-48.3-160000.2.1 * gnome-remote-desktop-debugsource-48.3-160000.2.1 * gnome-remote-desktop-debuginfo-48.3-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * gnome-remote-desktop-lang-48.3-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * gnome-remote-desktop-lang-48.3-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gnome-remote-desktop-debuginfo-48.3-160000.2.1 * gnome-remote-desktop-debugsource-48.3-160000.2.1 * gnome-remote-desktop-48.3-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:32:10 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:32:10 -0000 Subject: SUSE-SU-2026:22648-1: moderate: Security update for tomcat11 Message-ID: <178421953036.660.11675223991851749483@1437f03ce14a> # Security update for tomcat11 Announcement ID: SUSE-SU-2026:22648-1 Release Date: 2026-07-13T16:24:32Z Rating: moderate References: * bsc#1232390 * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for tomcat11 fixes the following issues Update to Tomcat 11.0.23. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Upgrade libtcnative to v2 (bsc#1232390) * Tomcat 11.0.23: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Lower the log level to debug when OpenSSL initialization fails in OpenSSLLifecycleListener to avoid stack traces when libssl.so is not present and to align the behavior of the isAvailable() check with the AprLifecycleListener and gracefully fail when natives are not present. (csutherl) * Fix: 70038: Cookie.clone() should also clone the internal attribute map. (markt) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix SSO cookie partitioned configuration. (remm) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Update default web.xml version to match supported Servlet specification version. (markt) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. All session cookie attributes are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This us a breaking change for the EncryptInterceptor.(markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 2.x to 2.0.15. (markt) * Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Use per connection authenticator when executing an Ant task. (remm/markt) * Update: Update Commons Daemon to 1.6.1. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update the packaged version of the Tomcat Migration Tool for Jakarta EE to 1.0.12. (markt) * Update: Update Tomcat Native to 2.0.15. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1233=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1233=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat11-doc-11.0.23-160000.1.1 * tomcat11-11.0.23-160000.1.1 * tomcat11-embed-11.0.23-160000.1.1 * tomcat11-jsvc-11.0.23-160000.1.1 * tomcat11-docs-webapp-11.0.23-160000.1.1 * tomcat11-webapps-11.0.23-160000.1.1 * tomcat11-jsp-4_0-api-11.0.23-160000.1.1 * tomcat11-lib-11.0.23-160000.1.1 * tomcat11-el-6_0-api-11.0.23-160000.1.1 * tomcat11-admin-webapps-11.0.23-160000.1.1 * tomcat11-servlet-6_1-api-11.0.23-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat11-doc-11.0.23-160000.1.1 * tomcat11-embed-11.0.23-160000.1.1 * tomcat11-jsvc-11.0.23-160000.1.1 * tomcat11-webapps-11.0.23-160000.1.1 * tomcat11-docs-webapp-11.0.23-160000.1.1 * tomcat11-jsp-4_0-api-11.0.23-160000.1.1 * tomcat11-el-6_0-api-11.0.23-160000.1.1 * tomcat11-lib-11.0.23-160000.1.1 * tomcat11-11.0.23-160000.1.1 * tomcat11-admin-webapps-11.0.23-160000.1.1 * tomcat11-servlet-6_1-api-11.0.23-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1232390 * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:32:23 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:32:23 -0000 Subject: SUSE-SU-2026:22647-1: moderate: Security update for tomcat10 Message-ID: <178421954306.660.7191400771535038829@1437f03ce14a> # Security update for tomcat10 Announcement ID: SUSE-SU-2026:22647-1 Release Date: 2026-07-13T16:24:32Z Rating: moderate References: * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for tomcat10 fixes the following issues Update to Tomcat 10.1.56. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Tomcat 10.1.56: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Fix: 70038: Cookie.clone() should also clone the internal attribute map. (markt) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. All session cookie attributes are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This is a breaking change for the EncryptInterceptor. (markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 2.x to 2.0.15. (markt) * Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Use per connection authenticator when executing an Ant task. (remm/markt) * Update: Update Commons Daemon to 1.6.1. (markt) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update the packaged version of the Tomcat Migration Tool for Jakarta EE to 1.0.12. (markt) * Update: Update Tomcat Native to 2.0.15. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1232=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1232=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat10-admin-webapps-10.1.56-160000.1.1 * tomcat10-lib-10.1.56-160000.1.1 * tomcat10-servlet-6_0-api-10.1.56-160000.1.1 * tomcat10-jsp-3_1-api-10.1.56-160000.1.1 * tomcat10-docs-webapp-10.1.56-160000.1.1 * tomcat10-webapps-10.1.56-160000.1.1 * tomcat10-jsvc-10.1.56-160000.1.1 * tomcat10-10.1.56-160000.1.1 * tomcat10-doc-10.1.56-160000.1.1 * tomcat10-el-5_0-api-10.1.56-160000.1.1 * tomcat10-embed-10.1.56-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat10-admin-webapps-10.1.56-160000.1.1 * tomcat10-lib-10.1.56-160000.1.1 * tomcat10-servlet-6_0-api-10.1.56-160000.1.1 * tomcat10-jsp-3_1-api-10.1.56-160000.1.1 * tomcat10-webapps-10.1.56-160000.1.1 * tomcat10-jsvc-10.1.56-160000.1.1 * tomcat10-docs-webapp-10.1.56-160000.1.1 * tomcat10-10.1.56-160000.1.1 * tomcat10-doc-10.1.56-160000.1.1 * tomcat10-el-5_0-api-10.1.56-160000.1.1 * tomcat10-embed-10.1.56-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:32:35 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:32:35 -0000 Subject: SUSE-SU-2026:22646-1: moderate: Security update for tomcat Message-ID: <178421955598.660.2019101202733554257@1437f03ce14a> # Security update for tomcat Announcement ID: SUSE-SU-2026:22646-1 Release Date: 2026-07-13T16:24:32Z Rating: moderate References: * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues Update to Tomcat 9.0.119. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Tomcat 9.0.119: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This is a breaking change for the EncryptInterceptor. (markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Wrong references to jakarta instead of javax. (remm) * Fix: Restore default authenticator to nullafter executing an Ant task. (remm) * Update: Update Commons Daemon to 1.6.1. (markt) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update Tomcat Native to 1.3.8. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1231=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1231=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat-lib-9.0.119-160000.1.1 * tomcat-webapps-9.0.119-160000.1.1 * tomcat-el-3_0-api-9.0.119-160000.1.1 * tomcat-9.0.119-160000.1.1 * tomcat-jsp-2_3-api-9.0.119-160000.1.1 * tomcat-embed-9.0.119-160000.1.1 * tomcat-jsvc-9.0.119-160000.1.1 * tomcat-admin-webapps-9.0.119-160000.1.1 * tomcat-servlet-4_0-api-9.0.119-160000.1.1 * tomcat-docs-webapp-9.0.119-160000.1.1 * tomcat-javadoc-9.0.119-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat-lib-9.0.119-160000.1.1 * tomcat-webapps-9.0.119-160000.1.1 * tomcat-el-3_0-api-9.0.119-160000.1.1 * tomcat-9.0.119-160000.1.1 * tomcat-jsp-2_3-api-9.0.119-160000.1.1 * tomcat-embed-9.0.119-160000.1.1 * tomcat-jsvc-9.0.119-160000.1.1 * tomcat-admin-webapps-9.0.119-160000.1.1 * tomcat-servlet-4_0-api-9.0.119-160000.1.1 * tomcat-docs-webapp-9.0.119-160000.1.1 * tomcat-javadoc-9.0.119-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:32:42 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:32:42 -0000 Subject: SUSE-SU-2026:22645-1: moderate: Security update for cryptsetup Message-ID: <178421956290.660.12578818610765186570@1437f03ce14a> # Security update for cryptsetup Announcement ID: SUSE-SU-2026:22645-1 Release Date: 2026-07-13T16:23:16Z Rating: moderate References: * bsc#1270252 * bsc#1270254 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for cryptsetup fixes the following issues: Changes in cryptsetup: * Fix for (bsc#1270254) to avoid undesired pinning of all volume keys (via the thread keyring) through the caller's credentials when the kernel opens a file. This is due to the refactoring in kernel commit a28d893eb327 ("md: port block device access to file") that accidentally causes the caller's thread keyring to be kept alive long beyond the caller's lifetime, the kernel part is tracked in (bsc#1270252). * Add keyring key type. [b6fb6fc0] * Load volume keys in intermediary keyring linked in thread keyring. [413a3dd0] * Use unique intermediary keyring name per device. [04ef07a7] * Add regression tests. [bfcb0c38, bb5e8e9f, e6573494, aa214c09] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1229=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1229=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cryptsetup-debugsource-2.8.4-160000.2.1 * cryptsetup-2.8.4-160000.2.1 * libcryptsetup12-2.8.4-160000.2.1 * cryptsetup-ssh-debuginfo-2.8.4-160000.2.1 * cryptsetup-ssh-2.8.4-160000.2.1 * libcryptsetup-devel-2.8.4-160000.2.1 * cryptsetup-debuginfo-2.8.4-160000.2.1 * libcryptsetup12-debuginfo-2.8.4-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * cryptsetup-doc-2.8.4-160000.2.1 * cryptsetup-lang-2.8.4-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * cryptsetup-doc-2.8.4-160000.2.1 * cryptsetup-lang-2.8.4-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cryptsetup-debugsource-2.8.4-160000.2.1 * cryptsetup-2.8.4-160000.2.1 * cryptsetup-ssh-debuginfo-2.8.4-160000.2.1 * libcryptsetup12-2.8.4-160000.2.1 * cryptsetup-ssh-2.8.4-160000.2.1 * libcryptsetup-devel-2.8.4-160000.2.1 * cryptsetup-debuginfo-2.8.4-160000.2.1 * libcryptsetup12-debuginfo-2.8.4-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270252 * https://bugzilla.suse.com/show_bug.cgi?id=1270254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:32:48 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:32:48 -0000 Subject: SUSE-RU-2026:22644-1: moderate: Recommended update for python-gcemetadata Message-ID: <178421956811.660.9223307572859335719@1437f03ce14a> # Recommended update for python-gcemetadata Announcement ID: SUSE-RU-2026:22644-1 Release Date: 2026-07-13T16:21:51Z Rating: moderate References: * bsc#1269423 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for python-gcemetadata fixes the following issues: * Update to version 1.1.1: * Fix UnboundLocalError when using --xml with --query (bsc#1269423) * Update comments ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1230=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1230=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python-gcemetadata-1.1.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python-gcemetadata-1.1.1-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269423 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:33:02 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:33:02 -0000 Subject: SUSE-SU-2026:22643-1: important: Security update for go1.25 Message-ID: <178421958294.660.15054565793393127132@1437f03ce14a> # Security update for go1.25 Announcement ID: SUSE-SU-2026:22643-1 Release Date: 2026-07-13T14:32:00Z Rating: important References: * bsc#1244485 * bsc#1245878 * bsc#1259264 * bsc#1259265 * bsc#1259268 * bsc#1264394 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 Cross-References: * CVE-2026-25679 * CVE-2026-27139 * CVE-2026-27142 * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-25679 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27139 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27142 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities, contains one feature and has three fixes can now be installed. ## Description: This update for go1.25 fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1228=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1228=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.25-1.25.12-160000.1.1 * go1.25-doc-1.25.12-160000.1.1 * go1.25-race-1.25.12-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-160000.1.1 * go1.25-doc-1.25.12-160000.1.1 * go1.25-race-1.25.12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25679.html * https://www.suse.com/security/cve/CVE-2026-27139.html * https://www.suse.com/security/cve/CVE-2026-27142.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1259264 * https://bugzilla.suse.com/show_bug.cgi?id=1259265 * https://bugzilla.suse.com/show_bug.cgi?id=1259268 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:33:13 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:33:13 -0000 Subject: SUSE-RU-2026:22642-1: moderate: Recommended update for go1.22-openssl, go1.23-openssl, go1.24-openssl Message-ID: <178421959327.660.2570560826092805913@1437f03ce14a> # Recommended update for go1.22-openssl, go1.23-openssl, go1.24-openssl Announcement ID: SUSE-RU-2026:22642-1 Release Date: 2026-07-13T14:05:15Z Rating: moderate References: * bsc#1245878 * bsc#1264391 * bsc#1264392 * bsc#1264393 * jsc#PED-1962 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature and has four fixes can now be installed. ## Description: This update for go1.22-openssl, go1.23-openssl, go1.24-openssl fixes the following issues: Changes in go1.22-openssl: * Packaging improvements: * Drop subpackage go1.x-libstd std library .so refs jsc#PED-1962 * Use of Go standard library as .so and -buildmode=shared is not recommended or supported by upstream Go * Subpackage go1.x-libstd was only ever built for Factory and removal does not affect SLE * No Go application packages in Factory use go1.x-libstd * Use libalternatives only on suse_version >= 1610 and keep update- alternatives support for older distributions. * Drop the update-alternatives migration path for libalternatives builds. * Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.22 dependency on update-alternatives fixes bsc#1264391 Changes in go1.23-openssl: * Packaging improvements: * Drop subpackage go1.x-libstd std library .so refs jsc#PED-1962 * Use of Go standard library as .so and -buildmode=shared is not recommended or supported by upstream Go * Subpackage go1.x-libstd was only ever built for Factory and removal does not affect SLE * No Go application packages in Factory use go1.x-libstd * Use libalternatives only on suse_version >= 1610 and keep update- alternatives support for older distributions. * Drop the update-alternatives migration path for libalternatives builds. * Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.23 dependency on update-alternatives fixes bsc#1264392 Changes in go1.24-openssl: * Packaging improvements: * Drop subpackage go1.x-libstd std library .so refs jsc#PED-1962 * Use of Go standard library as .so and -buildmode=shared is not recommended or supported by upstream Go * Subpackage go1.x-libstd was only ever built for Factory and removal does not affect SLE * No Go application packages in Factory use go1.x-libstd * Use libalternatives only on suse_version >= 1610 and keep update- alternatives support for older distributions. * Drop the update-alternatives migration path for libalternatives builds. * Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.24 dependency on update-alternatives fixes bsc#1264393 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1227=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1227=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.24-openssl-1.24.13-160000.2.1 * go1.24-openssl-debuginfo-1.24.13-160000.2.1 * go1.24-openssl-doc-1.24.13-160000.2.1 * go1.24-openssl-race-1.24.13-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.24-openssl-1.24.13-160000.2.1 * go1.24-openssl-debuginfo-1.24.13-160000.2.1 * go1.24-openssl-doc-1.24.13-160000.2.1 * go1.24-openssl-race-1.24.13-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1264391 * https://bugzilla.suse.com/show_bug.cgi?id=1264392 * https://bugzilla.suse.com/show_bug.cgi?id=1264393 * https://jira.suse.com/browse/PED-1962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:33:25 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:33:25 -0000 Subject: SUSE-SU-2026:22641-1: important: Security update for go1.26-openssl Message-ID: <178421960537.660.2532119525871444737@1437f03ce14a> # Security update for go1.26-openssl Announcement ID: SUSE-SU-2026:22641-1 Release Date: 2026-07-13T13:59:29Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities, contains two features and has three fixes can now be installed. ## Description: This update for go1.26-openssl fixes the following issues * Update to version go1.26.5 (bsc#1255111). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1225=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1225=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.26-openssl-1.26.5-160000.1.1 * go1.26-openssl-race-1.26.5-160000.1.1 * go1.26-openssl-doc-1.26.5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.26-openssl-1.26.5-160000.1.1 * go1.26-openssl-race-1.26.5-160000.1.1 * go1.26-openssl-doc-1.26.5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:33:35 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:33:35 -0000 Subject: SUSE-RU-2026:22640-1: moderate: Recommended update for adcli Message-ID: <178421961528.660.18145552279695444947@1437f03ce14a> # Recommended update for adcli Announcement ID: SUSE-RU-2026:22640-1 Release Date: 2026-07-13T13:56:55Z Rating: moderate References: * jsc#PED-16504 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for adcli fixes the following issues: Changes in adcli: * Split selinux policy to its own package * Fix issues if default keytab is used, strip 'FILE:' prefix before calling libselinux functions; Add patch Update to 0.9.3.1; (jsc#PED-16504); * fix typo in tests * add enable switches for SELinux and offline join support * include tests in release tar archive includes changes from 0.9.3: * enroll: check if AD accepts new password * enroll: allow to add SPNs to manages service accounts * enroll: add new SPNs from AD to keytab during update * conn: use 10s timeout for connect() * enroll: restore SELinux file context of keytab files * enroll: remove USE_DES_KEY_ONLY during join * entry: check user and group names for illegal characters * tools: add --recursive option to delete-computer * tools: testjoin, use realm from keytab as domain name * enroll: use realm form the HOST$ entry in the keytab * Tests: initial framework and tests for adcli based on sssd-test-framework * krb5: add adcli_krb5_get_error_message() * Various fixes for issues found by static code scanners * enroll: Populate Samba's secrets database using offline domain join ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1226=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1226=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * adcli-selinux-0.9.3.1-160000.1.1 * adcli-doc-0.9.3.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * adcli-debugsource-0.9.3.1-160000.1.1 * adcli-0.9.3.1-160000.1.1 * adcli-debuginfo-0.9.3.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * adcli-debugsource-0.9.3.1-160000.1.1 * adcli-0.9.3.1-160000.1.1 * adcli-debuginfo-0.9.3.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * adcli-selinux-0.9.3.1-160000.1.1 * adcli-doc-0.9.3.1-160000.1.1 ## References: * https://jira.suse.com/browse/PED-16504 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:33:40 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:33:40 -0000 Subject: SUSE-SU-2026:22639-1: moderate: Security update for pam Message-ID: <178421962099.660.8721433350376976978@1437f03ce14a> # Security update for pam Announcement ID: SUSE-SU-2026:22639-1 Release Date: 2026-07-13T13:54:56Z Rating: moderate References: * bsc#1268290 Cross-References: * CVE-2026-54411 CVSS scores: * CVE-2026-54411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-54411 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X * CVE-2026-54411 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for pam fixes the following issue * CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext- password comparison (bsc#1268290). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1224=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1224=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * pam-manpages-1.7.1-160000.5.1 * pam-doc-1.7.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * pam-devel-1.7.1-160000.5.1 * pam-extra-debuginfo-1.7.1-160000.5.1 * pam-extra-1.7.1-160000.5.1 * pam-debuginfo-1.7.1-160000.5.1 * pam-1.7.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x) * pam-full-src-debugsource-1.7.1-160000.5.1 * pam-debugsource-1.7.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * pam-devel-1.7.1-160000.5.1 * pam-extra-debuginfo-1.7.1-160000.5.1 * pam-extra-1.7.1-160000.5.1 * pam-debuginfo-1.7.1-160000.5.1 * pam-1.7.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le) * pam-full-src-debugsource-1.7.1-160000.5.1 * pam-debugsource-1.7.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * pam-manpages-1.7.1-160000.5.1 * pam-doc-1.7.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54411.html * https://bugzilla.suse.com/show_bug.cgi?id=1268290 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:34:36 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:34:36 -0000 Subject: SUSE-SU-2026:22638-1: critical: Security update for go1.25-openssl Message-ID: <178421967687.660.10694042496865715095@1437f03ce14a> # Security update for go1.25-openssl Announcement ID: SUSE-SU-2026:22638-1 Release Date: 2026-07-13T12:52:40Z Rating: critical References: * bsc#1170826 * bsc#1244485 * bsc#1245878 * bsc#1256818 * bsc#1257692 * bsc#1259264 * bsc#1259265 * bsc#1259268 * bsc#1261653 * bsc#1261654 * bsc#1261655 * bsc#1261656 * bsc#1261657 * bsc#1261658 * bsc#1261659 * bsc#1261660 * bsc#1261661 * bsc#1264394 * bsc#1264499 * bsc#1264500 * bsc#1264501 * bsc#1264502 * bsc#1264503 * bsc#1264504 * bsc#1264505 * bsc#1264506 * bsc#1264507 * bsc#1264508 * bsc#1264509 * bsc#1267442 * bsc#1267444 * bsc#1267450 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2025-61732 * CVE-2025-68121 * CVE-2026-25679 * CVE-2026-27139 * CVE-2026-27140 * CVE-2026-27142 * CVE-2026-27143 * CVE-2026-27144 * CVE-2026-27145 * CVE-2026-32280 * CVE-2026-32281 * CVE-2026-32282 * CVE-2026-32283 * CVE-2026-32288 * CVE-2026-32289 * CVE-2026-33811 * CVE-2026-33814 * CVE-2026-39817 * CVE-2026-39819 * CVE-2026-39820 * CVE-2026-39822 * CVE-2026-39823 * CVE-2026-39825 * CVE-2026-39826 * CVE-2026-39836 * CVE-2026-42499 * CVE-2026-42501 * CVE-2026-42504 * CVE-2026-42505 * CVE-2026-42507 CVSS scores: * CVE-2025-61732 ( SUSE ): 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-61732 ( SUSE ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-61732 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-61732 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-68121 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-68121 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-68121 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-68121 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-25679 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27139 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27140 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2026-27142 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27143 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-27144 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-27144 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32282 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32283 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32288 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-32288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-32288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-32289 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-32289 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-32289 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33811 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39817 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39817 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39817 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39819 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39819 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39819 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39820 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39823 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39823 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39825 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39825 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39826 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39826 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39836 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42501 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42501 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 30 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: This update for go1.25-openssl fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2025-61732: cmd/cgo: discrepancy between Go and C/C++ comment parsing allows for C code smuggling (bsc#1257692). * CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain (bsc#1256818). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265). * CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination (bsc#1261654). * CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking (bsc#1261655). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-32280: crypto/x509: unexpected work during chain building (bsc#1261656). * CVE-2026-32281: crypto/x509: inefficient policy validation (bsc#1261657). * CVE-2026-32282: os: Root.Chmod can follow symlinks out of the root on Linux (bsc#1261658). * CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock (bsc#1261659). * CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map (bsc#1261660). * CVE-2026-32289: html/template: JS template literal context incorrectly tracked (bsc#1261661). * CVE-2026-33811: net: crash when handling long CNAME response (bsc#1264508). * CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1264506). * CVE-2026-39817: cmd/go: "go tool pack" does not sanitize output paths (bsc#1264505). * CVE-2026-39819: cmd/go: "go bug" follows symlinks in predictable temporary filenames (bsc#1264504). * CVE-2026-39820: net/mail: quadratic string concatentation in consumeComment (bsc#1264503). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509). * CVE-2026-39825: net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters (bsc#1264500). * CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507). * CVE-2026-39836: net: panic in Dial and LookupPort when handling NUL byte on Windows (bsc#1264501). * CVE-2026-42499: net/mail: quadratic string concatenation in consumePhrase (bsc#1264502). * CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499). * CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). * CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1223=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1223=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.25-openssl-doc-1.25.12-160000.1.1 * go1.25-openssl-race-1.25.12-160000.1.1 * go1.25-openssl-debuginfo-1.25.12-160000.1.1 * go1.25-openssl-1.25.12-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.25-openssl-doc-1.25.12-160000.1.1 * go1.25-openssl-race-1.25.12-160000.1.1 * go1.25-openssl-1.25.12-160000.1.1 * go1.25-openssl-debuginfo-1.25.12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-61732.html * https://www.suse.com/security/cve/CVE-2025-68121.html * https://www.suse.com/security/cve/CVE-2026-25679.html * https://www.suse.com/security/cve/CVE-2026-27139.html * https://www.suse.com/security/cve/CVE-2026-27140.html * https://www.suse.com/security/cve/CVE-2026-27142.html * https://www.suse.com/security/cve/CVE-2026-27143.html * https://www.suse.com/security/cve/CVE-2026-27144.html * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-32280.html * https://www.suse.com/security/cve/CVE-2026-32281.html * https://www.suse.com/security/cve/CVE-2026-32282.html * https://www.suse.com/security/cve/CVE-2026-32283.html * https://www.suse.com/security/cve/CVE-2026-32288.html * https://www.suse.com/security/cve/CVE-2026-32289.html * https://www.suse.com/security/cve/CVE-2026-33811.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39817.html * https://www.suse.com/security/cve/CVE-2026-39819.html * https://www.suse.com/security/cve/CVE-2026-39820.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-39823.html * https://www.suse.com/security/cve/CVE-2026-39825.html * https://www.suse.com/security/cve/CVE-2026-39826.html * https://www.suse.com/security/cve/CVE-2026-39836.html * https://www.suse.com/security/cve/CVE-2026-42499.html * https://www.suse.com/security/cve/CVE-2026-42501.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1170826 * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1256818 * https://bugzilla.suse.com/show_bug.cgi?id=1257692 * https://bugzilla.suse.com/show_bug.cgi?id=1259264 * https://bugzilla.suse.com/show_bug.cgi?id=1259265 * https://bugzilla.suse.com/show_bug.cgi?id=1259268 * https://bugzilla.suse.com/show_bug.cgi?id=1261653 * https://bugzilla.suse.com/show_bug.cgi?id=1261654 * https://bugzilla.suse.com/show_bug.cgi?id=1261655 * https://bugzilla.suse.com/show_bug.cgi?id=1261656 * https://bugzilla.suse.com/show_bug.cgi?id=1261657 * https://bugzilla.suse.com/show_bug.cgi?id=1261658 * https://bugzilla.suse.com/show_bug.cgi?id=1261659 * https://bugzilla.suse.com/show_bug.cgi?id=1261660 * https://bugzilla.suse.com/show_bug.cgi?id=1261661 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1264499 * https://bugzilla.suse.com/show_bug.cgi?id=1264500 * https://bugzilla.suse.com/show_bug.cgi?id=1264501 * https://bugzilla.suse.com/show_bug.cgi?id=1264502 * https://bugzilla.suse.com/show_bug.cgi?id=1264503 * https://bugzilla.suse.com/show_bug.cgi?id=1264504 * https://bugzilla.suse.com/show_bug.cgi?id=1264505 * https://bugzilla.suse.com/show_bug.cgi?id=1264506 * https://bugzilla.suse.com/show_bug.cgi?id=1264507 * https://bugzilla.suse.com/show_bug.cgi?id=1264508 * https://bugzilla.suse.com/show_bug.cgi?id=1264509 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:34:48 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:34:48 -0000 Subject: SUSE-SU-2026:22637-1: important: Security update for jq Message-ID: <178421968854.660.2418495044079492784@1437f03ce14a> # Security update for jq Announcement ID: SUSE-SU-2026:22637-1 Release Date: 2026-07-13T10:47:46Z Rating: important References: * bsc#1265075 * bsc#1265076 * bsc#1269220 * bsc#1269390 Cross-References: * CVE-2026-43896 * CVE-2026-44777 * CVE-2026-49839 * CVE-2026-54679 CVSS scores: * CVE-2026-43896 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43896 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44777 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44777 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44777 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49839 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-49839 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-54679 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-54679 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues * CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075). * CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). * CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized- string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220). * CVE-2026-54679: integer overflow in jvp_string_append can lead to a buffer overrun on 32-bit systems (bsc#1269390). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1221=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1221=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jq-debugsource-1.7.1-160000.4.1 * libjq-devel-1.7.1-160000.4.1 * libjq1-1.7.1-160000.4.1 * jq-1.7.1-160000.4.1 * libjq1-debuginfo-1.7.1-160000.4.1 * jq-debuginfo-1.7.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * jq-debugsource-1.7.1-160000.4.1 * libjq-devel-1.7.1-160000.4.1 * libjq1-1.7.1-160000.4.1 * jq-1.7.1-160000.4.1 * libjq1-debuginfo-1.7.1-160000.4.1 * jq-debuginfo-1.7.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43896.html * https://www.suse.com/security/cve/CVE-2026-44777.html * https://www.suse.com/security/cve/CVE-2026-49839.html * https://www.suse.com/security/cve/CVE-2026-54679.html * https://bugzilla.suse.com/show_bug.cgi?id=1265075 * https://bugzilla.suse.com/show_bug.cgi?id=1265076 * https://bugzilla.suse.com/show_bug.cgi?id=1269220 * https://bugzilla.suse.com/show_bug.cgi?id=1269390 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:34:56 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:34:56 -0000 Subject: SUSE-SU-2026:22636-1: important: Security update for libxml2 Message-ID: <178421969602.660.5069111148914578412@1437f03ce14a> # Security update for libxml2 Announcement ID: SUSE-SU-2026:22636-1 Release Date: 2026-07-13T07:49:58Z Rating: important References: * bsc#1262719 * bsc#1269790 Cross-References: * CVE-2026-11979 * CVE-2026-6732 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6732 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6732 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6732 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6732 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libxml2 fixes the following issues * CVE-2026-6732: crafted XSD-validated document can cause a denial of service (bsc#1262719). * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1220=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1220=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-libxml2-2.13.8-160000.5.1 * libxml2-devel-2.13.8-160000.5.1 * python313-libxml2-debuginfo-2.13.8-160000.5.1 * libxml2-2-2.13.8-160000.5.1 * libxml2-debugsource-2.13.8-160000.5.1 * libxml2-tools-debuginfo-2.13.8-160000.5.1 * libxml2-python-debugsource-2.13.8-160000.5.1 * libxml2-tools-2.13.8-160000.5.1 * libxml2-2-debuginfo-2.13.8-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * libxml2-doc-2.13.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * libxml2-doc-2.13.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-libxml2-2.13.8-160000.5.1 * libxml2-devel-2.13.8-160000.5.1 * python313-libxml2-debuginfo-2.13.8-160000.5.1 * libxml2-tools-debuginfo-2.13.8-160000.5.1 * libxml2-debugsource-2.13.8-160000.5.1 * libxml2-python-debugsource-2.13.8-160000.5.1 * libxml2-2-debuginfo-2.13.8-160000.5.1 * libxml2-tools-2.13.8-160000.5.1 * libxml2-2-2.13.8-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://www.suse.com/security/cve/CVE-2026-6732.html * https://bugzilla.suse.com/show_bug.cgi?id=1262719 * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:04 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:04 -0000 Subject: SUSE-SU-2026:22635-1: moderate: Security update for php8 Message-ID: <178421970410.660.5297580429301791888@1437f03ce14a> # Security update for php8 Announcement ID: SUSE-SU-2026:22635-1 Release Date: 2026-07-12T13:00:50Z Rating: moderate References: * bsc#1270351 * bsc#1270712 Cross-References: * CVE-2026-12184 * CVE-2026-14355 CVSS scores: * CVE-2026-12184 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14355 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-14355 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14355 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14355 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for php8 fixes the following issues * Update to versio 8.4.23 * CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1219=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1219=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * php8-fpm-debuginfo-8.4.23-160000.1.1 * php8-sysvsem-8.4.23-160000.1.1 * php8-iconv-8.4.23-160000.1.1 * php8-sysvmsg-8.4.23-160000.1.1 * php8-fileinfo-8.4.23-160000.1.1 * php8-pdo-8.4.23-160000.1.1 * php8-xmlreader-debuginfo-8.4.23-160000.1.1 * php8-gd-debuginfo-8.4.23-160000.1.1 * php8-gd-8.4.23-160000.1.1 * php8-tokenizer-8.4.23-160000.1.1 * php8-soap-8.4.23-160000.1.1 * php8-openssl-8.4.23-160000.1.1 * php8-sysvmsg-debuginfo-8.4.23-160000.1.1 * php8-zip-8.4.23-160000.1.1 * php8-xmlreader-8.4.23-160000.1.1 * php8-gmp-debuginfo-8.4.23-160000.1.1 * php8-sockets-debuginfo-8.4.23-160000.1.1 * php8-bz2-8.4.23-160000.1.1 * php8-embed-debuginfo-8.4.23-160000.1.1 * php8-mbstring-debuginfo-8.4.23-160000.1.1 * php8-zlib-debuginfo-8.4.23-160000.1.1 * php8-opcache-8.4.23-160000.1.1 * php8-calendar-debuginfo-8.4.23-160000.1.1 * php8-debugsource-8.4.23-160000.1.1 * php8-zlib-8.4.23-160000.1.1 * php8-sysvshm-8.4.23-160000.1.1 * php8-embed-8.4.23-160000.1.1 * php8-posix-debuginfo-8.4.23-160000.1.1 * php8-zip-debuginfo-8.4.23-160000.1.1 * php8-embed-debugsource-8.4.23-160000.1.1 * php8-pcntl-debuginfo-8.4.23-160000.1.1 * apache2-mod_php8-debugsource-8.4.23-160000.1.1 * php8-bz2-debuginfo-8.4.23-160000.1.1 * php8-shmop-8.4.23-160000.1.1 * php8-tidy-debuginfo-8.4.23-160000.1.1 * php8-pdo-debuginfo-8.4.23-160000.1.1 * php8-bcmath-debuginfo-8.4.23-160000.1.1 * php8-xsl-8.4.23-160000.1.1 * php8-gmp-8.4.23-160000.1.1 * php8-xmlwriter-8.4.23-160000.1.1 * php8-ldap-debuginfo-8.4.23-160000.1.1 * php8-openssl-debuginfo-8.4.23-160000.1.1 * php8-phar-debuginfo-8.4.23-160000.1.1 * php8-readline-8.4.23-160000.1.1 * php8-xsl-debuginfo-8.4.23-160000.1.1 * php8-opcache-debuginfo-8.4.23-160000.1.1 * php8-soap-debuginfo-8.4.23-160000.1.1 * php8-dom-8.4.23-160000.1.1 * php8-ctype-8.4.23-160000.1.1 * php8-posix-8.4.23-160000.1.1 * php8-mysql-debuginfo-8.4.23-160000.1.1 * php8-curl-8.4.23-160000.1.1 * php8-iconv-debuginfo-8.4.23-160000.1.1 * php8-sysvshm-debuginfo-8.4.23-160000.1.1 * php8-odbc-8.4.23-160000.1.1 * php8-tokenizer-debuginfo-8.4.23-160000.1.1 * php8-dom-debuginfo-8.4.23-160000.1.1 * php8-8.4.23-160000.1.1 * php8-tidy-8.4.23-160000.1.1 * php8-dba-8.4.23-160000.1.1 * apache2-mod_php8-8.4.23-160000.1.1 * php8-snmp-8.4.23-160000.1.1 * php8-readline-debuginfo-8.4.23-160000.1.1 * php8-sodium-8.4.23-160000.1.1 * php8-fastcgi-8.4.23-160000.1.1 * php8-exif-8.4.23-160000.1.1 * php8-gettext-debuginfo-8.4.23-160000.1.1 * php8-sysvsem-debuginfo-8.4.23-160000.1.1 * php8-debuginfo-8.4.23-160000.1.1 * php8-devel-8.4.23-160000.1.1 * apache2-mod_php8-debuginfo-8.4.23-160000.1.1 * php8-phar-8.4.23-160000.1.1 * php8-enchant-debuginfo-8.4.23-160000.1.1 * php8-enchant-8.4.23-160000.1.1 * php8-calendar-8.4.23-160000.1.1 * php8-sqlite-8.4.23-160000.1.1 * php8-snmp-debuginfo-8.4.23-160000.1.1 * php8-sodium-debuginfo-8.4.23-160000.1.1 * php8-ldap-8.4.23-160000.1.1 * php8-ffi-debuginfo-8.4.23-160000.1.1 * php8-shmop-debuginfo-8.4.23-160000.1.1 * php8-fileinfo-debuginfo-8.4.23-160000.1.1 * php8-fpm-8.4.23-160000.1.1 * php8-xmlwriter-debuginfo-8.4.23-160000.1.1 * php8-pgsql-debuginfo-8.4.23-160000.1.1 * php8-ftp-debuginfo-8.4.23-160000.1.1 * php8-cli-8.4.23-160000.1.1 * php8-sockets-8.4.23-160000.1.1 * php8-ctype-debuginfo-8.4.23-160000.1.1 * php8-odbc-debuginfo-8.4.23-160000.1.1 * php8-pcntl-8.4.23-160000.1.1 * php8-pgsql-8.4.23-160000.1.1 * php8-cli-debuginfo-8.4.23-160000.1.1 * php8-dba-debuginfo-8.4.23-160000.1.1 * php8-intl-8.4.23-160000.1.1 * php8-fastcgi-debugsource-8.4.23-160000.1.1 * php8-mysql-8.4.23-160000.1.1 * php8-intl-debuginfo-8.4.23-160000.1.1 * php8-exif-debuginfo-8.4.23-160000.1.1 * php8-curl-debuginfo-8.4.23-160000.1.1 * php8-ftp-8.4.23-160000.1.1 * php8-ffi-8.4.23-160000.1.1 * php8-fastcgi-debuginfo-8.4.23-160000.1.1 * php8-gettext-8.4.23-160000.1.1 * php8-fpm-debugsource-8.4.23-160000.1.1 * php8-bcmath-8.4.23-160000.1.1 * php8-mbstring-8.4.23-160000.1.1 * php8-sqlite-debuginfo-8.4.23-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * php8-fpm-apache-8.4.23-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * php8-fpm-debuginfo-8.4.23-160000.1.1 * php8-sysvsem-8.4.23-160000.1.1 * php8-iconv-8.4.23-160000.1.1 * php8-sysvmsg-8.4.23-160000.1.1 * php8-fileinfo-8.4.23-160000.1.1 * php8-pdo-8.4.23-160000.1.1 * php8-xmlreader-debuginfo-8.4.23-160000.1.1 * php8-gd-debuginfo-8.4.23-160000.1.1 * php8-gd-8.4.23-160000.1.1 * php8-tokenizer-8.4.23-160000.1.1 * php8-soap-8.4.23-160000.1.1 * php8-openssl-8.4.23-160000.1.1 * php8-sysvmsg-debuginfo-8.4.23-160000.1.1 * php8-zip-8.4.23-160000.1.1 * php8-xmlreader-8.4.23-160000.1.1 * php8-gmp-debuginfo-8.4.23-160000.1.1 * php8-sockets-debuginfo-8.4.23-160000.1.1 * php8-bz2-8.4.23-160000.1.1 * php8-embed-debuginfo-8.4.23-160000.1.1 * php8-mbstring-debuginfo-8.4.23-160000.1.1 * php8-zlib-debuginfo-8.4.23-160000.1.1 * php8-opcache-8.4.23-160000.1.1 * php8-calendar-debuginfo-8.4.23-160000.1.1 * php8-debugsource-8.4.23-160000.1.1 * php8-zlib-8.4.23-160000.1.1 * php8-sysvshm-8.4.23-160000.1.1 * php8-embed-8.4.23-160000.1.1 * php8-posix-debuginfo-8.4.23-160000.1.1 * php8-pcntl-debuginfo-8.4.23-160000.1.1 * php8-embed-debugsource-8.4.23-160000.1.1 * apache2-mod_php8-debugsource-8.4.23-160000.1.1 * php8-zip-debuginfo-8.4.23-160000.1.1 * php8-bz2-debuginfo-8.4.23-160000.1.1 * php8-shmop-8.4.23-160000.1.1 * php8-tidy-debuginfo-8.4.23-160000.1.1 * php8-xsl-8.4.23-160000.1.1 * php8-bcmath-debuginfo-8.4.23-160000.1.1 * php8-pdo-debuginfo-8.4.23-160000.1.1 * php8-gmp-8.4.23-160000.1.1 * php8-xmlwriter-8.4.23-160000.1.1 * php8-ldap-debuginfo-8.4.23-160000.1.1 * php8-openssl-debuginfo-8.4.23-160000.1.1 * php8-phar-debuginfo-8.4.23-160000.1.1 * php8-readline-8.4.23-160000.1.1 * php8-xsl-debuginfo-8.4.23-160000.1.1 * php8-opcache-debuginfo-8.4.23-160000.1.1 * php8-ctype-8.4.23-160000.1.1 * php8-dom-8.4.23-160000.1.1 * php8-soap-debuginfo-8.4.23-160000.1.1 * php8-posix-8.4.23-160000.1.1 * php8-mysql-debuginfo-8.4.23-160000.1.1 * php8-curl-8.4.23-160000.1.1 * php8-iconv-debuginfo-8.4.23-160000.1.1 * php8-sysvshm-debuginfo-8.4.23-160000.1.1 * php8-odbc-8.4.23-160000.1.1 * php8-tokenizer-debuginfo-8.4.23-160000.1.1 * php8-dom-debuginfo-8.4.23-160000.1.1 * php8-8.4.23-160000.1.1 * php8-tidy-8.4.23-160000.1.1 * php8-dba-8.4.23-160000.1.1 * apache2-mod_php8-8.4.23-160000.1.1 * php8-snmp-8.4.23-160000.1.1 * php8-readline-debuginfo-8.4.23-160000.1.1 * php8-sodium-8.4.23-160000.1.1 * php8-fastcgi-8.4.23-160000.1.1 * php8-exif-8.4.23-160000.1.1 * php8-gettext-debuginfo-8.4.23-160000.1.1 * php8-sysvsem-debuginfo-8.4.23-160000.1.1 * php8-debuginfo-8.4.23-160000.1.1 * php8-devel-8.4.23-160000.1.1 * apache2-mod_php8-debuginfo-8.4.23-160000.1.1 * php8-phar-8.4.23-160000.1.1 * php8-enchant-debuginfo-8.4.23-160000.1.1 * php8-enchant-8.4.23-160000.1.1 * php8-calendar-8.4.23-160000.1.1 * php8-sqlite-8.4.23-160000.1.1 * php8-snmp-debuginfo-8.4.23-160000.1.1 * php8-sodium-debuginfo-8.4.23-160000.1.1 * php8-ldap-8.4.23-160000.1.1 * php8-ffi-debuginfo-8.4.23-160000.1.1 * php8-shmop-debuginfo-8.4.23-160000.1.1 * php8-fileinfo-debuginfo-8.4.23-160000.1.1 * php8-fpm-8.4.23-160000.1.1 * php8-xmlwriter-debuginfo-8.4.23-160000.1.1 * php8-pgsql-debuginfo-8.4.23-160000.1.1 * php8-ftp-debuginfo-8.4.23-160000.1.1 * php8-sockets-8.4.23-160000.1.1 * php8-cli-8.4.23-160000.1.1 * php8-ctype-debuginfo-8.4.23-160000.1.1 * php8-odbc-debuginfo-8.4.23-160000.1.1 * php8-pcntl-8.4.23-160000.1.1 * php8-pgsql-8.4.23-160000.1.1 * php8-cli-debuginfo-8.4.23-160000.1.1 * php8-dba-debuginfo-8.4.23-160000.1.1 * php8-intl-8.4.23-160000.1.1 * php8-fastcgi-debugsource-8.4.23-160000.1.1 * php8-mysql-8.4.23-160000.1.1 * php8-intl-debuginfo-8.4.23-160000.1.1 * php8-exif-debuginfo-8.4.23-160000.1.1 * php8-curl-debuginfo-8.4.23-160000.1.1 * php8-ftp-8.4.23-160000.1.1 * php8-ffi-8.4.23-160000.1.1 * php8-fastcgi-debuginfo-8.4.23-160000.1.1 * php8-gettext-8.4.23-160000.1.1 * php8-fpm-debugsource-8.4.23-160000.1.1 * php8-bcmath-8.4.23-160000.1.1 * php8-mbstring-8.4.23-160000.1.1 * php8-sqlite-debuginfo-8.4.23-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * php8-fpm-apache-8.4.23-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12184.html * https://www.suse.com/security/cve/CVE-2026-14355.html * https://bugzilla.suse.com/show_bug.cgi?id=1270351 * https://bugzilla.suse.com/show_bug.cgi?id=1270712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:08 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:08 -0000 Subject: SUSE-RU-2026:22634-1: moderate: Recommended update for flake-pilot Message-ID: <178421970801.660.12323380976917072916@1437f03ce14a> # Recommended update for flake-pilot Announcement ID: SUSE-RU-2026:22634-1 Release Date: 2026-07-12T04:39:56Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for flake-pilot fixes the following issues: * Update to version 3.1.34: * Reverse showing progress logic: Reverse the logic such that a user has to provide %progress to see the progress spinner while the pilot is working. * Update documentation * Add ECR container sources to appstore * Update to version 3.1.33: * Call tools from /usr/sbin with abspath: * Update documentation * Update examples and architecture diagram * Update to vesrion 3.1.32: * Create tap device ourselves * Update to version 3.1.31: * Require root permissions only for provisioning * Add appstore for prebuilt images * Update to version 3.1.30 * Start sshd in sci * Run sshd if present as part of the sci guest tool * Fix typo * Update to version 3.1.29: * Fix stdio/stderr and stdin channel setup * Update spec file due to new package restrictions (jsc#PCT-1054) * On SUSE new package restrictions where added to support the concept of the so called immutable mode. * Implements the suggested solution based on systemd-tmpfiles and only applies for SUSE. * Update to version 3.1.28: * Fix spec file * Require firecracker only for SUSE TW, it does not exists anywhere else * Add ai sandbox example workflow * Update documentation: * Fix language mistakes and wording ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1218=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1218=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * flake-pilot-3.1.34-160000.1.1 * flake-pilot-podman-3.1.34-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 s390x x86_64) * flake-pilot-debuginfo-3.1.34-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * flake-pilot-3.1.34-160000.1.1 * flake-pilot-podman-3.1.34-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * flake-pilot-debuginfo-3.1.34-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:11 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:11 -0000 Subject: SUSE-RU-2026:22633-1: moderate: Recommended update for keylime Message-ID: <178421971168.660.7574465759064720497@1437f03ce14a> # Recommended update for keylime Announcement ID: SUSE-RU-2026:22633-1 Release Date: 2026-07-11T20:40:04Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for keylime fixes the following issues: * Update to version 7.14.3: * tests: * Verify GET handler race condition fix with unit tests * Accept both error messages for invalid ECC points * Fix asyncio.Event() usage in shutdown tests * fix: * Handle concurrent agent deletion in verifier GET handler * Suppress type checker errors for compatibility import in types.py * Correct [A-z] regex in DM-IMA grammar STRING token * Update pre-commit isort to 8.0.1 to match tox * docs: * Empty refstate skips PCR replay and policy evaluation * Document qualifying data change for IAK certification in v2.6 * tpm: * Use only policy's relevant PCRs for event log verification * Parse TPM2B_NAME with _unpackv instead of fixed-size slice * Refactor verify_aik_with_iak to use proper TPMS_ATTEST parsing * elparsing: * Harden stderr decoding for tpm2_eventlog * Check tpm2_eventlog exit code instead of stderr * DB: Increase evidence_items.agent_id column length * [Automatic] Update Keylime base image (2026-07-02, 2026-06-01) * CI: Use PR label to disable e2e tests through Packit * [CI] Split e2e CI testing to fast and full * api: Bump pull-mode API version to 2.6 * registrar: Fix missing return after error in _bind_ak_to_iak * Fix mypy error and include runtime deps in test-requirements * Fix PUSH mode agent status tracking across restarts and recovery * Preserve FAIL status when timeout fires * Block PUSH mode FAIL to PASS auto-recovery * server: Add max_workers config to cap worker process count ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1216=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1216=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * keylime-config-7.14.3-160000.1.1 * keylime-tenant-7.14.3-160000.1.1 * keylime-logrotate-7.14.3-160000.1.1 * python313-keylime-7.14.3-160000.1.1 * keylime-registrar-7.14.3-160000.1.1 * keylime-verifier-7.14.3-160000.1.1 * keylime-firewalld-7.14.3-160000.1.1 * keylime-tpm_cert_store-7.14.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * keylime-config-7.14.3-160000.1.1 * keylime-tenant-7.14.3-160000.1.1 * python313-keylime-7.14.3-160000.1.1 * keylime-logrotate-7.14.3-160000.1.1 * keylime-registrar-7.14.3-160000.1.1 * keylime-verifier-7.14.3-160000.1.1 * keylime-firewalld-7.14.3-160000.1.1 * keylime-tpm_cert_store-7.14.3-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:15 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:15 -0000 Subject: SUSE-RU-2026:22632-1: moderate: Recommended update for vim Message-ID: <178421971566.660.13372586951978491272@1437f03ce14a> # Recommended update for vim Announcement ID: SUSE-RU-2026:22632-1 Release Date: 2026-07-11T19:14:24Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for vim fixes the following issues: * Updated to version 9.2.0725: * fixes issues ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1215=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1215=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * vim-debugsource-9.2.0725-160000.1.1 * gvim-9.2.0725-160000.1.1 * vim-9.2.0725-160000.1.1 * vim-small-9.2.0725-160000.1.1 * vim-small-debuginfo-9.2.0725-160000.1.1 * xxd-debuginfo-9.2.0725-160000.1.1 * gvim-debuginfo-9.2.0725-160000.1.1 * vim-debuginfo-9.2.0725-160000.1.1 * xxd-9.2.0725-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * vim-data-9.2.0725-160000.1.1 * vim-data-common-9.2.0725-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * vim-data-9.2.0725-160000.1.1 * vim-data-common-9.2.0725-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * vim-debugsource-9.2.0725-160000.1.1 * gvim-9.2.0725-160000.1.1 * vim-9.2.0725-160000.1.1 * vim-small-9.2.0725-160000.1.1 * vim-small-debuginfo-9.2.0725-160000.1.1 * xxd-debuginfo-9.2.0725-160000.1.1 * gvim-debuginfo-9.2.0725-160000.1.1 * vim-debuginfo-9.2.0725-160000.1.1 * xxd-9.2.0725-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:21 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:21 -0000 Subject: SUSE-SU-2026:22631-1: important: Security update for gsasl Message-ID: <178421972174.660.18294422955590314839@1437f03ce14a> # Security update for gsasl Announcement ID: SUSE-SU-2026:22631-1 Release Date: 2026-07-10T14:19:59Z Rating: important References: * bsc#1268885 Cross-References: * CVE-2026-56968 CVSS scores: * CVE-2026-56968 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-56968 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56968 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56968 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for gsasl fixes the following issue * CVE-2026-56968: improper sanitization of a short challenge in `_gsasl_ntlm_client_step` of the NTLM client can lead to memory disclosure (bsc#1268885). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1214=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1214=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libgsasl18-2.2.1-160000.4.1 * gsasl-debugsource-2.2.1-160000.4.1 * gsasl-devel-2.2.1-160000.4.1 * gsasl-debuginfo-2.2.1-160000.4.1 * gsasl-2.2.1-160000.4.1 * libgsasl18-debuginfo-2.2.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * gsasl-lang-2.2.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libgsasl18-2.2.1-160000.4.1 * gsasl-debugsource-2.2.1-160000.4.1 * gsasl-devel-2.2.1-160000.4.1 * gsasl-debuginfo-2.2.1-160000.4.1 * gsasl-2.2.1-160000.4.1 * libgsasl18-debuginfo-2.2.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * gsasl-lang-2.2.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56968.html * https://bugzilla.suse.com/show_bug.cgi?id=1268885 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:27 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:27 -0000 Subject: SUSE-SU-2026:22630-1: moderate: Security update for nghttp2 Message-ID: <178421972725.660.15486220796928232180@1437f03ce14a> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:22630-1 Release Date: 2026-07-10T13:25:42Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1213=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1213=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libnghttp2-14-1.64.0-160000.4.1 * libnghttp2-devel-1.64.0-160000.4.1 * nghttp2-1.64.0-160000.4.1 * nghttp2-debuginfo-1.64.0-160000.4.1 * libnghttp2-14-debuginfo-1.64.0-160000.4.1 * nghttp2-debugsource-1.64.0-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libnghttp2-14-1.64.0-160000.4.1 * libnghttp2-devel-1.64.0-160000.4.1 * nghttp2-1.64.0-160000.4.1 * nghttp2-debuginfo-1.64.0-160000.4.1 * libnghttp2-14-debuginfo-1.64.0-160000.4.1 * nghttp2-debugsource-1.64.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:33 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:33 -0000 Subject: SUSE-RU-2026:22629-1: important: Recommended update for ServiceReport Message-ID: <178421973307.660.1250779992000769307@1437f03ce14a> # Recommended update for ServiceReport Announcement ID: SUSE-RU-2026:22629-1 Release Date: 2026-07-10T09:55:55Z Rating: important References: * bsc#1270052 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for ServiceReport fixes the following issues: Changes in ServiceReport: * Update to version 2.2.4+git12.bc007b2 (bsc#1270052 ltc#218889): * [kdump] Fix TypeError in kdump component check Update to version 2.2.4+git11.8bf0f05: * Remove PrivateDevices=true * remove type=oneshot * add new plugin Spyre card configuration * Update to version 2.2.4+git3.f65dad0: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1209=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1209=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * ServiceReport-2.2.4+git12.bc007b2-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * ServiceReport-2.2.4+git12.bc007b2-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270052 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:36 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:36 -0000 Subject: SUSE-RU-2026:22628-1: moderate: Recommended update for python-rpm-macros Message-ID: <178421973691.660.13332022566175758834@1437f03ce14a> # Recommended update for python-rpm-macros Announcement ID: SUSE-RU-2026:22628-1 Release Date: 2026-07-10T09:54:15Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for python-rpm-macros fixes the following issues: Changes in python-rpm-macros: Update to version 20260629.bcd36db: * don't use realpath to the interpreter binary * doc: add a shot documentation text for %python_site{lib,arch}_module. * Add initial pyproject declarative buildsystem * fix: handle the situation when either `name` or `meta_name` is not found * Consolidate site directory name normalization into %__python_sitedir_name * Normalize the name of the directory * Definitions of %python_site{lib,arch}_module macros. Update to version 20260601.4a231f4: * fix: allow function of `%pythonXX_provides` w/o /usr/bin/python3 * Update python version handling in default-prjconf * Rewrite README.md to have headlines for each macro. Update to version 20260317.5e02b19: * fix: don't double escape %{**} code. * Copy libalternatives binaries from buildroot to flavorbin Update to version 20250923.c3cfac8: * Remove py_setup_args macro completely. * Move libalternative conf creation to FLAVOR_alternative_conf * Update default-prjconf for primary python: python313 * Drop python38, add python314 * Make RPM macro expansions POSIX sh-compatible ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1210=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1210=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python-rpm-generators-20260629.bcd36db-160000.1.1 * python-rpm-macros-20260629.bcd36db-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python-rpm-generators-20260629.bcd36db-160000.1.1 * python-rpm-macros-20260629.bcd36db-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:45 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:45 -0000 Subject: SUSE-SU-2026:22627-1: important: Security update for uriparser Message-ID: <178421974574.660.14514038862506866089@1437f03ce14a> # Security update for uriparser Announcement ID: SUSE-SU-2026:22627-1 Release Date: 2026-07-10T09:37:43Z Rating: important References: * bsc#1262999 * bsc#1264578 * bsc#1264579 Cross-References: * CVE-2026-42371 * CVE-2026-44927 * CVE-2026-44928 CVSS scores: * CVE-2026-42371 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42371 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42371 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42371 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44927 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-44927 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-44927 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44927 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-44928 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for uriparser fixes the following issues * CVE-2026-42371: numeric truncation in text range comparison when an application accepts URIs with a length in gigabytes (bsc#1262999). * CVE-2026-44927: truncation of `ptrdiff_t` to `int` in various places (bsc#1264578). * CVE-2026-44928: function family `EqualsUri` can misclassify two unequal URIs as equal (bsc#1264579). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1208=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1208=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * uriparser-debugsource-0.9.8-160000.5.1 * uriparser-0.9.8-160000.5.1 * liburiparser1-0.9.8-160000.5.1 * uriparser-doc-0.9.8-160000.5.1 * uriparser-debuginfo-0.9.8-160000.5.1 * liburiparser1-debuginfo-0.9.8-160000.5.1 * uriparser-devel-0.9.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * uriparser-debugsource-0.9.8-160000.5.1 * liburiparser1-0.9.8-160000.5.1 * uriparser-0.9.8-160000.5.1 * uriparser-doc-0.9.8-160000.5.1 * uriparser-debuginfo-0.9.8-160000.5.1 * liburiparser1-debuginfo-0.9.8-160000.5.1 * uriparser-devel-0.9.8-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42371.html * https://www.suse.com/security/cve/CVE-2026-44927.html * https://www.suse.com/security/cve/CVE-2026-44928.html * https://bugzilla.suse.com/show_bug.cgi?id=1262999 * https://bugzilla.suse.com/show_bug.cgi?id=1264578 * https://bugzilla.suse.com/show_bug.cgi?id=1264579 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:57 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:35:57 -0000 Subject: SUSE-SU-2026:22626-1: important: Security update for python-Pillow Message-ID: <178421975767.660.4855376557632326229@1437f03ce14a> # Security update for python-Pillow Announcement ID: SUSE-SU-2026:22626-1 Release Date: 2026-07-10T09:37:43Z Rating: important References: * bsc#1270404 * bsc#1270409 * bsc#1270410 * bsc#1270411 * bsc#1270412 Cross-References: * CVE-2026-42311 * CVE-2026-54059 * CVE-2026-54060 * CVE-2026-55379 * CVE-2026-55380 CVSS scores: * CVE-2026-42311 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42311 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42311 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42311 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-54059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues * CVE-2026-42311: malicious PSD file processing can lead to arbitrary code execution (bsc#1270404). * CVE-2026-54059: crafted PCF font data can cause excessive memory allocation (bsc#1270409). * CVE-2026-54060: fonts can trigger excessive memory allocation during conversion or saving (bsc#1270410). * CVE-2026-55379: bypass of decompression bomb protection allows excessive memory allocation (bsc#1270411). * CVE-2026-55380: crafted `.gd` file can trigger excessive C-heap allocation when loaded (bsc#1270412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1207=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1207=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-Pillow-tk-11.3.0-160000.6.1 * python313-Pillow-11.3.0-160000.6.1 * python313-Pillow-debuginfo-11.3.0-160000.6.1 * python-Pillow-debuginfo-11.3.0-160000.6.1 * python-Pillow-debugsource-11.3.0-160000.6.1 * python313-Pillow-tk-debuginfo-11.3.0-160000.6.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-Pillow-tk-11.3.0-160000.6.1 * python313-Pillow-11.3.0-160000.6.1 * python313-Pillow-debuginfo-11.3.0-160000.6.1 * python-Pillow-debuginfo-11.3.0-160000.6.1 * python-Pillow-debugsource-11.3.0-160000.6.1 * python313-Pillow-tk-debuginfo-11.3.0-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42311.html * https://www.suse.com/security/cve/CVE-2026-54059.html * https://www.suse.com/security/cve/CVE-2026-54060.html * https://www.suse.com/security/cve/CVE-2026-55379.html * https://www.suse.com/security/cve/CVE-2026-55380.html * https://bugzilla.suse.com/show_bug.cgi?id=1270404 * https://bugzilla.suse.com/show_bug.cgi?id=1270409 * https://bugzilla.suse.com/show_bug.cgi?id=1270410 * https://bugzilla.suse.com/show_bug.cgi?id=1270411 * https://bugzilla.suse.com/show_bug.cgi?id=1270412 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:03 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:36:03 -0000 Subject: SUSE-SU-2026:22625-1: important: Security update for yelp Message-ID: <178421976329.660.5016621222697619091@1437f03ce14a> # Security update for yelp Announcement ID: SUSE-SU-2026:22625-1 Release Date: 2026-07-10T09:31:14Z Rating: important References: * bsc#1269625 Cross-References: * CVE-2026-13601 CVSS scores: * CVE-2026-13601 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-13601 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issue * CVE-2026-13601: overly permissive Content Security Policy allows host file disclosure via Flatpak applications (bsc#1269625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1206=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1206=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * yelp-42.3-160000.3.1 * libyelp0-42.3-160000.3.1 * yelp-debuginfo-42.3-160000.3.1 * yelp-debugsource-42.3-160000.3.1 * libyelp0-debuginfo-42.3-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * yelp-lang-42.3-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * yelp-lang-42.3-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * yelp-42.3-160000.3.1 * libyelp0-42.3-160000.3.1 * yelp-debuginfo-42.3-160000.3.1 * yelp-debugsource-42.3-160000.3.1 * libyelp0-debuginfo-42.3-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13601.html * https://bugzilla.suse.com/show_bug.cgi?id=1269625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:21 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:36:21 -0000 Subject: SUSE-SU-2026:22624-1: important: Security update for python-cryptography Message-ID: <178421978178.660.2729818290441571654@1437f03ce14a> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:22624-1 Release Date: 2026-07-10T09:12:46Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1205=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1205=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-cryptography-debuginfo-44.0.3-160000.4.1 * python-cryptography-debugsource-44.0.3-160000.4.1 * python313-cryptography-44.0.3-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-cryptography-debuginfo-44.0.3-160000.4.1 * python-cryptography-debugsource-44.0.3-160000.4.1 * python313-cryptography-44.0.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:29 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:36:29 -0000 Subject: SUSE-SU-2026:22623-1: important: Security update for perl-DBI Message-ID: <178421978925.660.10122411757000414089@1437f03ce14a> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:22623-1 Release Date: 2026-07-10T09:10:39Z Rating: important References: * bsc#1271017 * bsc#1271018 Cross-References: * CVE-2026-14380 * CVE-2026-14740 CVSS scores: * CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). * CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1204=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1204=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.647.0-160000.4.1 * perl-DBI-1.647.0-160000.4.1 * perl-DBI-debuginfo-1.647.0-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-DBI-debugsource-1.647.0-160000.4.1 * perl-DBI-1.647.0-160000.4.1 * perl-DBI-debuginfo-1.647.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14380.html * https://www.suse.com/security/cve/CVE-2026-14740.html * https://bugzilla.suse.com/show_bug.cgi?id=1271017 * https://bugzilla.suse.com/show_bug.cgi?id=1271018 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:42 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:36:42 -0000 Subject: SUSE-SU-2026:22622-1: important: Security update for agama Message-ID: <178421980287.660.5493725747787353298@1437f03ce14a> # Security update for agama Announcement ID: SUSE-SU-2026:22622-1 Release Date: 2026-07-10T09:03:03Z Rating: important References: * bsc#1270526 * bsc#1270602 * bsc#1270678 * bsc#1270784 * bsc#1270850 * bsc#1270891 * bsc#1270992 Cross-References: * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for agama fixes the following issues * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270602). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270678). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270784). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270850). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270526). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270891). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270992). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1203=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1203=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * agama-debuginfo-17+647.daf9950fc-160000.12.1 * agama-debugsource-17+647.daf9950fc-160000.12.1 * agama-scripts-17+647.daf9950fc-160000.12.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * agama-debuginfo-17+647.daf9950fc-160000.12.1 * agama-debugsource-17+647.daf9950fc-160000.12.1 * agama-scripts-17+647.daf9950fc-160000.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270526 * https://bugzilla.suse.com/show_bug.cgi?id=1270602 * https://bugzilla.suse.com/show_bug.cgi?id=1270678 * https://bugzilla.suse.com/show_bug.cgi?id=1270784 * https://bugzilla.suse.com/show_bug.cgi?id=1270850 * https://bugzilla.suse.com/show_bug.cgi?id=1270891 * https://bugzilla.suse.com/show_bug.cgi?id=1270992 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:49 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:36:49 -0000 Subject: SUSE-SU-2026:22621-1: important: Security update for sssd Message-ID: <178421980972.660.11537961043300639360@1437f03ce14a> # Security update for sssd Announcement ID: SUSE-SU-2026:22621-1 Release Date: 2026-07-10T08:58:36Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1201=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1201=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * sssd-ldap-debuginfo-2.10.2-160000.3.1 * sssd-winbind-idmap-2.10.2-160000.3.1 * sssd-kcm-debuginfo-2.10.2-160000.3.1 * sssd-ad-debuginfo-2.10.2-160000.3.1 * python3-sss_nss_idmap-2.10.2-160000.3.1 * libsss_nss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-2.10.2-160000.3.1 * libipa_hbac0-2.10.2-160000.3.1 * libipa_hbac-devel-2.10.2-160000.3.1 * libsss_certmap0-debuginfo-2.10.2-160000.3.1 * sssd-winbind-idmap-debuginfo-2.10.2-160000.3.1 * sssd-ipa-2.10.2-160000.3.1 * sssd-krb5-common-debuginfo-2.10.2-160000.3.1 * sssd-kcm-2.10.2-160000.3.1 * libsss_idmap-devel-2.10.2-160000.3.1 * python3-ipa_hbac-2.10.2-160000.3.1 * libsss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-debuginfo-2.10.2-160000.3.1 * sssd-proxy-2.10.2-160000.3.1 * sssd-krb5-common-2.10.2-160000.3.1 * sssd-dbus-2.10.2-160000.3.1 * libnfsidmap-sss-2.10.2-160000.3.1 * python3-sss-murmur-2.10.2-160000.3.1 * sssd-tools-2.10.2-160000.3.1 * libsss_certmap0-2.10.2-160000.3.1 * sssd-dbus-debuginfo-2.10.2-160000.3.1 * sssd-ipa-debuginfo-2.10.2-160000.3.1 * sssd-debugsource-2.10.2-160000.3.1 * sssd-ldap-2.10.2-160000.3.1 * sssd-krb5-2.10.2-160000.3.1 * sssd-tools-debuginfo-2.10.2-160000.3.1 * libsss_idmap0-debuginfo-2.10.2-160000.3.1 * sssd-2.10.2-160000.3.1 * libsss_nss_idmap-devel-2.10.2-160000.3.1 * sssd-krb5-debuginfo-2.10.2-160000.3.1 * libsss_certmap-devel-2.10.2-160000.3.1 * sssd-debuginfo-2.10.2-160000.3.1 * sssd-proxy-debuginfo-2.10.2-160000.3.1 * libsss_nss_idmap0-debuginfo-2.10.2-160000.3.1 * python3-sss_nss_idmap-debuginfo-2.10.2-160000.3.1 * python3-sss-murmur-debuginfo-2.10.2-160000.3.1 * libipa_hbac0-debuginfo-2.10.2-160000.3.1 * sssd-ad-2.10.2-160000.3.1 * libnfsidmap-sss-debuginfo-2.10.2-160000.3.1 * python3-ipa_hbac-debuginfo-2.10.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * sssd-ldap-debuginfo-2.10.2-160000.3.1 * sssd-winbind-idmap-2.10.2-160000.3.1 * sssd-kcm-debuginfo-2.10.2-160000.3.1 * sssd-ad-debuginfo-2.10.2-160000.3.1 * python3-sss_nss_idmap-2.10.2-160000.3.1 * libsss_nss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-2.10.2-160000.3.1 * libipa_hbac0-2.10.2-160000.3.1 * libipa_hbac-devel-2.10.2-160000.3.1 * libsss_certmap0-debuginfo-2.10.2-160000.3.1 * sssd-winbind-idmap-debuginfo-2.10.2-160000.3.1 * sssd-ipa-2.10.2-160000.3.1 * libsss_idmap-devel-2.10.2-160000.3.1 * sssd-kcm-2.10.2-160000.3.1 * sssd-krb5-common-debuginfo-2.10.2-160000.3.1 * python3-ipa_hbac-2.10.2-160000.3.1 * libsss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-debuginfo-2.10.2-160000.3.1 * sssd-proxy-2.10.2-160000.3.1 * sssd-krb5-common-2.10.2-160000.3.1 * sssd-dbus-2.10.2-160000.3.1 * python3-sss-murmur-2.10.2-160000.3.1 * libnfsidmap-sss-2.10.2-160000.3.1 * sssd-tools-2.10.2-160000.3.1 * libsss_certmap0-2.10.2-160000.3.1 * sssd-dbus-debuginfo-2.10.2-160000.3.1 * sssd-ipa-debuginfo-2.10.2-160000.3.1 * sssd-debugsource-2.10.2-160000.3.1 * sssd-ldap-2.10.2-160000.3.1 * sssd-krb5-2.10.2-160000.3.1 * sssd-tools-debuginfo-2.10.2-160000.3.1 * libsss_idmap0-debuginfo-2.10.2-160000.3.1 * libsss_nss_idmap-devel-2.10.2-160000.3.1 * sssd-krb5-debuginfo-2.10.2-160000.3.1 * sssd-2.10.2-160000.3.1 * libsss_certmap-devel-2.10.2-160000.3.1 * sssd-debuginfo-2.10.2-160000.3.1 * sssd-proxy-debuginfo-2.10.2-160000.3.1 * libsss_nss_idmap0-debuginfo-2.10.2-160000.3.1 * python3-sss-murmur-debuginfo-2.10.2-160000.3.1 * python3-sss_nss_idmap-debuginfo-2.10.2-160000.3.1 * libipa_hbac0-debuginfo-2.10.2-160000.3.1 * sssd-ad-2.10.2-160000.3.1 * libnfsidmap-sss-debuginfo-2.10.2-160000.3.1 * python3-ipa_hbac-debuginfo-2.10.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:10 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:37:10 -0000 Subject: SUSE-SU-2026:22620-1: important: Security update for ImageMagick Message-ID: <178421983013.660.10094665879152576466@1437f03ce14a> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:22620-1 Release Date: 2026-07-10T08:56:16Z Rating: important References: * bsc#1268640 * bsc#1268878 * bsc#1270001 * bsc#1270002 * bsc#1270003 * bsc#1270073 * bsc#1270074 * bsc#1270077 * bsc#1270079 * bsc#1270080 * bsc#1271099 Cross-References: * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-55594 * CVE-2026-55595 * CVE-2026-55597 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56364 * CVE-2026-56374 * CVE-2026-56379 CVSS scores: * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55595 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56364 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56374 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56374 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56374 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56374 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 10 vulnerabilities and has one fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of- bounds read when a crafted image is read (bsc#1270073). * CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). * CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). * CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). * CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). * CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001). * CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002). * CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). * CVE-2026-56374: missing boundary checks can lead to a heap buffer overflow in the FTXT encoder when parsing `ftxt:format` (bsc#1271099). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1202=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1202=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * ImageMagick-7.1.2.0-160000.11.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.11.1 * libMagick++-devel-7.1.2.0-160000.11.1 * ImageMagick-debugsource-7.1.2.0-160000.11.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.11.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.11.1 * perl-PerlMagick-7.1.2.0-160000.11.1 * ImageMagick-devel-7.1.2.0-160000.11.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.11.1 * ImageMagick-debuginfo-7.1.2.0-160000.11.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.11.1 * ImageMagick-extra-7.1.2.0-160000.11.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.11.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.11.1 * libMagick++-7_Q16HDRI5-7.1.2.0-160000.11.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.11.1 * ImageMagick-doc-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.11.1 * ImageMagick-config-7-SUSE-7.1.2.0-160000.11.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * ImageMagick-7.1.2.0-160000.11.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.11.1 * libMagick++-devel-7.1.2.0-160000.11.1 * ImageMagick-debugsource-7.1.2.0-160000.11.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.11.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.11.1 * perl-PerlMagick-7.1.2.0-160000.11.1 * ImageMagick-devel-7.1.2.0-160000.11.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.11.1 * ImageMagick-debuginfo-7.1.2.0-160000.11.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.11.1 * ImageMagick-extra-7.1.2.0-160000.11.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.11.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.11.1 * libMagick++-7_Q16HDRI5-7.1.2.0-160000.11.1 * SUSE Linux Enterprise Server 16.0 (noarch) * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.11.1 * ImageMagick-doc-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.11.1 * ImageMagick-config-7-SUSE-7.1.2.0-160000.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-55594.html * https://www.suse.com/security/cve/CVE-2026-55595.html * https://www.suse.com/security/cve/CVE-2026-55597.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56364.html * https://www.suse.com/security/cve/CVE-2026-56374.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270003 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 * https://bugzilla.suse.com/show_bug.cgi?id=1270077 * https://bugzilla.suse.com/show_bug.cgi?id=1270079 * https://bugzilla.suse.com/show_bug.cgi?id=1270080 * https://bugzilla.suse.com/show_bug.cgi?id=1271099 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:14 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:37:14 -0000 Subject: SUSE-RU-2026:22619-1: moderate: Recommended update for fontforge Message-ID: <178421983412.660.2129617223142969142@1437f03ce14a> # Recommended update for fontforge Announcement ID: SUSE-RU-2026:22619-1 Release Date: 2026-07-10T08:53:56Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for fontforge fixes the following issues: * Fix buffer overflow in SCDefWidthVal() function * Fix crash in LoadPluginMetadata when distribution not found * Don't DECREF borrowed reference from PyDict_GetItemString * Fix memory leak: DECREF globals and locals dictionaries * Handle Py_None return (not just NULL) when no distribution matches * Print original Python exception if present, then set formatted error * Use importlib in plugin manager: * fixing LoadPluginMetadata crash * Fix memory allocation in utf8toutf7_copy() function * Fix crashes on importing Mac-style dfont/NFNT bitmap fonts with some legal values ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1198=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1198=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * fontforge-devel-20251009-160000.3.1 * fontforge-debuginfo-20251009-160000.3.1 * fontforge-debugsource-20251009-160000.3.1 * fontforge-20251009-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * fontforge-doc-20251009-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * fontforge-devel-20251009-160000.3.1 * fontforge-debuginfo-20251009-160000.3.1 * fontforge-debugsource-20251009-160000.3.1 * fontforge-20251009-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * fontforge-doc-20251009-160000.3.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:17 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:37:17 -0000 Subject: SUSE-RU-2026:22618-1: moderate: Recommended update for valgrind Message-ID: <178421983795.660.16645396352564712002@1437f03ce14a> # Recommended update for valgrind Announcement ID: SUSE-RU-2026:22618-1 Release Date: 2026-07-10T08:53:56Z Rating: moderate References: * jsc#PED-15483 * jsc#PED-15782 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains two features can now be installed. ## Description: This update for valgrind fixes the following issues: * update to 3.27.1 (jsc#PED-15483): * valgrind 3.27 "\--fair-sched=yes" does not work * Valgrind incorrectly unpacks the result of sys_port (port_getn) * on error, leading to a ~60s wallclock time delay on every call * n-i-bz Update vg-lifespan (copyright) years * n-i-bz Use SSizeT for VG_(readlink) result in VG_(realpath) * update to 3.27.0: * VALGRIND_REPLACES_MALLOC Returns 1 if the tool replaces malloc. * VALGRIND_GET_TOOLNAME Get the running tool name as a string. Takes two arguments, an input buffer pointer and the length of that buffer. * linux lightweight guard pages (madvise MADV_GUARD_INSTALL) supported * glibc 2.42+ (with linux 6.13+) uses MADV_GUARD_INSTALL to setup stack guard pages. These lightweight guard pages are now supported under valgrind. * If --max-guard-pages is not set explicitly, then it will default to the --max-threads setting. * \--num-callers now has a minimum value of 2. * x86: Support for SSE4.1 instructions has been ported from AMD64 to (32bit) x86. * s390x: Machine models older than z196 are no longer supported. * s390x: Support new z/Architecture features from the 15th edition. * remove 32bit for all SLES 16 based products (jsc#PED-15782) * update to 3.26.0: * Upgrade to the GNU General Public License version 3. * Control building documentation. When using make dist set the Makefile BUILD_DOCS to none, all or html. none, does not build any documentation. * New VEX API function LibVEX_set_VexControl * The deprecated IROps: Iop_Clz32/64 and Iop_Ctz32/64 have been removed * The Linux Test Project (LTP) integration has been updated to v20250930. * \--modify-fds=yes has been added. It acts like --modify-fds=high (the highest available file descriptor is returned first) except when when the lowers stdin/stdout/stderr (file descriptors 0, 1, 2) are available. * With --xml=yes log output protocol 6 is now always used. * Add "bad" option for --track-fds. When --track-fds=bad is specified, do not produce errors about unclosed file descriptors at program exit. * vgdb will now handle the qExecAndArgs packet. * DWARF inlined subroutine handling has been rewritten to work cross compile units. * updated keyring from https://www.klomp.org/mark/gnupg-pub.txt * Enable build on riscv64 * Fix file list ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1197=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1197=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * valgrind-debuginfo-3.27.1-160000.1.1 * valgrind-3.27.1-160000.1.1 * valgrind-debugsource-3.27.1-160000.1.1 * valgrind-devel-3.27.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * valgrind-client-headers-3.27.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * valgrind-debuginfo-3.27.1-160000.1.1 * valgrind-debugsource-3.27.1-160000.1.1 * valgrind-3.27.1-160000.1.1 * valgrind-devel-3.27.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * valgrind-client-headers-3.27.1-160000.1.1 ## References: * https://jira.suse.com/browse/PED-15483 * https://jira.suse.com/browse/PED-15782 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:24 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:37:24 -0000 Subject: SUSE-SU-2026:22617-1: important: Security update for xwayland Message-ID: <178421984498.660.11968586809218654448@1437f03ce14a> # Security update for xwayland Announcement ID: SUSE-SU-2026:22617-1 Release Date: 2026-07-10T08:53:56Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56000 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1194=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1194=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * xwayland-debuginfo-24.1.6-160000.6.1 * xwayland-debugsource-24.1.6-160000.6.1 * xwayland-24.1.6-160000.6.1 * xwayland-devel-24.1.6-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * xwayland-devel-24.1.6-160000.6.1 * xwayland-debugsource-24.1.6-160000.6.1 * xwayland-debuginfo-24.1.6-160000.6.1 * xwayland-24.1.6-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:32 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:37:32 -0000 Subject: SUSE-SU-2026:22616-1: important: Security update for tiff Message-ID: <178421985241.660.9805369869909094490@1437f03ce14a> # Security update for tiff Announcement ID: SUSE-SU-2026:22616-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 * CVE-2026-4775 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-4775 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4775 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Changes for tiff: * Update to 4.7.2: Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss- fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg- turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss- fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1200=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1200=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * tiff-4.7.2-160000.1.1 * tiff-debugsource-4.7.2-160000.1.1 * tiff-debuginfo-4.7.2-160000.1.1 * libtiff6-4.7.2-160000.1.1 * libtiff6-debuginfo-4.7.2-160000.1.1 * libtiff-devel-4.7.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * tiff-4.7.2-160000.1.1 * tiff-debugsource-4.7.2-160000.1.1 * tiff-debuginfo-4.7.2-160000.1.1 * libtiff6-4.7.2-160000.1.1 * libtiff6-debuginfo-4.7.2-160000.1.1 * libtiff-devel-4.7.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://www.suse.com/security/cve/CVE-2026-4775.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:50 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:37:50 -0000 Subject: SUSE-SU-2026:22615-1: important: Security update for python-maturin Message-ID: <178421987016.660.8259607681391409821@1437f03ce14a> # Security update for python-maturin Announcement ID: SUSE-SU-2026:22615-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-maturin fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1196=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1196=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-maturin-1.8.7-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-maturin-1.8.7-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:58 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:37:58 -0000 Subject: SUSE-SU-2026:22614-1: important: Security update for libXfont2 Message-ID: <178421987894.660.11510848718200399855@1437f03ce14a> # Security update for libXfont2 Announcement ID: SUSE-SU-2026:22614-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1269018 * bsc#1269019 * bsc#1269020 Cross-References: * CVE-2026-56001 * CVE-2026-56002 * CVE-2026-56003 CVSS scores: * CVE-2026-56001 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56001 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56001 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56001 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56002 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56002 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56002 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56002 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56003 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56003 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56003 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56003 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for libXfont2 fixes the following issues * CVE-2026-56001: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (bsc#1269018). * CVE-2026-56002: PCF Font Parsing Heap Buffer Overflow (bsc#1269019). * CVE-2026-56003: computeProps Property Buffer Heap Buffer Overflow (bsc#1269020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1195=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1195=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libXfont2-debugsource-2.0.7-160000.4.1 * libXfont2-2-2.0.7-160000.4.1 * libXfont2-devel-2.0.7-160000.4.1 * libXfont2-2-debuginfo-2.0.7-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libXfont2-debugsource-2.0.7-160000.4.1 * libXfont2-2-2.0.7-160000.4.1 * libXfont2-devel-2.0.7-160000.4.1 * libXfont2-2-debuginfo-2.0.7-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56001.html * https://www.suse.com/security/cve/CVE-2026-56002.html * https://www.suse.com/security/cve/CVE-2026-56003.html * https://bugzilla.suse.com/show_bug.cgi?id=1269018 * https://bugzilla.suse.com/show_bug.cgi?id=1269019 * https://bugzilla.suse.com/show_bug.cgi?id=1269020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:38:07 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:38:07 -0000 Subject: SUSE-SU-2026:22613-1: important: Security update for cosign Message-ID: <178421988726.660.3172729239406571136@1437f03ce14a> # Security update for cosign Announcement ID: SUSE-SU-2026:22613-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1261811 * bsc#1266049 * bsc#1267044 Cross-References: * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33815 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33815 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-33815 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-33815 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for cosign fixes the following issues * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: multiple issues when parsing HTML files (bsc#1267044). * CVE-2026-33815: memory-safety vulnerability (bsc#1261811). * CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833,CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: Fixed multiple issues in golang.org/x/crypto/ssh. (bsc#1266049). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1192=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1192=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cosign-debuginfo-3.1.1-160000.1.1 * cosign-3.1.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cosign-debuginfo-3.1.1-160000.1.1 * cosign-3.1.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33815.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1261811 * https://bugzilla.suse.com/show_bug.cgi?id=1266049 * https://bugzilla.suse.com/show_bug.cgi?id=1267044 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:38:11 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:38:11 -0000 Subject: SUSE-RU-2026:22612-1: moderate: Recommended update for meson Message-ID: <178421989116.660.4538562813832924893@1437f03ce14a> # Recommended update for meson Announcement ID: SUSE-RU-2026:22612-1 Release Date: 2026-07-10T08:44:43Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for meson fixes the following issues: * Fix shebang in /usr/bin/meson and meson.build depends on /usr/bin/python3 from python3-base package. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1199=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1199=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * meson-1.8.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * meson-1.8.1-160000.3.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:38:29 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:38:29 -0000 Subject: SUSE-SU-2026:3075-1: important: Security update for the Linux Kernel (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Message-ID: <178421990905.660.18133089305235553521@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3075-1 Release Date: 2026-07-16T10:03:56Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.55 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3075=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_55-default-2-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_15-debugsource-2-150700.2.2 * kernel-livepatch-6_4_0-150700_53_55-default-debuginfo-2-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:38:37 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:38:37 -0000 Subject: SUSE-SU-2026:3074-1: moderate: Security update for libssh2_org Message-ID: <178421991717.660.7750561659175587242@1437f03ce14a> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:3074-1 Release Date: 2026-07-16T09:59:26Z Rating: moderate References: * bsc#1227490 * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for libssh2_org fixes the following issue Security changes: * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). Other changes: * rebuild libssh2_org against openssl 1.1.1, enabling ed25519 support. (bsc#1227490) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3074=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3074=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3074=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3074=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3074=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3074=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3074=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3074=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3074=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3074=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3074=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3074=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3074=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1227490 * https://bugzilla.suse.com/show_bug.cgi?id=1268530 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:38:43 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 16:38:43 -0000 Subject: SUSE-RU-2026:3073-1: moderate: Recommended update for apparmor Message-ID: <178421992314.660.9438091393287982673@1437f03ce14a> # Recommended update for apparmor Announcement ID: SUSE-RU-2026:3073-1 Release Date: 2026-07-16T08:46:05Z Rating: moderate References: * jsc#PED-16287 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that contains one feature can now be installed. ## Description: This update for apparmor fixes the following issues: * Newer dnsmasq needs "CAP_CHOWN" for the PID file. (jsc#PED-16287) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3073=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3073=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * apparmor-utils-2.8.2-56.29.1 * apparmor-profiles-2.8.2-56.29.1 * apparmor-docs-2.8.2-56.29.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * apache2-mod_apparmor-2.8.2-56.29.1 * libapparmor-devel-2.8.2-56.29.1 * pam_apparmor-2.8.2-56.29.1 * perl-apparmor-2.8.2-56.29.1 * perl-apparmor-debuginfo-2.8.2-56.29.1 * apparmor-debugsource-2.8.2-56.29.1 * apache2-mod_apparmor-debuginfo-2.8.2-56.29.1 * apparmor-parser-debuginfo-2.8.2-56.29.1 * apparmor-parser-2.8.2-56.29.1 * libapparmor1-debuginfo-2.8.2-56.29.1 * libapparmor1-2.8.2-56.29.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * pam_apparmor-debuginfo-2.8.2-56.29.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * pam_apparmor-debuginfo-32bit-2.8.2-56.29.1 * libapparmor1-debuginfo-32bit-2.8.2-56.29.1 * libapparmor1-32bit-2.8.2-56.29.1 * pam_apparmor-32bit-2.8.2-56.29.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * apache2-mod_apparmor-2.8.2-56.29.1 * libapparmor-devel-2.8.2-56.29.1 * libapparmor1-debuginfo-32bit-2.8.2-56.29.1 * pam_apparmor-debuginfo-2.8.2-56.29.1 * perl-apparmor-2.8.2-56.29.1 * perl-apparmor-debuginfo-2.8.2-56.29.1 * apparmor-debugsource-2.8.2-56.29.1 * pam_apparmor-2.8.2-56.29.1 * libapparmor1-32bit-2.8.2-56.29.1 * apache2-mod_apparmor-debuginfo-2.8.2-56.29.1 * pam_apparmor-debuginfo-32bit-2.8.2-56.29.1 * apparmor-parser-2.8.2-56.29.1 * apparmor-parser-debuginfo-2.8.2-56.29.1 * libapparmor1-debuginfo-2.8.2-56.29.1 * pam_apparmor-32bit-2.8.2-56.29.1 * libapparmor1-2.8.2-56.29.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * apparmor-utils-2.8.2-56.29.1 * apparmor-profiles-2.8.2-56.29.1 * apparmor-docs-2.8.2-56.29.1 ## References: * https://jira.suse.com/browse/PED-16287 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 20:30:15 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 20:30:15 -0000 Subject: SUSE-RU-2026:3081-1: moderate: Recommended update for supportutils Message-ID: <178423381528.685.14124947677768400724@1437f03ce14a> # Recommended update for supportutils Announcement ID: SUSE-RU-2026:3081-1 Release Date: 2026-07-16T15:57:25Z Rating: moderate References: * bsc#1256709 * bsc#1257383 * bsc#1258069 * bsc#1259520 * jsc#PED-7324 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains one feature and has four fixes can now be installed. ## Description: This update for supportutils fixes the following issues: * Changes to version 3.2.14: * Integrates supportutils-scrub for data obfuscation, use -j (PED-7324, bsc#1259520) * Santize env.txt * ha.txt: Collect hacluster passwd entry * Added systemd cat unit.service output * Added softirqs to proc (bsc#1258069) * Check for /usr/lib/pam.d * Ignore deprecated crash variable message * Update supportconfig with note about bpftool * Added /boot/grub2/grubenv (bsc#1257383) * Verify procps pkg * scplugin.rc is restored in package 3.2.12.1 for continued compatibility. There is no furture development for scplugin.rc. Use supportconfig.rc. Package version 3.2.12.2 does not have scplugin.rc. (bsc#1256709) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3081=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3081=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3081=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3081=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * supportutils-3.2.14.2-150600.3.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * supportutils-3.2.14.2-150600.3.12.1 * Basesystem Module 15-SP7 (noarch) * supportutils-3.2.14.2-150600.3.12.1 * openSUSE Leap 15.6 (noarch) * supportutils-3.2.14.2-150600.3.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1256709 * https://bugzilla.suse.com/show_bug.cgi?id=1257383 * https://bugzilla.suse.com/show_bug.cgi?id=1258069 * https://bugzilla.suse.com/show_bug.cgi?id=1259520 * https://jira.suse.com/browse/PED-7324 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 20:30:22 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 20:30:22 -0000 Subject: SUSE-RU-2026:3080-1: moderate: Recommended update for gvfs Message-ID: <178423382231.685.8013268201616136881@1437f03ce14a> # Recommended update for gvfs Announcement ID: SUSE-RU-2026:3080-1 Release Date: 2026-07-16T15:57:03Z Rating: moderate References: * bsc#1261625 Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for gvfs fixes the following issues: * Fix crash of cancelled pending operation. (bsc#1261625) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3080=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3080=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3080=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3080=1 ## Package List: * openSUSE Leap 15.6 (noarch) * gvfs-devel-1.52.2-150600.3.6.1 * gvfs-lang-1.52.2-150600.3.6.1 * openSUSE Leap 15.6 (aarch64_ilp32) * gvfs-64bit-1.52.2-150600.3.6.1 * gvfs-64bit-debuginfo-1.52.2-150600.3.6.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * gvfs-debugsource-1.52.2-150600.3.6.1 * gvfs-backend-samba-debuginfo-1.52.2-150600.3.6.1 * gvfs-debuginfo-1.52.2-150600.3.6.1 * gvfs-1.52.2-150600.3.6.1 * gvfs-fuse-1.52.2-150600.3.6.1 * gvfs-backend-afc-debuginfo-1.52.2-150600.3.6.1 * gvfs-backend-goa-debuginfo-1.52.2-150600.3.6.1 * gvfs-fuse-debuginfo-1.52.2-150600.3.6.1 * gvfs-backends-1.52.2-150600.3.6.1 * gvfs-backends-debuginfo-1.52.2-150600.3.6.1 * gvfs-backend-afc-1.52.2-150600.3.6.1 * gvfs-backend-goa-1.52.2-150600.3.6.1 * gvfs-backend-samba-1.52.2-150600.3.6.1 * openSUSE Leap 15.6 (x86_64) * gvfs-32bit-debuginfo-1.52.2-150600.3.6.1 * gvfs-32bit-1.52.2-150600.3.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gvfs-debugsource-1.52.2-150600.3.6.1 * gvfs-backend-samba-debuginfo-1.52.2-150600.3.6.1 * gvfs-debuginfo-1.52.2-150600.3.6.1 * gvfs-1.52.2-150600.3.6.1 * gvfs-fuse-1.52.2-150600.3.6.1 * gvfs-backend-afc-debuginfo-1.52.2-150600.3.6.1 * gvfs-fuse-debuginfo-1.52.2-150600.3.6.1 * gvfs-backends-debuginfo-1.52.2-150600.3.6.1 * gvfs-backends-1.52.2-150600.3.6.1 * gvfs-backend-afc-1.52.2-150600.3.6.1 * gvfs-backend-samba-1.52.2-150600.3.6.1 * Desktop Applications Module 15-SP7 (noarch) * gvfs-devel-1.52.2-150600.3.6.1 * gvfs-lang-1.52.2-150600.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * gvfs-debugsource-1.52.2-150600.3.6.1 * gvfs-backend-samba-debuginfo-1.52.2-150600.3.6.1 * gvfs-debuginfo-1.52.2-150600.3.6.1 * gvfs-1.52.2-150600.3.6.1 * gvfs-backend-afc-debuginfo-1.52.2-150600.3.6.1 * gvfs-fuse-1.52.2-150600.3.6.1 * gvfs-fuse-debuginfo-1.52.2-150600.3.6.1 * gvfs-backends-1.52.2-150600.3.6.1 * gvfs-backends-debuginfo-1.52.2-150600.3.6.1 * gvfs-backend-afc-1.52.2-150600.3.6.1 * gvfs-backend-samba-1.52.2-150600.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gvfs-devel-1.52.2-150600.3.6.1 * gvfs-lang-1.52.2-150600.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * gvfs-debugsource-1.52.2-150600.3.6.1 * gvfs-backend-samba-debuginfo-1.52.2-150600.3.6.1 * gvfs-debuginfo-1.52.2-150600.3.6.1 * gvfs-1.52.2-150600.3.6.1 * gvfs-backend-afc-debuginfo-1.52.2-150600.3.6.1 * gvfs-fuse-1.52.2-150600.3.6.1 * gvfs-fuse-debuginfo-1.52.2-150600.3.6.1 * gvfs-backends-debuginfo-1.52.2-150600.3.6.1 * gvfs-backends-1.52.2-150600.3.6.1 * gvfs-backend-afc-1.52.2-150600.3.6.1 * gvfs-backend-samba-1.52.2-150600.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gvfs-devel-1.52.2-150600.3.6.1 * gvfs-lang-1.52.2-150600.3.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1261625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 20:30:28 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 20:30:28 -0000 Subject: SUSE-RU-2026:3079-1: moderate: Recommended update for gvfs Message-ID: <178423382856.685.14904591104204175656@1437f03ce14a> # Recommended update for gvfs Announcement ID: SUSE-RU-2026:3079-1 Release Date: 2026-07-16T15:56:40Z Rating: moderate References: * bsc#1261625 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has one fix can now be installed. ## Description: This update for gvfs fixes the following issues: * Fix crash of cancelled pending operation. (bsc#1261625) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3079=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3079=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3079=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3079=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3079=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3079=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3079=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3079=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3079=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * gvfs-lang-1.48.2-150400.4.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * gvfs-backend-afc-debuginfo-1.48.2-150400.4.12.1 * gvfs-1.48.2-150400.4.12.1 * gvfs-backends-1.48.2-150400.4.12.1 * gvfs-backends-debuginfo-1.48.2-150400.4.12.1 * gvfs-debugsource-1.48.2-150400.4.12.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.12.1 * gvfs-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-1.48.2-150400.4.12.1 * gvfs-backend-samba-1.48.2-150400.4.12.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.12.1 * gvfs-backend-afc-1.48.2-150400.4.12.1 * gvfs-devel-1.48.2-150400.4.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * gvfs-1.48.2-150400.4.12.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.12.1 * gvfs-backends-1.48.2-150400.4.12.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.12.1 * gvfs-debugsource-1.48.2-150400.4.12.1 * gvfs-backends-debuginfo-1.48.2-150400.4.12.1 * gvfs-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-1.48.2-150400.4.12.1 * gvfs-backend-samba-1.48.2-150400.4.12.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.12.1 * gvfs-backend-afc-1.48.2-150400.4.12.1 * gvfs-devel-1.48.2-150400.4.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gvfs-lang-1.48.2-150400.4.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gvfs-backend-afc-debuginfo-1.48.2-150400.4.12.1 * gvfs-1.48.2-150400.4.12.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.12.1 * gvfs-backends-1.48.2-150400.4.12.1 * gvfs-backends-debuginfo-1.48.2-150400.4.12.1 * gvfs-debugsource-1.48.2-150400.4.12.1 * gvfs-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-1.48.2-150400.4.12.1 * gvfs-backend-samba-1.48.2-150400.4.12.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.12.1 * gvfs-backend-afc-1.48.2-150400.4.12.1 * gvfs-devel-1.48.2-150400.4.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gvfs-lang-1.48.2-150400.4.12.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gvfs-backend-afc-debuginfo-1.48.2-150400.4.12.1 * gvfs-1.48.2-150400.4.12.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.12.1 * gvfs-backends-1.48.2-150400.4.12.1 * gvfs-debugsource-1.48.2-150400.4.12.1 * gvfs-backends-debuginfo-1.48.2-150400.4.12.1 * gvfs-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-1.48.2-150400.4.12.1 * gvfs-backend-samba-1.48.2-150400.4.12.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.12.1 * gvfs-backend-afc-1.48.2-150400.4.12.1 * gvfs-devel-1.48.2-150400.4.12.1 * openSUSE Leap 15.4 (x86_64) * gvfs-32bit-debuginfo-1.48.2-150400.4.12.1 * gvfs-32bit-1.48.2-150400.4.12.1 * openSUSE Leap 15.4 (aarch64_ilp32) * gvfs-64bit-debuginfo-1.48.2-150400.4.12.1 * gvfs-64bit-1.48.2-150400.4.12.1 * openSUSE Leap 15.4 (noarch) * gvfs-lang-1.48.2-150400.4.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * gvfs-lang-1.48.2-150400.4.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * gvfs-1.48.2-150400.4.12.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.12.1 * gvfs-backends-1.48.2-150400.4.12.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.12.1 * gvfs-debugsource-1.48.2-150400.4.12.1 * gvfs-backends-debuginfo-1.48.2-150400.4.12.1 * gvfs-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-1.48.2-150400.4.12.1 * gvfs-backend-samba-1.48.2-150400.4.12.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.12.1 * gvfs-backend-afc-1.48.2-150400.4.12.1 * gvfs-devel-1.48.2-150400.4.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * gvfs-backend-afc-debuginfo-1.48.2-150400.4.12.1 * gvfs-1.48.2-150400.4.12.1 * gvfs-backends-1.48.2-150400.4.12.1 * gvfs-backends-debuginfo-1.48.2-150400.4.12.1 * gvfs-debugsource-1.48.2-150400.4.12.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.12.1 * gvfs-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-1.48.2-150400.4.12.1 * gvfs-backend-samba-1.48.2-150400.4.12.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.12.1 * gvfs-backend-afc-1.48.2-150400.4.12.1 * gvfs-devel-1.48.2-150400.4.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * gvfs-lang-1.48.2-150400.4.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * gvfs-1.48.2-150400.4.12.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.12.1 * gvfs-backends-1.48.2-150400.4.12.1 * gvfs-debugsource-1.48.2-150400.4.12.1 * gvfs-backends-debuginfo-1.48.2-150400.4.12.1 * gvfs-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-1.48.2-150400.4.12.1 * gvfs-backend-samba-1.48.2-150400.4.12.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.12.1 * gvfs-backend-afc-1.48.2-150400.4.12.1 * gvfs-devel-1.48.2-150400.4.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * gvfs-lang-1.48.2-150400.4.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gvfs-lang-1.48.2-150400.4.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * gvfs-backend-afc-debuginfo-1.48.2-150400.4.12.1 * gvfs-1.48.2-150400.4.12.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.12.1 * gvfs-backends-debuginfo-1.48.2-150400.4.12.1 * gvfs-debugsource-1.48.2-150400.4.12.1 * gvfs-backends-1.48.2-150400.4.12.1 * gvfs-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-1.48.2-150400.4.12.1 * gvfs-backend-samba-1.48.2-150400.4.12.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.12.1 * gvfs-backend-afc-1.48.2-150400.4.12.1 * gvfs-devel-1.48.2-150400.4.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * gvfs-backend-afc-debuginfo-1.48.2-150400.4.12.1 * gvfs-1.48.2-150400.4.12.1 * gvfs-backends-1.48.2-150400.4.12.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.12.1 * gvfs-debugsource-1.48.2-150400.4.12.1 * gvfs-backends-debuginfo-1.48.2-150400.4.12.1 * gvfs-debuginfo-1.48.2-150400.4.12.1 * gvfs-fuse-1.48.2-150400.4.12.1 * gvfs-backend-samba-1.48.2-150400.4.12.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.12.1 * gvfs-backend-afc-1.48.2-150400.4.12.1 * gvfs-devel-1.48.2-150400.4.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gvfs-lang-1.48.2-150400.4.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1261625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 20:30:34 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 20:30:34 -0000 Subject: SUSE-SU-2026:3078-1: moderate: Security update for rpcbind Message-ID: <178423383474.685.15338439425987560007@1437f03ce14a> # Security update for rpcbind Announcement ID: SUSE-SU-2026:3078-1 Release Date: 2026-07-16T15:54:38Z Rating: moderate References: * bsc#1267212 Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has one security fix can now be installed. ## Description: This update for rpcbind fixes the following issue * Fix several memory leaks and buffer overflow (bsc#1267212). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3078=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * rpcbind-0.2.3-24.12.1 * rpcbind-debugsource-0.2.3-24.12.1 * rpcbind-debuginfo-0.2.3-24.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 20:30:41 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 20:30:41 -0000 Subject: SUSE-SU-2026:3077-1: moderate: Security update for rpcbind Message-ID: <178423384170.685.112504287486025511@1437f03ce14a> # Security update for rpcbind Announcement ID: SUSE-SU-2026:3077-1 Release Date: 2026-07-16T15:54:15Z Rating: moderate References: * bsc#1267212 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for rpcbind fixes the following issue * Fix several memory leaks and buffer overflow (bsc#1267212). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3077=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3077=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3077=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3077=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3077=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3077=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 20:30:47 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 16 Jul 2026 20:30:47 -0000 Subject: SUSE-SU-2026:3076-1: moderate: Security update for libssh2_org Message-ID: <178423384774.685.14226453076846836225@1437f03ce14a> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:3076-1 Release Date: 2026-07-16T13:04:25Z Rating: moderate References: * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libssh2_org fixes the following issue * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3076=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3076=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3076=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3076=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libssh2-devel-1.11.0-150600.20.3.1 * libssh2-1-1.11.0-150600.20.3.1 * libssh2_org-debugsource-1.11.0-150600.20.3.1 * libssh2-1-debuginfo-1.11.0-150600.20.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libssh2-1-32bit-1.11.0-150600.20.3.1 * libssh2-1-32bit-debuginfo-1.11.0-150600.20.3.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libssh2-devel-1.11.0-150600.20.3.1 * libssh2-1-1.11.0-150600.20.3.1 * libssh2_org-debugsource-1.11.0-150600.20.3.1 * libssh2-1-debuginfo-1.11.0-150600.20.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libssh2-1-64bit-1.11.0-150600.20.3.1 * libssh2-1-64bit-debuginfo-1.11.0-150600.20.3.1 * openSUSE Leap 15.6 (x86_64) * libssh2-1-32bit-1.11.0-150600.20.3.1 * libssh2-1-32bit-debuginfo-1.11.0-150600.20.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libssh2-1-32bit-1.11.0-150600.20.3.1 * libssh2-1-32bit-debuginfo-1.11.0-150600.20.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libssh2-devel-1.11.0-150600.20.3.1 * libssh2-1-1.11.0-150600.20.3.1 * libssh2_org-debugsource-1.11.0-150600.20.3.1 * libssh2-1-debuginfo-1.11.0-150600.20.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libssh2-devel-1.11.0-150600.20.3.1 * libssh2-1-1.11.0-150600.20.3.1 * libssh2_org-debugsource-1.11.0-150600.20.3.1 * libssh2-1-debuginfo-1.11.0-150600.20.3.1 * Basesystem Module 15-SP7 (x86_64) * libssh2-1-32bit-1.11.0-150600.20.3.1 * libssh2-1-32bit-debuginfo-1.11.0-150600.20.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:30:19 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 08:30:19 -0000 Subject: SUSE-SU-2026:3083-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Message-ID: <178427701919.28495.9014049302741986689@fcb35a5fe5ab> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3083-1 Release Date: 2026-07-16T16:33:31Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.60 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3083=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_60-default-2-150700.2.2 * kernel-livepatch-6_4_0-150700_53_60-default-debuginfo-2-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_16-debugsource-2-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:30:31 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 08:30:31 -0000 Subject: SUSE-SU-2026:3088-1: moderate: Security update for tomcat Message-ID: <178427703173.28495.6226961115771654220@fcb35a5fe5ab> # Security update for tomcat Announcement ID: SUSE-SU-2026:3088-1 Release Date: 2026-07-16T17:59:44Z Rating: moderate References: * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues Update to Tomcat 9.0.119. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Tomcat 9.0.119: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This is a breaking change for the EncryptInterceptor. (markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Wrong references to jakarta instead of javax. (remm) * Fix: Restore default authenticator to nullafter executing an Ant task. (remm) * Update: Update Commons Daemon to 1.6.1. (markt) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update Tomcat Native to 1.3.8. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3088=1 ## Package List: * Web and Scripting Module 15-SP7 (noarch) * tomcat-el-3_0-api-9.0.119-150200.111.1 * tomcat-webapps-9.0.119-150200.111.1 * tomcat-lib-9.0.119-150200.111.1 * tomcat-jsp-2_3-api-9.0.119-150200.111.1 * tomcat-servlet-4_0-api-9.0.119-150200.111.1 * tomcat-admin-webapps-9.0.119-150200.111.1 * tomcat-9.0.119-150200.111.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:30:46 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 08:30:46 -0000 Subject: SUSE-SU-2026:3087-1: moderate: Security update for tomcat11 Message-ID: <178427704609.28495.10595094274730738482@fcb35a5fe5ab> # Security update for tomcat11 Announcement ID: SUSE-SU-2026:3087-1 Release Date: 2026-07-16T17:56:56Z Rating: moderate References: * bsc#1232390 * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves six vulnerabilities and has one security fix can now be installed. ## Description: This update for tomcat11 fixes the following issues Update to Tomcat 11.0.23. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Upgrade libtcnative to v2 (bsc#1232390). * Tomcat 11.0.23: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Lower the log level to debug when OpenSSL initialization fails in OpenSSLLifecycleListener to avoid stack traces when libssl.so is not present and to align the behavior of the isAvailable() check with the AprLifecycleListener and gracefully fail when natives are not present. (csutherl) * Fix: 70038: Cookie.clone() should also clone the internal attribute map. (markt) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix SSO cookie partitioned configuration. (remm) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Update default web.xml version to match supported Servlet specification version. (markt) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. All session cookie attributes are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This us a breaking change for the EncryptInterceptor.(markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 2.x to 2.0.15. (markt) * Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Use per connection authenticator when executing an Ant task. (remm/markt) * Update: Update Commons Daemon to 1.6.1. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update the packaged version of the Tomcat Migration Tool for Jakarta EE to 1.0.12. (markt) * Update: Update Tomcat Native to 2.0.15. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3087=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3087=1 ## Package List: * Web and Scripting Module 15-SP7 (noarch) * tomcat11-11.0.23-150600.13.24.1 * tomcat11-el-6_0-api-11.0.23-150600.13.24.1 * tomcat11-servlet-6_1-api-11.0.23-150600.13.24.1 * tomcat11-lib-11.0.23-150600.13.24.1 * tomcat11-admin-webapps-11.0.23-150600.13.24.1 * tomcat11-jsp-4_0-api-11.0.23-150600.13.24.1 * tomcat11-webapps-11.0.23-150600.13.24.1 * openSUSE Leap 15.6 (noarch) * tomcat11-jsvc-11.0.23-150600.13.24.1 * tomcat11-docs-webapp-11.0.23-150600.13.24.1 * tomcat11-11.0.23-150600.13.24.1 * tomcat11-el-6_0-api-11.0.23-150600.13.24.1 * tomcat11-servlet-6_1-api-11.0.23-150600.13.24.1 * tomcat11-lib-11.0.23-150600.13.24.1 * tomcat11-admin-webapps-11.0.23-150600.13.24.1 * tomcat11-jsp-4_0-api-11.0.23-150600.13.24.1 * tomcat11-webapps-11.0.23-150600.13.24.1 * tomcat11-embed-11.0.23-150600.13.24.1 * tomcat11-doc-11.0.23-150600.13.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1232390 * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:30:53 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 08:30:53 -0000 Subject: SUSE-SU-2026:3086-1: important: Security update for python-python-socketio Message-ID: <178427705365.28495.16397751808059073474@fcb35a5fe5ab> # Security update for python-python-socketio Announcement ID: SUSE-SU-2026:3086-1 Release Date: 2026-07-16T17:53:06Z Rating: important References: * bsc#1269491 Cross-References: * CVE-2026-48804 CVSS scores: * CVE-2026-48804 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-python-socketio fixes the following issues: * CVE-2026-48804: Binary attachment accumulation can cause denial of service (bsc#1269491). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3086=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3086=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3086=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3086=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-python-socketio-5.7.2-150600.3.6.1 * Python 3 Module 15-SP7 (noarch) * python311-python-socketio-5.7.2-150600.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-python-socketio-5.7.2-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * python311-python-socketio-5.7.2-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48804.html * https://bugzilla.suse.com/show_bug.cgi?id=1269491 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:31:03 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 08:31:03 -0000 Subject: SUSE-SU-2026:3085-1: important: Security update for python-python-engineio Message-ID: <178427706350.28495.9193776539953289388@fcb35a5fe5ab> # Security update for python-python-engineio Announcement ID: SUSE-SU-2026:3085-1 Release Date: 2026-07-16T17:51:00Z Rating: important References: * bsc#1269544 * bsc#1269545 Cross-References: * CVE-2026-48802 * CVE-2026-48809 CVSS scores: * CVE-2026-48802 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48802 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48809 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48809 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-python-engineio fixes the following issues: * CVE-2026-48802: remote user can cause the creation of unnecessary background threads in the server through the heartbeat mechanism and cause a DoS (bsc#1269544). * CVE-2026-48809: size of incoming messages is not checked before they are loaded into memory and allows remote users to cause a DoS via excessive memory allocation (bsc#1269545). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3085=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3085=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3085=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3085=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-python-engineio-4.3.4-150600.3.3.1 * Python 3 Module 15-SP7 (noarch) * python311-python-engineio-4.3.4-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-python-engineio-4.3.4-150600.3.3.1 * openSUSE Leap 15.6 (noarch) * python311-python-engineio-4.3.4-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48802.html * https://www.suse.com/security/cve/CVE-2026-48809.html * https://bugzilla.suse.com/show_bug.cgi?id=1269544 * https://bugzilla.suse.com/show_bug.cgi?id=1269545 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:31:19 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 08:31:19 -0000 Subject: SUSE-SU-2026:3084-1: moderate: Security update for python-Pillow Message-ID: <178427707960.28495.7310757270518442421@fcb35a5fe5ab> # Security update for python-Pillow Announcement ID: SUSE-SU-2026:3084-1 Release Date: 2026-07-16T17:46:49Z Rating: moderate References: * bsc#1271418 * bsc#1271419 * bsc#1271420 * bsc#1271421 * bsc#1271422 * bsc#1271424 * bsc#1271425 Cross-References: * CVE-2026-54058 * CVE-2026-59197 * CVE-2026-59198 * CVE-2026-59199 * CVE-2026-59200 * CVE-2026-59204 * CVE-2026-59205 CVSS scores: * CVE-2026-54058 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54058 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-54058 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59197 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-59197 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-59197 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-59198 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59198 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59198 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-59199 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59199 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59200 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59200 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59200 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59204 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59204 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59205 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59205 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59205 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues * CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). * CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). * CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). * CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). * CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). * CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). * CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3084=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3084=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * python3-Pillow-debuginfo-7.2.0-150300.3.30.1 * python-Pillow-debuginfo-7.2.0-150300.3.30.1 * python3-Pillow-tk-debuginfo-7.2.0-150300.3.30.1 * python-Pillow-debugsource-7.2.0-150300.3.30.1 * python3-Pillow-7.2.0-150300.3.30.1 * python3-Pillow-tk-7.2.0-150300.3.30.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-Pillow-debuginfo-7.2.0-150300.3.30.1 * python-Pillow-debugsource-7.2.0-150300.3.30.1 * python-Pillow-debuginfo-7.2.0-150300.3.30.1 * python3-Pillow-7.2.0-150300.3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54058.html * https://www.suse.com/security/cve/CVE-2026-59197.html * https://www.suse.com/security/cve/CVE-2026-59198.html * https://www.suse.com/security/cve/CVE-2026-59199.html * https://www.suse.com/security/cve/CVE-2026-59200.html * https://www.suse.com/security/cve/CVE-2026-59204.html * https://www.suse.com/security/cve/CVE-2026-59205.html * https://bugzilla.suse.com/show_bug.cgi?id=1271418 * https://bugzilla.suse.com/show_bug.cgi?id=1271419 * https://bugzilla.suse.com/show_bug.cgi?id=1271420 * https://bugzilla.suse.com/show_bug.cgi?id=1271421 * https://bugzilla.suse.com/show_bug.cgi?id=1271422 * https://bugzilla.suse.com/show_bug.cgi?id=1271424 * https://bugzilla.suse.com/show_bug.cgi?id=1271425 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:31:27 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 08:31:27 -0000 Subject: SUSE-SU-2026:3082-1: moderate: Security update for libssh2_org Message-ID: <178427708722.28495.15534519307657056816@fcb35a5fe5ab> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:3082-1 Release Date: 2026-07-16T16:17:33Z Rating: moderate References: * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS An update that solves one vulnerability can now be installed. ## Description: This update for libssh2_org fixes the following issue * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3082=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3082=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3082=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libssh2-1-debuginfo-1.11.0-150000.4.32.1 * libssh2_org-debugsource-1.11.0-150000.4.32.1 * libssh2-1-32bit-1.11.0-150000.4.32.1 * libssh2-1-1.11.0-150000.4.32.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libssh2-1-debuginfo-1.11.0-150000.4.32.1 * libssh2-1-32bit-1.11.0-150000.4.32.1 * libssh2_org-debugsource-1.11.0-150000.4.32.1 * libssh2-1-1.11.0-150000.4.32.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libssh2-1-debuginfo-1.11.0-150000.4.32.1 * libssh2-1-32bit-1.11.0-150000.4.32.1 * libssh2_org-debugsource-1.11.0-150000.4.32.1 * libssh2-1-1.11.0-150000.4.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 12:30:17 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 12:30:17 -0000 Subject: SUSE-SU-2026:3090-1: moderate: Security update for ruby3.4 Message-ID: <178429141750.832.3552432331571865528@178315a69387> # Security update for ruby3.4 Announcement ID: SUSE-SU-2026:3090-1 Release Date: 2026-07-17T06:13:22Z Rating: moderate References: * bsc#1268011 * bsc#1268337 * bsc#1268338 * bsc#1268339 * bsc#1270034 Cross-References: * CVE-2025-61594 * CVE-2026-42258 * CVE-2026-47240 * CVE-2026-47241 * CVE-2026-47242 CVSS scores: * CVE-2025-61594 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-61594 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-61594 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42258 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-42258 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-42258 ( NVD ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42258 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-42258 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2026-47240 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-47240 ( NVD ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47241 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47241 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47242 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-47242 ( NVD ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities can now be installed. ## Description: This update for ruby3.4 fixes the following issues * CVE-2026-42258: Net:IMAP: Command Injection via Symbol Arguments (bsc#1268011). * CVE-2026-47240: Net:IMAP: Command Injection via non-synchronizing literal in "raw" argument (bsc#1268337). * CVE-2026-47241: Net:IMAP: Denial of Service via incomplete raw argument validation (bsc#1268338). * CVE-2026-47242: Net:IMAP: Command Injection via ID and ENABLE command arguments (bsc#1268339). * CVE-2025-61594: merging URIs using the + operator could expose sensitive user credentials (bsc#1270034). Changes for ruby3.4: * Update to 3.4.10: * bundling net-imap 0.5.15. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3090=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3090=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ruby3.4-devel-extra-3.4.10-150700.3.4.1 * ruby3.4-devel-3.4.10-150700.3.4.1 * ruby3.4-3.4.10-150700.3.4.1 * libruby3_4-3_4-3.4.10-150700.3.4.1 * ruby3.4-debugsource-3.4.10-150700.3.4.1 * ruby3.4-debuginfo-3.4.10-150700.3.4.1 * libruby3_4-3_4-debuginfo-3.4.10-150700.3.4.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ruby3.4-doc-3.4.10-150700.3.4.1 * ruby3.4-debugsource-3.4.10-150700.3.4.1 * ruby3.4-debuginfo-3.4.10-150700.3.4.1 * Development Tools Module 15-SP7 (noarch) * ruby3.4-doc-ri-3.4.10-150700.3.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-61594.html * https://www.suse.com/security/cve/CVE-2026-42258.html * https://www.suse.com/security/cve/CVE-2026-47240.html * https://www.suse.com/security/cve/CVE-2026-47241.html * https://www.suse.com/security/cve/CVE-2026-47242.html * https://bugzilla.suse.com/show_bug.cgi?id=1268011 * https://bugzilla.suse.com/show_bug.cgi?id=1268337 * https://bugzilla.suse.com/show_bug.cgi?id=1268338 * https://bugzilla.suse.com/show_bug.cgi?id=1268339 * https://bugzilla.suse.com/show_bug.cgi?id=1270034 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 12:31:06 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 12:31:06 -0000 Subject: SUSE-SU-2026:3089-1: important: Security update for the Linux Kernel Message-ID: <178429146610.832.1691652368149390560@178315a69387> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:3089-1 Release Date: 2026-07-17T01:35:33Z Rating: important References: * bsc#1264097 * bsc#1264145 * bsc#1265421 * bsc#1267381 * bsc#1267531 * bsc#1267567 * bsc#1267635 * bsc#1267684 * bsc#1267722 * bsc#1267918 * bsc#1267993 * bsc#1268022 * bsc#1268660 * bsc#1269022 * bsc#1269033 * bsc#1269036 * bsc#1269090 * bsc#1269100 * bsc#1269159 * bsc#1269184 * bsc#1269193 * bsc#1269195 * bsc#1269310 * bsc#1269398 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269821 * bsc#1270059 Cross-References: * CVE-2026-31771 * CVE-2026-43038 * CVE-2026-46090 * CVE-2026-46173 * CVE-2026-46197 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46331 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52943 * CVE-2026-52955 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-52993 * CVE-2026-53016 * CVE-2026-53041 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53133 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 29 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP5 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-31771: Bluetooth: Ignore HCI_ERROR_CANCELLED_BY_HOST on adv set terminated event (bsc#1264145). * CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3089=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3089=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3089=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3089=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3089=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3089=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3089=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * kernel-default-devel-5.14.21-150500.55.177.1 * reiserfs-kmp-default-5.14.21-150500.55.177.1 * reiserfs-kmp-default-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-syms-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (nosrc ppc64le x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-devel-5.14.21-150500.55.177.1 * reiserfs-kmp-default-5.14.21-150500.55.177.1 * reiserfs-kmp-default-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-syms-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64) * kernel-64kb-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-debugsource-5.14.21-150500.55.177.1 * kernel-64kb-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-devel-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le x86_64) * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 nosrc) * kernel-64kb-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (s390x) * kernel-zfcpdump-debugsource-5.14.21-150500.55.177.1 * kernel-zfcpdump-debuginfo-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (nosrc s390x) * kernel-zfcpdump-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * kernel-syms-5.14.21-150500.55.177.1 * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * kernel-default-devel-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 nosrc) * kernel-64kb-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64) * kernel-64kb-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-debugsource-5.14.21-150500.55.177.1 * kernel-64kb-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-devel-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-default-debugsource-5.14.21-150500.55.177.1 * kernel-livepatch-5_14_21-150500_55_177-default-debuginfo-1-150500.11.5.1 * kernel-livepatch-SLE15-SP5_Update_43-debugsource-1-150500.11.5.1 * kernel-default-livepatch-5.14.21-150500.55.177.1 * kernel-livepatch-5_14_21-150500_55_177-default-1-150500.11.5.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-livepatch-devel-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Live Patching 15-SP5 (nosrc) * kernel-default-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (nosrc s390x) * kernel-zfcpdump-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * kernel-default-devel-5.14.21-150500.55.177.1 * reiserfs-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-optional-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-default-extra-5.14.21-150500.55.177.1 * kselftests-kmp-default-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * kernel-default-extra-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-syms-5.14.21-150500.55.177.1 * kernel-obs-qa-5.14.21-150500.55.177.1 * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * kernel-default-optional-debuginfo-5.14.21-150500.55.177.1 * reiserfs-kmp-default-5.14.21-150500.55.177.1 * kernel-default-livepatch-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * kselftests-kmp-default-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64) * reiserfs-kmp-64kb-5.14.21-150500.55.177.1 * kernel-64kb-devel-debuginfo-5.14.21-150500.55.177.1 * dtb-amazon-5.14.21-150500.55.177.1 * dtb-nvidia-5.14.21-150500.55.177.1 * kernel-64kb-devel-5.14.21-150500.55.177.1 * dtb-mediatek-5.14.21-150500.55.177.1 * cluster-md-kmp-64kb-5.14.21-150500.55.177.1 * dtb-renesas-5.14.21-150500.55.177.1 * kselftests-kmp-64kb-5.14.21-150500.55.177.1 * reiserfs-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-allwinner-5.14.21-150500.55.177.1 * kernel-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-amlogic-5.14.21-150500.55.177.1 * dtb-socionext-5.14.21-150500.55.177.1 * kselftests-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-amd-5.14.21-150500.55.177.1 * dtb-broadcom-5.14.21-150500.55.177.1 * dtb-freescale-5.14.21-150500.55.177.1 * kernel-64kb-optional-debuginfo-5.14.21-150500.55.177.1 * dtb-rockchip-5.14.21-150500.55.177.1 * kernel-64kb-optional-5.14.21-150500.55.177.1 * dtb-xilinx-5.14.21-150500.55.177.1 * kernel-64kb-extra-debuginfo-5.14.21-150500.55.177.1 * dtb-sprd-5.14.21-150500.55.177.1 * dlm-kmp-64kb-5.14.21-150500.55.177.1 * dtb-arm-5.14.21-150500.55.177.1 * kernel-64kb-extra-5.14.21-150500.55.177.1 * dtb-apm-5.14.21-150500.55.177.1 * dtb-cavium-5.14.21-150500.55.177.1 * dtb-exynos-5.14.21-150500.55.177.1 * dtb-qcom-5.14.21-150500.55.177.1 * gfs2-kmp-64kb-5.14.21-150500.55.177.1 * cluster-md-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-debugsource-5.14.21-150500.55.177.1 * dlm-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-apple-5.14.21-150500.55.177.1 * ocfs2-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-marvell-5.14.21-150500.55.177.1 * dtb-hisilicon-5.14.21-150500.55.177.1 * dtb-altera-5.14.21-150500.55.177.1 * ocfs2-kmp-64kb-5.14.21-150500.55.177.1 * dtb-lg-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 ppc64le x86_64) * kernel-kvmsmall-devel-5.14.21-150500.55.177.1 * kernel-kvmsmall-debuginfo-5.14.21-150500.55.177.1 * kernel-kvmsmall-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * kernel-default-base-rebuild-5.14.21-150500.55.177.1.150500.6.83.2 * kernel-kvmsmall-debugsource-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_177-default-debuginfo-1-150500.11.5.1 * kernel-livepatch-SLE15-SP5_Update_43-debugsource-1-150500.11.5.1 * kernel-livepatch-5_14_21-150500_55_177-default-1-150500.11.5.1 * kernel-default-livepatch-devel-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (nosrc) * dtb-aarch64-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 nosrc) * kernel-64kb-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (x86_64) * kernel-kvmsmall-vdso-debuginfo-5.14.21-150500.55.177.1 * kernel-default-vdso-5.14.21-150500.55.177.1 * kernel-kvmsmall-vdso-5.14.21-150500.55.177.1 * kernel-default-vdso-debuginfo-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-docs-html-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * kernel-source-vanilla-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 nosrc ppc64le x86_64) * kernel-kvmsmall-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (s390x) * kernel-zfcpdump-debugsource-5.14.21-150500.55.177.1 * kernel-zfcpdump-debuginfo-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-devel-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-syms-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 nosrc) * kernel-64kb-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64) * kernel-64kb-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-debugsource-5.14.21-150500.55.177.1 * kernel-64kb-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-devel-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * kernel-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 x86_64) * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1264097 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:09 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:30:09 -0000 Subject: SUSE-SU-2026:3101-1: moderate: Security update for python-idna Message-ID: <178430580996.924.8362377154646930944@1437f03ce14a> # Security update for python-idna Announcement ID: SUSE-SU-2026:3101-1 Release Date: 2026-07-17T11:42:14Z Rating: moderate References: * bsc#1265413 Cross-References: * CVE-2026-45409 CVSS scores: * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-idna fixes the following issue * CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3101=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3101=1 ## Package List: * Public Cloud Module 12 (noarch) * python3-idna-2.5-3.16.1 * python-idna-2.5-3.16.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * python3-idna-2.5-3.16.1 * python-idna-2.5-3.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45409.html * https://bugzilla.suse.com/show_bug.cgi?id=1265413 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:17 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:30:17 -0000 Subject: SUSE-SU-2026:3100-1: moderate: Security update for python-idna Message-ID: <178430581796.924.2496156957584890088@1437f03ce14a> # Security update for python-idna Announcement ID: SUSE-SU-2026:3100-1 Release Date: 2026-07-17T11:42:01Z Rating: moderate References: * bsc#1265413 Cross-References: * CVE-2026-45409 CVSS scores: * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-idna fixes the following issue * CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3100=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3100=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3100=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3100=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3100=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3100=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-idna-2.6-150000.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45409.html * https://bugzilla.suse.com/show_bug.cgi?id=1265413 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:23 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:30:23 -0000 Subject: SUSE-SU-2026:3099-1: moderate: Security update for dash Message-ID: <178430582394.924.14725902151885875686@1437f03ce14a> # Security update for dash Announcement ID: SUSE-SU-2026:3099-1 Release Date: 2026-07-17T11:40:37Z Rating: moderate References: * bsc#1269494 Cross-References: * CVE-2026-31323 CVSS scores: * CVE-2026-31323 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31323 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for dash fixes the following issues * CVE-2026-31323: arithmetic expansion evaluating INTMAX_MIN / -1 can lead to a signed integer overflow and a denial of service (bsc#1269494). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3099=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dash-debugsource-0.5.11.2-150000.3.9.1 * dash-0.5.11.2-150000.3.9.1 * dash-debuginfo-0.5.11.2-150000.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31323.html * https://bugzilla.suse.com/show_bug.cgi?id=1269494 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:32 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:30:32 -0000 Subject: SUSE-SU-2026:3098-1: important: Security update for shibboleth-sp Message-ID: <178430583219.924.3477549602327153672@1437f03ce14a> # Security update for shibboleth-sp Announcement ID: SUSE-SU-2026:3098-1 Release Date: 2026-07-17T11:40:03Z Rating: important References: * bsc#1249394 Cross-References: * CVE-2025-9943 CVSS scores: * CVE-2025-9943 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-9943 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for shibboleth-sp fixes the following issue: * CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3098=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3098=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libshibsp-lite6-debuginfo-2.5.5-6.9.1 * shibboleth-sp-debugsource-2.5.5-6.9.1 * libshibsp6-2.5.5-6.9.1 * shibboleth-sp-devel-2.5.5-6.9.1 * libshibsp6-debuginfo-2.5.5-6.9.1 * shibboleth-sp-2.5.5-6.9.1 * libshibsp-lite6-2.5.5-6.9.1 * shibboleth-sp-debuginfo-2.5.5-6.9.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libshibsp6-2.5.5-6.9.1 * libshibsp-lite6-debuginfo-2.5.5-6.9.1 * shibboleth-sp-debugsource-2.5.5-6.9.1 * shibboleth-sp-devel-2.5.5-6.9.1 * libshibsp6-debuginfo-2.5.5-6.9.1 * shibboleth-sp-2.5.5-6.9.1 * libshibsp-lite6-2.5.5-6.9.1 * shibboleth-sp-debuginfo-2.5.5-6.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9943.html * https://bugzilla.suse.com/show_bug.cgi?id=1249394 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:39 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:30:39 -0000 Subject: SUSE-SU-2026:3097-1: important: Security update for libxml2 Message-ID: <178430583917.924.7575070313531169623@1437f03ce14a> # Security update for libxml2 Announcement ID: SUSE-SU-2026:3097-1 Release Date: 2026-07-17T11:39:38Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3097=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3097=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libxml2-tools-2.12.10-150700.4.14.1 * libxml2-devel-2.12.10-150700.4.14.1 * python3-libxml2-debuginfo-2.12.10-150700.4.14.1 * libxml2-2-2.12.10-150700.4.14.1 * libxml2-debugsource-2.12.10-150700.4.14.1 * libxml2-python-debugsource-2.12.10-150700.4.14.1 * libxml2-2-debuginfo-2.12.10-150700.4.14.1 * libxml2-tools-debuginfo-2.12.10-150700.4.14.1 * python3-libxml2-2.12.10-150700.4.14.1 * Basesystem Module 15-SP7 (x86_64) * libxml2-2-32bit-debuginfo-2.12.10-150700.4.14.1 * libxml2-2-32bit-2.12.10-150700.4.14.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-libxml2-2.12.10-150700.4.14.1 * libxml2-python-debugsource-2.12.10-150700.4.14.1 * python311-libxml2-debuginfo-2.12.10-150700.4.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:46 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:30:46 -0000 Subject: SUSE-SU-2026:3096-1: important: Security update for libxml2 Message-ID: <178430584640.924.713846677351323105@1437f03ce14a> # Security update for libxml2 Announcement ID: SUSE-SU-2026:3096-1 Release Date: 2026-07-17T11:39:17Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3096=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3096=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3096=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3096=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3096=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3096=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3096=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3096=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (x86_64) * libxml2-devel-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (noarch) * libxml2-doc-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libxml2-2-64bit-debuginfo-2.10.3-150500.5.41.1 * libxml2-2-64bit-2.10.3-150500.5.41.1 * libxml2-devel-64bit-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:54 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:30:54 -0000 Subject: SUSE-SU-2026:3095-1: important: Security update for libxml2 Message-ID: <178430585402.924.2728340259909836568@1437f03ce14a> # Security update for libxml2 Announcement ID: SUSE-SU-2026:3095-1 Release Date: 2026-07-17T11:38:38Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3095=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3095=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3095=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3095=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3095=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3095=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3095=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3095=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3095=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libxml2-2-64bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-64bit-2.9.14-150400.5.58.1 * libxml2-devel-64bit-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (noarch) * libxml2-doc-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * libxml2-devel-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:31:02 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:31:02 -0000 Subject: SUSE-SU-2026:3094-1: moderate: Security update for openssl-3 Message-ID: <178430586281.924.18035783371832651661@1437f03ce14a> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3094-1 Release Date: 2026-07-17T09:54:11Z Rating: moderate References: * bsc#1266344 * bsc#1266350 Cross-References: * CVE-2026-34182 * CVE-2026-42767 CVSS scores: * CVE-2026-34182 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34182 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities can now be installed. ## Description: This update for openssl-3 fixes the following issues * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3094=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3094=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3094=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3094=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3094=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3094=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3094=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3094=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3094=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * openSUSE Leap 15.4 (x86_64) * libopenssl3-32bit-3.0.8-150400.4.90.1 * libopenssl-3-devel-32bit-3.0.8-150400.4.90.1 * libopenssl3-32bit-debuginfo-3.0.8-150400.4.90.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libopenssl3-64bit-3.0.8-150400.4.90.1 * libopenssl3-64bit-debuginfo-3.0.8-150400.4.90.1 * libopenssl-3-devel-64bit-3.0.8-150400.4.90.1 * openSUSE Leap 15.4 (noarch) * openssl-3-doc-3.0.8-150400.4.90.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34182.html * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266344 * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:31:10 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:31:10 -0000 Subject: SUSE-SU-2026:3093-1: moderate: Security update for python-paramiko Message-ID: <178430587032.924.12424705311202263202@1437f03ce14a> # Security update for python-paramiko Announcement ID: SUSE-SU-2026:3093-1 Release Date: 2026-07-17T09:48:50Z Rating: moderate References: * bsc#1264225 Cross-References: * CVE-2026-44405 CVSS scores: * CVE-2026-44405 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-44405 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44405 ( NVD ): 3.4 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-paramiko fixes the following issue * CVE-2026-44405: data integrity compromise due to allowed SHA-1 algorithm use (bsc#1264225). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3093=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3093=1 ## Package List: * openSUSE Leap 15.4 (noarch) * python-paramiko-doc-3.4.0-150400.13.13.1 * python311-paramiko-3.4.0-150400.13.13.1 * Public Cloud Module 15-SP4 (noarch) * python-paramiko-doc-3.4.0-150400.13.13.1 * python311-paramiko-3.4.0-150400.13.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44405.html * https://bugzilla.suse.com/show_bug.cgi?id=1264225 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:31:15 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:31:15 -0000 Subject: SUSE-RU-2026:3092-1: moderate: Recommended update for ktls-utils Message-ID: <178430587568.924.11328395650585345219@1437f03ce14a> # Recommended update for ktls-utils Announcement ID: SUSE-RU-2026:3092-1 Release Date: 2026-07-17T08:46:00Z Rating: moderate References: Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that can now be installed. ## Description: This update for ktls-utils fixes the following issues: * tlshd: * fixup compile errors with HAVE_GNUTLS_PSK_ALLOCATE_CREDENTIALS2 * use gnutls_psk_allocate_{client,server}_credentials2 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3092=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3092=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3092=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * ktls-utils-debuginfo-0.10+15.gd504d8f-150600.3.6.1 * ktls-utils-0.10+15.gd504d8f-150600.3.6.1 * ktls-utils-debugsource-0.10+15.gd504d8f-150600.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * ktls-utils-debuginfo-0.10+15.gd504d8f-150600.3.6.1 * ktls-utils-0.10+15.gd504d8f-150600.3.6.1 * ktls-utils-debugsource-0.10+15.gd504d8f-150600.3.6.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * ktls-utils-debuginfo-0.10+15.gd504d8f-150600.3.6.1 * ktls-utils-0.10+15.gd504d8f-150600.3.6.1 * ktls-utils-debugsource-0.10+15.gd504d8f-150600.3.6.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:31:23 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 16:31:23 -0000 Subject: SUSE-RU-2026:3091-1: moderate: Recommended update for container-selinux Message-ID: <178430588373.924.9567912175955510363@1437f03ce14a> # Recommended update for container-selinux Announcement ID: SUSE-RU-2026:3091-1 Release Date: 2026-07-17T08:33:32Z Rating: moderate References: * bsc#1268490 Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that has one fix can now be installed. ## Description: This update for container-selinux fixes the following issues: * Allow spc_t execstack and execmem again to fix regression (bsc#1268490) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3091=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (noarch) * container-selinux-2.236.0-150500.3.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268490 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:30:07 -0000 Subject: SUSE-SU-2026:3117-1: moderate: Security update for python-dulwich Message-ID: <178432020750.935.1214921174494827714@f4f3e2688bac> # Security update for python-dulwich Announcement ID: SUSE-SU-2026:3117-1 Release Date: 2026-07-17T15:37:51Z Rating: moderate References: * bsc#1268138 Cross-References: * CVE-2026-47734 CVSS scores: * CVE-2026-47734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47734 ( NVD ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-dulwich fixes the following issue * CVE-2026-47734: Unbounded memory allocation in receive-pack from crafted thin packs (bsc#1268138). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3117=1 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * python-dulwich-0.18.5-4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47734.html * https://bugzilla.suse.com/show_bug.cgi?id=1268138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:30:13 -0000 Subject: SUSE-SU-2026:3116-1: moderate: Security update for libqt4 Message-ID: <178432021329.935.3746493659801074844@f4f3e2688bac> # Security update for libqt4 Announcement ID: SUSE-SU-2026:3116-1 Release Date: 2026-07-17T15:36:06Z Rating: moderate References: * bsc#1265896 Cross-References: * CVE-2025-14575 CVSS scores: * CVE-2025-14575 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-14575 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-14575 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libqt4 fixes the following issue * CVE-2025-14575: local user can load rogue CA certificates as trusted system authority via a crafted file placed in the application's working directory (bsc#1265896). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3116=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libqt4-x11-debuginfo-4.8.7-8.25.1 * libqt4-sql-plugins-debugsource-4.8.7-8.25.1 * libqt4-devel-4.8.7-8.25.1 * libqt4-sql-4.8.7-8.25.1 * libqt4-sql-mysql-debuginfo-4.8.7-8.25.1 * libqt4-sql-32bit-4.8.7-8.25.1 * qt4-x11-tools-4.8.7-8.25.1 * libqt4-x11-4.8.7-8.25.1 * libqt4-sql-mysql-4.8.7-8.25.1 * libqt4-qt3support-4.8.7-8.25.1 * libqt4-private-headers-devel-4.8.7-8.25.1 * libqt4-qt3support-32bit-4.8.7-8.25.1 * libqt4-x11-debuginfo-32bit-4.8.7-8.25.1 * qt4-x11-tools-debuginfo-4.8.7-8.25.1 * libqt4-sql-sqlite-debuginfo-4.8.7-8.25.1 * libqt4-qt3support-debuginfo-32bit-4.8.7-8.25.1 * libqt4-debuginfo-32bit-4.8.7-8.25.1 * libqt4-sql-debuginfo-4.8.7-8.25.1 * libqt4-debuginfo-4.8.7-8.25.1 * libqt4-sql-sqlite-4.8.7-8.25.1 * libqt4-4.8.7-8.25.1 * libqt4-devel-debuginfo-4.8.7-8.25.1 * libqt4-devel-doc-debugsource-4.8.7-8.25.1 * libqt4-devel-doc-4.8.7-8.25.1 * libqt4-32bit-4.8.7-8.25.1 * libqt4-sql-debuginfo-32bit-4.8.7-8.25.1 * libqt4-devel-doc-debuginfo-4.8.7-8.25.1 * libqt4-qt3support-debuginfo-4.8.7-8.25.1 * libqt4-debugsource-4.8.7-8.25.1 * libqt4-x11-32bit-4.8.7-8.25.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libqt4-devel-doc-data-4.8.7-8.25.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14575.html * https://bugzilla.suse.com/show_bug.cgi?id=1265896 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:21 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:30:21 -0000 Subject: SUSE-SU-2026:3115-1: moderate: Security update for vorbis-tools Message-ID: <178432022147.935.12035949749420180461@f4f3e2688bac> # Security update for vorbis-tools Announcement ID: SUSE-SU-2026:3115-1 Release Date: 2026-07-17T15:35:12Z Rating: moderate References: * bsc#1265361 Cross-References: * CVE-2026-34253 CVSS scores: * CVE-2026-34253 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34253 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-34253 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-34253 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for vorbis-tools fixes the following issue * CVE-2026-34253: buffer underflow in the `ogg123` utility in function `remotethread` of `remote.c` (bsc#1265361). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3115=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * vorbis-tools-debuginfo-1.4.0-150000.3.6.1 * vorbis-tools-debugsource-1.4.0-150000.3.6.1 * vorbis-tools-1.4.0-150000.3.6.1 * Desktop Applications Module 15-SP7 (noarch) * vorbis-tools-lang-1.4.0-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34253.html * https://bugzilla.suse.com/show_bug.cgi?id=1265361 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:27 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:30:27 -0000 Subject: SUSE-SU-2026:3114-1: moderate: Security update for vorbis-tools Message-ID: <178432022760.935.17543555711016178158@f4f3e2688bac> # Security update for vorbis-tools Announcement ID: SUSE-SU-2026:3114-1 Release Date: 2026-07-17T15:34:10Z Rating: moderate References: * bsc#1265361 Cross-References: * CVE-2026-34253 CVSS scores: * CVE-2026-34253 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34253 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-34253 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-34253 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for vorbis-tools fixes the following issue * CVE-2026-34253: buffer underflow in the `ogg123` utility in function `remotethread` of `remote.c` (bsc#1265361). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3114=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * vorbis-tools-debugsource-1.4.0-27.6.1 * vorbis-tools-1.4.0-27.6.1 * vorbis-tools-debuginfo-1.4.0-27.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * vorbis-tools-lang-1.4.0-27.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34253.html * https://bugzilla.suse.com/show_bug.cgi?id=1265361 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:33 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:30:33 -0000 Subject: SUSE-SU-2026:3113-1: important: Security update for python-msgpack Message-ID: <178432023355.935.14362153434348778584@f4f3e2688bac> # Security update for python-msgpack Announcement ID: SUSE-SU-2026:3113-1 Release Date: 2026-07-17T14:24:43Z Rating: important References: * bsc#1269947 Cross-References: * CVE-2026-57585 CVSS scores: * CVE-2026-57585 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57585 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-msgpack fixes the following issue * CVE-2026-57585: `Unpacker` reuse after a caught error can lead to an out-of- bounds read and a crash (bsc#1269947). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3113=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3113=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3113=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3113=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3113=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3113=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3113=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3113=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3113=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3113=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3113=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3113=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3113=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3113=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3113=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3113=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57585.html * https://bugzilla.suse.com/show_bug.cgi?id=1269947 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:47 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:30:47 -0000 Subject: SUSE-SU-2026:3112-1: moderate: Security update for tomcat10 Message-ID: <178432024701.935.12307778011563262316@f4f3e2688bac> # Security update for tomcat10 Announcement ID: SUSE-SU-2026:3112-1 Release Date: 2026-07-17T14:20:26Z Rating: moderate References: * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for tomcat10 fixes the following issues Update to Tomcat 10.1.56. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Tomcat 10.1.56: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Fix: 70038: Cookie.clone() should also clone the internal attribute map. (markt) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. All session cookie attributes are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This is a breaking change for the EncryptInterceptor. (markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 2.x to 2.0.15. (markt) * Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Use per connection authenticator when executing an Ant task. (remm/markt) * Update: Update Commons Daemon to 1.6.1. (markt) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update the packaged version of the Tomcat Migration Tool for Jakarta EE to 1.0.12. (markt) * Update: Update Tomcat Native to 2.0.15. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3112=1 ## Package List: * Web and Scripting Module 15-SP7 (noarch) * tomcat10-admin-webapps-10.1.56-150200.5.70.1 * tomcat10-lib-10.1.56-150200.5.70.1 * tomcat10-webapps-10.1.56-150200.5.70.1 * tomcat10-jsp-3_1-api-10.1.56-150200.5.70.1 * tomcat10-el-5_0-api-10.1.56-150200.5.70.1 * tomcat10-servlet-6_0-api-10.1.56-150200.5.70.1 * tomcat10-10.1.56-150200.5.70.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:52 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:30:52 -0000 Subject: SUSE-SU-2026:3111-1: important: Security update for libxml2 Message-ID: <178432025275.935.12334531055635478244@f4f3e2688bac> # Security update for libxml2 Announcement ID: SUSE-SU-2026:3111-1 Release Date: 2026-07-17T14:18:02Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3111=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3111=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-tools-2.9.4-46.102.2 * python-libxml2-debuginfo-2.9.4-46.102.2 * libxml2-tools-debuginfo-2.9.4-46.102.2 * libxml2-devel-2.9.4-46.102.2 * libxml2-2-debuginfo-2.9.4-46.102.2 * libxml2-2-2.9.4-46.102.2 * python-libxml2-debugsource-2.9.4-46.102.2 * libxml2-debugsource-2.9.4-46.102.2 * python-libxml2-2.9.4-46.102.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libxml2-2-32bit-2.9.4-46.102.2 * libxml2-2-debuginfo-32bit-2.9.4-46.102.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * libxml2-doc-2.9.4-46.102.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libxml2-2-debuginfo-32bit-2.9.4-46.102.2 * libxml2-tools-2.9.4-46.102.2 * python-libxml2-debuginfo-2.9.4-46.102.2 * libxml2-tools-debuginfo-2.9.4-46.102.2 * libxml2-2-2.9.4-46.102.2 * libxml2-devel-2.9.4-46.102.2 * libxml2-2-debuginfo-2.9.4-46.102.2 * libxml2-2-32bit-2.9.4-46.102.2 * python-libxml2-debugsource-2.9.4-46.102.2 * libxml2-debugsource-2.9.4-46.102.2 * python-libxml2-2.9.4-46.102.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libxml2-doc-2.9.4-46.102.2 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:00 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:31:00 -0000 Subject: SUSE-SU-2026:3110-1: important: Security update for mariadb-connector-c Message-ID: <178432026008.935.7029273678354130306@f4f3e2688bac> # Security update for mariadb-connector-c Announcement ID: SUSE-SU-2026:3110-1 Release Date: 2026-07-17T14:15:40Z Rating: important References: * bsc#1266438 Cross-References: * CVE-2026-44172 CVSS scores: * CVE-2026-44172 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for mariadb-connector-c fixes the following issue: * CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). Changes for mariadb-connector-c: * Update to 3.1.28. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3110=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3110=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3110=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3110=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3110=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libmariadb_plugins-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-debuginfo-3.1.28-150600.18.3.1 * libmariadb-devel-3.1.28-150600.18.3.1 * libmariadb-devel-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-3.1.28-150600.18.3.1 * libmariadb_plugins-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 * libmariadbprivate-3.1.28-150600.18.3.1 * libmariadbprivate-debuginfo-3.1.28-150600.18.3.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libmariadb_plugins-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-debuginfo-3.1.28-150600.18.3.1 * libmariadb-devel-3.1.28-150600.18.3.1 * libmariadb3-3.1.28-150600.18.3.1 * libmariadb-devel-debuginfo-3.1.28-150600.18.3.1 * libmariadb_plugins-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 * libmariadbprivate-3.1.28-150600.18.3.1 * libmariadbprivate-debuginfo-3.1.28-150600.18.3.1 * openSUSE Leap 15.6 (x86_64) * libmariadb3-32bit-3.1.28-150600.18.3.1 * libmariadb3-32bit-debuginfo-3.1.28-150600.18.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libmariadb3-64bit-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-64bit-3.1.28-150600.18.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libmariadb_plugins-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-debuginfo-3.1.28-150600.18.3.1 * libmariadb-devel-3.1.28-150600.18.3.1 * libmariadb3-3.1.28-150600.18.3.1 * libmariadb-devel-debuginfo-3.1.28-150600.18.3.1 * libmariadb_plugins-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 * libmariadbprivate-3.1.28-150600.18.3.1 * libmariadbprivate-debuginfo-3.1.28-150600.18.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libmariadb3-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 * libmariadbprivate-3.1.28-150600.18.3.1 * libmariadbprivate-debuginfo-3.1.28-150600.18.3.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libmariadb_plugins-debuginfo-3.1.28-150600.18.3.1 * libmariadb-devel-3.1.28-150600.18.3.1 * libmariadb-devel-debuginfo-3.1.28-150600.18.3.1 * libmariadb_plugins-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44172.html * https://bugzilla.suse.com/show_bug.cgi?id=1266438 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:06 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:31:06 -0000 Subject: SUSE-SU-2026:3108-1: important: Security update for joe Message-ID: <178432026602.935.10591102294614236685@f4f3e2688bac> # Security update for joe Announcement ID: SUSE-SU-2026:3108-1 Release Date: 2026-07-17T14:12:50Z Rating: important References: * bsc#1269379 Cross-References: * CVE-2026-13412 CVSS scores: * CVE-2026-13412 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-13412 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for joe fixes the following issue * CVE-2026-13412: arbitrary command execution via malicious tags file (bsc#1269379). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3108=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * joe-debuginfo-4.4-150000.3.3.1 * joe-4.4-150000.3.3.1 * joe-debugsource-4.4-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13412.html * https://bugzilla.suse.com/show_bug.cgi?id=1269379 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:14 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:31:14 -0000 Subject: SUSE-RU-2026:3107-1: moderate: Recommended update for bind Message-ID: <178432027451.935.8734676866232733613@f4f3e2688bac> # Recommended update for bind Announcement ID: SUSE-RU-2026:3107-1 Release Date: 2026-07-17T14:03:11Z Rating: moderate References: * bsc#1268896 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one fix can now be installed. ## Description: This update for bind fixes the following issues: * Force python3.11 for integration tests (bsc#1268896) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3107=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3107=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3107=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * bind-debuginfo-9.18.49-150600.3.29.1 * bind-9.18.49-150600.3.29.1 * bind-utils-debuginfo-9.18.49-150600.3.29.1 * bind-utils-9.18.49-150600.3.29.1 * bind-debugsource-9.18.49-150600.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * bind-doc-9.18.49-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * bind-debuginfo-9.18.49-150600.3.29.1 * bind-9.18.49-150600.3.29.1 * bind-utils-debuginfo-9.18.49-150600.3.29.1 * bind-utils-9.18.49-150600.3.29.1 * bind-debugsource-9.18.49-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * bind-doc-9.18.49-150600.3.29.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * bind-debuginfo-9.18.49-150600.3.29.1 * bind-9.18.49-150600.3.29.1 * bind-utils-debuginfo-9.18.49-150600.3.29.1 * bind-utils-9.18.49-150600.3.29.1 * bind-debugsource-9.18.49-150600.3.29.1 * openSUSE Leap 15.6 (noarch) * bind-doc-9.18.49-150600.3.29.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268896 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:18 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:31:18 -0000 Subject: SUSE-RU-2026:3106-1: moderate: Recommended update for kmod Message-ID: <178432027843.935.6566990007957862288@f4f3e2688bac> # Recommended update for kmod Announcement ID: SUSE-RU-2026:3106-1 Release Date: 2026-07-17T14:02:11Z Rating: moderate References: * jsc#PED-16303 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains one feature can now be installed. ## Description: This update for kmod fixes the following issues: * Use in-kernel decompression if available (jsc#PED-16303): * libkmod: * Add a separate function to load the file contents when it's needed. When it's not needed on the path of loading modules via finit_module(), there is no need to mmap the file. * Extract 2 functions to handle finit_module vs init_modules differences, with a fallback from the former to the latter. * Don't only set the type as direct, but also keep track of the compression being used. * When creating the context, read /sys/kernel/compression to check. what's the compression type supported by the kernel. * Use kernel decompression when available * add fallback MODULE_INIT_COMPRESSED_FILE define ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3106=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3106=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libkmod2-debuginfo-29-150600.13.6.1 * libkmod-devel-29-150600.13.6.1 * libkmod2-29-150600.13.6.1 * kmod-29-150600.13.6.1 * kmod-debugsource-29-150600.13.6.1 * kmod-debuginfo-29-150600.13.6.1 * openSUSE Leap 15.6 (noarch) * kmod-bash-completion-29-150600.13.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libkmod2-debuginfo-29-150600.13.6.1 * libkmod-devel-29-150600.13.6.1 * libkmod2-29-150600.13.6.1 * kmod-29-150600.13.6.1 * kmod-debugsource-29-150600.13.6.1 * kmod-debuginfo-29-150600.13.6.1 * Basesystem Module 15-SP7 (noarch) * kmod-bash-completion-29-150600.13.6.1 ## References: * https://jira.suse.com/browse/PED-16303 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:29 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:31:29 -0000 Subject: SUSE-SU-2026:3105-1: important: Security update for php-composer2 Message-ID: <178432028968.935.847242546403130020@f4f3e2688bac> # Security update for php-composer2 Announcement ID: SUSE-SU-2026:3105-1 Release Date: 2026-07-17T13:32:58Z Rating: important References: * bsc#1271122 * bsc#1271129 * bsc#1271151 * bsc#1271504 Cross-References: * CVE-2024-35241 * CVE-2024-35242 * CVE-2025-67746 * CVE-2026-40176 * CVE-2026-40261 * CVE-2026-45793 * CVE-2026-59946 * CVE-2026-59947 * CVE-2026-59948 CVSS scores: * CVE-2024-35241 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-35241 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-35242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-35242 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-67746 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-67746 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-67746 ( NVD ): 1.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-67746 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40261 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40261 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40261 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-45793 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-45793 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59946 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59946 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-59946 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-59947 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59947 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59947 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59948 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59948 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59948 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for php-composer2 fixes the following issues: * CVE-2026-45793: Github Actions issued `GITHUB_TOKEN` disclosure in GitHub Actions logs (bsc#1271504). * CVE-2026-59946: path traversal in package `bin` field lets dependencies `chmod` arbitrary host files (bsc#1271151). * CVE-2026-59947: URL-embedded HTTP-Basic username leaks to verbose logs (bsc#1271129). * CVE-2026-59948: arbitrary file write outside `vendor`directory via malicious transitive package name (bsc#1271122). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3105=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3105=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3105=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3105=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * php-composer2-2.6.4-150600.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * php-composer2-2.6.4-150600.3.12.1 * Web and Scripting Module 15-SP7 (noarch) * php-composer2-2.6.4-150600.3.12.1 * openSUSE Leap 15.6 (noarch) * php-composer2-2.6.4-150600.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35241.html * https://www.suse.com/security/cve/CVE-2024-35242.html * https://www.suse.com/security/cve/CVE-2025-67746.html * https://www.suse.com/security/cve/CVE-2026-40176.html * https://www.suse.com/security/cve/CVE-2026-40261.html * https://www.suse.com/security/cve/CVE-2026-45793.html * https://www.suse.com/security/cve/CVE-2026-59946.html * https://www.suse.com/security/cve/CVE-2026-59947.html * https://www.suse.com/security/cve/CVE-2026-59948.html * https://bugzilla.suse.com/show_bug.cgi?id=1271122 * https://bugzilla.suse.com/show_bug.cgi?id=1271129 * https://bugzilla.suse.com/show_bug.cgi?id=1271151 * https://bugzilla.suse.com/show_bug.cgi?id=1271504 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:41 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:31:41 -0000 Subject: SUSE-SU-2026:3104-1: important: Security update for python311 Message-ID: <178432030175.935.4629617101395290515@f4f3e2688bac> # Security update for python311 Announcement ID: SUSE-SU-2026:3104-1 Release Date: 2026-07-17T13:31:49Z Rating: important References: * bsc#1261969 * bsc#1262098 * bsc#1262319 * bsc#1262654 Cross-References: * CVE-2026-1502 * CVE-2026-4786 * CVE-2026-6019 * CVE-2026-6100 CVSS scores: * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues * CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969). * CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the `webbrowser.open()` API (bsc#1262319). * CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654). * CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the decompression instance is re- used (bsc#1262098). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3104=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3104=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3104=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3104=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3104=1 ## Package List: * openSUSE Leap 15.6 (aarch64_ilp32) * libpython3_11-1_0-64bit-3.11.15-150600.3.59.3 * python311-base-64bit-debuginfo-3.11.15-150600.3.59.3 * python311-64bit-3.11.15-150600.3.59.3 * python311-base-64bit-3.11.15-150600.3.59.3 * libpython3_11-1_0-64bit-debuginfo-3.11.15-150600.3.59.3 * python311-64bit-debuginfo-3.11.15-150600.3.59.3 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * python311-doc-devhelp-3.11.15-150600.3.59.1 * python311-3.11.15-150600.3.59.3 * python311-curses-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-tk-debuginfo-3.11.15-150600.3.59.3 * libpython3_11-1_0-debuginfo-3.11.15-150600.3.59.3 * python311-testsuite-3.11.15-150600.3.59.3 * python311-dbm-debuginfo-3.11.15-150600.3.59.3 * python311-dbm-3.11.15-150600.3.59.3 * python311-testsuite-debuginfo-3.11.15-150600.3.59.3 * python311-base-3.11.15-150600.3.59.3 * python311-curses-debuginfo-3.11.15-150600.3.59.3 * libpython3_11-1_0-3.11.15-150600.3.59.3 * python311-base-debuginfo-3.11.15-150600.3.59.3 * python311-debugsource-3.11.15-150600.3.59.3 * python311-tk-3.11.15-150600.3.59.3 * python311-tools-3.11.15-150600.3.59.3 * python311-idle-3.11.15-150600.3.59.3 * python311-doc-3.11.15-150600.3.59.1 * python311-debuginfo-3.11.15-150600.3.59.3 * python311-devel-3.11.15-150600.3.59.3 * openSUSE Leap 15.6 (x86_64) * python311-base-32bit-debuginfo-3.11.15-150600.3.59.3 * python311-base-32bit-3.11.15-150600.3.59.3 * libpython3_11-1_0-32bit-3.11.15-150600.3.59.3 * python311-32bit-debuginfo-3.11.15-150600.3.59.3 * python311-32bit-3.11.15-150600.3.59.3 * libpython3_11-1_0-32bit-debuginfo-3.11.15-150600.3.59.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-base-debuginfo-3.11.15-150600.3.59.3 * python311-dbm-debuginfo-3.11.15-150600.3.59.3 * python311-3.11.15-150600.3.59.3 * python311-curses-3.11.15-150600.3.59.3 * python311-dbm-3.11.15-150600.3.59.3 * python311-debugsource-3.11.15-150600.3.59.3 * libpython3_11-1_0-debuginfo-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-tk-3.11.15-150600.3.59.3 * python311-base-3.11.15-150600.3.59.3 * python311-curses-debuginfo-3.11.15-150600.3.59.3 * python311-tools-3.11.15-150600.3.59.3 * python311-tk-debuginfo-3.11.15-150600.3.59.3 * python311-idle-3.11.15-150600.3.59.3 * libpython3_11-1_0-3.11.15-150600.3.59.3 * python311-debuginfo-3.11.15-150600.3.59.3 * python311-devel-3.11.15-150600.3.59.3 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-base-debuginfo-3.11.15-150600.3.59.3 * python311-debugsource-3.11.15-150600.3.59.3 * python311-dbm-3.11.15-150600.3.59.3 * python311-curses-3.11.15-150600.3.59.3 * python311-dbm-debuginfo-3.11.15-150600.3.59.3 * python311-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-tk-3.11.15-150600.3.59.3 * python311-base-3.11.15-150600.3.59.3 * python311-curses-debuginfo-3.11.15-150600.3.59.3 * python311-tk-debuginfo-3.11.15-150600.3.59.3 * python311-tools-3.11.15-150600.3.59.3 * libpython3_11-1_0-3.11.15-150600.3.59.3 * python311-idle-3.11.15-150600.3.59.3 * libpython3_11-1_0-debuginfo-3.11.15-150600.3.59.3 * python311-debuginfo-3.11.15-150600.3.59.3 * python311-devel-3.11.15-150600.3.59.3 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-dbm-debuginfo-3.11.15-150600.3.59.3 * python311-dbm-3.11.15-150600.3.59.3 * python311-curses-3.11.15-150600.3.59.3 * python311-3.11.15-150600.3.59.3 * python311-debugsource-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-tk-3.11.15-150600.3.59.3 * python311-curses-debuginfo-3.11.15-150600.3.59.3 * python311-tk-debuginfo-3.11.15-150600.3.59.3 * python311-tools-3.11.15-150600.3.59.3 * python311-idle-3.11.15-150600.3.59.3 * python311-debuginfo-3.11.15-150600.3.59.3 * python311-devel-3.11.15-150600.3.59.3 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-base-debuginfo-3.11.15-150600.3.59.3 * libpython3_11-1_0-debuginfo-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-base-3.11.15-150600.3.59.3 * libpython3_11-1_0-3.11.15-150600.3.59.3 ## References: * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:49 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:31:49 -0000 Subject: SUSE-SU-2026:3103-1: moderate: Security update for wpa_supplicant Message-ID: <178432030960.935.14836384286204496585@f4f3e2688bac> # Security update for wpa_supplicant Announcement ID: SUSE-SU-2026:3103-1 Release Date: 2026-07-17T13:30:13Z Rating: moderate References: * bsc#1239461 * bsc#1269892 Cross-References: * CVE-2025-24912 * CVE-2026-58374 CVSS scores: * CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58374 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58374 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58374 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for wpa_supplicant fixes the following issues: * CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). * CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). * Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ * Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3103=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * wpa_supplicant-2.11-150700.3.3.1 * wpa_supplicant-debuginfo-2.11-150700.3.3.1 * wpa_supplicant-debugsource-2.11-150700.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24912.html * https://www.suse.com/security/cve/CVE-2026-58374.html * https://bugzilla.suse.com/show_bug.cgi?id=1239461 * https://bugzilla.suse.com/show_bug.cgi?id=1269892 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:32:06 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 17 Jul 2026 20:32:06 -0000 Subject: SUSE-SU-2026:3102-1: important: Security update for go1.26-openssl Message-ID: <178432032664.935.15730278641807490642@f4f3e2688bac> # Security update for go1.26-openssl Announcement ID: SUSE-SU-2026:3102-1 Release Date: 2026-07-17T13:10:42Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1267442 * bsc#1267444 * bsc#1267450 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-27145 * CVE-2026-39822 * CVE-2026-42504 * CVE-2026-42505 * CVE-2026-42507 CVSS scores: * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities, contains two features and has three security fixes can now be installed. ## Description: This update for go1.26-openssl fixes the following issues * Update to version go1.26.5 (bsc#1255111). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). * CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3102=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3102=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3102=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3102=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * go1.26-openssl-doc-1.26.5-150600.13.9.1 * go1.26-openssl-1.26.5-150600.13.9.1 * go1.26-openssl-race-1.26.5-150600.13.9.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * go1.26-openssl-race-1.26.5-150600.13.9.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * go1.26-openssl-doc-1.26.5-150600.13.9.1 * go1.26-openssl-1.26.5-150600.13.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * go1.26-openssl-doc-1.26.5-150600.13.9.1 * go1.26-openssl-1.26.5-150600.13.9.1 * go1.26-openssl-race-1.26.5-150600.13.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-openssl-doc-1.26.5-150600.13.9.1 * go1.26-openssl-1.26.5-150600.13.9.1 * go1.26-openssl-race-1.26.5-150600.13.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 08:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 08:30:24 -0000 Subject: SUSE-RU-2026:3120-1: moderate: Recommended update for stalld Message-ID: <178453622438.1473.3306968577260120617@178315a69387> # Recommended update for stalld Announcement ID: SUSE-RU-2026:3120-1 Release Date: 2026-07-18T08:23:02Z Rating: moderate References: * jsc#PED-15088 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains one feature can now be installed. ## Description: This update for stalld fixes the following issues: Ship stalld in version 1.19.8. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3120=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * stalld-1.19.8-150700.15.3.1 * stalld-debuginfo-1.19.8-150700.15.3.1 * stalld-debugsource-1.19.8-150700.15.3.1 ## References: * https://jira.suse.com/browse/PED-15088 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 08:30:41 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 08:30:41 -0000 Subject: SUSE-RU-2026:3119-1: moderate: Recommended update for rpmlint Message-ID: <178453624114.1473.3998529922869899206@178315a69387> # Recommended update for rpmlint Announcement ID: SUSE-RU-2026:3119-1 Release Date: 2026-07-17T20:22:41Z Rating: moderate References: * jsc#PED-16347 Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.3 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains one feature can now be installed. ## Description: This update for rpmlint fixes the following issues: * Replace group 'singularity' by 'apptainer' in config (jsc#PED-16347) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3119=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3119=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3119=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3119=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3119=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3119=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3119=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3119=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3119=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3119=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3119=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3119=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3119=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3119=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3119=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * rpmlint-mini-debuginfo-1.10-150300.18.33.1 * rpmlint-mini-debugsource-1.10-150300.18.33.1 * rpmlint-mini-1.10-150300.18.33.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * rpmlint-1.10-150000.7.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * rpmlint-mini-debuginfo-1.10-150400.23.36.1 * rpmlint-mini-1.10-150400.23.36.1 * rpmlint-mini-debugsource-1.10-150400.23.36.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * rpmlint-mini-debugsource-1.10-150600.31.18.1 * rpmlint-mini-debuginfo-1.10-150600.31.18.1 * rpmlint-mini-1.10-150600.31.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rpmlint-mini-debugsource-1.10-150600.31.18.1 * rpmlint-mini-debuginfo-1.10-150600.31.18.1 * rpmlint-mini-1.10-150600.31.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * rpmlint-1.10-150000.7.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rpmlint-mini-1.10-150500.26.21.1 * rpmlint-mini-debugsource-1.10-150500.26.21.1 * rpmlint-mini-debuginfo-1.10-150500.26.21.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * rpmlint-1.10-150000.7.104.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * rpmlint-mini-debuginfo-1.10-150400.23.36.1 * rpmlint-mini-1.10-150400.23.36.1 * rpmlint-mini-debugsource-1.10-150400.23.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * rpmlint-1.10-150000.7.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rpmlint-mini-1.10-150500.26.21.1 * rpmlint-mini-debugsource-1.10-150500.26.21.1 * rpmlint-mini-debuginfo-1.10-150500.26.21.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * rpmlint-mini-1.10-150500.26.21.1 * rpmlint-mini-debugsource-1.10-150500.26.21.1 * rpmlint-mini-debuginfo-1.10-150500.26.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * rpmlint-mini-1.10-150500.26.21.1 * rpmlint-mini-debugsource-1.10-150500.26.21.1 * rpmlint-mini-debuginfo-1.10-150500.26.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * rpmlint-1.10-150000.7.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rpmlint-mini-debugsource-1.10-150600.31.18.1 * rpmlint-mini-debuginfo-1.10-150600.31.18.1 * rpmlint-mini-1.10-150600.31.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * rpmlint-1.10-150000.7.104.1 * Development Tools Module 15-SP7 (noarch) * rpmlint-1.10-150000.7.104.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rpmlint-mini-1.10-150700.37.8.1 * rpmlint-mini-debugsource-1.10-150700.37.8.1 * rpmlint-mini-debuginfo-1.10-150700.37.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * rpmlint-mini-1.10-150500.26.21.1 * rpmlint-mini-debugsource-1.10-150500.26.21.1 * rpmlint-mini-debuginfo-1.10-150500.26.21.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * rpmlint-1.10-150000.7.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rpmlint-mini-debugsource-1.10-150400.23.36.1 * rpmlint-mini-1.10-150400.23.36.1 * rpmlint-mini-debuginfo-1.10-150400.23.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * rpmlint-1.10-150000.7.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * rpmlint-mini-debugsource-1.10-150400.23.36.1 * rpmlint-mini-1.10-150400.23.36.1 * rpmlint-mini-debuginfo-1.10-150400.23.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * rpmlint-1.10-150000.7.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rpmlint-mini-debuginfo-1.10-150400.23.36.1 * rpmlint-mini-1.10-150400.23.36.1 * rpmlint-mini-debugsource-1.10-150400.23.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * rpmlint-1.10-150000.7.104.1 ## References: * https://jira.suse.com/browse/PED-16347 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 08:31:06 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 08:31:06 -0000 Subject: SUSE-RU-2026:3118-1: moderate: Recommended update for gcc15 Message-ID: <178453626688.1473.7912873984924906883@178315a69387> # Recommended update for gcc15 Announcement ID: SUSE-RU-2026:3118-1 Release Date: 2026-07-17T20:20:09Z Rating: moderate References: * bsc#1252306 * bsc#1253043 * bsc#1257463 * jsc#PED-15601 Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP7 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP7 An update that contains one feature and has three fixes can now be installed. ## Description: This update for gcc15 fixes the following issues: * Update to GCC 15.3 release * Drop -fhardened from RPM_OPT_FLAGS * Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) * Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] * Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. * includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] * Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] * Check availability of builtins at expand time ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3118=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3118=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3118=1 * SUSE Linux Enterprise High Performance Computing 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3118=1 * SUSE Linux Enterprise Server 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3118=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3118=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3118=1 * SUSE Linux Enterprise Server 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3118=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3118=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3118=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3118=1 SUSE-SLE-Product- SLES_SAP-15-SP5-2026-3118=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3118=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3118=1 SUSE-SLE-Product- SLES_SAP-15-SP6-2026-3118=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3118=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3118=1 * SUSE Linux Enterprise Server 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3118=1 * SUSE Linux Enterprise High Performance Computing 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3118=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3118=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3118=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3118=1 * SUSE Linux Enterprise Desktop 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3118=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3118=1 * SUSE Linux Enterprise High Performance Computing 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3118=1 * SUSE Linux Enterprise Server 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3118=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3118=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3118=1 * SUSE Linux Enterprise Desktop 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3118=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3118=1 SUSE-SLE- INSTALLER-15-SP4-2026-3118=1 * SUSE Linux Enterprise High Performance Computing 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3118=1 * SUSE Linux Enterprise Desktop 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3118=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3118=1 * SUSE Linux Enterprise Desktop 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3118=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3118=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3118=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-locale-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libhwasan0-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * gcc15-info-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (ppc64le x86_64) * libquadmath0-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64) * libhwasan0-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (ppc64le s390x x86_64) * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * cross-nvptx-gcc15-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * cross-nvptx-gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * cross-nvptx-newlib15-devel-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-locale-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * libhwasan0-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le x86_64) * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (ppc64le x86_64) * libquadmath0-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gcc15-info-15.3.0+git11272-150000.1.12.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libasan8-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * Basesystem Module 15-SP7 (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * Basesystem Module 15-SP7 (ppc64le x86_64) * libquadmath0-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * Basesystem Module 15-SP7 (aarch64 x86_64) * libhwasan0-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * gcc15-locale-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-debuginfo-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libhwasan0-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gcc15-info-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * gcc15-locale-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * libquadmath0-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * cross-nvptx-gcc15-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libhwasan0-15.3.0+git11272-150000.1.12.1 * cross-nvptx-gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * cross-nvptx-newlib15-devel-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gcc15-info-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le x86_64) * libquadmath0-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * libhwasan0-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * gcc15-locale-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libhwasan0-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gcc15-info-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-locale-15.3.0+git11272-150000.1.12.1 * libquadmath0-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libhwasan0-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * gcc15-info-15.3.0+git11272-150000.1.12.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * gcc15-ada-15.3.0+git11272-150000.1.12.1 * libm2iso20-15.3.0+git11272-150000.1.12.1 * gcc15-ada-debuginfo-15.3.0+git11272-150000.1.12.1 * libm2log20-15.3.0+git11272-150000.1.12.1 * libm2cor20-15.3.0+git11272-150000.1.12.1 * libada15-15.3.0+git11272-150000.1.12.1 * libm2cor20-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-obj-c++-15.3.0+git11272-150000.1.12.1 * gcc15-go-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-m2-15.3.0+git11272-150000.1.12.1 * gcc15-go-15.3.0+git11272-150000.1.12.1 * gcc15-m2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-objc-debuginfo-15.3.0+git11272-150000.1.12.1 * libada15-debuginfo-15.3.0+git11272-150000.1.12.1 * libgo24-debuginfo-15.3.0+git11272-150000.1.12.1 * libm2pim20-debuginfo-15.3.0+git11272-150000.1.12.1 * libm2min20-15.3.0+git11272-150000.1.12.1 * libm2min20-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-obj-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * libm2pim20-15.3.0+git11272-150000.1.12.1 * gcc15-objc-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * libgo24-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libm2log20-debuginfo-15.3.0+git11272-150000.1.12.1 * libm2iso20-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Package Hub 15 15-SP7 (x86_64) * libgdruntime6-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-d-32bit-15.3.0+git11272-150000.1.12.1 * libada15-32bit-15.3.0+git11272-150000.1.12.1 * libm2cor20-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libm2log20-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgo24-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-go-32bit-15.3.0+git11272-150000.1.12.1 * libgdruntime6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-m2-32bit-15.3.0+git11272-150000.1.12.1 * libm2iso20-32bit-15.3.0+git11272-150000.1.12.1 * libm2pim20-32bit-15.3.0+git11272-150000.1.12.1 * libgphobos6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-ada-32bit-15.3.0+git11272-150000.1.12.1 * libm2log20-32bit-15.3.0+git11272-150000.1.12.1 * libgo24-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-obj-c++-32bit-15.3.0+git11272-150000.1.12.1 * libm2min20-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libm2pim20-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libm2iso20-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgphobos6-32bit-15.3.0+git11272-150000.1.12.1 * libm2min20-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-objc-32bit-15.3.0+git11272-150000.1.12.1 * libm2cor20-32bit-15.3.0+git11272-150000.1.12.1 * libada15-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Package Hub 15 15-SP7 (aarch64 s390x x86_64) * gcc15-d-debuginfo-15.3.0+git11272-150000.1.12.1 * libgdruntime6-15.3.0+git11272-150000.1.12.1 * libgphobos6-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-d-15.3.0+git11272-150000.1.12.1 * libgdruntime6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgphobos6-15.3.0+git11272-150000.1.12.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * Development Tools Module 15-SP7 (x86_64) * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * cross-nvptx-gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * cross-nvptx-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * cross-nvptx-newlib15-devel-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * Development Tools Module 15-SP7 (noarch) * gcc15-info-15.3.0+git11272-150000.1.12.1 * Development Tools Module 15-SP7 (ppc64le x86_64) * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-locale-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libhwasan0-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * gcc15-info-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libgcc_s1-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libgcc_s1-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * gcc15-fortran-15.3.0+git11272-150000.1.12.1 * gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * gcc15-locale-15.3.0+git11272-150000.1.12.1 * libasan8-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-debuginfo-15.3.0+git11272-150000.1.12.1 * libhwasan0-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-15.3.0+git11272-150000.1.12.1 * liblsan0-15.3.0+git11272-150000.1.12.1 * liblsan0-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-c++-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-15.3.0+git11272-150000.1.12.1 * libhwasan0-15.3.0+git11272-150000.1.12.1 * libobjc4-debuginfo-15.3.0+git11272-150000.1.12.1 * cpp15-15.3.0+git11272-150000.1.12.1 * libasan8-debuginfo-15.3.0+git11272-150000.1.12.1 * libtsan2-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-PIE-15.3.0+git11272-150000.1.12.1 * libubsan1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgomp1-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-locale-15.3.0+git11272-150000.1.12.1 * gcc15-c++-15.3.0+git11272-150000.1.12.1 * cpp15-debuginfo-15.3.0+git11272-150000.1.12.1 * libubsan1-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libitm1-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-15.3.0+git11272-150000.1.12.1 * libgfortran5-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libgfortran5-32bit-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgfortran5-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-15.3.0+git11272-150000.1.12.1 * gcc15-c++-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libobjc4-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * gcc15-32bit-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libgcc_s1-32bit-15.3.0+git11272-150000.1.12.1 * libubsan1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * libasan8-32bit-15.3.0+git11272-150000.1.12.1 * libgomp1-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-devel-gcc15-15.3.0+git11272-150000.1.12.1 * libstdc++6-32bit-15.3.0+git11272-150000.1.12.1 * libstdc++6-pp-32bit-15.3.0+git11272-150000.1.12.1 * gcc15-fortran-32bit-15.3.0+git11272-150000.1.12.1 * libquadmath0-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-32bit-15.3.0+git11272-150000.1.12.1 * libitm1-32bit-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gcc15-info-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libgcc_s1-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libgcc_s1-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP7 (aarch64 ppc64le s390x x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libgcc_s1-15.3.0+git11272-150000.1.12.1 * libstdc++6-15.3.0+git11272-150000.1.12.1 * libstdc++6-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-debuginfo-15.3.0+git11272-150000.1.12.1 * libatomic1-15.3.0+git11272-150000.1.12.1 * libgcc_s1-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * gcc15-debugsource-15.3.0+git11272-150000.1.12.1 * gcc15-debuginfo-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP5 (aarch64 ppc64le s390x x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP6 (aarch64 ppc64le s390x x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing 15 SP5 (aarch64 x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing 15 SP4 (aarch64 x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP4 (aarch64 ppc64le s390x x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing 15 SP6 (aarch64 x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Desktop 15 SP5 (x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Desktop 15 SP4 (x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Manager Proxy 4.3 (x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 (ppc64le x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing 15 SP7 (aarch64 x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Desktop 15 SP7 (x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 * SUSE Linux Enterprise Desktop 15 SP6 (x86_64) * libstdc++6-15.3.0+git11272-150000.1.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1252306 * https://bugzilla.suse.com/show_bug.cgi?id=1253043 * https://bugzilla.suse.com/show_bug.cgi?id=1257463 * https://jira.suse.com/browse/PED-15601 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 12:30:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 12:30:25 -0000 Subject: SUSE-SU-2026:3125-1: important: Security update for gstreamer-plugins-bad Message-ID: <178455062527.1527.16909181043520376266@ddd703581f31> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:3125-1 Release Date: 2026-07-20T07:01:47Z Rating: important References: * bsc#1268168 * bsc#1268406 * bsc#1268408 * bsc#1268410 * bsc#1268971 * bsc#1271051 * bsc#1271168 Cross-References: * CVE-2026-12892 * CVE-2026-14935 * CVE-2026-52720 * CVE-2026-52721 * CVE-2026-52722 * CVE-2026-53702 * CVE-2026-59692 CVSS scores: * CVE-2026-12892 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12892 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12892 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-14935 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-14935 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-14935 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-52720 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52721 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-52721 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53702 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53702 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59692 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issues: * CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser (bsc#1268971). * CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check (bsc#1271051). * CVE-2026-52720: invalid check of total area instead of individual dimensions could trigger a heap out-of-bounds write (bsc#1268406). * CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could cause an out-of-bounds read (bsc#1268408). * CVE-2026-52722: crafted VMnc stream with large cursor dimensions can overflow signed integer (bsc#1268410). * CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could result in a stack buffer overflow (bsc#1268168). * CVE-2026-59692: unvalidated peer certificate Subject DN printed during a DTLS handshake could cause a stack buffer overflow (bsc#1271168). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3125=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3125=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3125=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3125=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3125=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-1.22.0-150500.3.34.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1 * libgstva-1_0-0-1.22.0-150500.3.34.1 * libgstplay-1_0-0-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.34.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-transcoder-devel-1.22.0-150500.3.34.1 * typelib-1_0-GstTranscoder-1_0-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-1.22.0-150500.3.34.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-transcoder-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-transcoder-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-1.22.0-150500.3.34.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1 * typelib-1_0-GstVulkanWayland-1_0-1.22.0-150500.3.34.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1 * libgstplay-1_0-0-1.22.0-150500.3.34.1 * libgstva-1_0-0-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1 * typelib-1_0-GstVulkanXCB-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstVulkan-1_0-1.22.0-150500.3.34.1 * openSUSE Leap 15.5 (aarch64_ilp32) * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstva-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-64bit-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstplay-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-64bit-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-64bit-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstplay-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstva-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-64bit-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1 * openSUSE Leap 15.5 (x86_64) * libgstcuda-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstva-1_0-0-32bit-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstva-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-32bit-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-32bit-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-32bit-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-32bit-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstplay-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstplay-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-32bit-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1 * openSUSE Leap 15.5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-1.22.0-150500.3.34.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1 * libgstplay-1_0-0-1.22.0-150500.3.34.1 * libgstva-1_0-0-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.34.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-1.22.0-150500.3.34.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-1.22.0-150500.3.34.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1 * libgstplay-1_0-0-1.22.0-150500.3.34.1 * libgstva-1_0-0-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.34.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-1.22.0-150500.3.34.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstvulkan-1_0-0-1.22.0-150500.3.34.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstcuda-1_0-0-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1 * libgstplay-1_0-0-1.22.0-150500.3.34.1 * libgstva-1_0-0-1.22.0-150500.3.34.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1 * gstreamer-plugins-bad-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.34.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.34.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1 * libgstplayer-1_0-0-1.22.0-150500.3.34.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.34.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12892.html * https://www.suse.com/security/cve/CVE-2026-14935.html * https://www.suse.com/security/cve/CVE-2026-52720.html * https://www.suse.com/security/cve/CVE-2026-52721.html * https://www.suse.com/security/cve/CVE-2026-52722.html * https://www.suse.com/security/cve/CVE-2026-53702.html * https://www.suse.com/security/cve/CVE-2026-59692.html * https://bugzilla.suse.com/show_bug.cgi?id=1268168 * https://bugzilla.suse.com/show_bug.cgi?id=1268406 * https://bugzilla.suse.com/show_bug.cgi?id=1268408 * https://bugzilla.suse.com/show_bug.cgi?id=1268410 * https://bugzilla.suse.com/show_bug.cgi?id=1268971 * https://bugzilla.suse.com/show_bug.cgi?id=1271051 * https://bugzilla.suse.com/show_bug.cgi?id=1271168 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 12:30:37 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 12:30:37 -0000 Subject: SUSE-SU-2026:3124-1: moderate: Security update for microcode_ctl Message-ID: <178455063773.1527.7706158053396064445@ddd703581f31> # Security update for microcode_ctl Announcement ID: SUSE-SU-2026:3124-1 Release Date: 2026-07-20T07:01:24Z Rating: moderate References: * bsc#1265189 Cross-References: * CVE-2025-35979 CVSS scores: * CVE-2025-35979 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35979 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-35979 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 11 SP4 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE An update that solves one vulnerability can now be installed. ## Description: This update for microcode_ctl fixes the following issue: * CVE-2025-35979: shared microarchitectural predictor state in VMX non-root operation could lead to data leaks (bsc#1265189). Changes for microcode_ctl: * Intel CPU Microcode was updated to the 20260512 release (bsc#1265189): * Update for various functional issues. ### New Platforms | Processor | Stepping | F-M-S/PI | Old Ver | New Ver | Products |:---------------|:---------|:------------|:---------|:---------|:--------- | PTL 404 | A1 | 06-cc-03/90 | | 0000011b | Intel Core Ultra Processor (Series 3) | PTL-H 484/12Xe | A0/B0 | 06-cc-02/90 | | 0000011b | Intel Core Ultra Processor (Series 3) ### Updated Platforms | ARL-H | A1 | 06-c5-02/82 | 0000011b | 00000121 | Core Ultra Processor (Series 2) | ARL-S/HX (8P) | B0 | 06-c6-02/82 | 0000011b | 00000121 | Core Ultra Processor (Series 2) | EMR- SP | A1 | 06-cf-02/87 | 210002d3 | 210002e0 | Xeon Scalable Gen5 | GNR-AP/SP | Bx/Hx/Lx | 06-ad-01/95 | 01000405 | 01000423 | Xeon 6900/6700/6500 Series Processors with P-Cores | GNR-D | B0/B1 | 06-ae-01/97 | 01000303 | 01000307 | Xeon 6700P-B/6500P-B Series SoC with P-Cores | GNR-SP R1S | Bx/Hx/Lx | 06-ad-01/20 | 0a000133 | 0a000142 | Xeon 6700/6500-Series Processors with P-Cores | LNL | B0 | 06-bd-01/80 | 00000125 | 00000126 | Core Ultra 200 V Series Processor | SPR-SP | E4/S2 | 06-8f-07/87 | 2b000661 | 2b000670 | Xeon Scalable Gen4 | SPR-SP | E5/S3 | 06-8f-08/87 | 2b000661 | 2b000670 | Xeon Scalable Gen4 | SRF-AP/SP | C0 | 06-af-03/01 | 03000382 | 030003a3 | Xeon 6900/6700-Series Processors with E-Cores * Intel CPU Microcode was updated to the 20260227 release: * Update for functional issues. Refer to Intel Xeon 6700P-B/6500P-B-Series SoC with P-Cores for details. * ### Updated Platforms * | GNR-D | B0/B1 | 06-ae-01/97 | 010002f3 | 01000303 | Xeon 6700P-B/6500P-B Series SoC with P-Cores ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-3124=1 * SUSE Linux Enterprise Server 11 SP4 zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-3124=1 ## Package List: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (x86_64) * microcode_ctl-1.17-102.83.95.1 * SUSE Linux Enterprise Server 11 SP4 (x86_64) * microcode_ctl-1.17-102.83.95.1 ## References: * https://www.suse.com/security/cve/CVE-2025-35979.html * https://bugzilla.suse.com/show_bug.cgi?id=1265189 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 12:30:43 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 12:30:43 -0000 Subject: SUSE-SU-2026:3123-1: important: Security update for shibboleth-sp Message-ID: <178455064397.1527.12412920900068342645@ddd703581f31> # Security update for shibboleth-sp Announcement ID: SUSE-SU-2026:3123-1 Release Date: 2026-07-20T07:01:17Z Rating: important References: * bsc#1249394 Cross-References: * CVE-2025-9943 CVSS scores: * CVE-2025-9943 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-9943 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.3 * Server Applications Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for shibboleth-sp fixes the following issue: * CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3123=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3123=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3123=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3123=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3123=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3123=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3123=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3123=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3123=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3123=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3123=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3123=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libshibsp9-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-3.1.0-150300.3.6.1 * libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1 * shibboleth-sp-debuginfo-3.1.0-150300.3.6.1 * libshibsp-lite8-3.1.0-150300.3.6.1 * shibboleth-sp-debugsource-3.1.0-150300.3.6.1 * libshibsp9-3.1.0-150300.3.6.1 * shibboleth-sp-devel-3.1.0-150300.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9943.html * https://bugzilla.suse.com/show_bug.cgi?id=1249394 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 12:30:53 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 12:30:53 -0000 Subject: SUSE-SU-2026:3122-1: moderate: Security update for systemd, systemd-mini Message-ID: <178455065300.1527.5673222760638767000@ddd703581f31> # Security update for systemd, systemd-mini Announcement ID: SUSE-SU-2026:3122-1 Release Date: 2026-07-20T06:59:45Z Rating: moderate References: * bsc#1261982 * bsc#1267647 Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has two security fixes can now be installed. ## Description: This update for systemd, systemd-mini fixes the following issues Changes for systemd: * Import commit 435c5779a785b4263b4dcacb70f50ef1cc3f9a7b (bsc#1267647). * Import commit 7aa089f75b77b2db22941081c37b8917ea8d0dda (bsc#1261982). * udev/scsi-id: check for invalid chars in various fields received from the kernel. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3122=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libudev1-32bit-228-157.82.1 * libudev-devel-228-157.82.1 * systemd-32bit-228-157.82.1 * libsystemd0-debuginfo-32bit-228-157.82.1 * systemd-debuginfo-32bit-228-157.82.1 * systemd-debugsource-228-157.82.1 * systemd-debuginfo-228-157.82.1 * libsystemd0-228-157.82.1 * systemd-228-157.82.1 * libsystemd0-debuginfo-228-157.82.1 * libudev1-debuginfo-32bit-228-157.82.1 * libsystemd0-32bit-228-157.82.1 * libudev1-228-157.82.1 * udev-debuginfo-228-157.82.1 * libudev1-debuginfo-228-157.82.1 * udev-228-157.82.1 * systemd-devel-228-157.82.1 * systemd-sysvinit-228-157.82.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * systemd-bash-completion-228-157.82.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 12:31:01 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 12:31:01 -0000 Subject: SUSE-SU-2026:3121-1: moderate: Security update for glib-networking Message-ID: <178455066160.1527.11603057173696841787@ddd703581f31> # Security update for glib-networking Announcement ID: SUSE-SU-2026:3121-1 Release Date: 2026-07-20T06:59:38Z Rating: moderate References: * bsc#1267979 Cross-References: * CVE-2026-10028 CVSS scores: * CVE-2026-10028 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-10028 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-10028 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for glib-networking fixes the following issue * CVE-2026-10028: two certificates which are each signed by the other can lead to an infinite loop (bsc#1267979). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3121=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * glib-networking-debugsource-2.48.2-6.6.1 * glib-networking-debuginfo-2.48.2-6.6.1 * glib-networking-2.48.2-6.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * glib-networking-lang-2.48.2-6.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10028.html * https://bugzilla.suse.com/show_bug.cgi?id=1267979 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:32:17 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:32:17 -0000 Subject: SUSE-SU-2026:22699-1: important: Security update for the Linux Kernel Message-ID: <178456513770.28209.13079983943087594799@39bfbf14787b> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22699-1 Release Date: 2026-07-06T13:11:36Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52962 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 * SUSE Linux Micro Extras 6.1 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-Extras-6.1-kernel-501=1 ## Package List: * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-49.1 * kernel-obs-build-debugsource-6.4.0-49.1 * kernel-syms-6.4.0-49.1 * SUSE Linux Micro Extras 6.1 (nosrc) * kernel-64kb-6.4.0-49.1 * SUSE Linux Micro Extras 6.1 (aarch64) * kernel-64kb-devel-6.4.0-49.1 * kernel-64kb-debugsource-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:32:35 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:32:35 -0000 Subject: SUSE-SU-2026:22698-1: important: Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456515559.28209.2783265765732908943@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22698-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-521=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-47-rt-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_24-debugsource-2-1.1 * kernel-livepatch-6_4_0-47-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:33:10 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:33:10 -0000 Subject: SUSE-SU-2026:22697-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456519004.28209.14004728562296095604@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22697-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-520=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-3-1.1 * kernel-livepatch-6_4_0-46-rt-debuginfo-3-1.1 * kernel-livepatch-6_4_0-46-rt-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:33:47 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:33:47 -0000 Subject: SUSE-SU-2026:22696-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456522750.28209.16263612940217177730@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22696-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-519=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-9-1.1 * kernel-livepatch-6_4_0-38-rt-debuginfo-9-1.1 * kernel-livepatch-6_4_0-38-rt-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:34:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:34:20 -0000 Subject: SUSE-SU-2026:22695-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456526080.28209.18077344075696561068@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22695-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-511=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-3-1.2 * kernel-livepatch-6_4_0-45-rt-debuginfo-3-1.2 * kernel-livepatch-6_4_0-45-rt-3-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:34:52 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:34:52 -0000 Subject: SUSE-SU-2026:22694-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456529244.28209.8490102350286135567@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22694-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-510=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-43-rt-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-3-1.1 * kernel-livepatch-6_4_0-43-rt-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:35:24 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:35:24 -0000 Subject: SUSE-SU-2026:22693-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456532442.28209.8224091139444696567@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22693-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-509=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-4-1.1 * kernel-livepatch-6_4_0-42-rt-debuginfo-4-1.1 * kernel-livepatch-6_4_0-42-rt-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:35:56 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:35:56 -0000 Subject: SUSE-SU-2026:22692-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456535658.28209.7899332773597264811@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22692-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-508=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-6-1.1 * kernel-livepatch-6_4_0-41-rt-debuginfo-6-1.1 * kernel-livepatch-6_4_0-41-rt-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:36:32 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:36:32 -0000 Subject: SUSE-SU-2026:22691-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456539285.28209.9989577007894978023@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22691-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-507=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-40-rt-debuginfo-7-1.1 * kernel-livepatch-6_4_0-40-rt-7-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:37:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:37:11 -0000 Subject: SUSE-SU-2026:22690-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456543102.28209.8702901025745381280@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22690-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-506=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-39-rt-debuginfo-8-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-8-1.1 * kernel-livepatch-6_4_0-39-rt-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:37:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:37:49 -0000 Subject: SUSE-SU-2026:22689-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456546902.28209.262832512440094694@39bfbf14787b> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22689-1 Release Date: 2026-07-16T08:21:48Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-504=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-37-rt-9-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-9-1.1 * kernel-livepatch-6_4_0-37-rt-debuginfo-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:37:53 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:37:53 -0000 Subject: SUSE-SU-2026:22688-1: moderate: Security update for kernel-livepatch-MICRO-6-0-RT_Update_26 Message-ID: <178456547344.28209.11520487647889299457@39bfbf14787b> # Security update for kernel-livepatch-MICRO-6-0-RT_Update_26 Announcement ID: SUSE-SU-2026:22688-1 Release Date: 2026-07-06T09:18:54Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.1 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_26 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 26 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-503=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_26-debugsource-1-1.1 * kernel-livepatch-6_4_0-49-rt-1-1.1 * kernel-livepatch-6_4_0-49-rt-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:38:26 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:38:26 -0000 Subject: SUSE-SU-2026:22687-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456550695.28209.3912260880720479422@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22687-1 Release Date: 2026-07-16T08:59:23Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-529=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-45-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_22-debugsource-3-1.1 * kernel-livepatch-6_4_0-45-default-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:39:00 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:39:00 -0000 Subject: SUSE-SU-2026:22686-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456554006.28209.5013366973777636535@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22686-1 Release Date: 2026-07-16T08:59:23Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-528=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-3-1.1 * kernel-livepatch-6_4_0-43-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:39:33 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:39:33 -0000 Subject: SUSE-SU-2026:22685-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456557360.28209.7852862636346825143@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22685-1 Release Date: 2026-07-16T08:59:23Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-527=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-42-default-debuginfo-4-1.1 * kernel-livepatch-MICRO-6-0_Update_19-debugsource-4-1.1 * kernel-livepatch-6_4_0-42-default-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:40:07 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:40:07 -0000 Subject: SUSE-SU-2026:22684-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456560715.28209.2347828627964979950@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22684-1 Release Date: 2026-07-16T08:59:23Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-526=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_18-debugsource-6-1.1 * kernel-livepatch-6_4_0-41-default-6-1.1 * kernel-livepatch-6_4_0-41-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:40:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:40:49 -0000 Subject: SUSE-SU-2026:22683-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456564981.28209.2176566975594507058@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22683-1 Release Date: 2026-07-16T08:59:23Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-525=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-40-default-7-1.1 * kernel-livepatch-MICRO-6-0_Update_17-debugsource-7-1.1 * kernel-livepatch-6_4_0-40-default-debuginfo-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:41:32 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:41:32 -0000 Subject: SUSE-SU-2026:22682-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456569222.28209.16180307023568497818@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22682-1 Release Date: 2026-07-16T08:59:23Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-524=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-38-default-debuginfo-9-1.2 * kernel-livepatch-MICRO-6-0_Update_14-debugsource-9-1.2 * kernel-livepatch-6_4_0-38-default-9-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:42:10 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:42:10 -0000 Subject: SUSE-SU-2026:22681-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456573083.28209.8255059878583164896@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22681-1 Release Date: 2026-07-16T08:59:22Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-523=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-31-default-20-1.2 * kernel-livepatch-MICRO-6-0_Update_9-debugsource-20-1.2 * kernel-livepatch-6_4_0-31-default-debuginfo-20-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:42:56 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:42:56 -0000 Subject: SUSE-SU-2026:22680-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456577622.28209.7590331221636431910@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22680-1 Release Date: 2026-07-16T08:59:22Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-30.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-522=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-debuginfo-20-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-20-1.2 * kernel-livepatch-6_4_0-30-default-20-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:43:12 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:43:12 -0000 Subject: SUSE-SU-2026:22679-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456579210.28209.18037041877255973754@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22679-1 Release Date: 2026-07-16T08:57:34Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-518=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-46-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-46-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_23-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:43:44 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:43:44 -0000 Subject: SUSE-SU-2026:22678-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456582427.28209.4163623588316046084@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22678-1 Release Date: 2026-07-16T08:24:09Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-517=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-44-default-3-1.1 * kernel-livepatch-6_4_0-44-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_21-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:44:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:44:20 -0000 Subject: SUSE-SU-2026:22677-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456586053.28209.13712160285689362805@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22677-1 Release Date: 2026-07-16T08:24:09Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-516=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-39-default-debuginfo-8-1.1 * kernel-livepatch-6_4_0-39-default-8-1.1 * kernel-livepatch-MICRO-6-0_Update_16-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:44:58 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:44:58 -0000 Subject: SUSE-SU-2026:22676-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456589893.28209.18094472735261449467@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22676-1 Release Date: 2026-07-16T08:24:09Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-515=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-36-default-11-1.1 * kernel-livepatch-MICRO-6-0_Update_13-debugsource-11-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:45:42 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:45:42 -0000 Subject: SUSE-SU-2026:22675-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456594273.28209.6628330777783998868@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22675-1 Release Date: 2026-07-16T08:24:09Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-514=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-debuginfo-13-1.1 * kernel-livepatch-6_4_0-35-default-13-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:46:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:46:21 -0000 Subject: SUSE-SU-2026:22674-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456598131.28209.14920766284906016328@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22674-1 Release Date: 2026-07-16T08:24:09Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-513=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_11-debugsource-13-1.1 * kernel-livepatch-6_4_0-34-default-13-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:46:59 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:46:59 -0000 Subject: SUSE-SU-2026:22673-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456601961.28209.6014620191179635473@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22673-1 Release Date: 2026-07-16T08:24:09Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-512=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-debuginfo-14-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-14-1.1 * kernel-livepatch-6_4_0-32-default-14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:47:15 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:47:15 -0000 Subject: SUSE-SU-2026:22672-1: important: Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178456603579.28209.9556069696447023560@39bfbf14787b> # Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22672-1 Release Date: 2026-07-16T08:21:33Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-505=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-47-default-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0_Update_24-debugsource-2-1.1 * kernel-livepatch-6_4_0-47-default-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:47:19 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:47:19 -0000 Subject: SUSE-SU-2026:22671-1: important: Security update for kernel-livepatch-MICRO-6-0_Update_26 Message-ID: <178456603988.28209.15925294432298999772@39bfbf14787b> # Security update for kernel-livepatch-MICRO-6-0_Update_26 Announcement ID: SUSE-SU-2026:22671-1 Release Date: 2026-07-06T09:32:56Z Rating: important References: Affected Products: * SUSE Linux Micro 6.1 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_26 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 26 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-500=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_26-debugsource-1-1.1 * kernel-livepatch-6_4_0-49-default-debuginfo-1-1.1 * kernel-livepatch-6_4_0-49-default-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:47:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:47:25 -0000 Subject: SUSE-RU-2026:22670-1: moderate: Recommended update for pcr-oracle Message-ID: <178456604530.28209.1879801450925124142@39bfbf14787b> # Recommended update for pcr-oracle Announcement ID: SUSE-RU-2026:22670-1 Release Date: 2026-07-16T07:29:17Z Rating: moderate References: * bsc#1270265 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for pcr-oracle fixes the following issues: Update to 0.6.4: * Support TPM PCR snapshot on PowerPC 64 platform * Fix SBAT string length calculations (bsc#1270265) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-615=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 x86_64) * pcr-oracle-debuginfo-0.6.4-slfo.1.1_1.1 * pcr-oracle-debugsource-0.6.4-slfo.1.1_1.1 * pcr-oracle-0.6.4-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270265 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:47:30 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:47:30 -0000 Subject: SUSE-RU-2026:22669-1: moderate: Recommended update for csp-billing-adapter-local, csp-billing-adapter-amazon, csp-billing-adapter, csp-billing-adapter-microsoft Message-ID: <178456605053.28209.10527124359766839819@39bfbf14787b> # Recommended update for csp-billing-adapter-local, csp-billing-adapter-amazon, csp-billing-adapter, csp-billing-adapter-microsoft Announcement ID: SUSE-RU-2026:22669-1 Release Date: 2026-07-15T08:10:59Z Rating: moderate References: * bsc#1227329 * jsc#PED-8482 Affected Products: * SUSE Linux Micro 6.1 An update that contains one feature and has one fix can now be installed. ## Description: This update for csp-billing-adapter-local, csp-billing-adapter-amazon, csp- billing-adapter, csp-billing-adapter-microsoft fixes the following issues: csp-billing-adapter: * Update to version 1.5.0 * Update spec to match the build in pypi * Fix license classifier in setup.py * Add option to manually run action * Add action to publish new versions to pypi * Update to version 1.4.0 * Add env var to override log level * Update to version 1.3.2 * Make customer id required in meter billing hookspec * Update to version 1.3.1 * Fix bug, Make the datetime timezone aware * Update to version 1.3.0 * Add batch metering workflow for SaaS billing * Update to version 1.2.0 * Add fixed billing feature * Fix update-alternatives to ensure there is a symlink for csp-billing-adapter binary * Update to version 1.1.0: * Fix unit file jsc#PED-8482 bsc#1227329 * Support daily billing interval to enable testing on Azure * Update to version 1.0.0: * Switch spec build to python 3.11 * Update to version 0.10.0: * Add free trial feature * Update to version 0.9.0: * Add metering archive feature * Update to version 0.8.0: * Clear billing status with an empty dictionary * Update to version 0.7.0: * Add get version hook spec * Update to version 0.6.0 Update message when records list is empty Only sleep at initial deployment Skip invalid records Log format variables on a const * Update to version 0.5.0 * Integrate log handling and log configuration * Fix python3-csp-billing-adapter dependency for service * Update to version 0.4.0 * Handle status dictionary from meter billing and legacy string response. * Implement supported for tiered consumption reporting. * Update to version 0.3.1 * Add -service subpackage * systemd enablement to run the code as a daemon in a VM * Update to version v0.3.0 * Add new exception type * Improved initial metering test exception handling * Update to version 0.2.0 * Split up `create_csp_config` into smaller components. * Update to version 0.1.1 * Fix retry on exception in the meter billing test. * Fix the timestamp in meter billing test call. This is a datetime object not a string timestamp. * Update to version 0.1.0 * Wait one cycle at startup before checking usage data * Dry run metering against API at startup * Sleep only for remainder of cycle to account for processing time. * Handle multiple errors using error list * Use cache and csp config in memory * Pass in now timestamp instead of re-generating * Save config map and cache once at end of loop * Add base product to csp config * Add timestamps to log messages * Add retry mechanism for functions that may fail randomly * Update to version 0.0.2 * Handle no matching dimension found for volume billing * Only load testing support plugins in unit tests * Add additional logging to core paths * Add Initial exception handling * initial build csp-billing-adapter-amazon: * Update to version 1.4.0: * Fix csp billing adapter requirement * Add pypy publish workflow * Update to version 1.3.0 * Add handling for REGION environment variable. If it is set this is preferred to checking the metadata. * Add handling for SKIP_METADATA environment variable. If it is set the metadata request will be skipped in account info function. * Update to version 1.2.1 * Make customer id required in meter billing hookspec * Update to version 1.2.0 * Add batch metering function to handle subscription billing * Update to version 1.1.0 * Add plugin file with plugin name for verification * Update to version 1.0.0: * Switch build to python 3.11 * Update to version 0.5.1: * Fix typo in metadata url * Update to version 0.5.0: * Add get version hook implementation * Update to version 0.4.0: * Add IPv6 support and IMDSv2 * Update to version 0.3.0 * Handle billing multiple dimensions. * Update to version 0.2.1 * Add region to boto3 client session. * Update to version 0.2.0 * Use existing `get_csp_name` function to prevent duplication. * update to version 0.1.0 * Add logging and tests to cover fail cases * Initial build csp-billing-adapter-local: \- Update to version 1.1.0: * Fix csp billing adapter requirement * Drop old python versions from ci testing * Add pypi publishing workflow * Fix license classifier in setup.py * Add obsoletes to spec file * Update to version 1.0.0: * Switch build to python 3.11 * Update to version 0.5.1: * Cast file path to a string for usage * Update to version 0.5.0: * Attempt to backup archive before saving * Add get_archive_location function * Add metering archive hook implementations * Update to version 0.4.1: * Edit the build requirement for core adapter module * Update to version 0.4.0: * Drop logs for cache and csp-config functions * Update to version 0.3.0: * Add get version hook implementation * Update to version 0.2.1 * Add timestamp with the same format as core adapter * Update to version 0.2.0 * Use the same formatter for log file as core adapter * Update to version 0.1.1 * Add reporting time to usage data * Refactor tests * Update to 0.1.0 * Logging changes * Access application reporting API * Cast data to internal reporting format * Initial build * Version 0.0.1 csp-billing-adapter-microsoft: * Update to version 1.3.1: * Fix billing adapter dependency * Update to version 1.3.0 * Add pypi publishing workflow * Update to version 1.2.2 * Make customer id required in meter billing hookspec * Update to version 1.2.1 * Fix bug in meter billing. Handle no api flag in config file * Update to version 1.2.0 * Add customer id to handle subscription billing * Update to version 1.1.0 * Add plugin file with plugin name for verification * Update to version 1.0.0: * Switch build to python 3.11 * Update to version 0.2.1: * Get credentials for VM * Update to version 0.2.0: * Add get version hook implementation * Update to version 0.1.1: * Bump version: 0.1.0 ? 0.1.1 * Update spec file to match the other csp-billing-adapter plugin spec files * Update to version 0.1.0~git2.e424147: * Implement meter_billing() for Azure and corresponding test cases * Bump version: 0.0.1 ? 0.1.0 * Update changelog for v0.1.0 * Add github workflows now that there are unit tests in place * Update plugin and unit test to use new exception type. * Fix pytest config is setup.cfg * add unit tests for metadata in plugin.py * update spec file to match Amazon * Initial build * Version 0.0.1 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-614=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * python311-csp-billing-adapter-local-1.1.0-slfo.1.1_1.1 * python311-csp-billing-adapter-amazon-1.4.0-slfo.1.1_1.1 * python311-csp-billing-adapter-microsoft-1.3.1-slfo.1.1_1.1 * python311-csp-billing-adapter-1.5.0-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1227329 * https://jira.suse.com/browse/PED-8482 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:47:35 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:47:35 -0000 Subject: SUSE-SU-2026:22668-1: moderate: Security update for dnsmasq Message-ID: <178456605591.28209.8611629514146061657@39bfbf14787b> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:22668-1 Release Date: 2026-07-09T07:34:28Z Rating: moderate References: * bsc#1268882 Cross-References: * CVE-2026-12969 CVSS scores: * CVE-2026-12969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12969 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for dnsmasq fixes the following issues * CVE-2026-12969: out-of-bounds read in `find_soa()` due to missing extrabytes validation (bsc#1268882). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-612=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * dnsmasq-2.93-slfo.1.1_2.1 * dnsmasq-debuginfo-2.93-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12969.html * https://bugzilla.suse.com/show_bug.cgi?id=1268882 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:47:41 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:47:41 -0000 Subject: SUSE-SU-2026:22667-1: moderate: Security update for alsa Message-ID: <178456606138.28209.4280870846374974699@39bfbf14787b> # Security update for alsa Announcement ID: SUSE-SU-2026:22667-1 Release Date: 2026-07-07T11:46:47Z Rating: moderate References: * bsc#1268853 Cross-References: * CVE-2026-56109 CVSS scores: * CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56109 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for alsa fixes the following issue * CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory (bsc#1268853). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-611=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libasound2-debuginfo-1.2.10-slfo.1.1_2.1 * alsa-debugsource-1.2.10-slfo.1.1_2.1 * libasound2-1.2.10-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56109.html * https://bugzilla.suse.com/show_bug.cgi?id=1268853 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:49:46 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:49:46 -0000 Subject: SUSE-SU-2026:22666-1: important: Security update for the Linux Kernel Message-ID: <178456618627.28209.10905177514144808089@39bfbf14787b> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22666-1 Release Date: 2026-07-06T13:11:38Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52962 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-502=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 x86_64) * kernel-rt-devel-6.4.0-49.1 * kernel-rt-debugsource-6.4.0-49.1 * kernel-rt-debuginfo-6.4.0-49.1 * SUSE Linux Micro 6.1 (noarch) * kernel-devel-rt-6.4.0-49.1 * kernel-source-rt-6.4.0-49.1 * SUSE Linux Micro 6.1 (aarch64 nosrc x86_64) * kernel-rt-6.4.0-49.1 * SUSE Linux Micro 6.1 (x86_64) * kernel-rt-livepatch-6.4.0-49.1 * kernel-rt-devel-debuginfo-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:51:51 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:51:51 -0000 Subject: SUSE-SU-2026:22665-1: important: Security update for the Linux Kernel Message-ID: <178456631151.28209.11044228321288333032@39bfbf14787b> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22665-1 Release Date: 2026-07-06T13:11:36Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52962 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-501=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-49.1 * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-49.1 * kernel-default-devel-6.4.0-49.1 * kernel-default-debuginfo-6.4.0-49.1 * SUSE Linux Micro 6.1 (noarch) * kernel-devel-6.4.0-49.1 * kernel-source-6.4.0-49.1 * kernel-macros-6.4.0-49.1 * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-default-livepatch-6.4.0-49.1 * SUSE Linux Micro 6.1 (nosrc x86_64) * kernel-kvmsmall-6.4.0-49.1 * SUSE Linux Micro 6.1 (ppc64le x86_64) * kernel-default-devel-debuginfo-6.4.0-49.1 * SUSE Linux Micro 6.1 (x86_64) * kernel-kvmsmall-debuginfo-6.4.0-49.1 * kernel-kvmsmall-debugsource-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:52:09 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:52:09 -0000 Subject: SUSE-SU-2026:22664-1: important: Security update for jq Message-ID: <178456632997.28209.303184993242564099@39bfbf14787b> # Security update for jq Announcement ID: SUSE-SU-2026:22664-1 Release Date: 2026-07-03T12:16:11Z Rating: important References: * bsc#1262043 * bsc#1262044 * bsc#1262069 * bsc#1262070 * bsc#1262071 * bsc#1262072 * bsc#1265060 * bsc#1265061 * bsc#1265062 * bsc#1265070 Cross-References: * CVE-2026-32316 * CVE-2026-33947 * CVE-2026-33948 * CVE-2026-39956 * CVE-2026-39979 * CVE-2026-40164 * CVE-2026-40612 * CVE-2026-41256 * CVE-2026-41257 * CVE-2026-43894 CVSS scores: * CVE-2026-32316 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-32316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32316 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-33947 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33947 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33948 ( SUSE ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-33948 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-39956 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39956 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39956 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39979 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39979 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-39979 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40164 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40612 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40612 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-40612 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40612 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41256 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41256 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41257 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41257 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-41257 ( NVD ): 6.4 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43894 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43894 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43894 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). * CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). * CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). * CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). * CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre- computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). * CVE-2026-40612: recursion into nested arrays/objects with no depth limit in `jv_contains` can lead to a C stack exhaustion when processing crafted input (bsc#1265060). * CVE-2026-41256: truncation of top-level jq programs loaded with `-f` and can lead to the execution of unintended programs (bsc#1265061). * CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS when processing jq bytecode (bsc#1265062). * CVE-2026-43894: signed integer overflow in the `decNumberFromString` `D2U()` macro can lead to an out-of-bounds memory write when processing large number literals (bsc#1265070). * CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-610=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * jq-1.7.1-slfo.1.1_3.1 * jq-debugsource-1.7.1-slfo.1.1_3.1 * libjq1-debuginfo-1.7.1-slfo.1.1_3.1 * libjq1-1.7.1-slfo.1.1_3.1 * jq-debuginfo-1.7.1-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32316.html * https://www.suse.com/security/cve/CVE-2026-33947.html * https://www.suse.com/security/cve/CVE-2026-33948.html * https://www.suse.com/security/cve/CVE-2026-39956.html * https://www.suse.com/security/cve/CVE-2026-39979.html * https://www.suse.com/security/cve/CVE-2026-40164.html * https://www.suse.com/security/cve/CVE-2026-40612.html * https://www.suse.com/security/cve/CVE-2026-41256.html * https://www.suse.com/security/cve/CVE-2026-41257.html * https://www.suse.com/security/cve/CVE-2026-43894.html * https://bugzilla.suse.com/show_bug.cgi?id=1262043 * https://bugzilla.suse.com/show_bug.cgi?id=1262044 * https://bugzilla.suse.com/show_bug.cgi?id=1262069 * https://bugzilla.suse.com/show_bug.cgi?id=1262070 * https://bugzilla.suse.com/show_bug.cgi?id=1262071 * https://bugzilla.suse.com/show_bug.cgi?id=1262072 * https://bugzilla.suse.com/show_bug.cgi?id=1265060 * https://bugzilla.suse.com/show_bug.cgi?id=1265061 * https://bugzilla.suse.com/show_bug.cgi?id=1265062 * https://bugzilla.suse.com/show_bug.cgi?id=1265070 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:52:16 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:52:16 -0000 Subject: SUSE-SU-2026:22663-1: important: Security update for haproxy Message-ID: <178456633659.28209.103749846975851323@39bfbf14787b> # Security update for haproxy Announcement ID: SUSE-SU-2026:22663-1 Release Date: 2026-07-03T12:16:11Z Rating: important References: * bsc#1268557 * bsc#1268558 Cross-References: * CVE-2026-55203 * CVE-2026-55204 CVSS scores: * CVE-2026-55203 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-55203 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55203 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N * CVE-2026-55204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues * CVE-2026-55203: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557). * CVE-2026-55204: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-609=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * haproxy-2.8.11+git0.01c1056a4-slfo.1.1_4.1 * haproxy-debuginfo-2.8.11+git0.01c1056a4-slfo.1.1_4.1 * haproxy-debugsource-2.8.11+git0.01c1056a4-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55203.html * https://www.suse.com/security/cve/CVE-2026-55204.html * https://bugzilla.suse.com/show_bug.cgi?id=1268557 * https://bugzilla.suse.com/show_bug.cgi?id=1268558 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:52:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:52:20 -0000 Subject: SUSE-RU-2026:3129-1: moderate: Recommended update for tiertune Message-ID: <178456634093.28209.4659713174264101137@39bfbf14787b> # Recommended update for tiertune Announcement ID: SUSE-RU-2026:3129-1 Release Date: 2026-07-20T09:41:36Z Rating: moderate References: * jsc#PED-16415 * jsc#PED-16423 Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains two features can now be installed. ## Description: This update for tiertune fixes the following issues: * Implement the package 'tiertune' to dynamically configure systemd and kernel settings based on specific cloud instance types across GCE, AWS, and Azure ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3129=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3129=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3129=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * tiertune-gce-0.1.1-150600.13.3.1 * tiertune-azure-0.1.1-150600.13.3.1 * tiertune-aws-0.1.1-150600.13.3.1 * python311-tiertune-0.1.1-150600.13.3.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * tiertune-gce-0.1.1-150600.13.3.1 * tiertune-azure-0.1.1-150600.13.3.1 * tiertune-aws-0.1.1-150600.13.3.1 * python311-tiertune-0.1.1-150600.13.3.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * tiertune-gce-0.1.1-150600.13.3.1 * tiertune-azure-0.1.1-150600.13.3.1 * tiertune-aws-0.1.1-150600.13.3.1 * python311-tiertune-0.1.1-150600.13.3.1 ## References: * https://jira.suse.com/browse/PED-16415 * https://jira.suse.com/browse/PED-16423 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:52:26 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:52:26 -0000 Subject: SUSE-OU-2026:3128-1: low: Optional update for python-contextwars, python3-immutables Message-ID: <178456634632.28209.7008339969907949924@39bfbf14787b> # Optional update for python-contextwars, python3-immutables Announcement ID: SUSE-OU-2026:3128-1 Release Date: 2026-07-20T09:07:26Z Rating: low References: * bsc#1267981 Affected Products: * Public Cloud Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for python-contextwars, python3-immutables fixes the following issue: * Add python3-contextwars and python3-immutables to Server Applications Module. No source change. (bsc#1267981) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3128=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3128=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3128=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3128=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3128=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3128=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3128=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python-immutables-debugsource-0.11-150000.1.5.1 * python3-immutables-0.11-150000.1.5.1 * python3-immutables-debuginfo-0.11-150000.1.5.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-contextvars-2.4-150000.1.5.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python-immutables-debugsource-0.11-150000.1.5.1 * python3-immutables-0.11-150000.1.5.1 * python3-immutables-debuginfo-0.11-150000.1.5.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-contextvars-2.4-150000.1.5.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python-immutables-debugsource-0.11-150000.1.5.1 * python3-immutables-0.11-150000.1.5.1 * python3-immutables-debuginfo-0.11-150000.1.5.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-contextvars-2.4-150000.1.5.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python-immutables-debugsource-0.11-150000.1.5.1 * python3-immutables-0.11-150000.1.5.1 * python3-immutables-debuginfo-0.11-150000.1.5.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-contextvars-2.4-150000.1.5.1 * Public Cloud Module 15-SP7 (noarch) * python3-contextvars-2.4-150000.1.5.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-immutables-debugsource-0.11-150000.1.5.1 * python3-immutables-0.11-150000.1.5.1 * python3-immutables-debuginfo-0.11-150000.1.5.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-immutables-0.11-150000.1.5.1 * Server Applications Module 15-SP7 (noarch) * python3-contextvars-2.4-150000.1.5.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python-immutables-debugsource-0.11-150000.1.5.1 * python3-immutables-0.11-150000.1.5.1 * python3-immutables-debuginfo-0.11-150000.1.5.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-contextvars-2.4-150000.1.5.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267981 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:52:30 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:52:30 -0000 Subject: SUSE-RU-2026:3127-1: moderate: Recommended update for amazon-cloudwatch-agent Message-ID: <178456635041.28209.8330715471296687582@39bfbf14787b> # Recommended update for amazon-cloudwatch-agent Announcement ID: SUSE-RU-2026:3127-1 Release Date: 2026-07-20T09:06:19Z Rating: moderate References: * jsc#PED-12675 Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that contains one feature can now be installed. ## Description: This update for amazon-cloudwatch-agent fixes the following issues: * Add amazon-cloudwatch-agent (jsc#PED-12675) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3127=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3127=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3127=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3127=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3127=1 ## Package List: * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.5.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.5.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.5.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.5.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.5.1 ## References: * https://jira.suse.com/browse/PED-12675 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 16:52:34 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 16:52:34 -0000 Subject: SUSE-SU-2026:3126-1: important: Security update for podman Message-ID: <178456635452.28209.17792623827447680501@39bfbf14787b> # Security update for podman Announcement ID: SUSE-SU-2026:3126-1 Release Date: 2026-07-20T08:27:54Z Rating: important References: Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that can now be installed. ## Description: This update for podman rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3126=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3126=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3126=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3126=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3126=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3126=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3126=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3126=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3126=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * podman-remote-debuginfo-4.9.5-150400.4.76.1 * podman-remote-4.9.5-150400.4.76.1 * podman-4.9.5-150400.4.76.1 * podman-debuginfo-4.9.5-150400.4.76.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.76.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * podman-remote-4.9.5-150400.4.76.1 * podmansh-4.9.5-150400.4.76.1 * podman-debuginfo-4.9.5-150400.4.76.1 * podman-remote-debuginfo-4.9.5-150400.4.76.1 * podman-4.9.5-150400.4.76.1 * openSUSE Leap 15.4 (noarch) * podman-docker-4.9.5-150400.4.76.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.76.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * podman-debuginfo-4.9.5-150400.4.76.1 * podman-remote-4.9.5-150400.4.76.1 * podman-4.9.5-150400.4.76.1 * podman-remote-debuginfo-4.9.5-150400.4.76.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * podman-debuginfo-4.9.5-150400.4.76.1 * podman-remote-4.9.5-150400.4.76.1 * podman-4.9.5-150400.4.76.1 * podman-remote-debuginfo-4.9.5-150400.4.76.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * podman-docker-4.9.5-150400.4.76.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * podman-remote-4.9.5-150400.4.76.1 * podman-remote-debuginfo-4.9.5-150400.4.76.1 * podman-4.9.5-150400.4.76.1 * podman-debuginfo-4.9.5-150400.4.76.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * podman-remote-4.9.5-150400.4.76.1 * podman-remote-debuginfo-4.9.5-150400.4.76.1 * podman-4.9.5-150400.4.76.1 * podman-debuginfo-4.9.5-150400.4.76.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.76.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * podman-remote-debuginfo-4.9.5-150400.4.76.1 * podman-remote-4.9.5-150400.4.76.1 * podman-4.9.5-150400.4.76.1 * podman-debuginfo-4.9.5-150400.4.76.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * podman-remote-debuginfo-4.9.5-150400.4.76.1 * podman-remote-4.9.5-150400.4.76.1 * podman-4.9.5-150400.4.76.1 * podman-debuginfo-4.9.5-150400.4.76.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * podman-remote-debuginfo-4.9.5-150400.4.76.1 * podman-remote-4.9.5-150400.4.76.1 * podman-4.9.5-150400.4.76.1 * podman-debuginfo-4.9.5-150400.4.76.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 20:41:50 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 20:41:50 -0000 Subject: SUSE-SU-2026:3130-1: important: Security update for the Linux Kernel Message-ID: <178458011049.1659.13653892631518136319@ddd703581f31> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:3130-1 Release Date: 2026-07-20T12:25:32Z Rating: important References: * bsc#1204315 * bsc#1243603 * bsc#1251942 * bsc#1256564 * bsc#1257605 * bsc#1257777 * bsc#1260012 * bsc#1260593 * bsc#1261250 * bsc#1261562 * bsc#1262391 * bsc#1262603 * bsc#1262605 * bsc#1262614 * bsc#1262637 * bsc#1262639 * bsc#1262649 * bsc#1262653 * bsc#1262658 * bsc#1262659 * bsc#1262678 * bsc#1262723 * bsc#1262751 * bsc#1262757 * bsc#1262765 * bsc#1262768 * bsc#1262992 * bsc#1263008 * bsc#1263011 * bsc#1263013 * bsc#1263014 * bsc#1263016 * bsc#1263017 * bsc#1263020 * bsc#1263025 * bsc#1263030 * bsc#1263031 * bsc#1263045 * bsc#1263055 * bsc#1263059 * bsc#1263068 * bsc#1263073 * bsc#1263075 * bsc#1263077 * bsc#1263097 * bsc#1263111 * bsc#1263128 * bsc#1263134 * bsc#1263139 * bsc#1263142 * bsc#1263145 * bsc#1263167 * bsc#1263173 * bsc#1263175 * bsc#1263491 * bsc#1263493 * bsc#1263495 * bsc#1263539 * bsc#1263562 * bsc#1263598 * bsc#1263657 * bsc#1263776 * bsc#1263777 * bsc#1263778 * bsc#1263780 * bsc#1263782 * bsc#1263785 * bsc#1263786 * bsc#1263806 * bsc#1263876 * bsc#1263904 * bsc#1263905 * bsc#1263911 * bsc#1263923 * bsc#1263975 * bsc#1263999 * bsc#1264003 * bsc#1264006 * bsc#1264008 * bsc#1264009 * bsc#1264019 * bsc#1264030 * bsc#1264032 * bsc#1264033 * bsc#1264035 * bsc#1264039 * bsc#1264041 * bsc#1264044 * bsc#1264048 * bsc#1264056 * bsc#1264065 * bsc#1264070 * bsc#1264071 * bsc#1264073 * bsc#1264074 * bsc#1264075 * bsc#1264079 * bsc#1264088 * bsc#1264100 * bsc#1264101 * bsc#1264110 * bsc#1264121 * bsc#1264122 * bsc#1264125 * bsc#1264129 * bsc#1264142 * bsc#1264180 * bsc#1264188 * bsc#1264189 * bsc#1264190 * bsc#1264197 * bsc#1264237 * bsc#1264247 * bsc#1264257 * bsc#1264270 * bsc#1264296 * bsc#1264302 * bsc#1264304 * bsc#1264308 * bsc#1264313 * bsc#1264315 * bsc#1264317 * bsc#1264321 * bsc#1264322 * bsc#1264328 * bsc#1264331 * bsc#1264336 * bsc#1264338 * bsc#1264339 * bsc#1264340 * bsc#1264365 * bsc#1264377 * bsc#1264379 * bsc#1264386 * bsc#1264387 * bsc#1264388 * bsc#1264414 * bsc#1264416 * bsc#1264417 * bsc#1264419 * bsc#1264423 * bsc#1264424 * bsc#1264425 * bsc#1264429 * bsc#1264431 * bsc#1264436 * bsc#1264442 * bsc#1264451 * bsc#1264473 * bsc#1264477 * bsc#1264479 * bsc#1264480 * bsc#1264520 * bsc#1264526 * bsc#1264531 * bsc#1264538 * bsc#1264540 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264553 * bsc#1264556 * bsc#1264560 * bsc#1264564 * bsc#1264580 * bsc#1264584 * bsc#1264590 * bsc#1264592 * bsc#1264594 * bsc#1264598 * bsc#1264600 * bsc#1264613 * bsc#1264615 * bsc#1264616 * bsc#1264618 * bsc#1264620 * bsc#1264624 * bsc#1264626 * bsc#1264630 * bsc#1264633 * bsc#1264637 * bsc#1264640 * bsc#1264642 * bsc#1264644 * bsc#1264645 * bsc#1264668 * bsc#1264677 * bsc#1264731 * bsc#1264739 * bsc#1264744 * bsc#1264746 * bsc#1264758 * bsc#1264768 * bsc#1264780 * bsc#1264781 * bsc#1264782 * bsc#1264783 * bsc#1264785 * bsc#1264788 * bsc#1264790 * bsc#1264791 * bsc#1264794 * bsc#1264803 * bsc#1264809 * bsc#1264815 * bsc#1264816 * bsc#1264819 * bsc#1264821 * bsc#1264822 * bsc#1264826 * bsc#1264830 * bsc#1264835 * bsc#1264837 * bsc#1264844 * bsc#1264846 * bsc#1264853 * bsc#1264978 * bsc#1264987 * bsc#1264988 * bsc#1264991 * bsc#1264993 * bsc#1264997 * bsc#1265019 * bsc#1265023 * bsc#1265032 * bsc#1265037 * bsc#1265041 * bsc#1265047 * bsc#1265054 * bsc#1265074 * bsc#1265078 * bsc#1265079 * bsc#1265080 * bsc#1265089 * bsc#1265092 * bsc#1265093 * bsc#1265096 * bsc#1265100 * bsc#1265101 * bsc#1265102 * bsc#1265105 * bsc#1265112 * bsc#1265133 * bsc#1265138 * bsc#1265142 * bsc#1265249 * bsc#1265257 * bsc#1265264 * bsc#1265627 * bsc#1266000 * bsc#1266003 * bsc#1266399 * bsc#1266411 * bsc#1266412 * bsc#1266458 * bsc#1266467 * bsc#1266468 * bsc#1266677 * bsc#1266679 * bsc#1266684 * bsc#1266686 * bsc#1266688 * bsc#1266692 * bsc#1266703 * bsc#1266707 * bsc#1266721 * bsc#1266722 * bsc#1266726 * bsc#1266729 * bsc#1266732 * bsc#1266739 * bsc#1266740 * bsc#1266741 * bsc#1266743 * bsc#1266744 * bsc#1266751 * bsc#1266755 * bsc#1266762 * bsc#1266773 * bsc#1266774 * bsc#1266775 * bsc#1266777 * bsc#1266780 * bsc#1266805 * bsc#1266806 * bsc#1266831 * bsc#1266832 * bsc#1266834 * bsc#1266836 * bsc#1266838 * bsc#1266839 * bsc#1266841 * bsc#1266842 * bsc#1266846 * bsc#1266854 * bsc#1266855 * bsc#1266863 * bsc#1266864 * bsc#1266870 * bsc#1266872 * bsc#1266879 * bsc#1266883 * bsc#1266884 * bsc#1266886 * bsc#1266893 * bsc#1266894 * bsc#1266898 * bsc#1266908 * bsc#1266910 * bsc#1266917 * bsc#1266920 * bsc#1266925 * bsc#1266934 * bsc#1266935 * bsc#1266939 * bsc#1266947 * bsc#1267021 * bsc#1267027 * bsc#1267198 * bsc#1267204 * bsc#1267213 * bsc#1267226 * bsc#1267234 * bsc#1267251 * bsc#1267360 * bsc#1267367 * bsc#1267380 * bsc#1267432 * bsc#1267435 * bsc#1267436 * bsc#1267445 * bsc#1267448 * bsc#1267449 * bsc#1267466 * bsc#1267472 * bsc#1267473 * bsc#1267479 * bsc#1267491 * bsc#1267493 * bsc#1267494 * bsc#1267495 * bsc#1267496 * bsc#1267497 * bsc#1267502 * bsc#1267524 * bsc#1267555 * bsc#1267565 * bsc#1267571 * bsc#1267583 * bsc#1267592 * bsc#1267595 * bsc#1267611 * bsc#1267615 * bsc#1267616 * bsc#1267618 * bsc#1267623 * bsc#1267627 * bsc#1267630 * bsc#1267632 * bsc#1267636 * bsc#1267638 * bsc#1267643 * bsc#1267646 * bsc#1267649 * bsc#1267658 * bsc#1267661 * bsc#1267666 * bsc#1267667 * bsc#1267669 * bsc#1267676 * bsc#1267677 * bsc#1267680 * bsc#1267683 * bsc#1267690 * bsc#1267691 * bsc#1267693 * bsc#1267701 * bsc#1267702 * bsc#1267704 * bsc#1267712 * bsc#1267719 * bsc#1267725 * bsc#1267728 * bsc#1267922 * bsc#1267932 * bsc#1267939 * bsc#1267948 * bsc#1267968 * bsc#1267987 * bsc#1267990 * bsc#1267991 * bsc#1267992 * bsc#1267994 * bsc#1268024 * bsc#1268049 * bsc#1268051 * bsc#1268220 * bsc#1268221 * bsc#1268223 * bsc#1268981 * bsc#1268986 * bsc#1268989 * bsc#1269001 * bsc#1269002 * bsc#1269008 * bsc#1269025 * bsc#1269030 * bsc#1269031 * bsc#1269036 * bsc#1269081 * bsc#1269095 * bsc#1269098 * bsc#1269106 * bsc#1269111 * bsc#1269116 * bsc#1269124 * bsc#1269125 * bsc#1269129 * bsc#1269131 * bsc#1269133 * bsc#1269141 * bsc#1269151 * bsc#1269153 * bsc#1269159 * bsc#1269164 * bsc#1269172 * bsc#1269174 * bsc#1269177 * bsc#1269178 * bsc#1269187 * bsc#1269188 * bsc#1269190 * bsc#1269193 * bsc#1269230 * bsc#1269236 * bsc#1269239 * bsc#1269245 * bsc#1269254 * bsc#1269255 * bsc#1269257 * bsc#1269258 * bsc#1269262 * bsc#1269273 * bsc#1269283 * bsc#1269304 * bsc#1269364 * bsc#1269378 * bsc#1269385 * bsc#1269386 * bsc#1269389 * bsc#1269392 * bsc#1269403 * bsc#1269404 * bsc#1269410 * bsc#1269414 * bsc#1269493 * bsc#1269505 * bsc#1269527 * bsc#1269532 * bsc#1269537 * bsc#1269556 * bsc#1269587 * bsc#1269637 * bsc#1269644 * bsc#1269645 * bsc#1269646 * bsc#1269651 * bsc#1269652 * bsc#1269654 * bsc#1269661 * bsc#1269663 * bsc#1269669 * bsc#1269670 * bsc#1269674 * bsc#1269675 * bsc#1269677 * bsc#1269680 * bsc#1269682 * bsc#1269684 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269709 * bsc#1269710 * bsc#1269711 * bsc#1269719 * bsc#1269726 * bsc#1269733 * bsc#1269768 * bsc#1269770 * bsc#1269772 * bsc#1269786 * bsc#1269795 * bsc#1269796 * bsc#1269799 * bsc#1269809 * bsc#1269811 * bsc#1269814 * bsc#1269817 * bsc#1269826 * bsc#1269877 * bsc#1269886 * bsc#1269889 * bsc#1269898 * bsc#1269899 * bsc#1269904 * bsc#1269976 * bsc#1269984 * bsc#1269986 * bsc#1269988 * bsc#1269989 * bsc#1269992 * bsc#1269993 * bsc#1269996 * bsc#1269997 * bsc#1269998 * bsc#1270022 * bsc#1270042 * bsc#1270058 * bsc#1270059 * bsc#1270112 * bsc#1270226 * bsc#1270241 * bsc#1270244 * bsc#1270248 * bsc#1270249 * bsc#1270257 * bsc#1270260 * bsc#1270263 * bsc#1270268 * bsc#1270302 * bsc#1270396 * bsc#1271040 * bsc#1271050 * bsc#1271248 * bsc#1271249 * bsc#1271287 * bsc#1271366 * bsc#1271402 * jsc#PED-15897 Cross-References: * CVE-2023-20585 * CVE-2025-71274 * CVE-2025-71286 * CVE-2025-71291 * CVE-2025-71297 * CVE-2025-71302 * CVE-2025-71305 * CVE-2025-71314 * CVE-2026-23276 * CVE-2026-31430 * CVE-2026-31439 * CVE-2026-31440 * CVE-2026-31441 * CVE-2026-31447 * CVE-2026-31474 * CVE-2026-31479 * CVE-2026-31485 * CVE-2026-31497 * CVE-2026-31498 * CVE-2026-31503 * CVE-2026-31509 * CVE-2026-31510 * CVE-2026-31511 * CVE-2026-31513 * CVE-2026-31520 * CVE-2026-31522 * CVE-2026-31523 * CVE-2026-31524 * CVE-2026-31532 * CVE-2026-31540 * CVE-2026-31545 * CVE-2026-31548 * CVE-2026-31549 * CVE-2026-31551 * CVE-2026-31552 * CVE-2026-31561 * CVE-2026-31566 * CVE-2026-31568 * CVE-2026-31576 * CVE-2026-31578 * CVE-2026-31581 * CVE-2026-31583 * CVE-2026-31585 * CVE-2026-31587 * CVE-2026-31599 * CVE-2026-31603 * CVE-2026-31604 * CVE-2026-31605 * CVE-2026-31615 * CVE-2026-31616 * CVE-2026-31617 * CVE-2026-31618 * CVE-2026-31619 * CVE-2026-31623 * CVE-2026-31624 * CVE-2026-31625 * CVE-2026-31626 * CVE-2026-31627 * CVE-2026-31651 * CVE-2026-31657 * CVE-2026-31659 * CVE-2026-31660 * CVE-2026-31661 * CVE-2026-31667 * CVE-2026-31672 * CVE-2026-31678 * CVE-2026-31687 * CVE-2026-31701 * CVE-2026-31720 * CVE-2026-31726 * CVE-2026-31727 * CVE-2026-31728 * CVE-2026-31730 * CVE-2026-31747 * CVE-2026-31748 * CVE-2026-31749 * CVE-2026-31751 * CVE-2026-31754 * CVE-2026-31755 * CVE-2026-31756 * CVE-2026-31761 * CVE-2026-31762 * CVE-2026-31763 * CVE-2026-31765 * CVE-2026-31768 * CVE-2026-31770 * CVE-2026-31773 * CVE-2026-31776 * CVE-2026-31778 * CVE-2026-31779 * CVE-2026-31780 * CVE-2026-31781 * CVE-2026-43007 * CVE-2026-43011 * CVE-2026-43017 * CVE-2026-43018 * CVE-2026-43019 * CVE-2026-43020 * CVE-2026-43032 * CVE-2026-43043 * CVE-2026-43047 * CVE-2026-43051 * CVE-2026-43057 * CVE-2026-43058 * CVE-2026-43061 * CVE-2026-43062 * CVE-2026-43064 * CVE-2026-43069 * CVE-2026-43072 * CVE-2026-43092 * CVE-2026-43098 * CVE-2026-43104 * CVE-2026-43105 * CVE-2026-43111 * CVE-2026-43113 * CVE-2026-43117 * CVE-2026-43118 * CVE-2026-43123 * CVE-2026-43124 * CVE-2026-43129 * CVE-2026-43133 * CVE-2026-43134 * CVE-2026-43135 * CVE-2026-43136 * CVE-2026-43137 * CVE-2026-43140 * CVE-2026-43141 * CVE-2026-43143 * CVE-2026-43147 * CVE-2026-43149 * CVE-2026-43152 * CVE-2026-43156 * CVE-2026-43157 * CVE-2026-43159 * CVE-2026-43162 * CVE-2026-43167 * CVE-2026-43169 * CVE-2026-43177 * CVE-2026-43180 * CVE-2026-43182 * CVE-2026-43183 * CVE-2026-43189 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43196 * CVE-2026-43199 * CVE-2026-43200 * CVE-2026-43202 * CVE-2026-43203 * CVE-2026-43204 * CVE-2026-43205 * CVE-2026-43207 * CVE-2026-43211 * CVE-2026-43215 * CVE-2026-43218 * CVE-2026-43220 * CVE-2026-43221 * CVE-2026-43222 * CVE-2026-43223 * CVE-2026-43225 * CVE-2026-43226 * CVE-2026-43231 * CVE-2026-43232 * CVE-2026-43236 * CVE-2026-43240 * CVE-2026-43241 * CVE-2026-43242 * CVE-2026-43243 * CVE-2026-43244 * CVE-2026-43246 * CVE-2026-43248 * CVE-2026-43251 * CVE-2026-43253 * CVE-2026-43255 * CVE-2026-43256 * CVE-2026-43257 * CVE-2026-43260 * CVE-2026-43264 * CVE-2026-43269 * CVE-2026-43270 * CVE-2026-43277 * CVE-2026-43278 * CVE-2026-43279 * CVE-2026-43287 * CVE-2026-43291 * CVE-2026-43294 * CVE-2026-43295 * CVE-2026-43300 * CVE-2026-43302 * CVE-2026-43304 * CVE-2026-43312 * CVE-2026-43313 * CVE-2026-43314 * CVE-2026-43316 * CVE-2026-43318 * CVE-2026-43319 * CVE-2026-43320 * CVE-2026-43324 * CVE-2026-43327 * CVE-2026-43337 * CVE-2026-43340 * CVE-2026-43342 * CVE-2026-43343 * CVE-2026-43346 * CVE-2026-43353 * CVE-2026-43357 * CVE-2026-43370 * CVE-2026-43373 * CVE-2026-43380 * CVE-2026-43381 * CVE-2026-43382 * CVE-2026-43383 * CVE-2026-43387 * CVE-2026-43395 * CVE-2026-43397 * CVE-2026-43412 * CVE-2026-43425 * CVE-2026-43426 * CVE-2026-43427 * CVE-2026-43428 * CVE-2026-43429 * CVE-2026-43430 * CVE-2026-43432 * CVE-2026-43436 * CVE-2026-43443 * CVE-2026-43444 * CVE-2026-43445 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43459 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43467 * CVE-2026-43468 * CVE-2026-43473 * CVE-2026-43476 * CVE-2026-43480 * CVE-2026-43488 * CVE-2026-43493 * CVE-2026-43496 * CVE-2026-43497 * CVE-2026-45834 * CVE-2026-45835 * CVE-2026-45839 * CVE-2026-45851 * CVE-2026-45853 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45867 * CVE-2026-45868 * CVE-2026-45869 * CVE-2026-45871 * CVE-2026-45875 * CVE-2026-45877 * CVE-2026-45879 * CVE-2026-45880 * CVE-2026-45881 * CVE-2026-45883 * CVE-2026-45885 * CVE-2026-45899 * CVE-2026-45902 * CVE-2026-45911 * CVE-2026-45914 * CVE-2026-45916 * CVE-2026-45919 * CVE-2026-45920 * CVE-2026-45921 * CVE-2026-45922 * CVE-2026-45923 * CVE-2026-45928 * CVE-2026-45936 * CVE-2026-45941 * CVE-2026-45946 * CVE-2026-45947 * CVE-2026-45954 * CVE-2026-45958 * CVE-2026-45963 * CVE-2026-45969 * CVE-2026-45976 * CVE-2026-45981 * CVE-2026-45982 * CVE-2026-45986 * CVE-2026-45987 * CVE-2026-45994 * CVE-2026-45996 * CVE-2026-45997 * CVE-2026-46006 * CVE-2026-46009 * CVE-2026-46011 * CVE-2026-46016 * CVE-2026-46018 * CVE-2026-46019 * CVE-2026-46023 * CVE-2026-46027 * CVE-2026-46033 * CVE-2026-46040 * CVE-2026-46046 * CVE-2026-46048 * CVE-2026-46049 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46052 * CVE-2026-46056 * CVE-2026-46058 * CVE-2026-46059 * CVE-2026-46064 * CVE-2026-46068 * CVE-2026-46075 * CVE-2026-46077 * CVE-2026-46082 * CVE-2026-46086 * CVE-2026-46088 * CVE-2026-46089 * CVE-2026-46092 * CVE-2026-46099 * CVE-2026-46102 * CVE-2026-46103 * CVE-2026-46108 * CVE-2026-46122 * CVE-2026-46125 * CVE-2026-46128 * CVE-2026-46131 * CVE-2026-46132 * CVE-2026-46136 * CVE-2026-46138 * CVE-2026-46140 * CVE-2026-46143 * CVE-2026-46146 * CVE-2026-46151 * CVE-2026-46152 * CVE-2026-46161 * CVE-2026-46163 * CVE-2026-46165 * CVE-2026-46166 * CVE-2026-46167 * CVE-2026-46177 * CVE-2026-46178 * CVE-2026-46179 * CVE-2026-46184 * CVE-2026-46186 * CVE-2026-46187 * CVE-2026-46190 * CVE-2026-46191 * CVE-2026-46198 * CVE-2026-46199 * CVE-2026-46201 * CVE-2026-46204 * CVE-2026-46205 * CVE-2026-46206 * CVE-2026-46207 * CVE-2026-46211 * CVE-2026-46212 * CVE-2026-46216 * CVE-2026-46218 * CVE-2026-46219 * CVE-2026-46220 * CVE-2026-46225 * CVE-2026-46230 * CVE-2026-46231 * CVE-2026-46232 * CVE-2026-46233 * CVE-2026-46235 * CVE-2026-46236 * CVE-2026-46238 * CVE-2026-46242 * CVE-2026-46247 * CVE-2026-46249 * CVE-2026-46252 * CVE-2026-46261 * CVE-2026-46263 * CVE-2026-46267 * CVE-2026-46270 * CVE-2026-46275 * CVE-2026-46276 * CVE-2026-46285 * CVE-2026-46286 * CVE-2026-46294 * CVE-2026-46307 * CVE-2026-46312 * CVE-2026-46313 * CVE-2026-46314 * CVE-2026-46321 * CVE-2026-46322 * CVE-2026-46330 * CVE-2026-52904 * CVE-2026-52914 * CVE-2026-52915 * CVE-2026-52916 * CVE-2026-52919 * CVE-2026-52922 * CVE-2026-52924 * CVE-2026-52926 * CVE-2026-52931 * CVE-2026-52933 * CVE-2026-52936 * CVE-2026-52948 * CVE-2026-52951 * CVE-2026-52953 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52961 * CVE-2026-52963 * CVE-2026-52964 * CVE-2026-52976 * CVE-2026-52981 * CVE-2026-52982 * CVE-2026-52989 * CVE-2026-52993 * CVE-2026-52995 * CVE-2026-53003 * CVE-2026-53004 * CVE-2026-53009 * CVE-2026-53013 * CVE-2026-53021 * CVE-2026-53022 * CVE-2026-53035 * CVE-2026-53036 * CVE-2026-53037 * CVE-2026-53039 * CVE-2026-53045 * CVE-2026-53047 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53056 * CVE-2026-53058 * CVE-2026-53060 * CVE-2026-53065 * CVE-2026-53066 * CVE-2026-53068 * CVE-2026-53070 * CVE-2026-53073 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53080 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53093 * CVE-2026-53098 * CVE-2026-53112 * CVE-2026-53135 * CVE-2026-53136 * CVE-2026-53137 * CVE-2026-53139 * CVE-2026-53140 * CVE-2026-53143 * CVE-2026-53144 * CVE-2026-53146 * CVE-2026-53147 * CVE-2026-53148 * CVE-2026-53149 * CVE-2026-53150 * CVE-2026-53158 * CVE-2026-53159 * CVE-2026-53160 * CVE-2026-53161 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53181 * CVE-2026-53186 * CVE-2026-53190 * CVE-2026-53192 * CVE-2026-53194 * CVE-2026-53195 * CVE-2026-53196 * CVE-2026-53202 * CVE-2026-53203 * CVE-2026-53208 * CVE-2026-53209 * CVE-2026-53213 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53218 * CVE-2026-53224 * CVE-2026-53225 * CVE-2026-53227 * CVE-2026-53229 * CVE-2026-53237 * CVE-2026-53239 * CVE-2026-53241 * CVE-2026-53242 * CVE-2026-53245 * CVE-2026-53246 * CVE-2026-53249 * CVE-2026-53254 * CVE-2026-53255 * CVE-2026-53256 * CVE-2026-53258 * CVE-2026-53268 * CVE-2026-53272 * CVE-2026-53274 * CVE-2026-53279 * CVE-2026-53285 * CVE-2026-53293 * CVE-2026-53306 * CVE-2026-53313 * CVE-2026-53325 * CVE-2026-53329 * CVE-2026-53339 * CVE-2026-53347 * CVE-2026-53350 * CVE-2026-53355 * CVE-2026-53356 * CVE-2026-53357 * CVE-2026-53358 * CVE-2026-53359 * CVE-2026-53360 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2023-20585 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-20585 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2023-20585 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-71274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71274 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71286 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71291 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71297 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71297 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71302 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71302 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71302 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71305 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71305 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71305 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23276 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23276 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31430 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31430 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31430 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31439 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31439 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31439 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31440 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31440 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31440 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31441 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31441 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31441 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31447 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31447 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31447 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-31474 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31474 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31474 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31474 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31479 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31479 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31485 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31485 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31485 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31497 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31497 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31498 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31498 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31498 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31503 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31503 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31503 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31509 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31509 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31509 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31510 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31510 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31510 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31511 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31513 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31513 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-31513 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31520 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31520 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31520 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31522 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31522 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31522 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31523 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31523 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31524 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31524 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31524 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31532 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31532 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31532 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31532 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31540 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31540 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31540 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31545 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31545 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31545 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31548 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31549 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31549 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31551 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31551 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31551 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31552 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31552 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31552 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31561 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31561 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31561 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31566 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31566 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31566 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31566 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31568 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31568 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31568 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31576 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31576 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31576 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31578 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31578 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31578 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31581 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31583 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31583 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31585 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31585 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31585 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31587 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31587 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31587 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31599 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31599 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31603 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31603 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31603 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31604 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31604 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31604 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31605 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31605 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31605 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31615 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31615 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31615 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31616 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31616 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31616 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31617 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31617 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31617 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31617 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31618 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31618 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31618 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31619 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31619 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31619 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31623 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-31623 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-31623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31624 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31624 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31624 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31625 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31625 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31625 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31626 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31626 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-31626 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31627 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31627 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31627 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31651 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31651 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31651 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31657 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31657 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31657 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31659 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-31659 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-31659 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31660 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31660 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31660 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31661 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31661 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31661 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31667 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31667 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31667 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31672 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31672 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-31672 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31678 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31687 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31687 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31687 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31701 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31701 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31701 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31720 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31720 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31720 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31726 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31726 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31726 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31727 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31727 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31727 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31728 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31728 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31728 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31730 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31730 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31730 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31730 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31747 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31747 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31747 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31748 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31748 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31748 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31749 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31749 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31749 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31751 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31751 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31754 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31754 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31754 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31755 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31755 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31755 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31756 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31756 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-31756 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31761 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31761 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31761 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31762 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31762 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31763 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31763 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31763 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31765 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31765 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31765 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31768 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31768 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-31768 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31770 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31770 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31770 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31773 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31773 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31776 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31776 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31778 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31778 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31778 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31779 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31779 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31780 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31780 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31781 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31781 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43007 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43007 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43011 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43011 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43017 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43017 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43018 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43018 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43020 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43020 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43032 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43032 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43043 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43043 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43043 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43047 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43047 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43051 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43058 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43058 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43058 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43061 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43061 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43062 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43062 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-43064 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43064 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43069 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43072 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43072 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43072 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43098 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43098 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43104 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43105 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43105 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43111 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43111 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43113 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43113 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43117 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43117 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43117 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43118 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-43118 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-43118 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43123 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43123 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43129 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43129 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43133 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-43133 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-43134 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43134 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-43135 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43135 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43136 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43136 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43137 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43137 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43137 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43140 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43140 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43140 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43141 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43141 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43141 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43143 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43143 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43147 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43147 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43149 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43149 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43152 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43152 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43156 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43156 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43156 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43159 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43159 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43162 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43169 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43180 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43180 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43182 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43183 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43183 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43183 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43189 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43189 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43189 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43196 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43200 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43200 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43202 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43202 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43203 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43203 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43207 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43211 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43211 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43215 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43215 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43215 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43218 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43221 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43221 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43223 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43223 ( SUSE ): 4.3 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43223 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43225 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43231 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43231 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43232 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43232 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43241 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43241 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43241 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43242 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43242 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43243 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43246 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43246 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43251 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43255 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43255 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43255 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43256 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43256 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43256 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43257 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43264 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43264 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43264 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43269 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43269 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43270 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43270 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43277 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43279 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43279 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43291 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43295 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43295 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43295 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43300 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43302 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43302 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43312 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43313 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43313 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43316 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43316 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43318 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43324 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43327 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43327 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43340 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43340 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43340 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43342 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43342 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43343 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43346 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43346 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43353 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43353 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43353 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43357 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-43357 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-43357 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43370 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43380 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43380 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43380 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43381 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43381 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43382 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43387 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43387 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43395 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43397 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43397 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43397 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43412 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43412 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43425 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43425 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43426 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43426 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43427 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43428 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43428 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43428 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43430 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43430 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43430 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43432 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43436 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43443 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43459 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43459 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43467 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43476 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43476 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43480 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43488 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43488 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43488 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43493 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43493 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43493 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43496 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43496 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43497 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43497 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43497 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-45834 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45834 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45834 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45835 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45835 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45835 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45839 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45839 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45839 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45851 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45853 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45853 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45853 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45867 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-45867 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45868 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45868 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45869 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45869 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45869 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45871 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45871 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45875 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45875 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45875 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45877 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45877 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45877 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45879 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45879 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45880 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45880 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45881 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45881 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45881 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45883 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45883 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45885 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45885 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45902 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45902 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45902 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45911 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45914 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45914 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45914 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45916 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45916 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45919 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45919 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45919 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45921 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45921 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45921 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45922 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45922 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45922 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45923 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45923 ( SUSE ): 4.9 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45923 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45928 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45936 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45936 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45936 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45941 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45941 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45941 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45946 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45946 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45947 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45947 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45954 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45954 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45954 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45958 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45958 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45958 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45963 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45963 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45969 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45976 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45976 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45981 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45982 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45982 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45982 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45986 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45986 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45994 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45996 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45996 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46006 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46006 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46009 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46009 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46011 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46016 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46016 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46018 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46018 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46019 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46023 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46023 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46027 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46027 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46033 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46033 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46033 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46040 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46040 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46048 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46048 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46049 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46056 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46056 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46058 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46058 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46064 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46064 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46068 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46068 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46068 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46075 ( SUSE ): 5.6 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46082 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46082 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46086 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46088 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46088 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46088 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46092 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46102 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46102 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46103 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46103 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46108 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46108 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46122 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46122 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46122 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46125 ( NVD ): 6.8 CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46131 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46132 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46136 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46136 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46138 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46138 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46140 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46140 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46140 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46143 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46143 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46143 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46146 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46146 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46146 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46151 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46151 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46151 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46152 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46152 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46152 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46163 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46165 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46165 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46166 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46166 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46177 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46179 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46179 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46184 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46184 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46186 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46186 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46187 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46187 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46190 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46190 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46191 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46191 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46198 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46198 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46199 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46201 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46201 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46207 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46207 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-46207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46211 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46211 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46211 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46212 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46212 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46212 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46216 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46216 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46218 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46219 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46225 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46230 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46230 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46231 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46231 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46232 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46232 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46233 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46233 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46233 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46235 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46235 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46235 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46236 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46238 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46247 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46252 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46263 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46267 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46267 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46270 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46270 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46275 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46276 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46276 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46285 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46286 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-46286 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46294 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46294 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46307 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-46307 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-46307 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46312 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46312 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46313 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46313 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46321 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46321 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46330 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46330 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46330 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52904 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52904 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52904 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52914 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52914 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52914 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52915 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52915 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52915 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52916 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52916 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52916 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52919 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52919 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52922 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52922 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52922 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52926 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52931 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52931 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52936 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52936 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52951 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52951 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52951 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52953 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52953 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52961 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52963 ( SUSE ): 5.9 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52963 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52964 ( SUSE ): 4.3 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-52964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52976 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52976 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52976 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52981 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52981 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52982 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52982 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52989 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52989 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52989 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52995 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52995 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53003 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53003 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53004 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53009 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53009 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53009 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53013 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53013 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53037 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53037 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53037 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53045 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53045 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53047 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53056 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53056 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53058 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53065 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53066 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53066 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53068 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53068 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53068 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53070 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53070 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53073 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53080 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53080 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53093 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53093 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53098 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53135 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53135 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53136 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53136 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53136 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53137 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53137 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53140 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53140 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53140 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53143 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53143 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53144 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53146 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53146 ( SUSE ): 5.2 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53146 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-53147 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53147 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53148 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53148 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53148 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53148 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53149 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53149 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53150 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53150 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53150 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53158 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53158 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53158 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53159 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53159 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53160 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53161 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53181 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53181 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53186 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53190 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53190 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53192 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53194 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53194 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53194 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53195 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53195 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53195 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53202 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53202 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53202 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53203 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53203 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53203 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53203 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53208 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53208 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53208 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53213 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53218 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53225 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53227 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53227 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53227 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53237 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53237 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53239 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53241 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53241 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53241 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53242 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53254 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53254 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53254 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53255 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53268 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53268 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53272 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53272 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53272 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53279 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53279 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53293 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53293 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53313 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53313 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53325 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53325 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53325 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53329 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53339 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53347 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53347 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53355 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53355 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-53355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53356 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53356 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53356 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53358 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53358 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Real Time Module 15-SP7 An update that solves 513 vulnerabilities, contains one feature and has 26 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). * CVE-2025-71302: drm/panthor: fix for dma-fence safe access rules (bsc#1264837). * CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765). * CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). * CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). * CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593 bsc#1264419). * CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429). * CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). * CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). * CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). * CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112). * CVE-2026-43353: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue (bsc#1265089). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). * CVE-2026-43496: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1266000). * CVE-2026-45839: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (bsc#1266399). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805). * CVE-2026-45981: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() (bsc#1267204). * CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). * CVE-2026-45994: ibmasm: fix OOB reads in command_file_write due to missing size checks (bsc#1267432). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-46023: dm mirror: fix integer overflow in create_dirty_log() (bsc#1267449). * CVE-2026-46027: net/smc: avoid early lgr access in smc_clc_wait_msg (bsc#1266744). * CVE-2026-46040: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (bsc#1267472). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). * CVE-2026-46064: ibmasm: fix heap over-read in ibmasm_send_i2o_message() (bsc#1267497). * CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (bsc#1267592). * CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524). * CVE-2026-46089: zram: do not forget to endio for partial discard requests (bsc#1267445). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46102: net: strparser: fix skb_head leak in strp_abort_strp() (bsc#1267502). * CVE-2026-46132: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (bsc#1267616). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690). * CVE-2026-46207: vsock/virtio: fix length and offset in tap skb for split packets (bsc#1267691). * CVE-2026-46216: drm/xe/hdcp: Add NULL check for media_gt in (bsc#1267234). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46249: octeontx2-af: Fix PF driver crash with kexec kernel booting (bsc#1267683). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one() (bsc#1268024). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-46330: Revert "net/smc: Introduce TCP ULP support" (bsc#1268049). * CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52953: iommu/vt-d: Fix oops due to out of scope access (bsc#1269133). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). * CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124). * CVE-2026-53003: pppoe: drop PFC frames (bsc#1269111). * CVE-2026-53004: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (bsc#1269106). * CVE-2026-53009: ice: fix double-free of tx_buf skb (bsc#1269098). * CVE-2026-53013: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (bsc#1269095). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). * CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (bsc#1269273). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). * CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (bsc#1269711). * CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR (bsc#1269877). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (bsc#1269677). * CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257). * CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress (bsc#1269809). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). * CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270302). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271366). The following non security issues were fixed: * ALSA: hda: conexant: Remove mic bias threshold override (git-fixes). * ALSA: hda: Fix cached processing coefficient verbs (git-fixes). * ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (git-fixes). * ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (git- fixes). * ASoC: cs42l43: Correct report for forced microphone jack (git-fixes). * ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (git-fixes). * ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (git-fixes). * batman-adv: access unicast_ttvn skb->data only after skb realloc (git- fixes). * batman-adv: bla: reacquire gw address after skb realloc (git-fixes). * batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). * batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). * batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). * bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). * bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). * bnxt_en: Add TX timestamp completion logic (bsc#1264180). * bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). * bnxt_en: fix module unload sequence (bsc#1264180). * bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). * bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). * bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). * bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). * bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). * bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). * bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). * bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). * bnxt_en: silence clang build warning (bsc#1264180). * bpf: Disambiguate SCALAR register state output in verifier logs (bsc#1271249). * crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). * crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable- fixes). * drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). * drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git- fixes). * drm/amd/pm: fix amdgpu_pm_info power display units (git-fixes). * drm/amd/pm: fix smu13 power limit range calculation (git-fixes). * drm/amdgpu: fix aperture mapping leak (git-fixes). * drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). * drm/gfx10: Program DB_RING_CONTROL (git-fixes). * drm/i915/bios: range check LFP Data Block panel_type2 (git-fixes). * drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). * drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). * drm/i915: Return NULL on error in active_instance (git-fixes). * drm/imagination: Fix double call to drm_sched_entity_fini() (git-fixes). * drm/imagination: fix error checking of pvr_vm_context_lookup() (git-fixes). * drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY (git-fixes). * drm/imagination: Fix user array stride in pvr_set_uobj_array() (git-fixes). * drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() (git-fixes). * drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced (git-fixes). * drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() (git-fixes). * drm/panthor: Interrupt group start/resumption if group_bind_locked() fails (git-fixes). * drm/v3d: Reject invalid indirect BO handle in indirect CSD setup (git- fixes). * drm/virtio: bound EDID block reads to the response buffer (git-fixes). * drm/xe/hw_engine: Fix double-free of managed BO in error path (git-fixes). * drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays (git-fixes). * drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() (git- fixes). * drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (git- fixes). * drm/xe: remove duplicate include (git-fixes). * fbdev: efifb: fix memory leak in efifb_probe() (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes). * git_sort: Add workqueue maintainer tree. * git_sort: Update nf-next branch. * gpio-f7188x: Add support for NCT6126D version B (git-fixes). * gpio: htc-egpio: use managed gpiochip registration (git-fixes). * gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). * gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git- fixes). * gpios: palmas: add .get_direction() op (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue (git- fixes). * i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring (git-fixes). * iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). * iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git- fixes). * iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). * iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). * iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). * iio: event: Fix event FIFO reset race (git-fixes). * iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). * iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). * iio: light: al3010: fix incorrect scale for the highest gain range (git- fixes). * iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). * iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). * Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). * Input: mms114 - fix multi-touch slot corruption (git-fixes). * io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF (bsc#1261250). * io_uring/kbuf: propagate BUF_MORE through early buffer commit path (bsc#1261250). * io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git- fixes bsc#1261250 bsc#1271287). * iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). * ipv4: account for fraggap on the paged allocation path (git-fixes). * ipvs: Move defense_work to system_dfl_long_wq (bsc#1257605). * ixgbe: reduce number of reads when getting OROM data (bsc#1269637). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042 bsc#1270396). * mm: Do not allocate shrinker info with cgroup.memory=nokmem (bsc#1256564). * net/handshake: do not send request when the socket is closed (bsc#1251942). * net: mana: Sync page pool RX frags for CPU (git-fixes). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562). * pinctrl: meson: restore non-sleeping GPIO access (git-fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). * s390/ap: Externalize AP bus specific bitmap reading function (jsc#PED-15897). * s390/pkey: Check length in pkey_pckmo handler implementation (bsc#1270268). * s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (bsc#1270263). * s390/vfio-ap: Add sysfs attr, ap_config, to export mdev state (jsc#PED-15897). * s390/vfio-ap: Add write support to sysfs attr ap_config (jsc#PED-15897). * s390/vfio-ap: Driver feature advertisement (jsc#PED-15897). * s390/vfio-ap: Ignore duplicate link requests in vfio_ap_mdev_link_queue (jsc#PED-15897). * scripts/submit_branch: do submission right after upload. * sctp: validate embedded address parameter length (git-fixes). * selftests/alsa: Fix memory leak in find_controls error path (git-fixes). * selftests/bpf: Add uprobe_multi to gen_tar target (bsc#1271248). * selftests/bpf: Make align selftests more robust (bsc#1271249). * serial: 8250_omap: clear rx_running on zero-length DMA completes (git- fixes). * serial: msm: Disable DMA for kernel console UART (git-fixes). * staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). * staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git- fixes). * staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). * staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). * staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). * staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git- fixes). * tools: hv: Fix cross-compilation (git-fixes). * tpm: Make the TPM character devices non-seekable (git-fixes). * usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git- fixes). * USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). * usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git- fixes). * usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). * usb: free iso schedules on failed submit (git-fixes). * usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git- fixes). * usb: gadget: f_printer: take kref only for successful open (git-fixes). * USB: idmouse: fix use-after-free on disconnect race (git-fixes). * USB: iowarrior: fix use-after-free on disconnect (git-fixes). * USB: ldusb: fix use-after-free on disconnect race (git-fixes). * USB: legousbtower: fix use-after-free on disconnect race (git-fixes). * USB: misc: uss720: unregister parport on probe failure (git-fixes). * usb: mtu3: unmap request DMA on queue failure (git-fixes). * USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). * USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). * USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). * USB: serial: keyspan_pda: fix information leak (git-fixes). * usb: sl811-hcd: disable controller wakeup on remove (git-fixes). * USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). * usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). * usb: typec: class: drop PD lookup reference (git-fixes). * usb: typec: tcpm: Fix VDM type for Enter Mode commands (git-fixes). * usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). * usb: typec: ucsi: cancel pending work on system suspend (git-fixes). * usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). * usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). * usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). * USB: ulpi: fix memory leak on registration failure (git-fixes). * USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). * usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). * usbip: tools: support SuperSpeedPlus devices (git-fixes). * usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). * wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Real Time Module 15-SP7 zypper in -t patch SUSE-SLE-Module-RT-15-SP7-2026-3130=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3130=1 ## Package List: * SUSE Real Time Module 15-SP7 (x86_64) * kernel-rt-devel-debuginfo-6.4.0-150700.7.67.1 * ocfs2-kmp-rt-6.4.0-150700.7.67.1 * gfs2-kmp-rt-6.4.0-150700.7.67.1 * dlm-kmp-rt-debuginfo-6.4.0-150700.7.67.1 * kernel-rt-devel-6.4.0-150700.7.67.1 * gfs2-kmp-rt-debuginfo-6.4.0-150700.7.67.1 * cluster-md-kmp-rt-debuginfo-6.4.0-150700.7.67.1 * kernel-syms-rt-6.4.0-150700.7.67.1 * ocfs2-kmp-rt-debuginfo-6.4.0-150700.7.67.1 * kernel-rt-debugsource-6.4.0-150700.7.67.1 * cluster-md-kmp-rt-6.4.0-150700.7.67.1 * dlm-kmp-rt-6.4.0-150700.7.67.1 * kernel-rt-debuginfo-6.4.0-150700.7.67.1 * SUSE Real Time Module 15-SP7 (noarch) * kernel-devel-rt-6.4.0-150700.7.67.1 * kernel-source-rt-6.4.0-150700.7.67.1 * SUSE Real Time Module 15-SP7 (nosrc x86_64) * kernel-rt-6.4.0-150700.7.67.1 * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_67-rt-debuginfo-1-150700.1.5.1 * kernel-livepatch-SLE15-SP7-RT_Update_18-debugsource-1-150700.1.5.1 * kernel-livepatch-6_4_0-150700_7_67-rt-1-150700.1.5.1 ## References: * https://www.suse.com/security/cve/CVE-2023-20585.html * https://www.suse.com/security/cve/CVE-2025-71274.html * https://www.suse.com/security/cve/CVE-2025-71286.html * https://www.suse.com/security/cve/CVE-2025-71291.html * https://www.suse.com/security/cve/CVE-2025-71297.html * https://www.suse.com/security/cve/CVE-2025-71302.html * https://www.suse.com/security/cve/CVE-2025-71305.html * https://www.suse.com/security/cve/CVE-2025-71314.html * https://www.suse.com/security/cve/CVE-2026-23276.html * https://www.suse.com/security/cve/CVE-2026-31430.html * https://www.suse.com/security/cve/CVE-2026-31439.html * https://www.suse.com/security/cve/CVE-2026-31440.html * https://www.suse.com/security/cve/CVE-2026-31441.html * https://www.suse.com/security/cve/CVE-2026-31447.html * https://www.suse.com/security/cve/CVE-2026-31474.html * https://www.suse.com/security/cve/CVE-2026-31479.html * https://www.suse.com/security/cve/CVE-2026-31485.html * https://www.suse.com/security/cve/CVE-2026-31497.html * https://www.suse.com/security/cve/CVE-2026-31498.html * https://www.suse.com/security/cve/CVE-2026-31503.html * https://www.suse.com/security/cve/CVE-2026-31509.html * https://www.suse.com/security/cve/CVE-2026-31510.html * https://www.suse.com/security/cve/CVE-2026-31511.html * https://www.suse.com/security/cve/CVE-2026-31513.html * https://www.suse.com/security/cve/CVE-2026-31520.html * https://www.suse.com/security/cve/CVE-2026-31522.html * https://www.suse.com/security/cve/CVE-2026-31523.html * https://www.suse.com/security/cve/CVE-2026-31524.html * https://www.suse.com/security/cve/CVE-2026-31532.html * https://www.suse.com/security/cve/CVE-2026-31540.html * https://www.suse.com/security/cve/CVE-2026-31545.html * https://www.suse.com/security/cve/CVE-2026-31548.html * https://www.suse.com/security/cve/CVE-2026-31549.html * https://www.suse.com/security/cve/CVE-2026-31551.html * https://www.suse.com/security/cve/CVE-2026-31552.html * https://www.suse.com/security/cve/CVE-2026-31561.html * https://www.suse.com/security/cve/CVE-2026-31566.html * https://www.suse.com/security/cve/CVE-2026-31568.html * https://www.suse.com/security/cve/CVE-2026-31576.html * https://www.suse.com/security/cve/CVE-2026-31578.html * https://www.suse.com/security/cve/CVE-2026-31581.html * https://www.suse.com/security/cve/CVE-2026-31583.html * https://www.suse.com/security/cve/CVE-2026-31585.html * https://www.suse.com/security/cve/CVE-2026-31587.html * https://www.suse.com/security/cve/CVE-2026-31599.html * https://www.suse.com/security/cve/CVE-2026-31603.html * https://www.suse.com/security/cve/CVE-2026-31604.html * https://www.suse.com/security/cve/CVE-2026-31605.html * https://www.suse.com/security/cve/CVE-2026-31615.html * https://www.suse.com/security/cve/CVE-2026-31616.html * https://www.suse.com/security/cve/CVE-2026-31617.html * https://www.suse.com/security/cve/CVE-2026-31618.html * https://www.suse.com/security/cve/CVE-2026-31619.html * https://www.suse.com/security/cve/CVE-2026-31623.html * https://www.suse.com/security/cve/CVE-2026-31624.html * https://www.suse.com/security/cve/CVE-2026-31625.html * https://www.suse.com/security/cve/CVE-2026-31626.html * https://www.suse.com/security/cve/CVE-2026-31627.html * https://www.suse.com/security/cve/CVE-2026-31651.html * https://www.suse.com/security/cve/CVE-2026-31657.html * https://www.suse.com/security/cve/CVE-2026-31659.html * https://www.suse.com/security/cve/CVE-2026-31660.html * https://www.suse.com/security/cve/CVE-2026-31661.html * https://www.suse.com/security/cve/CVE-2026-31667.html * https://www.suse.com/security/cve/CVE-2026-31672.html * https://www.suse.com/security/cve/CVE-2026-31678.html * https://www.suse.com/security/cve/CVE-2026-31687.html * https://www.suse.com/security/cve/CVE-2026-31701.html * https://www.suse.com/security/cve/CVE-2026-31720.html * https://www.suse.com/security/cve/CVE-2026-31726.html * https://www.suse.com/security/cve/CVE-2026-31727.html * https://www.suse.com/security/cve/CVE-2026-31728.html * https://www.suse.com/security/cve/CVE-2026-31730.html * https://www.suse.com/security/cve/CVE-2026-31747.html * https://www.suse.com/security/cve/CVE-2026-31748.html * https://www.suse.com/security/cve/CVE-2026-31749.html * https://www.suse.com/security/cve/CVE-2026-31751.html * https://www.suse.com/security/cve/CVE-2026-31754.html * https://www.suse.com/security/cve/CVE-2026-31755.html * https://www.suse.com/security/cve/CVE-2026-31756.html * https://www.suse.com/security/cve/CVE-2026-31761.html * https://www.suse.com/security/cve/CVE-2026-31762.html * https://www.suse.com/security/cve/CVE-2026-31763.html * https://www.suse.com/security/cve/CVE-2026-31765.html * https://www.suse.com/security/cve/CVE-2026-31768.html * https://www.suse.com/security/cve/CVE-2026-31770.html * https://www.suse.com/security/cve/CVE-2026-31773.html * https://www.suse.com/security/cve/CVE-2026-31776.html * https://www.suse.com/security/cve/CVE-2026-31778.html * https://www.suse.com/security/cve/CVE-2026-31779.html * https://www.suse.com/security/cve/CVE-2026-31780.html * https://www.suse.com/security/cve/CVE-2026-31781.html * https://www.suse.com/security/cve/CVE-2026-43007.html * https://www.suse.com/security/cve/CVE-2026-43011.html * https://www.suse.com/security/cve/CVE-2026-43017.html * https://www.suse.com/security/cve/CVE-2026-43018.html * https://www.suse.com/security/cve/CVE-2026-43019.html * https://www.suse.com/security/cve/CVE-2026-43020.html * https://www.suse.com/security/cve/CVE-2026-43032.html * https://www.suse.com/security/cve/CVE-2026-43043.html * https://www.suse.com/security/cve/CVE-2026-43047.html * https://www.suse.com/security/cve/CVE-2026-43051.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43058.html * https://www.suse.com/security/cve/CVE-2026-43061.html * https://www.suse.com/security/cve/CVE-2026-43062.html * https://www.suse.com/security/cve/CVE-2026-43064.html * https://www.suse.com/security/cve/CVE-2026-43069.html * https://www.suse.com/security/cve/CVE-2026-43072.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43098.html * https://www.suse.com/security/cve/CVE-2026-43104.html * https://www.suse.com/security/cve/CVE-2026-43105.html * https://www.suse.com/security/cve/CVE-2026-43111.html * https://www.suse.com/security/cve/CVE-2026-43113.html * https://www.suse.com/security/cve/CVE-2026-43117.html * https://www.suse.com/security/cve/CVE-2026-43118.html * https://www.suse.com/security/cve/CVE-2026-43123.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43129.html * https://www.suse.com/security/cve/CVE-2026-43133.html * https://www.suse.com/security/cve/CVE-2026-43134.html * https://www.suse.com/security/cve/CVE-2026-43135.html * https://www.suse.com/security/cve/CVE-2026-43136.html * https://www.suse.com/security/cve/CVE-2026-43137.html * https://www.suse.com/security/cve/CVE-2026-43140.html * https://www.suse.com/security/cve/CVE-2026-43141.html * https://www.suse.com/security/cve/CVE-2026-43143.html * https://www.suse.com/security/cve/CVE-2026-43147.html * https://www.suse.com/security/cve/CVE-2026-43149.html * https://www.suse.com/security/cve/CVE-2026-43152.html * https://www.suse.com/security/cve/CVE-2026-43156.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43159.html * https://www.suse.com/security/cve/CVE-2026-43162.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43169.html * https://www.suse.com/security/cve/CVE-2026-43177.html * https://www.suse.com/security/cve/CVE-2026-43180.html * https://www.suse.com/security/cve/CVE-2026-43182.html * https://www.suse.com/security/cve/CVE-2026-43183.html * https://www.suse.com/security/cve/CVE-2026-43189.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43196.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43200.html * https://www.suse.com/security/cve/CVE-2026-43202.html * https://www.suse.com/security/cve/CVE-2026-43203.html * https://www.suse.com/security/cve/CVE-2026-43204.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43207.html * https://www.suse.com/security/cve/CVE-2026-43211.html * https://www.suse.com/security/cve/CVE-2026-43215.html * https://www.suse.com/security/cve/CVE-2026-43218.html * https://www.suse.com/security/cve/CVE-2026-43220.html * https://www.suse.com/security/cve/CVE-2026-43221.html * https://www.suse.com/security/cve/CVE-2026-43222.html * https://www.suse.com/security/cve/CVE-2026-43223.html * https://www.suse.com/security/cve/CVE-2026-43225.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43231.html * https://www.suse.com/security/cve/CVE-2026-43232.html * https://www.suse.com/security/cve/CVE-2026-43236.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43241.html * https://www.suse.com/security/cve/CVE-2026-43242.html * https://www.suse.com/security/cve/CVE-2026-43243.html * https://www.suse.com/security/cve/CVE-2026-43244.html * https://www.suse.com/security/cve/CVE-2026-43246.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43251.html * https://www.suse.com/security/cve/CVE-2026-43253.html * https://www.suse.com/security/cve/CVE-2026-43255.html * https://www.suse.com/security/cve/CVE-2026-43256.html * https://www.suse.com/security/cve/CVE-2026-43257.html * https://www.suse.com/security/cve/CVE-2026-43260.html * https://www.suse.com/security/cve/CVE-2026-43264.html * https://www.suse.com/security/cve/CVE-2026-43269.html * https://www.suse.com/security/cve/CVE-2026-43270.html * https://www.suse.com/security/cve/CVE-2026-43277.html * https://www.suse.com/security/cve/CVE-2026-43278.html * https://www.suse.com/security/cve/CVE-2026-43279.html * https://www.suse.com/security/cve/CVE-2026-43287.html * https://www.suse.com/security/cve/CVE-2026-43291.html * https://www.suse.com/security/cve/CVE-2026-43294.html * https://www.suse.com/security/cve/CVE-2026-43295.html * https://www.suse.com/security/cve/CVE-2026-43300.html * https://www.suse.com/security/cve/CVE-2026-43302.html * https://www.suse.com/security/cve/CVE-2026-43304.html * https://www.suse.com/security/cve/CVE-2026-43312.html * https://www.suse.com/security/cve/CVE-2026-43313.html * https://www.suse.com/security/cve/CVE-2026-43314.html * https://www.suse.com/security/cve/CVE-2026-43316.html * https://www.suse.com/security/cve/CVE-2026-43318.html * https://www.suse.com/security/cve/CVE-2026-43319.html * https://www.suse.com/security/cve/CVE-2026-43320.html * https://www.suse.com/security/cve/CVE-2026-43324.html * https://www.suse.com/security/cve/CVE-2026-43327.html * https://www.suse.com/security/cve/CVE-2026-43337.html * https://www.suse.com/security/cve/CVE-2026-43340.html * https://www.suse.com/security/cve/CVE-2026-43342.html * https://www.suse.com/security/cve/CVE-2026-43343.html * https://www.suse.com/security/cve/CVE-2026-43346.html * https://www.suse.com/security/cve/CVE-2026-43353.html * https://www.suse.com/security/cve/CVE-2026-43357.html * https://www.suse.com/security/cve/CVE-2026-43370.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43380.html * https://www.suse.com/security/cve/CVE-2026-43381.html * https://www.suse.com/security/cve/CVE-2026-43382.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43387.html * https://www.suse.com/security/cve/CVE-2026-43395.html * https://www.suse.com/security/cve/CVE-2026-43397.html * https://www.suse.com/security/cve/CVE-2026-43412.html * https://www.suse.com/security/cve/CVE-2026-43425.html * https://www.suse.com/security/cve/CVE-2026-43426.html * https://www.suse.com/security/cve/CVE-2026-43427.html * https://www.suse.com/security/cve/CVE-2026-43428.html * https://www.suse.com/security/cve/CVE-2026-43429.html * https://www.suse.com/security/cve/CVE-2026-43430.html * https://www.suse.com/security/cve/CVE-2026-43432.html * https://www.suse.com/security/cve/CVE-2026-43436.html * https://www.suse.com/security/cve/CVE-2026-43443.html * https://www.suse.com/security/cve/CVE-2026-43444.html * https://www.suse.com/security/cve/CVE-2026-43445.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43459.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43467.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43473.html * https://www.suse.com/security/cve/CVE-2026-43476.html * https://www.suse.com/security/cve/CVE-2026-43480.html * https://www.suse.com/security/cve/CVE-2026-43488.html * https://www.suse.com/security/cve/CVE-2026-43493.html * https://www.suse.com/security/cve/CVE-2026-43496.html * https://www.suse.com/security/cve/CVE-2026-43497.html * https://www.suse.com/security/cve/CVE-2026-45834.html * https://www.suse.com/security/cve/CVE-2026-45835.html * https://www.suse.com/security/cve/CVE-2026-45839.html * https://www.suse.com/security/cve/CVE-2026-45851.html * https://www.suse.com/security/cve/CVE-2026-45853.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45867.html * https://www.suse.com/security/cve/CVE-2026-45868.html * https://www.suse.com/security/cve/CVE-2026-45869.html * https://www.suse.com/security/cve/CVE-2026-45871.html * https://www.suse.com/security/cve/CVE-2026-45875.html * https://www.suse.com/security/cve/CVE-2026-45877.html * https://www.suse.com/security/cve/CVE-2026-45879.html * https://www.suse.com/security/cve/CVE-2026-45880.html * https://www.suse.com/security/cve/CVE-2026-45881.html * https://www.suse.com/security/cve/CVE-2026-45883.html * https://www.suse.com/security/cve/CVE-2026-45885.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45902.html * https://www.suse.com/security/cve/CVE-2026-45911.html * https://www.suse.com/security/cve/CVE-2026-45914.html * https://www.suse.com/security/cve/CVE-2026-45916.html * https://www.suse.com/security/cve/CVE-2026-45919.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45921.html * https://www.suse.com/security/cve/CVE-2026-45922.html * https://www.suse.com/security/cve/CVE-2026-45923.html * https://www.suse.com/security/cve/CVE-2026-45928.html * https://www.suse.com/security/cve/CVE-2026-45936.html * https://www.suse.com/security/cve/CVE-2026-45941.html * https://www.suse.com/security/cve/CVE-2026-45946.html * https://www.suse.com/security/cve/CVE-2026-45947.html * https://www.suse.com/security/cve/CVE-2026-45954.html * https://www.suse.com/security/cve/CVE-2026-45958.html * https://www.suse.com/security/cve/CVE-2026-45963.html * https://www.suse.com/security/cve/CVE-2026-45969.html * https://www.suse.com/security/cve/CVE-2026-45976.html * https://www.suse.com/security/cve/CVE-2026-45981.html * https://www.suse.com/security/cve/CVE-2026-45982.html * https://www.suse.com/security/cve/CVE-2026-45986.html * https://www.suse.com/security/cve/CVE-2026-45987.html * https://www.suse.com/security/cve/CVE-2026-45994.html * https://www.suse.com/security/cve/CVE-2026-45996.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-46006.html * https://www.suse.com/security/cve/CVE-2026-46009.html * https://www.suse.com/security/cve/CVE-2026-46011.html * https://www.suse.com/security/cve/CVE-2026-46016.html * https://www.suse.com/security/cve/CVE-2026-46018.html * https://www.suse.com/security/cve/CVE-2026-46019.html * https://www.suse.com/security/cve/CVE-2026-46023.html * https://www.suse.com/security/cve/CVE-2026-46027.html * https://www.suse.com/security/cve/CVE-2026-46033.html * https://www.suse.com/security/cve/CVE-2026-46040.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46048.html * https://www.suse.com/security/cve/CVE-2026-46049.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46056.html * https://www.suse.com/security/cve/CVE-2026-46058.html * https://www.suse.com/security/cve/CVE-2026-46059.html * https://www.suse.com/security/cve/CVE-2026-46064.html * https://www.suse.com/security/cve/CVE-2026-46068.html * https://www.suse.com/security/cve/CVE-2026-46075.html * https://www.suse.com/security/cve/CVE-2026-46077.html * https://www.suse.com/security/cve/CVE-2026-46082.html * https://www.suse.com/security/cve/CVE-2026-46086.html * https://www.suse.com/security/cve/CVE-2026-46088.html * https://www.suse.com/security/cve/CVE-2026-46089.html * https://www.suse.com/security/cve/CVE-2026-46092.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46102.html * https://www.suse.com/security/cve/CVE-2026-46103.html * https://www.suse.com/security/cve/CVE-2026-46108.html * https://www.suse.com/security/cve/CVE-2026-46122.html * https://www.suse.com/security/cve/CVE-2026-46125.html * https://www.suse.com/security/cve/CVE-2026-46128.html * https://www.suse.com/security/cve/CVE-2026-46131.html * https://www.suse.com/security/cve/CVE-2026-46132.html * https://www.suse.com/security/cve/CVE-2026-46136.html * https://www.suse.com/security/cve/CVE-2026-46138.html * https://www.suse.com/security/cve/CVE-2026-46140.html * https://www.suse.com/security/cve/CVE-2026-46143.html * https://www.suse.com/security/cve/CVE-2026-46146.html * https://www.suse.com/security/cve/CVE-2026-46151.html * https://www.suse.com/security/cve/CVE-2026-46152.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46163.html * https://www.suse.com/security/cve/CVE-2026-46165.html * https://www.suse.com/security/cve/CVE-2026-46166.html * https://www.suse.com/security/cve/CVE-2026-46167.html * https://www.suse.com/security/cve/CVE-2026-46177.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46179.html * https://www.suse.com/security/cve/CVE-2026-46184.html * https://www.suse.com/security/cve/CVE-2026-46186.html * https://www.suse.com/security/cve/CVE-2026-46187.html * https://www.suse.com/security/cve/CVE-2026-46190.html * https://www.suse.com/security/cve/CVE-2026-46191.html * https://www.suse.com/security/cve/CVE-2026-46198.html * https://www.suse.com/security/cve/CVE-2026-46199.html * https://www.suse.com/security/cve/CVE-2026-46201.html * https://www.suse.com/security/cve/CVE-2026-46204.html * https://www.suse.com/security/cve/CVE-2026-46205.html * https://www.suse.com/security/cve/CVE-2026-46206.html * https://www.suse.com/security/cve/CVE-2026-46207.html * https://www.suse.com/security/cve/CVE-2026-46211.html * https://www.suse.com/security/cve/CVE-2026-46212.html * https://www.suse.com/security/cve/CVE-2026-46216.html * https://www.suse.com/security/cve/CVE-2026-46218.html * https://www.suse.com/security/cve/CVE-2026-46219.html * https://www.suse.com/security/cve/CVE-2026-46220.html * https://www.suse.com/security/cve/CVE-2026-46225.html * https://www.suse.com/security/cve/CVE-2026-46230.html * https://www.suse.com/security/cve/CVE-2026-46231.html * https://www.suse.com/security/cve/CVE-2026-46232.html * https://www.suse.com/security/cve/CVE-2026-46233.html * https://www.suse.com/security/cve/CVE-2026-46235.html * https://www.suse.com/security/cve/CVE-2026-46236.html * https://www.suse.com/security/cve/CVE-2026-46238.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46247.html * https://www.suse.com/security/cve/CVE-2026-46249.html * https://www.suse.com/security/cve/CVE-2026-46252.html * https://www.suse.com/security/cve/CVE-2026-46261.html * https://www.suse.com/security/cve/CVE-2026-46263.html * https://www.suse.com/security/cve/CVE-2026-46267.html * https://www.suse.com/security/cve/CVE-2026-46270.html * https://www.suse.com/security/cve/CVE-2026-46275.html * https://www.suse.com/security/cve/CVE-2026-46276.html * https://www.suse.com/security/cve/CVE-2026-46285.html * https://www.suse.com/security/cve/CVE-2026-46286.html * https://www.suse.com/security/cve/CVE-2026-46294.html * https://www.suse.com/security/cve/CVE-2026-46307.html * https://www.suse.com/security/cve/CVE-2026-46312.html * https://www.suse.com/security/cve/CVE-2026-46313.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46321.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-46330.html * https://www.suse.com/security/cve/CVE-2026-52904.html * https://www.suse.com/security/cve/CVE-2026-52914.html * https://www.suse.com/security/cve/CVE-2026-52915.html * https://www.suse.com/security/cve/CVE-2026-52916.html * https://www.suse.com/security/cve/CVE-2026-52919.html * https://www.suse.com/security/cve/CVE-2026-52922.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52926.html * https://www.suse.com/security/cve/CVE-2026-52931.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52936.html * https://www.suse.com/security/cve/CVE-2026-52948.html * https://www.suse.com/security/cve/CVE-2026-52951.html * https://www.suse.com/security/cve/CVE-2026-52953.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52961.html * https://www.suse.com/security/cve/CVE-2026-52963.html * https://www.suse.com/security/cve/CVE-2026-52964.html * https://www.suse.com/security/cve/CVE-2026-52976.html * https://www.suse.com/security/cve/CVE-2026-52981.html * https://www.suse.com/security/cve/CVE-2026-52982.html * https://www.suse.com/security/cve/CVE-2026-52989.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-52995.html * https://www.suse.com/security/cve/CVE-2026-53003.html * https://www.suse.com/security/cve/CVE-2026-53004.html * https://www.suse.com/security/cve/CVE-2026-53009.html * https://www.suse.com/security/cve/CVE-2026-53013.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53022.html * https://www.suse.com/security/cve/CVE-2026-53035.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53037.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53045.html * https://www.suse.com/security/cve/CVE-2026-53047.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53056.html * https://www.suse.com/security/cve/CVE-2026-53058.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53065.html * https://www.suse.com/security/cve/CVE-2026-53066.html * https://www.suse.com/security/cve/CVE-2026-53068.html * https://www.suse.com/security/cve/CVE-2026-53070.html * https://www.suse.com/security/cve/CVE-2026-53073.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53080.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53093.html * https://www.suse.com/security/cve/CVE-2026-53098.html * https://www.suse.com/security/cve/CVE-2026-53112.html * https://www.suse.com/security/cve/CVE-2026-53135.html * https://www.suse.com/security/cve/CVE-2026-53136.html * https://www.suse.com/security/cve/CVE-2026-53137.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53140.html * https://www.suse.com/security/cve/CVE-2026-53143.html * https://www.suse.com/security/cve/CVE-2026-53144.html * https://www.suse.com/security/cve/CVE-2026-53146.html * https://www.suse.com/security/cve/CVE-2026-53147.html * https://www.suse.com/security/cve/CVE-2026-53148.html * https://www.suse.com/security/cve/CVE-2026-53149.html * https://www.suse.com/security/cve/CVE-2026-53150.html * https://www.suse.com/security/cve/CVE-2026-53158.html * https://www.suse.com/security/cve/CVE-2026-53159.html * https://www.suse.com/security/cve/CVE-2026-53160.html * https://www.suse.com/security/cve/CVE-2026-53161.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53181.html * https://www.suse.com/security/cve/CVE-2026-53186.html * https://www.suse.com/security/cve/CVE-2026-53190.html * https://www.suse.com/security/cve/CVE-2026-53192.html * https://www.suse.com/security/cve/CVE-2026-53194.html * https://www.suse.com/security/cve/CVE-2026-53195.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53202.html * https://www.suse.com/security/cve/CVE-2026-53203.html * https://www.suse.com/security/cve/CVE-2026-53208.html * https://www.suse.com/security/cve/CVE-2026-53209.html * https://www.suse.com/security/cve/CVE-2026-53213.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53218.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53225.html * https://www.suse.com/security/cve/CVE-2026-53227.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53237.html * https://www.suse.com/security/cve/CVE-2026-53239.html * https://www.suse.com/security/cve/CVE-2026-53241.html * https://www.suse.com/security/cve/CVE-2026-53242.html * https://www.suse.com/security/cve/CVE-2026-53245.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53254.html * https://www.suse.com/security/cve/CVE-2026-53255.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53268.html * https://www.suse.com/security/cve/CVE-2026-53272.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53279.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53293.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53313.html * https://www.suse.com/security/cve/CVE-2026-53325.html * https://www.suse.com/security/cve/CVE-2026-53329.html * https://www.suse.com/security/cve/CVE-2026-53339.html * https://www.suse.com/security/cve/CVE-2026-53347.html * https://www.suse.com/security/cve/CVE-2026-53350.html * https://www.suse.com/security/cve/CVE-2026-53355.html * https://www.suse.com/security/cve/CVE-2026-53356.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53358.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1204315 * https://bugzilla.suse.com/show_bug.cgi?id=1243603 * https://bugzilla.suse.com/show_bug.cgi?id=1251942 * https://bugzilla.suse.com/show_bug.cgi?id=1256564 * https://bugzilla.suse.com/show_bug.cgi?id=1257605 * https://bugzilla.suse.com/show_bug.cgi?id=1257777 * https://bugzilla.suse.com/show_bug.cgi?id=1260012 * https://bugzilla.suse.com/show_bug.cgi?id=1260593 * https://bugzilla.suse.com/show_bug.cgi?id=1261250 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1262391 * https://bugzilla.suse.com/show_bug.cgi?id=1262603 * https://bugzilla.suse.com/show_bug.cgi?id=1262605 * https://bugzilla.suse.com/show_bug.cgi?id=1262614 * https://bugzilla.suse.com/show_bug.cgi?id=1262637 * https://bugzilla.suse.com/show_bug.cgi?id=1262639 * https://bugzilla.suse.com/show_bug.cgi?id=1262649 * https://bugzilla.suse.com/show_bug.cgi?id=1262653 * https://bugzilla.suse.com/show_bug.cgi?id=1262658 * https://bugzilla.suse.com/show_bug.cgi?id=1262659 * https://bugzilla.suse.com/show_bug.cgi?id=1262678 * https://bugzilla.suse.com/show_bug.cgi?id=1262723 * https://bugzilla.suse.com/show_bug.cgi?id=1262751 * https://bugzilla.suse.com/show_bug.cgi?id=1262757 * https://bugzilla.suse.com/show_bug.cgi?id=1262765 * https://bugzilla.suse.com/show_bug.cgi?id=1262768 * https://bugzilla.suse.com/show_bug.cgi?id=1262992 * https://bugzilla.suse.com/show_bug.cgi?id=1263008 * https://bugzilla.suse.com/show_bug.cgi?id=1263011 * https://bugzilla.suse.com/show_bug.cgi?id=1263013 * https://bugzilla.suse.com/show_bug.cgi?id=1263014 * https://bugzilla.suse.com/show_bug.cgi?id=1263016 * https://bugzilla.suse.com/show_bug.cgi?id=1263017 * https://bugzilla.suse.com/show_bug.cgi?id=1263020 * https://bugzilla.suse.com/show_bug.cgi?id=1263025 * https://bugzilla.suse.com/show_bug.cgi?id=1263030 * https://bugzilla.suse.com/show_bug.cgi?id=1263031 * https://bugzilla.suse.com/show_bug.cgi?id=1263045 * https://bugzilla.suse.com/show_bug.cgi?id=1263055 * https://bugzilla.suse.com/show_bug.cgi?id=1263059 * https://bugzilla.suse.com/show_bug.cgi?id=1263068 * https://bugzilla.suse.com/show_bug.cgi?id=1263073 * https://bugzilla.suse.com/show_bug.cgi?id=1263075 * https://bugzilla.suse.com/show_bug.cgi?id=1263077 * https://bugzilla.suse.com/show_bug.cgi?id=1263097 * https://bugzilla.suse.com/show_bug.cgi?id=1263111 * https://bugzilla.suse.com/show_bug.cgi?id=1263128 * https://bugzilla.suse.com/show_bug.cgi?id=1263134 * https://bugzilla.suse.com/show_bug.cgi?id=1263139 * https://bugzilla.suse.com/show_bug.cgi?id=1263142 * https://bugzilla.suse.com/show_bug.cgi?id=1263145 * https://bugzilla.suse.com/show_bug.cgi?id=1263167 * https://bugzilla.suse.com/show_bug.cgi?id=1263173 * https://bugzilla.suse.com/show_bug.cgi?id=1263175 * https://bugzilla.suse.com/show_bug.cgi?id=1263491 * https://bugzilla.suse.com/show_bug.cgi?id=1263493 * https://bugzilla.suse.com/show_bug.cgi?id=1263495 * https://bugzilla.suse.com/show_bug.cgi?id=1263539 * https://bugzilla.suse.com/show_bug.cgi?id=1263562 * https://bugzilla.suse.com/show_bug.cgi?id=1263598 * https://bugzilla.suse.com/show_bug.cgi?id=1263657 * https://bugzilla.suse.com/show_bug.cgi?id=1263776 * https://bugzilla.suse.com/show_bug.cgi?id=1263777 * https://bugzilla.suse.com/show_bug.cgi?id=1263778 * https://bugzilla.suse.com/show_bug.cgi?id=1263780 * https://bugzilla.suse.com/show_bug.cgi?id=1263782 * https://bugzilla.suse.com/show_bug.cgi?id=1263785 * https://bugzilla.suse.com/show_bug.cgi?id=1263786 * https://bugzilla.suse.com/show_bug.cgi?id=1263806 * https://bugzilla.suse.com/show_bug.cgi?id=1263876 * https://bugzilla.suse.com/show_bug.cgi?id=1263904 * https://bugzilla.suse.com/show_bug.cgi?id=1263905 * https://bugzilla.suse.com/show_bug.cgi?id=1263911 * https://bugzilla.suse.com/show_bug.cgi?id=1263923 * https://bugzilla.suse.com/show_bug.cgi?id=1263975 * https://bugzilla.suse.com/show_bug.cgi?id=1263999 * https://bugzilla.suse.com/show_bug.cgi?id=1264003 * https://bugzilla.suse.com/show_bug.cgi?id=1264006 * https://bugzilla.suse.com/show_bug.cgi?id=1264008 * https://bugzilla.suse.com/show_bug.cgi?id=1264009 * https://bugzilla.suse.com/show_bug.cgi?id=1264019 * https://bugzilla.suse.com/show_bug.cgi?id=1264030 * https://bugzilla.suse.com/show_bug.cgi?id=1264032 * https://bugzilla.suse.com/show_bug.cgi?id=1264033 * https://bugzilla.suse.com/show_bug.cgi?id=1264035 * https://bugzilla.suse.com/show_bug.cgi?id=1264039 * https://bugzilla.suse.com/show_bug.cgi?id=1264041 * https://bugzilla.suse.com/show_bug.cgi?id=1264044 * https://bugzilla.suse.com/show_bug.cgi?id=1264048 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264065 * https://bugzilla.suse.com/show_bug.cgi?id=1264070 * https://bugzilla.suse.com/show_bug.cgi?id=1264071 * https://bugzilla.suse.com/show_bug.cgi?id=1264073 * https://bugzilla.suse.com/show_bug.cgi?id=1264074 * https://bugzilla.suse.com/show_bug.cgi?id=1264075 * https://bugzilla.suse.com/show_bug.cgi?id=1264079 * https://bugzilla.suse.com/show_bug.cgi?id=1264088 * https://bugzilla.suse.com/show_bug.cgi?id=1264100 * https://bugzilla.suse.com/show_bug.cgi?id=1264101 * https://bugzilla.suse.com/show_bug.cgi?id=1264110 * https://bugzilla.suse.com/show_bug.cgi?id=1264121 * https://bugzilla.suse.com/show_bug.cgi?id=1264122 * https://bugzilla.suse.com/show_bug.cgi?id=1264125 * https://bugzilla.suse.com/show_bug.cgi?id=1264129 * https://bugzilla.suse.com/show_bug.cgi?id=1264142 * https://bugzilla.suse.com/show_bug.cgi?id=1264180 * https://bugzilla.suse.com/show_bug.cgi?id=1264188 * https://bugzilla.suse.com/show_bug.cgi?id=1264189 * https://bugzilla.suse.com/show_bug.cgi?id=1264190 * https://bugzilla.suse.com/show_bug.cgi?id=1264197 * https://bugzilla.suse.com/show_bug.cgi?id=1264237 * https://bugzilla.suse.com/show_bug.cgi?id=1264247 * https://bugzilla.suse.com/show_bug.cgi?id=1264257 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264296 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264308 * https://bugzilla.suse.com/show_bug.cgi?id=1264313 * https://bugzilla.suse.com/show_bug.cgi?id=1264315 * https://bugzilla.suse.com/show_bug.cgi?id=1264317 * https://bugzilla.suse.com/show_bug.cgi?id=1264321 * https://bugzilla.suse.com/show_bug.cgi?id=1264322 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264331 * https://bugzilla.suse.com/show_bug.cgi?id=1264336 * https://bugzilla.suse.com/show_bug.cgi?id=1264338 * https://bugzilla.suse.com/show_bug.cgi?id=1264339 * https://bugzilla.suse.com/show_bug.cgi?id=1264340 * https://bugzilla.suse.com/show_bug.cgi?id=1264365 * https://bugzilla.suse.com/show_bug.cgi?id=1264377 * https://bugzilla.suse.com/show_bug.cgi?id=1264379 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264387 * https://bugzilla.suse.com/show_bug.cgi?id=1264388 * https://bugzilla.suse.com/show_bug.cgi?id=1264414 * https://bugzilla.suse.com/show_bug.cgi?id=1264416 * https://bugzilla.suse.com/show_bug.cgi?id=1264417 * https://bugzilla.suse.com/show_bug.cgi?id=1264419 * https://bugzilla.suse.com/show_bug.cgi?id=1264423 * https://bugzilla.suse.com/show_bug.cgi?id=1264424 * https://bugzilla.suse.com/show_bug.cgi?id=1264425 * https://bugzilla.suse.com/show_bug.cgi?id=1264429 * https://bugzilla.suse.com/show_bug.cgi?id=1264431 * https://bugzilla.suse.com/show_bug.cgi?id=1264436 * https://bugzilla.suse.com/show_bug.cgi?id=1264442 * https://bugzilla.suse.com/show_bug.cgi?id=1264451 * https://bugzilla.suse.com/show_bug.cgi?id=1264473 * https://bugzilla.suse.com/show_bug.cgi?id=1264477 * https://bugzilla.suse.com/show_bug.cgi?id=1264479 * https://bugzilla.suse.com/show_bug.cgi?id=1264480 * https://bugzilla.suse.com/show_bug.cgi?id=1264520 * https://bugzilla.suse.com/show_bug.cgi?id=1264526 * https://bugzilla.suse.com/show_bug.cgi?id=1264531 * https://bugzilla.suse.com/show_bug.cgi?id=1264538 * https://bugzilla.suse.com/show_bug.cgi?id=1264540 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264553 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264560 * https://bugzilla.suse.com/show_bug.cgi?id=1264564 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264584 * https://bugzilla.suse.com/show_bug.cgi?id=1264590 * https://bugzilla.suse.com/show_bug.cgi?id=1264592 * https://bugzilla.suse.com/show_bug.cgi?id=1264594 * https://bugzilla.suse.com/show_bug.cgi?id=1264598 * https://bugzilla.suse.com/show_bug.cgi?id=1264600 * https://bugzilla.suse.com/show_bug.cgi?id=1264613 * https://bugzilla.suse.com/show_bug.cgi?id=1264615 * https://bugzilla.suse.com/show_bug.cgi?id=1264616 * https://bugzilla.suse.com/show_bug.cgi?id=1264618 * https://bugzilla.suse.com/show_bug.cgi?id=1264620 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264626 * https://bugzilla.suse.com/show_bug.cgi?id=1264630 * https://bugzilla.suse.com/show_bug.cgi?id=1264633 * https://bugzilla.suse.com/show_bug.cgi?id=1264637 * https://bugzilla.suse.com/show_bug.cgi?id=1264640 * https://bugzilla.suse.com/show_bug.cgi?id=1264642 * https://bugzilla.suse.com/show_bug.cgi?id=1264644 * https://bugzilla.suse.com/show_bug.cgi?id=1264645 * https://bugzilla.suse.com/show_bug.cgi?id=1264668 * https://bugzilla.suse.com/show_bug.cgi?id=1264677 * https://bugzilla.suse.com/show_bug.cgi?id=1264731 * https://bugzilla.suse.com/show_bug.cgi?id=1264739 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264746 * https://bugzilla.suse.com/show_bug.cgi?id=1264758 * https://bugzilla.suse.com/show_bug.cgi?id=1264768 * https://bugzilla.suse.com/show_bug.cgi?id=1264780 * https://bugzilla.suse.com/show_bug.cgi?id=1264781 * https://bugzilla.suse.com/show_bug.cgi?id=1264782 * https://bugzilla.suse.com/show_bug.cgi?id=1264783 * https://bugzilla.suse.com/show_bug.cgi?id=1264785 * https://bugzilla.suse.com/show_bug.cgi?id=1264788 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264791 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264803 * https://bugzilla.suse.com/show_bug.cgi?id=1264809 * https://bugzilla.suse.com/show_bug.cgi?id=1264815 * https://bugzilla.suse.com/show_bug.cgi?id=1264816 * https://bugzilla.suse.com/show_bug.cgi?id=1264819 * https://bugzilla.suse.com/show_bug.cgi?id=1264821 * https://bugzilla.suse.com/show_bug.cgi?id=1264822 * https://bugzilla.suse.com/show_bug.cgi?id=1264826 * https://bugzilla.suse.com/show_bug.cgi?id=1264830 * https://bugzilla.suse.com/show_bug.cgi?id=1264835 * https://bugzilla.suse.com/show_bug.cgi?id=1264837 * https://bugzilla.suse.com/show_bug.cgi?id=1264844 * https://bugzilla.suse.com/show_bug.cgi?id=1264846 * https://bugzilla.suse.com/show_bug.cgi?id=1264853 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264987 * https://bugzilla.suse.com/show_bug.cgi?id=1264988 * https://bugzilla.suse.com/show_bug.cgi?id=1264991 * https://bugzilla.suse.com/show_bug.cgi?id=1264993 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265019 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265032 * https://bugzilla.suse.com/show_bug.cgi?id=1265037 * https://bugzilla.suse.com/show_bug.cgi?id=1265041 * https://bugzilla.suse.com/show_bug.cgi?id=1265047 * https://bugzilla.suse.com/show_bug.cgi?id=1265054 * https://bugzilla.suse.com/show_bug.cgi?id=1265074 * https://bugzilla.suse.com/show_bug.cgi?id=1265078 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265080 * https://bugzilla.suse.com/show_bug.cgi?id=1265089 * https://bugzilla.suse.com/show_bug.cgi?id=1265092 * https://bugzilla.suse.com/show_bug.cgi?id=1265093 * https://bugzilla.suse.com/show_bug.cgi?id=1265096 * https://bugzilla.suse.com/show_bug.cgi?id=1265100 * https://bugzilla.suse.com/show_bug.cgi?id=1265101 * https://bugzilla.suse.com/show_bug.cgi?id=1265102 * https://bugzilla.suse.com/show_bug.cgi?id=1265105 * https://bugzilla.suse.com/show_bug.cgi?id=1265112 * https://bugzilla.suse.com/show_bug.cgi?id=1265133 * https://bugzilla.suse.com/show_bug.cgi?id=1265138 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1265249 * https://bugzilla.suse.com/show_bug.cgi?id=1265257 * https://bugzilla.suse.com/show_bug.cgi?id=1265264 * https://bugzilla.suse.com/show_bug.cgi?id=1265627 * https://bugzilla.suse.com/show_bug.cgi?id=1266000 * https://bugzilla.suse.com/show_bug.cgi?id=1266003 * https://bugzilla.suse.com/show_bug.cgi?id=1266399 * https://bugzilla.suse.com/show_bug.cgi?id=1266411 * https://bugzilla.suse.com/show_bug.cgi?id=1266412 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266467 * https://bugzilla.suse.com/show_bug.cgi?id=1266468 * https://bugzilla.suse.com/show_bug.cgi?id=1266677 * https://bugzilla.suse.com/show_bug.cgi?id=1266679 * https://bugzilla.suse.com/show_bug.cgi?id=1266684 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266688 * https://bugzilla.suse.com/show_bug.cgi?id=1266692 * https://bugzilla.suse.com/show_bug.cgi?id=1266703 * https://bugzilla.suse.com/show_bug.cgi?id=1266707 * https://bugzilla.suse.com/show_bug.cgi?id=1266721 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266729 * https://bugzilla.suse.com/show_bug.cgi?id=1266732 * https://bugzilla.suse.com/show_bug.cgi?id=1266739 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266741 * https://bugzilla.suse.com/show_bug.cgi?id=1266743 * https://bugzilla.suse.com/show_bug.cgi?id=1266744 * https://bugzilla.suse.com/show_bug.cgi?id=1266751 * https://bugzilla.suse.com/show_bug.cgi?id=1266755 * https://bugzilla.suse.com/show_bug.cgi?id=1266762 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266774 * https://bugzilla.suse.com/show_bug.cgi?id=1266775 * https://bugzilla.suse.com/show_bug.cgi?id=1266777 * https://bugzilla.suse.com/show_bug.cgi?id=1266780 * https://bugzilla.suse.com/show_bug.cgi?id=1266805 * https://bugzilla.suse.com/show_bug.cgi?id=1266806 * https://bugzilla.suse.com/show_bug.cgi?id=1266831 * https://bugzilla.suse.com/show_bug.cgi?id=1266832 * https://bugzilla.suse.com/show_bug.cgi?id=1266834 * https://bugzilla.suse.com/show_bug.cgi?id=1266836 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266839 * https://bugzilla.suse.com/show_bug.cgi?id=1266841 * https://bugzilla.suse.com/show_bug.cgi?id=1266842 * https://bugzilla.suse.com/show_bug.cgi?id=1266846 * https://bugzilla.suse.com/show_bug.cgi?id=1266854 * https://bugzilla.suse.com/show_bug.cgi?id=1266855 * https://bugzilla.suse.com/show_bug.cgi?id=1266863 * https://bugzilla.suse.com/show_bug.cgi?id=1266864 * https://bugzilla.suse.com/show_bug.cgi?id=1266870 * https://bugzilla.suse.com/show_bug.cgi?id=1266872 * https://bugzilla.suse.com/show_bug.cgi?id=1266879 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266884 * https://bugzilla.suse.com/show_bug.cgi?id=1266886 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1266894 * https://bugzilla.suse.com/show_bug.cgi?id=1266898 * https://bugzilla.suse.com/show_bug.cgi?id=1266908 * https://bugzilla.suse.com/show_bug.cgi?id=1266910 * https://bugzilla.suse.com/show_bug.cgi?id=1266917 * https://bugzilla.suse.com/show_bug.cgi?id=1266920 * https://bugzilla.suse.com/show_bug.cgi?id=1266925 * https://bugzilla.suse.com/show_bug.cgi?id=1266934 * https://bugzilla.suse.com/show_bug.cgi?id=1266935 * https://bugzilla.suse.com/show_bug.cgi?id=1266939 * https://bugzilla.suse.com/show_bug.cgi?id=1266947 * https://bugzilla.suse.com/show_bug.cgi?id=1267021 * https://bugzilla.suse.com/show_bug.cgi?id=1267027 * https://bugzilla.suse.com/show_bug.cgi?id=1267198 * https://bugzilla.suse.com/show_bug.cgi?id=1267204 * https://bugzilla.suse.com/show_bug.cgi?id=1267213 * https://bugzilla.suse.com/show_bug.cgi?id=1267226 * https://bugzilla.suse.com/show_bug.cgi?id=1267234 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267367 * https://bugzilla.suse.com/show_bug.cgi?id=1267380 * https://bugzilla.suse.com/show_bug.cgi?id=1267432 * https://bugzilla.suse.com/show_bug.cgi?id=1267435 * https://bugzilla.suse.com/show_bug.cgi?id=1267436 * https://bugzilla.suse.com/show_bug.cgi?id=1267445 * https://bugzilla.suse.com/show_bug.cgi?id=1267448 * https://bugzilla.suse.com/show_bug.cgi?id=1267449 * https://bugzilla.suse.com/show_bug.cgi?id=1267466 * https://bugzilla.suse.com/show_bug.cgi?id=1267472 * https://bugzilla.suse.com/show_bug.cgi?id=1267473 * https://bugzilla.suse.com/show_bug.cgi?id=1267479 * https://bugzilla.suse.com/show_bug.cgi?id=1267491 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267495 * https://bugzilla.suse.com/show_bug.cgi?id=1267496 * https://bugzilla.suse.com/show_bug.cgi?id=1267497 * https://bugzilla.suse.com/show_bug.cgi?id=1267502 * https://bugzilla.suse.com/show_bug.cgi?id=1267524 * https://bugzilla.suse.com/show_bug.cgi?id=1267555 * https://bugzilla.suse.com/show_bug.cgi?id=1267565 * https://bugzilla.suse.com/show_bug.cgi?id=1267571 * https://bugzilla.suse.com/show_bug.cgi?id=1267583 * https://bugzilla.suse.com/show_bug.cgi?id=1267592 * https://bugzilla.suse.com/show_bug.cgi?id=1267595 * https://bugzilla.suse.com/show_bug.cgi?id=1267611 * https://bugzilla.suse.com/show_bug.cgi?id=1267615 * https://bugzilla.suse.com/show_bug.cgi?id=1267616 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267623 * https://bugzilla.suse.com/show_bug.cgi?id=1267627 * https://bugzilla.suse.com/show_bug.cgi?id=1267630 * https://bugzilla.suse.com/show_bug.cgi?id=1267632 * https://bugzilla.suse.com/show_bug.cgi?id=1267636 * https://bugzilla.suse.com/show_bug.cgi?id=1267638 * https://bugzilla.suse.com/show_bug.cgi?id=1267643 * https://bugzilla.suse.com/show_bug.cgi?id=1267646 * https://bugzilla.suse.com/show_bug.cgi?id=1267649 * https://bugzilla.suse.com/show_bug.cgi?id=1267658 * https://bugzilla.suse.com/show_bug.cgi?id=1267661 * https://bugzilla.suse.com/show_bug.cgi?id=1267666 * https://bugzilla.suse.com/show_bug.cgi?id=1267667 * https://bugzilla.suse.com/show_bug.cgi?id=1267669 * https://bugzilla.suse.com/show_bug.cgi?id=1267676 * https://bugzilla.suse.com/show_bug.cgi?id=1267677 * https://bugzilla.suse.com/show_bug.cgi?id=1267680 * https://bugzilla.suse.com/show_bug.cgi?id=1267683 * https://bugzilla.suse.com/show_bug.cgi?id=1267690 * https://bugzilla.suse.com/show_bug.cgi?id=1267691 * https://bugzilla.suse.com/show_bug.cgi?id=1267693 * https://bugzilla.suse.com/show_bug.cgi?id=1267701 * https://bugzilla.suse.com/show_bug.cgi?id=1267702 * https://bugzilla.suse.com/show_bug.cgi?id=1267704 * https://bugzilla.suse.com/show_bug.cgi?id=1267712 * https://bugzilla.suse.com/show_bug.cgi?id=1267719 * https://bugzilla.suse.com/show_bug.cgi?id=1267725 * https://bugzilla.suse.com/show_bug.cgi?id=1267728 * https://bugzilla.suse.com/show_bug.cgi?id=1267922 * https://bugzilla.suse.com/show_bug.cgi?id=1267932 * https://bugzilla.suse.com/show_bug.cgi?id=1267939 * https://bugzilla.suse.com/show_bug.cgi?id=1267948 * https://bugzilla.suse.com/show_bug.cgi?id=1267968 * https://bugzilla.suse.com/show_bug.cgi?id=1267987 * https://bugzilla.suse.com/show_bug.cgi?id=1267990 * https://bugzilla.suse.com/show_bug.cgi?id=1267991 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268024 * https://bugzilla.suse.com/show_bug.cgi?id=1268049 * https://bugzilla.suse.com/show_bug.cgi?id=1268051 * https://bugzilla.suse.com/show_bug.cgi?id=1268220 * https://bugzilla.suse.com/show_bug.cgi?id=1268221 * https://bugzilla.suse.com/show_bug.cgi?id=1268223 * https://bugzilla.suse.com/show_bug.cgi?id=1268981 * https://bugzilla.suse.com/show_bug.cgi?id=1268986 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269001 * https://bugzilla.suse.com/show_bug.cgi?id=1269002 * https://bugzilla.suse.com/show_bug.cgi?id=1269008 * https://bugzilla.suse.com/show_bug.cgi?id=1269025 * https://bugzilla.suse.com/show_bug.cgi?id=1269030 * https://bugzilla.suse.com/show_bug.cgi?id=1269031 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269081 * https://bugzilla.suse.com/show_bug.cgi?id=1269095 * https://bugzilla.suse.com/show_bug.cgi?id=1269098 * https://bugzilla.suse.com/show_bug.cgi?id=1269106 * https://bugzilla.suse.com/show_bug.cgi?id=1269111 * https://bugzilla.suse.com/show_bug.cgi?id=1269116 * https://bugzilla.suse.com/show_bug.cgi?id=1269124 * https://bugzilla.suse.com/show_bug.cgi?id=1269125 * https://bugzilla.suse.com/show_bug.cgi?id=1269129 * https://bugzilla.suse.com/show_bug.cgi?id=1269131 * https://bugzilla.suse.com/show_bug.cgi?id=1269133 * https://bugzilla.suse.com/show_bug.cgi?id=1269141 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269153 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269177 * https://bugzilla.suse.com/show_bug.cgi?id=1269178 * https://bugzilla.suse.com/show_bug.cgi?id=1269187 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269190 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269236 * https://bugzilla.suse.com/show_bug.cgi?id=1269239 * https://bugzilla.suse.com/show_bug.cgi?id=1269245 * https://bugzilla.suse.com/show_bug.cgi?id=1269254 * https://bugzilla.suse.com/show_bug.cgi?id=1269255 * https://bugzilla.suse.com/show_bug.cgi?id=1269257 * https://bugzilla.suse.com/show_bug.cgi?id=1269258 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269273 * https://bugzilla.suse.com/show_bug.cgi?id=1269283 * https://bugzilla.suse.com/show_bug.cgi?id=1269304 * https://bugzilla.suse.com/show_bug.cgi?id=1269364 * https://bugzilla.suse.com/show_bug.cgi?id=1269378 * https://bugzilla.suse.com/show_bug.cgi?id=1269385 * https://bugzilla.suse.com/show_bug.cgi?id=1269386 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269403 * https://bugzilla.suse.com/show_bug.cgi?id=1269404 * https://bugzilla.suse.com/show_bug.cgi?id=1269410 * https://bugzilla.suse.com/show_bug.cgi?id=1269414 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269505 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269556 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269637 * https://bugzilla.suse.com/show_bug.cgi?id=1269644 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269652 * https://bugzilla.suse.com/show_bug.cgi?id=1269654 * https://bugzilla.suse.com/show_bug.cgi?id=1269661 * https://bugzilla.suse.com/show_bug.cgi?id=1269663 * https://bugzilla.suse.com/show_bug.cgi?id=1269669 * https://bugzilla.suse.com/show_bug.cgi?id=1269670 * https://bugzilla.suse.com/show_bug.cgi?id=1269674 * https://bugzilla.suse.com/show_bug.cgi?id=1269675 * https://bugzilla.suse.com/show_bug.cgi?id=1269677 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269682 * https://bugzilla.suse.com/show_bug.cgi?id=1269684 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269709 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269711 * https://bugzilla.suse.com/show_bug.cgi?id=1269719 * https://bugzilla.suse.com/show_bug.cgi?id=1269726 * https://bugzilla.suse.com/show_bug.cgi?id=1269733 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269770 * https://bugzilla.suse.com/show_bug.cgi?id=1269772 * https://bugzilla.suse.com/show_bug.cgi?id=1269786 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269796 * https://bugzilla.suse.com/show_bug.cgi?id=1269799 * https://bugzilla.suse.com/show_bug.cgi?id=1269809 * https://bugzilla.suse.com/show_bug.cgi?id=1269811 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269817 * https://bugzilla.suse.com/show_bug.cgi?id=1269826 * https://bugzilla.suse.com/show_bug.cgi?id=1269877 * https://bugzilla.suse.com/show_bug.cgi?id=1269886 * https://bugzilla.suse.com/show_bug.cgi?id=1269889 * https://bugzilla.suse.com/show_bug.cgi?id=1269898 * https://bugzilla.suse.com/show_bug.cgi?id=1269899 * https://bugzilla.suse.com/show_bug.cgi?id=1269904 * https://bugzilla.suse.com/show_bug.cgi?id=1269976 * https://bugzilla.suse.com/show_bug.cgi?id=1269984 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269988 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1269996 * https://bugzilla.suse.com/show_bug.cgi?id=1269997 * https://bugzilla.suse.com/show_bug.cgi?id=1269998 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270042 * https://bugzilla.suse.com/show_bug.cgi?id=1270058 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270112 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1270241 * https://bugzilla.suse.com/show_bug.cgi?id=1270244 * https://bugzilla.suse.com/show_bug.cgi?id=1270248 * https://bugzilla.suse.com/show_bug.cgi?id=1270249 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1270260 * https://bugzilla.suse.com/show_bug.cgi?id=1270263 * https://bugzilla.suse.com/show_bug.cgi?id=1270268 * https://bugzilla.suse.com/show_bug.cgi?id=1270302 * https://bugzilla.suse.com/show_bug.cgi?id=1270396 * https://bugzilla.suse.com/show_bug.cgi?id=1271040 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271248 * https://bugzilla.suse.com/show_bug.cgi?id=1271249 * https://bugzilla.suse.com/show_bug.cgi?id=1271287 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271402 * https://jira.suse.com/browse/PED-15897 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 20:42:17 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 20:42:17 -0000 Subject: SUSE-SU-2026:3138-1: important: Security update for 389-ds Message-ID: <178458013797.1659.2838914315160968460@ddd703581f31> # Security update for 389-ds Announcement ID: SUSE-SU-2026:3138-1 Release Date: 2026-07-20T15:10:54Z Rating: important References: * bsc#1267975 * bsc#1268041 * bsc#1268046 * bsc#1268047 * bsc#1268057 * bsc#1268058 * bsc#1268060 * bsc#1268062 * bsc#1268064 * bsc#1268065 * bsc#1268115 * bsc#1268298 * bsc#1268491 * bsc#1269120 * bsc#1270695 Cross-References: * CVE-2026-11610 * CVE-2026-11611 * CVE-2026-11774 * CVE-2026-11785 * CVE-2026-11786 * CVE-2026-11787 * CVE-2026-11788 * CVE-2026-11789 * CVE-2026-11790 * CVE-2026-11791 * CVE-2026-11792 * CVE-2026-11793 * CVE-2026-11884 * CVE-2026-12528 CVSS scores: * CVE-2026-11610 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-11610 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-11611 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11611 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11611 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11774 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-11774 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11785 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11785 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11785 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11786 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11786 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-11786 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11786 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11787 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-11787 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11787 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11787 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11788 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11788 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11788 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11788 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11789 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11790 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11790 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11790 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11791 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-11791 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-11792 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-11792 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-11792 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-11793 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11793 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11793 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-11884 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-12528 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 14 vulnerabilities and has one security fix can now be installed. ## Description: This update for 389-ds fixes the following issues * Update to version 2.7.0~git212.9b0755edb. * CVE-2026-11610: heap buffer overflow in `sasl_io_recv()` via padded SASL UNBIND (bsc#1270695). * CVE-2026-11611: content synchronization persistent search plugin can allow unbounded memory growth (bsc#1267975). * CVE-2026-11774: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (bsc#1268298). * CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure (bsc#1268065). * CVE-2026-11786: lack of length check can cause an out-of-bounds read (bsc#1268064). * CVE-2026-11787: lack of bounds check can lead to a heap buffer overread (bsc#1268062). * CVE-2026-11788: lack of allocation failure check can lead to NULL pointer dereference (bsc#1268057). * CVE-2026-11789: crafted SMD5 hash can lead to an integer underflow (bsc#1268058). * CVE-2026-11790: crafted password hash can cause excessive CPU consumption (bsc#1268060). * CVE-2026-11791: schema reload triggered during concurrent LDAP query traffic can lead to a use-after-free (bsc#1268047). * CVE-2026-11792: password value shorter than 23 characters can cause a heap buffer overflow (bsc#1268046). * CVE-2026-11793: crafted `nsDS5ReplicaCredentials` can lead to a stack buffer overflow (bsc#1268041). * CVE-2026-11884: remote code execution and denial of service via heap buffer overflow (bsc#1268115). * CVE-2026-12528: heap buffer overflows in `__aclp__normalize_acltxt()` (bsc#1268491). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3138=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * 389-ds-debugsource-2.7.0~git212.9b0755edb-150700.3.19.1 * libsvrcore0-2.7.0~git212.9b0755edb-150700.3.19.1 * 389-ds-debuginfo-2.7.0~git212.9b0755edb-150700.3.19.1 * 389-ds-2.7.0~git212.9b0755edb-150700.3.19.1 * 389-ds-devel-2.7.0~git212.9b0755edb-150700.3.19.1 * libsvrcore0-debuginfo-2.7.0~git212.9b0755edb-150700.3.19.1 * lib389-2.7.0~git212.9b0755edb-150700.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11610.html * https://www.suse.com/security/cve/CVE-2026-11611.html * https://www.suse.com/security/cve/CVE-2026-11774.html * https://www.suse.com/security/cve/CVE-2026-11785.html * https://www.suse.com/security/cve/CVE-2026-11786.html * https://www.suse.com/security/cve/CVE-2026-11787.html * https://www.suse.com/security/cve/CVE-2026-11788.html * https://www.suse.com/security/cve/CVE-2026-11789.html * https://www.suse.com/security/cve/CVE-2026-11790.html * https://www.suse.com/security/cve/CVE-2026-11791.html * https://www.suse.com/security/cve/CVE-2026-11792.html * https://www.suse.com/security/cve/CVE-2026-11793.html * https://www.suse.com/security/cve/CVE-2026-11884.html * https://www.suse.com/security/cve/CVE-2026-12528.html * https://bugzilla.suse.com/show_bug.cgi?id=1267975 * https://bugzilla.suse.com/show_bug.cgi?id=1268041 * https://bugzilla.suse.com/show_bug.cgi?id=1268046 * https://bugzilla.suse.com/show_bug.cgi?id=1268047 * https://bugzilla.suse.com/show_bug.cgi?id=1268057 * https://bugzilla.suse.com/show_bug.cgi?id=1268058 * https://bugzilla.suse.com/show_bug.cgi?id=1268060 * https://bugzilla.suse.com/show_bug.cgi?id=1268062 * https://bugzilla.suse.com/show_bug.cgi?id=1268064 * https://bugzilla.suse.com/show_bug.cgi?id=1268065 * https://bugzilla.suse.com/show_bug.cgi?id=1268115 * https://bugzilla.suse.com/show_bug.cgi?id=1268298 * https://bugzilla.suse.com/show_bug.cgi?id=1268491 * https://bugzilla.suse.com/show_bug.cgi?id=1269120 * https://bugzilla.suse.com/show_bug.cgi?id=1270695 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 20:42:42 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 20:42:42 -0000 Subject: SUSE-SU-2026:3137-1: important: Security update for 389-ds Message-ID: <178458016264.1659.2390470035830128230@ddd703581f31> # Security update for 389-ds Announcement ID: SUSE-SU-2026:3137-1 Release Date: 2026-07-20T15:10:33Z Rating: important References: * bsc#1267975 * bsc#1268041 * bsc#1268046 * bsc#1268047 * bsc#1268057 * bsc#1268058 * bsc#1268060 * bsc#1268062 * bsc#1268064 * bsc#1268065 * bsc#1268115 * bsc#1268298 * bsc#1268491 * bsc#1269120 * bsc#1270695 Cross-References: * CVE-2026-11610 * CVE-2026-11611 * CVE-2026-11774 * CVE-2026-11785 * CVE-2026-11786 * CVE-2026-11787 * CVE-2026-11788 * CVE-2026-11789 * CVE-2026-11790 * CVE-2026-11791 * CVE-2026-11792 * CVE-2026-11793 * CVE-2026-11884 * CVE-2026-12528 CVSS scores: * CVE-2026-11610 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-11610 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-11611 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11611 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11611 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11774 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-11774 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11785 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11785 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11785 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11786 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11786 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-11786 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11786 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11787 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-11787 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11787 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11787 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11788 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11788 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11788 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11788 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11789 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11790 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11790 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11790 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11791 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-11791 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-11792 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-11792 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-11792 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-11793 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11793 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11793 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-11884 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-12528 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 14 vulnerabilities and has one security fix can now be installed. ## Description: This update for 389-ds fixes the following issues: Update to version 2.2.10~git255.752643c78. Security issues fixed: * CVE-2026-11610: missing bounds check in `sasl_io_recv()` can lead to a heap buffer overflow when processing a specially crafted oversized LDAP UNBIND packet (bsc#1270695). * CVE-2026-11611: Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses(bsc#1267975). * CVE-2026-11774: integer overflow in `sasl_io_start_packet()` can lead to heap buffer overflow when processing a crafted SASL packet length prefix (bsc#1268298). * CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure in LDA responses (bsc#1268065). * CVE-2026-11786: out-of-bounds read in the LDIF parser when processing attribute types with trailing semicolons during database import (bsc#1268064). * CVE-2026-11787: missing bounds check in the `ldap_utf8prev()` functioncan can lead to a heap buffer overread in string filter parsing(bsc#1268062). * CVE-2026-11788: missing allocation check in the dereference control plugin before using a BER structure can lead to LDAP server crash when the system is under memory pressure (bsc#1268057). * CVE-2026-11789: integer underflow in the SMD5 password storage plugin can lead to a buffer overread when computing salt length from a crafted password hash shorter than 16 bytes (bsc#1268058). * CVE-2026-11790: improper bounds enforcement in the BKDF2-SHA256 password storage plugin can lead to excessive resource consumption during authentication and cause a DoS (bsc#1268060). * CVE-2026-11791: use-after-free in the schema reload mechanism can lead to a `ns-slapd` crash when concurrent LDAP query traffic is active (bsc#1268047). * CVE-2026-11792: missing checks in `create_masked_entry_string` can lead to a heap and log output corruption whe a short cleartext password is logged (bsc#1268046). * CVE-2026-11793: missing bounds check in `checkPrefix()` can lead to a stack buffer overflow when processing an algorithm ID during parsing of reversible-encrypted attribute values (bsc#1268041). * CVE-2026-11884: improper string management can lead to heap buffer overflow when serializing objectclass definitions (bsc#1268115). * CVE-2026-12528: missing length checks in the `__aclp__normalize_acltxt()` function can lead to heap buffer overflow when processing a malformed ACI string (bsc#1268491). Other updates and bugfixes: * Version 2.2.10~git255.752643c78. * Issue 7406 - Fix `ldap-agent` SNMP stats file loading (#7630) * Issue 7621 - Stack Buffer Overflow in Password `checkPrefix` * Issue 7623 - Heap Buffer Overflow in `389-ds-base` Audit Log Password Masking * Issue 6625 - Backport `get_pid` to fix `check_asan_report` (#7625) * Issue 7602 - CI - `lib389` user compare fails due to parentid mismatch (#7603) * Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592) * Issue 7593 - Fix testimony docstring for SASL overflow test (#7606) * Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572) * Issue 7593 - Reject invalid SASL packet length values in `sasl_io_start_packet` (#7594) * Issue 3555 - UI - Fix audit issue with `npm` \- `ws`, `js-yaml`, `js-yaml` , `postcss`, `uuid` * Issue 7541 - Add invalid ACL text header regression test (#7591) * Issue 7541 - heap-buffer-overflows in `__aclp__normalize_acltxt()` (#7542) * Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload * Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559) * Issue 7500 - Prevent unsigned integer underflow during stalled import * Issue 7560 - `lib389` \- Add helper function for checking ASAN files * Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540) * Issue 7549 - Substring index should validate minimum `nsSubStrBegin`/`nsSubStrEnd` values (#7550) * Issue 7440 - Substring index produces empty results and can crash when non- default `nsSubStrBegin`/`nsSubStrEnd` lengths are configured (#7441) * Fix test389 imports on older branches * Issue 7437 - `LeakSanitizer`: memory leaks in CoS cache error paths (#7438) * Issue 6922 - `AddressSanitizer`: leaks found by acl test suite * Issue 3555 - UI - Fix audit issue with `npm` \- `brace-expansion` (#7556) * Issue 7554 - deref plugin null pointer dereference if `ber_init` fails * Issue 7514 - Crash when doing moddn on very large subtree * Issue 7516 - `dblayer_bulk_nextdata` should not return an error when maxrecords is hit ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3137=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3137=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3137=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3137=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3137=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * lib389-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * 389-ds-snmp-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * lib389-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-snmp-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * lib389-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * lib389-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * lib389-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1 * 389-ds-2.2.10~git255.752643c78-150500.3.48.1 * libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11610.html * https://www.suse.com/security/cve/CVE-2026-11611.html * https://www.suse.com/security/cve/CVE-2026-11774.html * https://www.suse.com/security/cve/CVE-2026-11785.html * https://www.suse.com/security/cve/CVE-2026-11786.html * https://www.suse.com/security/cve/CVE-2026-11787.html * https://www.suse.com/security/cve/CVE-2026-11788.html * https://www.suse.com/security/cve/CVE-2026-11789.html * https://www.suse.com/security/cve/CVE-2026-11790.html * https://www.suse.com/security/cve/CVE-2026-11791.html * https://www.suse.com/security/cve/CVE-2026-11792.html * https://www.suse.com/security/cve/CVE-2026-11793.html * https://www.suse.com/security/cve/CVE-2026-11884.html * https://www.suse.com/security/cve/CVE-2026-12528.html * https://bugzilla.suse.com/show_bug.cgi?id=1267975 * https://bugzilla.suse.com/show_bug.cgi?id=1268041 * https://bugzilla.suse.com/show_bug.cgi?id=1268046 * https://bugzilla.suse.com/show_bug.cgi?id=1268047 * https://bugzilla.suse.com/show_bug.cgi?id=1268057 * https://bugzilla.suse.com/show_bug.cgi?id=1268058 * https://bugzilla.suse.com/show_bug.cgi?id=1268060 * https://bugzilla.suse.com/show_bug.cgi?id=1268062 * https://bugzilla.suse.com/show_bug.cgi?id=1268064 * https://bugzilla.suse.com/show_bug.cgi?id=1268065 * https://bugzilla.suse.com/show_bug.cgi?id=1268115 * https://bugzilla.suse.com/show_bug.cgi?id=1268298 * https://bugzilla.suse.com/show_bug.cgi?id=1268491 * https://bugzilla.suse.com/show_bug.cgi?id=1269120 * https://bugzilla.suse.com/show_bug.cgi?id=1270695 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 20:43:07 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 20:43:07 -0000 Subject: SUSE-SU-2026:3136-1: important: Security update for 389-ds Message-ID: <178458018778.1659.5220175698671562697@ddd703581f31> # Security update for 389-ds Announcement ID: SUSE-SU-2026:3136-1 Release Date: 2026-07-20T15:10:11Z Rating: important References: * bsc#1267975 * bsc#1268041 * bsc#1268046 * bsc#1268047 * bsc#1268057 * bsc#1268058 * bsc#1268060 * bsc#1268062 * bsc#1268064 * bsc#1268065 * bsc#1268115 * bsc#1268298 * bsc#1268491 * bsc#1269120 * bsc#1270695 Cross-References: * CVE-2026-11610 * CVE-2026-11611 * CVE-2026-11774 * CVE-2026-11785 * CVE-2026-11786 * CVE-2026-11787 * CVE-2026-11788 * CVE-2026-11789 * CVE-2026-11790 * CVE-2026-11791 * CVE-2026-11792 * CVE-2026-11793 * CVE-2026-11884 * CVE-2026-12528 CVSS scores: * CVE-2026-11610 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-11610 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-11611 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11611 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11611 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11774 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-11774 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11785 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11785 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11785 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11786 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11786 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-11786 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11786 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11787 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-11787 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11787 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11787 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11788 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11788 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11788 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11788 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11789 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11790 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11790 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11790 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11791 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-11791 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-11792 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-11792 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-11792 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-11793 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11793 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11793 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-11884 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-12528 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 14 vulnerabilities and has one security fix can now be installed. ## Description: This update for 389-ds fixes the following issues: Update to version 2.2.10~git255.752643c78. Security issues fixed: * CVE-2026-11610: missing bounds check in `sasl_io_recv()` can lead to a heap buffer overflow when processing a specially crafted oversized LDAP UNBIND packet (bsc#1270695). * CVE-2026-11611: Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses(bsc#1267975). * CVE-2026-11774: integer overflow in `sasl_io_start_packet()` can lead to heap buffer overflow when processing a crafted SASL packet length prefix (bsc#1268298). * CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure in LDA responses (bsc#1268065). * CVE-2026-11786: out-of-bounds read in the LDIF parser when processing attribute types with trailing semicolons during database import (bsc#1268064). * CVE-2026-11787: missing bounds check in the `ldap_utf8prev()` functioncan can lead to a heap buffer overread in string filter parsing(bsc#1268062). * CVE-2026-11788: missing allocation check in the dereference control plugin before using a BER structure can lead to LDAP server crash when the system is under memory pressure (bsc#1268057). * CVE-2026-11789: integer underflow in the SMD5 password storage plugin can lead to a buffer overread when computing salt length from a crafted password hash shorter than 16 bytes (bsc#1268058). * CVE-2026-11790: improper bounds enforcement in the BKDF2-SHA256 password storage plugin can lead to excessive resource consumption during authentication and cause a DoS (bsc#1268060). * CVE-2026-11791: use-after-free in the schema reload mechanism can lead to a `ns-slapd` crash when concurrent LDAP query traffic is active (bsc#1268047). * CVE-2026-11792: missing checks in `create_masked_entry_string` can lead to a heap and log output corruption whe a short cleartext password is logged (bsc#1268046). * CVE-2026-11793: missing bounds check in `checkPrefix()` can lead to a stack buffer overflow when processing an algorithm ID during parsing of reversible-encrypted attribute values (bsc#1268041). * CVE-2026-11884: improper string management can lead to heap buffer overflow when serializing objectclass definitions (bsc#1268115). * CVE-2026-12528: missing length checks in the `__aclp__normalize_acltxt()` function can lead to heap buffer overflow when processing a malformed ACI string (bsc#1268491). Other updates and bugfixes: * Version 2.2.10~git255.752643c78. * Issue 7406 - Fix `ldap-agent` SNMP stats file loading (#7630) * Issue 7621 - Stack Buffer Overflow in Password `checkPrefix` * Issue 7623 - Heap Buffer Overflow in `389-ds-base` Audit Log Password Masking * Issue 6625 - Backport `get_pid` to fix `check_asan_report` (#7625) * Issue 7602 - CI - `lib389` user compare fails due to parentid mismatch (#7603) * Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592) * Issue 7593 - Fix testimony docstring for SASL overflow test (#7606) * Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572) * Issue 7593 - Reject invalid SASL packet length values in `sasl_io_start_packet` (#7594) * Issue 3555 - UI - Fix audit issue with `npm` \- `ws`, `js-yaml`, `js-yaml` , `postcss`, `uuid` * Issue 7541 - Add invalid ACL text header regression test (#7591) * Issue 7541 - heap-buffer-overflows in `__aclp__normalize_acltxt()` (#7542) * Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload * Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559) * Issue 7500 - Prevent unsigned integer underflow during stalled import * Issue 7560 - `lib389` \- Add helper function for checking ASAN files * Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540) * Issue 7549 - Substring index should validate minimum `nsSubStrBegin`/`nsSubStrEnd` values (#7550) * Issue 7440 - Substring index produces empty results and can crash when non- default `nsSubStrBegin`/`nsSubStrEnd` lengths are configured (#7441) * Fix test389 imports on older branches * Issue 7437 - `LeakSanitizer`: memory leaks in CoS cache error paths (#7438) * Issue 6922 - `AddressSanitizer`: leaks found by acl test suite * Issue 3555 - UI - Fix audit issue with `npm` \- `brace-expansion` (#7556) * Issue 7554 - deref plugin null pointer dereference if `ber_init` fails * Issue 7514 - Crash when doing moddn on very large subtree * Issue 7516 - `dblayer_bulk_nextdata` should not return an error when maxrecords is hit ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3136=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3136=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3136=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * 389-ds-debuginfo-2.2.10~git255.752643c78-150600.8.32.1 * libsvrcore0-debuginfo-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-debugsource-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-2.2.10~git255.752643c78-150600.8.32.1 * libsvrcore0-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-devel-2.2.10~git255.752643c78-150600.8.32.1 * lib389-2.2.10~git255.752643c78-150600.8.32.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * 389-ds-debuginfo-2.2.10~git255.752643c78-150600.8.32.1 * libsvrcore0-debuginfo-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-snmp-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-debugsource-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-snmp-debuginfo-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-2.2.10~git255.752643c78-150600.8.32.1 * libsvrcore0-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-devel-2.2.10~git255.752643c78-150600.8.32.1 * lib389-2.2.10~git255.752643c78-150600.8.32.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * 389-ds-debuginfo-2.2.10~git255.752643c78-150600.8.32.1 * libsvrcore0-debuginfo-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-debugsource-2.2.10~git255.752643c78-150600.8.32.1 * lib389-2.2.10~git255.752643c78-150600.8.32.1 * libsvrcore0-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-devel-2.2.10~git255.752643c78-150600.8.32.1 * 389-ds-2.2.10~git255.752643c78-150600.8.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11610.html * https://www.suse.com/security/cve/CVE-2026-11611.html * https://www.suse.com/security/cve/CVE-2026-11774.html * https://www.suse.com/security/cve/CVE-2026-11785.html * https://www.suse.com/security/cve/CVE-2026-11786.html * https://www.suse.com/security/cve/CVE-2026-11787.html * https://www.suse.com/security/cve/CVE-2026-11788.html * https://www.suse.com/security/cve/CVE-2026-11789.html * https://www.suse.com/security/cve/CVE-2026-11790.html * https://www.suse.com/security/cve/CVE-2026-11791.html * https://www.suse.com/security/cve/CVE-2026-11792.html * https://www.suse.com/security/cve/CVE-2026-11793.html * https://www.suse.com/security/cve/CVE-2026-11884.html * https://www.suse.com/security/cve/CVE-2026-12528.html * https://bugzilla.suse.com/show_bug.cgi?id=1267975 * https://bugzilla.suse.com/show_bug.cgi?id=1268041 * https://bugzilla.suse.com/show_bug.cgi?id=1268046 * https://bugzilla.suse.com/show_bug.cgi?id=1268047 * https://bugzilla.suse.com/show_bug.cgi?id=1268057 * https://bugzilla.suse.com/show_bug.cgi?id=1268058 * https://bugzilla.suse.com/show_bug.cgi?id=1268060 * https://bugzilla.suse.com/show_bug.cgi?id=1268062 * https://bugzilla.suse.com/show_bug.cgi?id=1268064 * https://bugzilla.suse.com/show_bug.cgi?id=1268065 * https://bugzilla.suse.com/show_bug.cgi?id=1268115 * https://bugzilla.suse.com/show_bug.cgi?id=1268298 * https://bugzilla.suse.com/show_bug.cgi?id=1268491 * https://bugzilla.suse.com/show_bug.cgi?id=1269120 * https://bugzilla.suse.com/show_bug.cgi?id=1270695 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 20:43:14 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 20:43:14 -0000 Subject: SUSE-SU-2026:3135-1: important: Security update for mariadb-connector-c Message-ID: <178458019451.1659.3799449802086581347@ddd703581f31> # Security update for mariadb-connector-c Announcement ID: SUSE-SU-2026:3135-1 Release Date: 2026-07-20T14:24:39Z Rating: important References: * bsc#1266438 Cross-References: * CVE-2026-44172 CVSS scores: * CVE-2026-44172 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for mariadb-connector-c fixes the following issue: * CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). Changes for mariadb-connector-c: * Update to 3.1.28. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3135=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3135=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libmariadb_plugins-3.1.28-2.38.1 * libmariadb_plugins-debuginfo-3.1.28-2.38.1 * libmariadb3-3.1.28-2.38.1 * libmariadb3-debuginfo-3.1.28-2.38.1 * mariadb-connector-c-debugsource-3.1.28-2.38.1 * libmariadb-devel-3.1.28-2.38.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libmariadb_plugins-3.1.28-2.38.1 * libmariadb_plugins-debuginfo-3.1.28-2.38.1 * libmariadb3-3.1.28-2.38.1 * libmariadb3-debuginfo-3.1.28-2.38.1 * mariadb-connector-c-debugsource-3.1.28-2.38.1 * libmariadb-devel-3.1.28-2.38.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44172.html * https://bugzilla.suse.com/show_bug.cgi?id=1266438 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 20:43:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 20:43:21 -0000 Subject: SUSE-SU-2026:3134-1: important: Security update for mariadb-connector-c Message-ID: <178458020103.1659.8260759774654821558@ddd703581f31> # Security update for mariadb-connector-c Announcement ID: SUSE-SU-2026:3134-1 Release Date: 2026-07-20T14:24:25Z Rating: important References: * bsc#1266438 Cross-References: * CVE-2026-44172 CVSS scores: * CVE-2026-44172 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for mariadb-connector-c fixes the following issue: * CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). Changes for mariadb-connector-c: * Update to 3.1.28. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3134=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3134=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3134=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3134=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3134=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3134=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3134=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3134=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * mariadb-connector-c-debugsource-3.1.28-150000.3.39.1 * libmariadb_plugins-3.1.28-150000.3.39.1 * libmariadbprivate-3.1.28-150000.3.39.1 * libmariadb-devel-debuginfo-3.1.28-150000.3.39.1 * libmariadb3-3.1.28-150000.3.39.1 * libmariadb3-debuginfo-3.1.28-150000.3.39.1 * libmariadbprivate-debuginfo-3.1.28-150000.3.39.1 * libmariadb-devel-3.1.28-150000.3.39.1 * libmariadb_plugins-debuginfo-3.1.28-150000.3.39.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * mariadb-connector-c-debugsource-3.1.28-150000.3.39.1 * libmariadb3-3.1.28-150000.3.39.1 * libmariadbprivate-3.1.28-150000.3.39.1 * libmariadb_plugins-3.1.28-150000.3.39.1 * libmariadb-devel-debuginfo-3.1.28-150000.3.39.1 * libmariadb3-debuginfo-3.1.28-150000.3.39.1 * libmariadbprivate-debuginfo-3.1.28-150000.3.39.1 * libmariadb-devel-3.1.28-150000.3.39.1 * libmariadb_plugins-debuginfo-3.1.28-150000.3.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * mariadb-connector-c-debugsource-3.1.28-150000.3.39.1 * libmariadb3-3.1.28-150000.3.39.1 * libmariadbprivate-3.1.28-150000.3.39.1 * libmariadb-devel-debuginfo-3.1.28-150000.3.39.1 * libmariadb_plugins-3.1.28-150000.3.39.1 * libmariadb3-debuginfo-3.1.28-150000.3.39.1 * libmariadbprivate-debuginfo-3.1.28-150000.3.39.1 * libmariadb-devel-3.1.28-150000.3.39.1 * libmariadb_plugins-debuginfo-3.1.28-150000.3.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * mariadb-connector-c-debugsource-3.1.28-150000.3.39.1 * libmariadb_plugins-3.1.28-150000.3.39.1 * libmariadb3-3.1.28-150000.3.39.1 * libmariadb-devel-debuginfo-3.1.28-150000.3.39.1 * libmariadbprivate-3.1.28-150000.3.39.1 * libmariadb3-debuginfo-3.1.28-150000.3.39.1 * libmariadbprivate-debuginfo-3.1.28-150000.3.39.1 * libmariadb-devel-3.1.28-150000.3.39.1 * libmariadb_plugins-debuginfo-3.1.28-150000.3.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * mariadb-connector-c-debugsource-3.1.28-150000.3.39.1 * libmariadb3-3.1.28-150000.3.39.1 * libmariadbprivate-3.1.28-150000.3.39.1 * libmariadb_plugins-3.1.28-150000.3.39.1 * libmariadb-devel-debuginfo-3.1.28-150000.3.39.1 * libmariadb3-debuginfo-3.1.28-150000.3.39.1 * libmariadbprivate-debuginfo-3.1.28-150000.3.39.1 * libmariadb-devel-3.1.28-150000.3.39.1 * libmariadb_plugins-debuginfo-3.1.28-150000.3.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * mariadb-connector-c-debugsource-3.1.28-150000.3.39.1 * libmariadb_plugins-3.1.28-150000.3.39.1 * libmariadbprivate-3.1.28-150000.3.39.1 * libmariadb-devel-debuginfo-3.1.28-150000.3.39.1 * libmariadb3-3.1.28-150000.3.39.1 * libmariadb3-debuginfo-3.1.28-150000.3.39.1 * libmariadbprivate-debuginfo-3.1.28-150000.3.39.1 * libmariadb-devel-3.1.28-150000.3.39.1 * libmariadb_plugins-debuginfo-3.1.28-150000.3.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * mariadb-connector-c-debugsource-3.1.28-150000.3.39.1 * libmariadb_plugins-3.1.28-150000.3.39.1 * libmariadbprivate-3.1.28-150000.3.39.1 * libmariadb3-3.1.28-150000.3.39.1 * libmariadb-devel-debuginfo-3.1.28-150000.3.39.1 * libmariadb3-debuginfo-3.1.28-150000.3.39.1 * libmariadbprivate-debuginfo-3.1.28-150000.3.39.1 * libmariadb-devel-3.1.28-150000.3.39.1 * libmariadb_plugins-debuginfo-3.1.28-150000.3.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * mariadb-connector-c-debugsource-3.1.28-150000.3.39.1 * libmariadb_plugins-3.1.28-150000.3.39.1 * libmariadbprivate-3.1.28-150000.3.39.1 * libmariadb3-3.1.28-150000.3.39.1 * libmariadb-devel-debuginfo-3.1.28-150000.3.39.1 * libmariadb3-debuginfo-3.1.28-150000.3.39.1 * libmariadbprivate-debuginfo-3.1.28-150000.3.39.1 * libmariadb-devel-3.1.28-150000.3.39.1 * libmariadb_plugins-debuginfo-3.1.28-150000.3.39.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44172.html * https://bugzilla.suse.com/show_bug.cgi?id=1266438 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 20:43:35 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 20:43:35 -0000 Subject: SUSE-SU-2026:3133-1: important: Security update for gstreamer-plugins-bad Message-ID: <178458021500.1659.2597111624646561640@ddd703581f31> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:3133-1 Release Date: 2026-07-20T13:58:55Z Rating: important References: * bsc#1268168 * bsc#1268406 * bsc#1268408 * bsc#1268410 * bsc#1268971 * bsc#1271051 * bsc#1271168 Cross-References: * CVE-2026-12892 * CVE-2026-14935 * CVE-2026-52720 * CVE-2026-52721 * CVE-2026-52722 * CVE-2026-53702 * CVE-2026-59692 CVSS scores: * CVE-2026-12892 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12892 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12892 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-14935 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-14935 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-14935 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-52720 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52721 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-52721 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53702 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53702 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59692 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves seven vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issues * CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser (bsc#1268971). * CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check (bsc#1271051). * CVE-2026-52720: invalid check of total area instead of individual dimensions could trigger a heap out-of-bounds write (bsc#1268406). * CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could cause an out-of-bounds read (bsc#1268408). * CVE-2026-52722: crafted VMnc stream with large cursor dimensions can overflow signed integer (bsc#1268410). * CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could result in a stack buffer overflow (bsc#1268168). * CVE-2026-59692: unvalidated peer certificate Subject DN printed during a DTLS handshake could cause a stack buffer overflow (bsc#1271168). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3133=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3133=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3133=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3133=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3133=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gstreamer-plugins-bad-1.20.1-150400.3.29.1 * libgstva-1_0-0-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-1.20.1-150400.3.29.1 * libgsttranscoder-1_0-0-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgsttranscoder-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-1.20.1-150400.3.29.1 * libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1 * typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1 * typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1 * gstreamer-transcoder-debuginfo-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-1.20.1-150400.3.29.1 * gstreamer-transcoder-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-1.20.1-150400.3.29.1 * gstreamer-transcoder-devel-1.20.1-150400.3.29.1 * libgstplay-1_0-0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-1.20.1-150400.3.29.1 * libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstVulkan-1_0-1.20.1-150400.3.29.1 * typelib-1_0-GstVulkanWayland-1_0-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstVulkanXCB-1_0-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1 * typelib-1_0-GstTranscoder-1_0-1.20.1-150400.3.29.1 * typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgstcodecparsers-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstva-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstplay-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-64bit-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-64bit-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-64bit-debuginfo-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-64bit-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-64bit-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstplay-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstva-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-64bit-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1 * openSUSE Leap 15.4 (x86_64) * libgstisoff-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstplay-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-32bit-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-32bit-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-32bit-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-32bit-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-32bit-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstva-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1 * libgstplay-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.20.1-150400.3.29.1 * libgstva-1_0-0-32bit-1.20.1-150400.3.29.1 * openSUSE Leap 15.4 (noarch) * gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * gstreamer-plugins-bad-1.20.1-150400.3.29.1 * libgstva-1_0-0-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-1.20.1-150400.3.29.1 * libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1 * typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1 * typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-1.20.1-150400.3.29.1 * libgstplay-1_0-0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-1.20.1-150400.3.29.1 * libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1 * typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-bad-1.20.1-150400.3.29.1 * libgstva-1_0-0-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-1.20.1-150400.3.29.1 * libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1 * typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1 * typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstplay-1_0-0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-1.20.1-150400.3.29.1 * libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1 * typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1 * typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1 * typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * gstreamer-plugins-bad-1.20.1-150400.3.29.1 * libgstva-1_0-0-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1 * typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1 * typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-1.20.1-150400.3.29.1 * libgstplay-1_0-0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-1.20.1-150400.3.29.1 * libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1 * typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * gstreamer-plugins-bad-1.20.1-150400.3.29.1 * libgstva-1_0-0-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-1.20.1-150400.3.29.1 * libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1 * typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1 * typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstvulkan-1_0-0-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-1.20.1-150400.3.29.1 * libgstmpegts-1_0-0-1.20.1-150400.3.29.1 * libgstplay-1_0-0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-1.20.1-150400.3.29.1 * libgstwayland-1_0-0-1.20.1-150400.3.29.1 * libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1 * libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1 * libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstsctp-1_0-0-1.20.1-150400.3.29.1 * libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-1.20.1-150400.3.29.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1 * libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1 * libgsturidownloader-1_0-0-1.20.1-150400.3.29.1 * libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1 * gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1 * libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1 * typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1 * libgstcodecs-1_0-0-1.20.1-150400.3.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12892.html * https://www.suse.com/security/cve/CVE-2026-14935.html * https://www.suse.com/security/cve/CVE-2026-52720.html * https://www.suse.com/security/cve/CVE-2026-52721.html * https://www.suse.com/security/cve/CVE-2026-52722.html * https://www.suse.com/security/cve/CVE-2026-53702.html * https://www.suse.com/security/cve/CVE-2026-59692.html * https://bugzilla.suse.com/show_bug.cgi?id=1268168 * https://bugzilla.suse.com/show_bug.cgi?id=1268406 * https://bugzilla.suse.com/show_bug.cgi?id=1268408 * https://bugzilla.suse.com/show_bug.cgi?id=1268410 * https://bugzilla.suse.com/show_bug.cgi?id=1268971 * https://bugzilla.suse.com/show_bug.cgi?id=1271051 * https://bugzilla.suse.com/show_bug.cgi?id=1271168 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 20:43:46 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 20:43:46 -0000 Subject: SUSE-SU-2026:3132-1: important: Security update for python311 Message-ID: <178458022620.1659.7012409032214234374@ddd703581f31> # Security update for python311 Announcement ID: SUSE-SU-2026:3132-1 Release Date: 2026-07-20T13:56:06Z Rating: important References: * bsc#1261969 * bsc#1262098 * bsc#1262319 * bsc#1262654 Cross-References: * CVE-2026-1502 * CVE-2026-4786 * CVE-2026-6019 * CVE-2026-6100 CVSS scores: * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves four vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues * CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969). * CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the `webbrowser.open()` API (bsc#1262319). * CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654). * CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the decompression instance is re- used (bsc#1262098). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3132=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3132=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3132=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3132=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3132=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3132=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3132=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3132=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3132=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3132=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-tools-3.11.15-150400.9.91.1 * python311-debuginfo-3.11.15-150400.9.91.1 * python311-tk-3.11.15-150400.9.91.1 * python311-doc-3.11.15-150400.9.91.1 * python311-idle-3.11.15-150400.9.91.1 * python311-doc-devhelp-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1 * python311-debugsource-3.11.15-150400.9.91.1 * python311-dbm-debuginfo-3.11.15-150400.9.91.1 * python311-core-debugsource-3.11.15-150400.9.91.1 * python311-devel-3.11.15-150400.9.91.1 * python311-curses-3.11.15-150400.9.91.1 * python311-tk-debuginfo-3.11.15-150400.9.91.1 * python311-curses-debuginfo-3.11.15-150400.9.91.1 * python311-base-debuginfo-3.11.15-150400.9.91.1 * python311-dbm-3.11.15-150400.9.91.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-testsuite-3.11.15-150400.9.91.1 * python311-tools-3.11.15-150400.9.91.1 * python311-debuginfo-3.11.15-150400.9.91.1 * python311-tk-3.11.15-150400.9.91.1 * python311-testsuite-debuginfo-3.11.15-150400.9.91.1 * python311-doc-3.11.15-150400.9.91.1 * python311-idle-3.11.15-150400.9.91.1 * python311-doc-devhelp-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1 * python311-debugsource-3.11.15-150400.9.91.1 * python311-dbm-debuginfo-3.11.15-150400.9.91.1 * python311-core-debugsource-3.11.15-150400.9.91.1 * python311-devel-3.11.15-150400.9.91.1 * python311-curses-3.11.15-150400.9.91.1 * python311-tk-debuginfo-3.11.15-150400.9.91.1 * python311-curses-debuginfo-3.11.15-150400.9.91.1 * python311-base-debuginfo-3.11.15-150400.9.91.1 * python311-dbm-3.11.15-150400.9.91.1 * openSUSE Leap 15.4 (aarch64_ilp32) * python311-base-64bit-debuginfo-3.11.15-150400.9.91.1 * python311-64bit-3.11.15-150400.9.91.1 * python311-64bit-debuginfo-3.11.15-150400.9.91.1 * python311-base-64bit-3.11.15-150400.9.91.1 * libpython3_11-1_0-64bit-3.11.15-150400.9.91.1 * libpython3_11-1_0-64bit-debuginfo-3.11.15-150400.9.91.1 * openSUSE Leap 15.4 (x86_64) * libpython3_11-1_0-32bit-3.11.15-150400.9.91.1 * libpython3_11-1_0-32bit-debuginfo-3.11.15-150400.9.91.1 * python311-base-32bit-3.11.15-150400.9.91.1 * python311-32bit-3.11.15-150400.9.91.1 * python311-base-32bit-debuginfo-3.11.15-150400.9.91.1 * python311-32bit-debuginfo-3.11.15-150400.9.91.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-tools-3.11.15-150400.9.91.1 * python311-debuginfo-3.11.15-150400.9.91.1 * python311-tk-3.11.15-150400.9.91.1 * python311-doc-3.11.15-150400.9.91.1 * python311-idle-3.11.15-150400.9.91.1 * python311-doc-devhelp-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * python311-debugsource-3.11.15-150400.9.91.1 * python311-dbm-debuginfo-3.11.15-150400.9.91.1 * python311-core-debugsource-3.11.15-150400.9.91.1 * python311-devel-3.11.15-150400.9.91.1 * python311-curses-3.11.15-150400.9.91.1 * python311-tk-debuginfo-3.11.15-150400.9.91.1 * python311-curses-debuginfo-3.11.15-150400.9.91.1 * python311-base-debuginfo-3.11.15-150400.9.91.1 * python311-dbm-3.11.15-150400.9.91.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-tools-3.11.15-150400.9.91.1 * python311-debuginfo-3.11.15-150400.9.91.1 * python311-tk-3.11.15-150400.9.91.1 * python311-doc-3.11.15-150400.9.91.1 * python311-idle-3.11.15-150400.9.91.1 * python311-doc-devhelp-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1 * python311-debugsource-3.11.15-150400.9.91.1 * python311-dbm-debuginfo-3.11.15-150400.9.91.1 * python311-core-debugsource-3.11.15-150400.9.91.1 * python311-devel-3.11.15-150400.9.91.1 * python311-curses-3.11.15-150400.9.91.1 * python311-tk-debuginfo-3.11.15-150400.9.91.1 * python311-curses-debuginfo-3.11.15-150400.9.91.1 * python311-base-debuginfo-3.11.15-150400.9.91.1 * python311-dbm-3.11.15-150400.9.91.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-tools-3.11.15-150400.9.91.1 * python311-debuginfo-3.11.15-150400.9.91.1 * python311-tk-3.11.15-150400.9.91.1 * python311-doc-3.11.15-150400.9.91.1 * python311-idle-3.11.15-150400.9.91.1 * python311-doc-devhelp-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1 * python311-debugsource-3.11.15-150400.9.91.1 * python311-dbm-debuginfo-3.11.15-150400.9.91.1 * python311-core-debugsource-3.11.15-150400.9.91.1 * python311-devel-3.11.15-150400.9.91.1 * python311-curses-3.11.15-150400.9.91.1 * python311-tk-debuginfo-3.11.15-150400.9.91.1 * python311-curses-debuginfo-3.11.15-150400.9.91.1 * python311-base-debuginfo-3.11.15-150400.9.91.1 * python311-dbm-3.11.15-150400.9.91.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-tools-3.11.15-150400.9.91.1 * python311-debuginfo-3.11.15-150400.9.91.1 * python311-tk-3.11.15-150400.9.91.1 * python311-doc-3.11.15-150400.9.91.1 * python311-idle-3.11.15-150400.9.91.1 * python311-doc-devhelp-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1 * python311-debugsource-3.11.15-150400.9.91.1 * python311-dbm-debuginfo-3.11.15-150400.9.91.1 * python311-core-debugsource-3.11.15-150400.9.91.1 * python311-devel-3.11.15-150400.9.91.1 * python311-curses-3.11.15-150400.9.91.1 * python311-tk-debuginfo-3.11.15-150400.9.91.1 * python311-curses-debuginfo-3.11.15-150400.9.91.1 * python311-base-debuginfo-3.11.15-150400.9.91.1 * python311-dbm-3.11.15-150400.9.91.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-tools-3.11.15-150400.9.91.1 * python311-debuginfo-3.11.15-150400.9.91.1 * python311-tk-3.11.15-150400.9.91.1 * python311-doc-3.11.15-150400.9.91.1 * python311-idle-3.11.15-150400.9.91.1 * python311-doc-devhelp-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1 * python311-debugsource-3.11.15-150400.9.91.1 * python311-dbm-debuginfo-3.11.15-150400.9.91.1 * python311-core-debugsource-3.11.15-150400.9.91.1 * python311-devel-3.11.15-150400.9.91.1 * python311-curses-3.11.15-150400.9.91.1 * python311-tk-debuginfo-3.11.15-150400.9.91.1 * python311-curses-debuginfo-3.11.15-150400.9.91.1 * python311-base-debuginfo-3.11.15-150400.9.91.1 * python311-dbm-3.11.15-150400.9.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-tools-3.11.15-150400.9.91.1 * python311-debuginfo-3.11.15-150400.9.91.1 * python311-tk-3.11.15-150400.9.91.1 * python311-doc-3.11.15-150400.9.91.1 * python311-idle-3.11.15-150400.9.91.1 * python311-doc-devhelp-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1 * python311-debugsource-3.11.15-150400.9.91.1 * python311-dbm-debuginfo-3.11.15-150400.9.91.1 * python311-core-debugsource-3.11.15-150400.9.91.1 * python311-devel-3.11.15-150400.9.91.1 * python311-curses-3.11.15-150400.9.91.1 * python311-tk-debuginfo-3.11.15-150400.9.91.1 * python311-curses-debuginfo-3.11.15-150400.9.91.1 * python311-base-debuginfo-3.11.15-150400.9.91.1 * python311-dbm-3.11.15-150400.9.91.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libpython3_11-1_0-3.11.15-150400.9.91.1 * python311-tools-3.11.15-150400.9.91.1 * python311-debuginfo-3.11.15-150400.9.91.1 * python311-tk-3.11.15-150400.9.91.1 * python311-doc-3.11.15-150400.9.91.1 * python311-idle-3.11.15-150400.9.91.1 * python311-doc-devhelp-3.11.15-150400.9.91.1 * python311-base-3.11.15-150400.9.91.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1 * python311-3.11.15-150400.9.91.1 * python311-debugsource-3.11.15-150400.9.91.1 * python311-dbm-debuginfo-3.11.15-150400.9.91.1 * python311-core-debugsource-3.11.15-150400.9.91.1 * python311-devel-3.11.15-150400.9.91.1 * python311-curses-3.11.15-150400.9.91.1 * python311-tk-debuginfo-3.11.15-150400.9.91.1 * python311-curses-debuginfo-3.11.15-150400.9.91.1 * python311-base-debuginfo-3.11.15-150400.9.91.1 * python311-dbm-3.11.15-150400.9.91.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 20 20:43:54 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 20 Jul 2026 20:43:54 -0000 Subject: SUSE-SU-2026:3131-1: important: Security update for sssd Message-ID: <178458023498.1659.11372899980166224893@ddd703581f31> # Security update for sssd Announcement ID: SUSE-SU-2026:3131-1 Release Date: 2026-07-20T13:26:30Z Rating: important References: * bsc#1246196 * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3131=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3131=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * sssd-ipa-debuginfo-1.16.1-7.73.1 * sssd-krb5-1.16.1-7.73.1 * libsss_idmap0-1.16.1-7.73.1 * sssd-dbus-debuginfo-1.16.1-7.73.1 * libsss_certmap0-1.16.1-7.73.1 * sssd-tools-1.16.1-7.73.1 * sssd-ipa-1.16.1-7.73.1 * libsss_nss_idmap0-1.16.1-7.73.1 * libsss_simpleifp0-debuginfo-1.16.1-7.73.1 * sssd-krb5-common-debuginfo-1.16.1-7.73.1 * libipa_hbac0-1.16.1-7.73.1 * sssd-tools-debuginfo-1.16.1-7.73.1 * libipa_hbac-devel-1.16.1-7.73.1 * libsss_nss_idmap-devel-1.16.1-7.73.1 * sssd-dbus-1.16.1-7.73.1 * sssd-debugsource-1.16.1-7.73.1 * sssd-1.16.1-7.73.1 * sssd-proxy-1.16.1-7.73.1 * libsss_simpleifp0-1.16.1-7.73.1 * sssd-proxy-debuginfo-1.16.1-7.73.1 * libsss_idmap0-debuginfo-1.16.1-7.73.1 * libsss_certmap0-debuginfo-1.16.1-7.73.1 * python-sssd-config-debuginfo-1.16.1-7.73.1 * python-sssd-config-1.16.1-7.73.1 * sssd-ad-1.16.1-7.73.1 * sssd-ldap-1.16.1-7.73.1 * sssd-common-debuginfo-1.16.1-7.73.1 * sssd-ad-debuginfo-1.16.1-7.73.1 * sssd-krb5-common-1.16.1-7.73.1 * sssd-common-1.16.1-7.73.1 * sssd-krb5-debuginfo-1.16.1-7.73.1 * libipa_hbac0-debuginfo-1.16.1-7.73.1 * libsss_idmap-devel-1.16.1-7.73.1 * sssd-ldap-debuginfo-1.16.1-7.73.1 * libsss_nss_idmap0-debuginfo-1.16.1-7.73.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * sssd-common-debuginfo-32bit-1.16.1-7.73.1 * sssd-common-32bit-1.16.1-7.73.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * sssd-ipa-debuginfo-1.16.1-7.73.1 * sssd-krb5-1.16.1-7.73.1 * libsss_idmap0-1.16.1-7.73.1 * sssd-dbus-debuginfo-1.16.1-7.73.1 * libsss_certmap0-1.16.1-7.73.1 * sssd-tools-1.16.1-7.73.1 * sssd-ipa-1.16.1-7.73.1 * libsss_nss_idmap0-1.16.1-7.73.1 * sssd-tools-debuginfo-1.16.1-7.73.1 * libipa_hbac0-1.16.1-7.73.1 * libsss_simpleifp0-debuginfo-1.16.1-7.73.1 * sssd-krb5-common-debuginfo-1.16.1-7.73.1 * libipa_hbac-devel-1.16.1-7.73.1 * libsss_nss_idmap-devel-1.16.1-7.73.1 * sssd-dbus-1.16.1-7.73.1 * sssd-debugsource-1.16.1-7.73.1 * sssd-1.16.1-7.73.1 * sssd-proxy-1.16.1-7.73.1 * libsss_simpleifp0-1.16.1-7.73.1 * sssd-proxy-debuginfo-1.16.1-7.73.1 * libsss_idmap0-debuginfo-1.16.1-7.73.1 * libsss_certmap0-debuginfo-1.16.1-7.73.1 * python-sssd-config-debuginfo-1.16.1-7.73.1 * python-sssd-config-1.16.1-7.73.1 * sssd-ad-1.16.1-7.73.1 * sssd-ldap-1.16.1-7.73.1 * sssd-common-debuginfo-1.16.1-7.73.1 * sssd-ad-debuginfo-1.16.1-7.73.1 * sssd-common-debuginfo-32bit-1.16.1-7.73.1 * sssd-common-32bit-1.16.1-7.73.1 * sssd-krb5-common-1.16.1-7.73.1 * sssd-common-1.16.1-7.73.1 * sssd-krb5-debuginfo-1.16.1-7.73.1 * libipa_hbac0-debuginfo-1.16.1-7.73.1 * libsss_idmap-devel-1.16.1-7.73.1 * sssd-ldap-debuginfo-1.16.1-7.73.1 * libsss_nss_idmap0-debuginfo-1.16.1-7.73.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1246196 * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 08:30:25 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 08:30:25 -0000 Subject: SUSE-SU-2026:3140-1: important: Security update for libreoffice Message-ID: <178462262597.1816.534252102732402801@f4f3e2688bac> # Security update for libreoffice Announcement ID: SUSE-SU-2026:3140-1 Release Date: 2026-07-20T18:01:17Z Rating: important References: * bsc#1264357 * bsc#1267735 * bsc#1268494 * bsc#1268497 * bsc#1268504 * bsc#1268522 * bsc#1268527 * bsc#1268528 * bsc#1268529 * jsc#PED-16098 Cross-References: * CVE-2026-4430 * CVE-2026-50593 * CVE-2026-6039 * CVE-2026-6040 * CVE-2026-6045 * CVE-2026-6047 * CVE-2026-8356 * CVE-2026-8357 * CVE-2026-8358 CVSS scores: * CVE-2026-4430 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4430 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4430 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4430 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-50593 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-50593 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-50593 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-6039 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6039 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6040 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-6040 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-6040 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6040 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6045 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-6045 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-6045 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6047 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-6047 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6047 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8356 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-8356 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-8356 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8357 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-8357 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-8357 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8357 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8358 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-8358 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-8358 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves nine vulnerabilities and contains one feature can now be installed. ## Description: This update for libreoffice fixes the following issues: Update to LibreOffice 26.2.5.1. Security issues fixed: * CVE-2026-4430: out-of-bounds write via crafted OOXML documents with mismatched encryption salt parameters (bsc#1264357). * CVE-2026-6039: denial of service via specially crafted DXF polyline import (bsc#1268494). * CVE-2026-6040: heap use-after-free when importing the blank-width characters of an ODF number format (bsc#1268527). * CVE-2026-6045: heap buffer overflow via crafted EMF+ graphics import (bsc#1268497). * CVE-2026-6047: denial of service via heap buffer overflow in OOXML document processing (bsc#1268504). * CVE-2026-8356: denial of service via a specially crafted PPT file (bsc#1268522). * CVE-2026-8357: heap buffer overflow in Calc formula compilation (bsc#1268528). * CVE-2026-8358: heap buffer overflow in spreadsheet tracked-changes import (bsc#1268529). * CVE-2026-50593: graphite2: out-of-bounds write via Graphite actions (bsc#1267735). Other updates and bugfixes: * Update to LibreOffice 26.2.5.1. * Update bundled dependencies: * `fontconfig` 2.17.1 -> 2.18.0 * `graphite2-minimal` 1.3.14 -> 1.3.15 * `libcmis` 0.6.2 -> 0.6.3 * `libgpg-error` 1.59 -> 1.61 * `lxml` 6.1.0 -> 6.1.1 * `md4c` 0.5.2 -> 0.5.3 * `poppler` 26.04.0 -> 26.06.0 * `sqlite-amalgamation` 3530000 -> 3530100 * `xmlsec1` 1.3.9 -> 1.3.11 * Update to LibreOffice 26.2.3.2 (jsc#PED-16098). * Upgraded dependencies: * `boost`: 1_88_0 -> 1_89_0 * `freetype`: 2.14.1 -> 2.14.3 * `harfbuzz`: 12.3.0 -> 12.3.2 * `icu4c`: 77_1 -> 78.3 * `libgpg-error`: 1.56 -> 1.59 * `liborcus`: 0.20.1 -> 0.21.0 * `pdfium`: 7012 -> 7471 * `poppler`: 25.12.0 -> 26.04.0 * `skia`: m136 -> m142 * New bundled sources: * `afdko` 4.0.3 * `antlr4-cpp-runtime` 4.13.2 * `fast_float` 8.2.2 * `libffi` 3.5.2 * `lxml` 6.1.0 * `md4c` 0.5.2 * `meson` 1.8.3 * `Python` 3.12.13 * `sqlite` 3530000 * `xmlsec1` 1.3.9 * `xz` 5.8.3 * Add `patch`, required to build the bundled Python on all architectures. * Bundling a specific Python is now required as the one we ship (3.6) is too old to build `harfbuzz`. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3140=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3140=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3140=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * libreoffice-l10n-sa_IN-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ne-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-et-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sq-26.2.5.1-150500.20.37.1 * libreoffice-l10n-as-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lo-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ug-26.2.5.1-150500.20.37.1 * libreoffice-l10n-om-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kab-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sd-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kok-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-en_ZA-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-brx-26.2.5.1-150500.20.37.1 * libreoffice-l10n-be-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tt-26.2.5.1-150500.20.37.1 * libreoffice-branding-upstream-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ar-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hi-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-af-26.2.5.1-150500.20.37.1 * libreoffice-l10n-szl-26.2.5.1-150500.20.37.1 * libreoffice-icon-themes-26.2.5.1-150500.20.37.1 * libreoffice-l10n-oc-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sid-26.2.5.1-150500.20.37.1 * libreoffice-l10n-he-26.2.5.1-150500.20.37.1 * libreoffice-l10n-eu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-vec-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ga-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ks-26.2.5.1-150500.20.37.1 * libreoffice-l10n-km-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ka-26.2.5.1-150500.20.37.1 * libreoffice-l10n-dgo-26.2.5.1-150500.20.37.1 * libreoffice-l10n-el-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ve-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mr-26.2.5.1-150500.20.37.1 * libreoffice-gdb-pretty-printers-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fa-26.2.5.1-150500.20.37.1 * libreoffice-l10n-st-26.2.5.1-150500.20.37.1 * libreoffice-l10n-th-26.2.5.1-150500.20.37.1 * libreoffice-l10n-zh_CN-26.2.5.1-150500.20.37.1 * libreoffice-l10n-xh-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ro-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hsb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-am-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ml-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-zu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-cy-26.2.5.1-150500.20.37.1 * libreoffice-l10n-my-26.2.5.1-150500.20.37.1 * libreoffice-l10n-da-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gu-26.2.5.1-150500.20.37.1 * libreoffice-glade-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-dsb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ss-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lt-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mai-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fur-26.2.5.1-150500.20.37.1 * libreoffice-l10n-de-26.2.5.1-150500.20.37.1 * libreoffice-l10n-or-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ta-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bo-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ru-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bg-26.2.5.1-150500.20.37.1 * libreoffice-l10n-eo-26.2.5.1-150500.20.37.1 * libreoffice-l10n-dz-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mni-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ckb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-en_GB-26.2.5.1-150500.20.37.1 * libreoffice-l10n-vi-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bn_IN-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gug-26.2.5.1-150500.20.37.1 * libreoffice-l10n-en-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-es-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-is-26.2.5.1-150500.20.37.1 * libreoffice-l10n-it-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ca_valencia-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sw_TZ-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ts-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ja-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fy-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fi-26.2.5.1-150500.20.37.1 * libreoffice-l10n-si-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ast-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kmr_Latn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ca-26.2.5.1-150500.20.37.1 * libreoffice-l10n-te-26.2.5.1-150500.20.37.1 * libreoffice-l10n-uz-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nso-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gd-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lv-26.2.5.1-150500.20.37.1 * libreoffice-l10n-id-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sv-26.2.5.1-150500.20.37.1 * libreoffice-l10n-rw-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pt_BR-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ko-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tg-26.2.5.1-150500.20.37.1 * libreoffice-l10n-br-26.2.5.1-150500.20.37.1 * libreoffice-l10n-cs-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pt_PT-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pa-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sat-26.2.5.1-150500.20.37.1 * libreoffice-l10n-uk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-zh_TW-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bs-26.2.5.1-150500.20.37.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le) * libreoffice-base-26.2.5.1-150500.20.37.1 * libreoffice-writer-extensions-26.2.5.1-150500.20.37.1 * libreoffice-sdk-26.2.5.1-150500.20.37.1 * libreoffice-mailmerge-26.2.5.1-150500.20.37.1 * libreoffice-calc-26.2.5.1-150500.20.37.1 * libreoffice-math-26.2.5.1-150500.20.37.1 * libreoffice-writer-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-officebean-26.2.5.1-150500.20.37.1 * libreofficekit-devel-26.2.5.1-150500.20.37.1 * libreoffice-officebean-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-draw-26.2.5.1-150500.20.37.1 * libreoffice-gnome-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-sdk-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-pyuno-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-26.2.5.1-150500.20.37.1 * libreoffice-pyuno-26.2.5.1-150500.20.37.1 * libreoffice-impress-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-librelogo-26.2.5.1-150500.20.37.1 * libreoffice-gtk3-debuginfo-26.2.5.1-150500.20.37.1 * libreofficekit-26.2.5.1-150500.20.37.1 * libreoffice-filters-optional-26.2.5.1-150500.20.37.1 * libreoffice-math-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-calc-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-calc-extensions-26.2.5.1-150500.20.37.1 * libreoffice-impress-26.2.5.1-150500.20.37.1 * libreoffice-qt5-26.2.5.1-150500.20.37.1 * libreoffice-sdk-doc-26.2.5.1-150500.20.37.1 * libreoffice-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-debugsource-26.2.5.1-150500.20.37.1 * libreoffice-gnome-26.2.5.1-150500.20.37.1 * libreoffice-base-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-gtk3-26.2.5.1-150500.20.37.1 * libreoffice-qt5-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-writer-26.2.5.1-150500.20.37.1 * libreoffice-base-drivers-postgresql-26.2.5.1-150500.20.37.1 * libreoffice-draw-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-base-drivers-postgresql-debuginfo-26.2.5.1-150500.20.37.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le x86_64) * libreoffice-base-drivers-firebird-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-base-drivers-firebird-26.2.5.1-150500.20.37.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (noarch) * libreoffice-l10n-ja-26.2.5.1-150500.20.37.1 * libreoffice-l10n-da-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fi-26.2.5.1-150500.20.37.1 * libreoffice-l10n-si-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-et-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ca-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ga-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-as-26.2.5.1-150500.20.37.1 * libreoffice-l10n-te-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ts-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ss-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nso-26.2.5.1-150500.20.37.1 * libreoffice-l10n-cy-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lt-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mai-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fur-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-or-26.2.5.1-150500.20.37.1 * libreoffice-l10n-de-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ta-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bg-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lv-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ru-26.2.5.1-150500.20.37.1 * libreoffice-l10n-el-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sv-26.2.5.1-150500.20.37.1 * libreoffice-l10n-eo-26.2.5.1-150500.20.37.1 * libreoffice-l10n-zh_TW-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ve-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pt_BR-26.2.5.1-150500.20.37.1 * libreoffice-l10n-dz-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ko-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ckb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fa-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-br-26.2.5.1-150500.20.37.1 * libreoffice-l10n-cs-26.2.5.1-150500.20.37.1 * libreoffice-l10n-st-26.2.5.1-150500.20.37.1 * libreoffice-l10n-th-26.2.5.1-150500.20.37.1 * libreoffice-l10n-zh_CN-26.2.5.1-150500.20.37.1 * libreoffice-l10n-xh-26.2.5.1-150500.20.37.1 * libreoffice-l10n-en-26.2.5.1-150500.20.37.1 * libreoffice-branding-upstream-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ar-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hi-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ro-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-af-26.2.5.1-150500.20.37.1 * libreoffice-icon-themes-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pt_PT-26.2.5.1-150500.20.37.1 * libreoffice-l10n-es-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-it-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pa-26.2.5.1-150500.20.37.1 * libreoffice-l10n-he-26.2.5.1-150500.20.37.1 * libreoffice-l10n-eu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ml-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-zu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-uk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hy-26.2.5.1-150500.20.37.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * libreoffice-base-26.2.5.1-150500.20.37.1 * libreoffice-writer-extensions-26.2.5.1-150500.20.37.1 * libreoffice-mailmerge-26.2.5.1-150500.20.37.1 * libreoffice-calc-26.2.5.1-150500.20.37.1 * libreoffice-math-26.2.5.1-150500.20.37.1 * libreoffice-writer-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-officebean-26.2.5.1-150500.20.37.1 * libreoffice-officebean-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-draw-26.2.5.1-150500.20.37.1 * libreoffice-pyuno-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-gnome-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-26.2.5.1-150500.20.37.1 * libreoffice-pyuno-26.2.5.1-150500.20.37.1 * libreoffice-impress-debuginfo-26.2.5.1-150500.20.37.1 * libreofficekit-26.2.5.1-150500.20.37.1 * libreoffice-gtk3-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-filters-optional-26.2.5.1-150500.20.37.1 * libreoffice-math-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-calc-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-calc-extensions-26.2.5.1-150500.20.37.1 * libreoffice-impress-26.2.5.1-150500.20.37.1 * libreoffice-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-debugsource-26.2.5.1-150500.20.37.1 * libreoffice-gnome-26.2.5.1-150500.20.37.1 * libreoffice-base-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-gtk3-26.2.5.1-150500.20.37.1 * libreoffice-writer-26.2.5.1-150500.20.37.1 * libreoffice-base-drivers-postgresql-26.2.5.1-150500.20.37.1 * libreoffice-base-drivers-postgresql-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-draw-debuginfo-26.2.5.1-150500.20.37.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libreoffice-base-26.2.5.1-150500.20.37.1 * libreoffice-mailmerge-26.2.5.1-150500.20.37.1 * libreoffice-sdk-26.2.5.1-150500.20.37.1 * libreoffice-writer-extensions-26.2.5.1-150500.20.37.1 * libreoffice-calc-26.2.5.1-150500.20.37.1 * libreoffice-math-26.2.5.1-150500.20.37.1 * libreoffice-writer-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-officebean-26.2.5.1-150500.20.37.1 * libreofficekit-devel-26.2.5.1-150500.20.37.1 * libreoffice-officebean-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-draw-26.2.5.1-150500.20.37.1 * libreoffice-pyuno-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-sdk-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-gnome-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-26.2.5.1-150500.20.37.1 * libreoffice-impress-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-pyuno-26.2.5.1-150500.20.37.1 * libreoffice-librelogo-26.2.5.1-150500.20.37.1 * libreofficekit-26.2.5.1-150500.20.37.1 * libreoffice-gtk3-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-filters-optional-26.2.5.1-150500.20.37.1 * libreoffice-math-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-calc-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-calc-extensions-26.2.5.1-150500.20.37.1 * libreoffice-impress-26.2.5.1-150500.20.37.1 * libreoffice-qt5-26.2.5.1-150500.20.37.1 * libreoffice-sdk-doc-26.2.5.1-150500.20.37.1 * libreoffice-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-debugsource-26.2.5.1-150500.20.37.1 * libreoffice-base-drivers-firebird-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-base-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-gnome-26.2.5.1-150500.20.37.1 * libreoffice-gtk3-26.2.5.1-150500.20.37.1 * libreoffice-qt5-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-writer-26.2.5.1-150500.20.37.1 * libreoffice-base-drivers-postgresql-26.2.5.1-150500.20.37.1 * libreoffice-base-drivers-postgresql-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-draw-debuginfo-26.2.5.1-150500.20.37.1 * libreoffice-base-drivers-firebird-26.2.5.1-150500.20.37.1 * openSUSE Leap 15.5 (noarch) * libreoffice-l10n-sa_IN-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ne-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-et-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sq-26.2.5.1-150500.20.37.1 * libreoffice-l10n-as-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lo-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ug-26.2.5.1-150500.20.37.1 * libreoffice-l10n-om-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kab-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sd-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kok-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-en_ZA-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-brx-26.2.5.1-150500.20.37.1 * libreoffice-l10n-be-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tt-26.2.5.1-150500.20.37.1 * libreoffice-branding-upstream-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ar-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hi-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-af-26.2.5.1-150500.20.37.1 * libreoffice-icon-themes-26.2.5.1-150500.20.37.1 * libreoffice-l10n-szl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-oc-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sid-26.2.5.1-150500.20.37.1 * libreoffice-l10n-he-26.2.5.1-150500.20.37.1 * libreoffice-l10n-eu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-vec-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ga-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ks-26.2.5.1-150500.20.37.1 * libreoffice-l10n-km-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ka-26.2.5.1-150500.20.37.1 * libreoffice-l10n-dgo-26.2.5.1-150500.20.37.1 * libreoffice-l10n-el-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ve-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mr-26.2.5.1-150500.20.37.1 * libreoffice-gdb-pretty-printers-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fa-26.2.5.1-150500.20.37.1 * libreoffice-l10n-st-26.2.5.1-150500.20.37.1 * libreoffice-l10n-th-26.2.5.1-150500.20.37.1 * libreoffice-l10n-zh_CN-26.2.5.1-150500.20.37.1 * libreoffice-l10n-xh-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ro-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hsb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-am-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ml-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-zu-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hy-26.2.5.1-150500.20.37.1 * libreoffice-l10n-da-26.2.5.1-150500.20.37.1 * libreoffice-l10n-cy-26.2.5.1-150500.20.37.1 * libreoffice-l10n-my-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gu-26.2.5.1-150500.20.37.1 * libreoffice-glade-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gl-26.2.5.1-150500.20.37.1 * libreoffice-l10n-dsb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ss-26.2.5.1-150500.20.37.1 * libreoffice-l10n-or-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mai-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fur-26.2.5.1-150500.20.37.1 * libreoffice-l10n-de-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lt-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ta-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bo-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ru-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bg-26.2.5.1-150500.20.37.1 * libreoffice-l10n-eo-26.2.5.1-150500.20.37.1 * libreoffice-l10n-dz-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mni-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ckb-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-en_GB-26.2.5.1-150500.20.37.1 * libreoffice-l10n-vi-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bn_IN-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gug-26.2.5.1-150500.20.37.1 * libreoffice-l10n-en-26.2.5.1-150500.20.37.1 * libreoffice-l10n-mn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-es-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-is-26.2.5.1-150500.20.37.1 * libreoffice-l10n-it-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ca_valencia-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sw_TZ-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ts-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fy-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ja-26.2.5.1-150500.20.37.1 * libreoffice-l10n-fi-26.2.5.1-150500.20.37.1 * libreoffice-l10n-si-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ast-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kmr_Latn-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ca-26.2.5.1-150500.20.37.1 * libreoffice-l10n-te-26.2.5.1-150500.20.37.1 * libreoffice-l10n-uz-26.2.5.1-150500.20.37.1 * libreoffice-l10n-hr-26.2.5.1-150500.20.37.1 * libreoffice-l10n-nso-26.2.5.1-150500.20.37.1 * libreoffice-l10n-gd-26.2.5.1-150500.20.37.1 * libreoffice-kdeintegration-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-lv-26.2.5.1-150500.20.37.1 * libreoffice-l10n-id-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sv-26.2.5.1-150500.20.37.1 * libreoffice-l10n-rw-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ab-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pt_BR-26.2.5.1-150500.20.37.1 * libreoffice-l10n-ko-26.2.5.1-150500.20.37.1 * libreoffice-l10n-tg-26.2.5.1-150500.20.37.1 * libreoffice-l10n-br-26.2.5.1-150500.20.37.1 * libreoffice-l10n-cs-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sat_Olck-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pt_PT-26.2.5.1-150500.20.37.1 * libreoffice-l10n-kk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-pa-26.2.5.1-150500.20.37.1 * libreoffice-l10n-sat-26.2.5.1-150500.20.37.1 * libreoffice-l10n-uk-26.2.5.1-150500.20.37.1 * libreoffice-l10n-zh_TW-26.2.5.1-150500.20.37.1 * libreoffice-l10n-bs-26.2.5.1-150500.20.37.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4430.html * https://www.suse.com/security/cve/CVE-2026-50593.html * https://www.suse.com/security/cve/CVE-2026-6039.html * https://www.suse.com/security/cve/CVE-2026-6040.html * https://www.suse.com/security/cve/CVE-2026-6045.html * https://www.suse.com/security/cve/CVE-2026-6047.html * https://www.suse.com/security/cve/CVE-2026-8356.html * https://www.suse.com/security/cve/CVE-2026-8357.html * https://www.suse.com/security/cve/CVE-2026-8358.html * https://bugzilla.suse.com/show_bug.cgi?id=1264357 * https://bugzilla.suse.com/show_bug.cgi?id=1267735 * https://bugzilla.suse.com/show_bug.cgi?id=1268494 * https://bugzilla.suse.com/show_bug.cgi?id=1268497 * https://bugzilla.suse.com/show_bug.cgi?id=1268504 * https://bugzilla.suse.com/show_bug.cgi?id=1268522 * https://bugzilla.suse.com/show_bug.cgi?id=1268527 * https://bugzilla.suse.com/show_bug.cgi?id=1268528 * https://bugzilla.suse.com/show_bug.cgi?id=1268529 * https://jira.suse.com/browse/PED-16098 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 08:30:37 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 08:30:37 -0000 Subject: SUSE-SU-2026:3139-1: important: Security update for sssd Message-ID: <178462263784.1816.8034066010726890791@f4f3e2688bac> # Security update for sssd Announcement ID: SUSE-SU-2026:3139-1 Release Date: 2026-07-20T17:56:06Z Rating: important References: * bsc#1246196 * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3139=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3139=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3139=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3139=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3139=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3139=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3139=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3139=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3139=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * sssd-debugsource-2.5.2-150400.4.45.1 * libnfsidmap-sss-debuginfo-2.5.2-150400.4.45.1 * sssd-ad-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-2.5.2-150400.4.45.1 * sssd-kcm-debuginfo-2.5.2-150400.4.45.1 * python3-sss_nss_idmap-2.5.2-150400.4.45.1 * sssd-proxy-2.5.2-150400.4.45.1 * sssd-krb5-debuginfo-2.5.2-150400.4.45.1 * python3-ipa_hbac-debuginfo-2.5.2-150400.4.45.1 * sssd-ldap-debuginfo-2.5.2-150400.4.45.1 * sssd-krb5-2.5.2-150400.4.45.1 * libsss_idmap-devel-2.5.2-150400.4.45.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap0-2.5.2-150400.4.45.1 * sssd-kcm-2.5.2-150400.4.45.1 * libsss_nss_idmap-devel-2.5.2-150400.4.45.1 * python3-sss-murmur-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp0-2.5.2-150400.4.45.1 * sssd-krb5-common-2.5.2-150400.4.45.1 * python3-ipa_hbac-2.5.2-150400.4.45.1 * sssd-dbus-2.5.2-150400.4.45.1 * libsss_nss_idmap0-2.5.2-150400.4.45.1 * libipa_hbac-devel-2.5.2-150400.4.45.1 * python3-sss_nss_idmap-debuginfo-2.5.2-150400.4.45.1 * libnfsidmap-sss-2.5.2-150400.4.45.1 * sssd-ipa-debuginfo-2.5.2-150400.4.45.1 * sssd-proxy-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1 * sssd-ipa-2.5.2-150400.4.45.1 * sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp-devel-2.5.2-150400.4.45.1 * sssd-ldap-2.5.2-150400.4.45.1 * python3-sss-murmur-2.5.2-150400.4.45.1 * sssd-tools-debuginfo-2.5.2-150400.4.45.1 * python3-sssd-config-debuginfo-2.5.2-150400.4.45.1 * libipa_hbac0-2.5.2-150400.4.45.1 * sssd-dbus-debuginfo-2.5.2-150400.4.45.1 * libipa_hbac0-debuginfo-2.5.2-150400.4.45.1 * sssd-common-2.5.2-150400.4.45.1 * sssd-tools-2.5.2-150400.4.45.1 * python3-sssd-config-2.5.2-150400.4.45.1 * sssd-winbind-idmap-2.5.2-150400.4.45.1 * sssd-2.5.2-150400.4.45.1 * sssd-ad-2.5.2-150400.4.45.1 * sssd-common-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap-devel-2.5.2-150400.4.45.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1 * openSUSE Leap 15.4 (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1 * sssd-common-32bit-2.5.2-150400.4.45.1 * openSUSE Leap 15.4 (aarch64_ilp32) * sssd-common-64bit-2.5.2-150400.4.45.1 * sssd-common-64bit-debuginfo-2.5.2-150400.4.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * sssd-debugsource-2.5.2-150400.4.45.1 * libsss_idmap0-2.5.2-150400.4.45.1 * sssd-kcm-debuginfo-2.5.2-150400.4.45.1 * sssd-ad-debuginfo-2.5.2-150400.4.45.1 * sssd-proxy-2.5.2-150400.4.45.1 * sssd-krb5-debuginfo-2.5.2-150400.4.45.1 * sssd-ldap-debuginfo-2.5.2-150400.4.45.1 * sssd-krb5-2.5.2-150400.4.45.1 * libsss_idmap-devel-2.5.2-150400.4.45.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap0-2.5.2-150400.4.45.1 * sssd-kcm-2.5.2-150400.4.45.1 * libsss_simpleifp0-2.5.2-150400.4.45.1 * libsss_nss_idmap-devel-2.5.2-150400.4.45.1 * sssd-krb5-common-2.5.2-150400.4.45.1 * sssd-dbus-2.5.2-150400.4.45.1 * libsss_nss_idmap0-2.5.2-150400.4.45.1 * libipa_hbac-devel-2.5.2-150400.4.45.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1 * sssd-proxy-debuginfo-2.5.2-150400.4.45.1 * sssd-ipa-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1 * sssd-ipa-2.5.2-150400.4.45.1 * sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp-devel-2.5.2-150400.4.45.1 * sssd-ldap-2.5.2-150400.4.45.1 * sssd-tools-debuginfo-2.5.2-150400.4.45.1 * python3-sssd-config-debuginfo-2.5.2-150400.4.45.1 * libipa_hbac0-2.5.2-150400.4.45.1 * sssd-dbus-debuginfo-2.5.2-150400.4.45.1 * libipa_hbac0-debuginfo-2.5.2-150400.4.45.1 * sssd-common-2.5.2-150400.4.45.1 * python3-sssd-config-2.5.2-150400.4.45.1 * sssd-winbind-idmap-2.5.2-150400.4.45.1 * sssd-2.5.2-150400.4.45.1 * sssd-ad-2.5.2-150400.4.45.1 * sssd-common-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap-devel-2.5.2-150400.4.45.1 * sssd-tools-2.5.2-150400.4.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1 * sssd-common-32bit-2.5.2-150400.4.45.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * sssd-debugsource-2.5.2-150400.4.45.1 * libsss_idmap0-2.5.2-150400.4.45.1 * sssd-ad-debuginfo-2.5.2-150400.4.45.1 * sssd-kcm-debuginfo-2.5.2-150400.4.45.1 * sssd-proxy-2.5.2-150400.4.45.1 * sssd-krb5-debuginfo-2.5.2-150400.4.45.1 * sssd-ldap-debuginfo-2.5.2-150400.4.45.1 * sssd-krb5-2.5.2-150400.4.45.1 * libsss_idmap-devel-2.5.2-150400.4.45.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap0-2.5.2-150400.4.45.1 * sssd-kcm-2.5.2-150400.4.45.1 * libsss_simpleifp0-2.5.2-150400.4.45.1 * libsss_nss_idmap-devel-2.5.2-150400.4.45.1 * sssd-krb5-common-2.5.2-150400.4.45.1 * libsss_nss_idmap0-2.5.2-150400.4.45.1 * sssd-dbus-2.5.2-150400.4.45.1 * libipa_hbac-devel-2.5.2-150400.4.45.1 * sssd-ipa-debuginfo-2.5.2-150400.4.45.1 * sssd-proxy-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1 * sssd-ipa-2.5.2-150400.4.45.1 * sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp-devel-2.5.2-150400.4.45.1 * sssd-ldap-2.5.2-150400.4.45.1 * sssd-tools-debuginfo-2.5.2-150400.4.45.1 * python3-sssd-config-debuginfo-2.5.2-150400.4.45.1 * libipa_hbac0-2.5.2-150400.4.45.1 * libipa_hbac0-debuginfo-2.5.2-150400.4.45.1 * sssd-dbus-debuginfo-2.5.2-150400.4.45.1 * sssd-common-2.5.2-150400.4.45.1 * sssd-tools-2.5.2-150400.4.45.1 * python3-sssd-config-2.5.2-150400.4.45.1 * sssd-winbind-idmap-2.5.2-150400.4.45.1 * sssd-2.5.2-150400.4.45.1 * sssd-ad-2.5.2-150400.4.45.1 * sssd-common-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap-devel-2.5.2-150400.4.45.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1 * sssd-common-32bit-2.5.2-150400.4.45.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * sssd-debugsource-2.5.2-150400.4.45.1 * sssd-kcm-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-2.5.2-150400.4.45.1 * sssd-ad-debuginfo-2.5.2-150400.4.45.1 * sssd-proxy-2.5.2-150400.4.45.1 * sssd-krb5-debuginfo-2.5.2-150400.4.45.1 * sssd-ldap-debuginfo-2.5.2-150400.4.45.1 * sssd-krb5-2.5.2-150400.4.45.1 * libsss_idmap-devel-2.5.2-150400.4.45.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap0-2.5.2-150400.4.45.1 * sssd-kcm-2.5.2-150400.4.45.1 * libsss_nss_idmap-devel-2.5.2-150400.4.45.1 * libsss_simpleifp0-2.5.2-150400.4.45.1 * sssd-krb5-common-2.5.2-150400.4.45.1 * sssd-dbus-2.5.2-150400.4.45.1 * libsss_nss_idmap0-2.5.2-150400.4.45.1 * libipa_hbac-devel-2.5.2-150400.4.45.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1 * sssd-ipa-debuginfo-2.5.2-150400.4.45.1 * sssd-proxy-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1 * sssd-ipa-2.5.2-150400.4.45.1 * sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp-devel-2.5.2-150400.4.45.1 * sssd-ldap-2.5.2-150400.4.45.1 * sssd-tools-debuginfo-2.5.2-150400.4.45.1 * python3-sssd-config-debuginfo-2.5.2-150400.4.45.1 * libipa_hbac0-2.5.2-150400.4.45.1 * sssd-dbus-debuginfo-2.5.2-150400.4.45.1 * libipa_hbac0-debuginfo-2.5.2-150400.4.45.1 * sssd-common-2.5.2-150400.4.45.1 * python3-sssd-config-2.5.2-150400.4.45.1 * sssd-winbind-idmap-2.5.2-150400.4.45.1 * sssd-2.5.2-150400.4.45.1 * sssd-ad-2.5.2-150400.4.45.1 * sssd-common-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap-devel-2.5.2-150400.4.45.1 * sssd-tools-2.5.2-150400.4.45.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1 * sssd-common-32bit-2.5.2-150400.4.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * sssd-debugsource-2.5.2-150400.4.45.1 * sssd-kcm-debuginfo-2.5.2-150400.4.45.1 * sssd-ad-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-2.5.2-150400.4.45.1 * sssd-proxy-2.5.2-150400.4.45.1 * sssd-krb5-debuginfo-2.5.2-150400.4.45.1 * sssd-ldap-debuginfo-2.5.2-150400.4.45.1 * sssd-krb5-2.5.2-150400.4.45.1 * libsss_idmap-devel-2.5.2-150400.4.45.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap0-2.5.2-150400.4.45.1 * sssd-kcm-2.5.2-150400.4.45.1 * libsss_nss_idmap-devel-2.5.2-150400.4.45.1 * libsss_simpleifp0-2.5.2-150400.4.45.1 * sssd-krb5-common-2.5.2-150400.4.45.1 * sssd-dbus-2.5.2-150400.4.45.1 * libsss_nss_idmap0-2.5.2-150400.4.45.1 * libipa_hbac-devel-2.5.2-150400.4.45.1 * sssd-ipa-debuginfo-2.5.2-150400.4.45.1 * sssd-proxy-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1 * sssd-ipa-2.5.2-150400.4.45.1 * sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1 * libsss_simpleifp-devel-2.5.2-150400.4.45.1 * sssd-ldap-2.5.2-150400.4.45.1 * sssd-tools-debuginfo-2.5.2-150400.4.45.1 * python3-sssd-config-debuginfo-2.5.2-150400.4.45.1 * libipa_hbac0-2.5.2-150400.4.45.1 * sssd-dbus-debuginfo-2.5.2-150400.4.45.1 * libipa_hbac0-debuginfo-2.5.2-150400.4.45.1 * sssd-tools-2.5.2-150400.4.45.1 * sssd-common-2.5.2-150400.4.45.1 * python3-sssd-config-2.5.2-150400.4.45.1 * sssd-winbind-idmap-2.5.2-150400.4.45.1 * sssd-2.5.2-150400.4.45.1 * sssd-ad-2.5.2-150400.4.45.1 * sssd-common-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap-devel-2.5.2-150400.4.45.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1 * sssd-common-32bit-2.5.2-150400.4.45.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libsss_certmap0-2.5.2-150400.4.45.1 * sssd-debugsource-2.5.2-150400.4.45.1 * sssd-ldap-2.5.2-150400.4.45.1 * libsss_idmap0-2.5.2-150400.4.45.1 * sssd-common-2.5.2-150400.4.45.1 * sssd-krb5-common-2.5.2-150400.4.45.1 * sssd-ldap-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-2.5.2-150400.4.45.1 * sssd-2.5.2-150400.4.45.1 * sssd-common-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.45.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libsss_certmap0-2.5.2-150400.4.45.1 * sssd-debugsource-2.5.2-150400.4.45.1 * sssd-ldap-2.5.2-150400.4.45.1 * libsss_idmap0-2.5.2-150400.4.45.1 * sssd-common-2.5.2-150400.4.45.1 * sssd-krb5-common-2.5.2-150400.4.45.1 * sssd-ldap-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-2.5.2-150400.4.45.1 * sssd-2.5.2-150400.4.45.1 * sssd-common-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.45.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libsss_certmap0-2.5.2-150400.4.45.1 * sssd-debugsource-2.5.2-150400.4.45.1 * sssd-ldap-2.5.2-150400.4.45.1 * libsss_idmap0-2.5.2-150400.4.45.1 * sssd-krb5-common-2.5.2-150400.4.45.1 * sssd-common-2.5.2-150400.4.45.1 * sssd-ldap-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-2.5.2-150400.4.45.1 * sssd-2.5.2-150400.4.45.1 * sssd-common-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.45.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libsss_certmap0-2.5.2-150400.4.45.1 * sssd-debugsource-2.5.2-150400.4.45.1 * sssd-ldap-2.5.2-150400.4.45.1 * libsss_idmap0-2.5.2-150400.4.45.1 * sssd-krb5-common-2.5.2-150400.4.45.1 * sssd-common-2.5.2-150400.4.45.1 * sssd-ldap-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-2.5.2-150400.4.45.1 * sssd-2.5.2-150400.4.45.1 * sssd-common-debuginfo-2.5.2-150400.4.45.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.45.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1246196 * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 12:30:05 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 12:30:05 -0000 Subject: SUSE-RU-2026:3144-1: moderate: Recommended update for himmelblau Message-ID: <178463700597.1897.8376155154282559393@ddd703581f31> # Recommended update for himmelblau Announcement ID: SUSE-RU-2026:3144-1 Release Date: 2026-07-21T07:08:57Z Rating: moderate References: Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for himmelblau fixes the following issues: * Update to version 2.3.12: * Fix cargo-fuzz install in fuzz CI * Update ldap3_proto to 0.7.1 * Update openssl * Update cargo vet audits for backport * Remove invalid himmelblau.conf example info * Fix SSHd configuration load order on Fedora/RHEL systems * himmelblau-init-hsm-pin: don't bind the hsm-pin to PCR7 * qr-greeter: Support GNOME Shell 50 * Reject auth when token spn local part differs from requested account_id * nss/pam: Bail out early when SYSTEMD_ACTIVATION_UNIT points to himmelblau * selinux: Allow unconfined_service_t to search himmelblaud_t dirs * idprovider: Release providers lock before async alias lookup ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3144=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 x86_64) * himmelblau-2.3.12+git0.9d56c6f1-150700.3.20.1 * pam-himmelblau-2.3.12+git0.9d56c6f1-150700.3.20.1 * himmelblau-debuginfo-2.3.12+git0.9d56c6f1-150700.3.20.1 * libnss_himmelblau2-2.3.12+git0.9d56c6f1-150700.3.20.1 * Basesystem Module 15-SP7 (noarch) * himmelblau-sshd-config-2.3.12+git0.9d56c6f1-150700.3.20.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 12:30:18 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 12:30:18 -0000 Subject: SUSE-RU-2026:3143-1: important: Recommended update for ServiceReport Message-ID: <178463701882.1897.14095827577985679543@ddd703581f31> # Recommended update for ServiceReport Announcement ID: SUSE-RU-2026:3143-1 Release Date: 2026-07-21T07:08:33Z Rating: important References: * bsc#1244547 * bsc#1270052 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has two fixes can now be installed. ## Description: This update for ServiceReport fixes the following issues: * Fix TypeError in kdump component check that was causing ServiceReport to crash on first run (bsc#1270052) * Fix crash caused by Python related macros (bsc#1244547) * Add new plugin Spyre card configuration ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3143=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3143=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3143=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3143=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * ServiceReport-2.2.4+git12.bc007b2-150600.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * ServiceReport-2.2.4+git12.bc007b2-150600.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * ServiceReport-2.2.4+git12.bc007b2-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * ServiceReport-2.2.4+git12.bc007b2-150600.3.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1244547 * https://bugzilla.suse.com/show_bug.cgi?id=1270052 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 12:30:28 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 12:30:28 -0000 Subject: SUSE-RU-2026:3142-1: moderate: Recommended update for valgrind Message-ID: <178463702836.1897.1807111743887554511@ddd703581f31> # Recommended update for valgrind Announcement ID: SUSE-RU-2026:3142-1 Release Date: 2026-07-21T07:05:49Z Rating: moderate References: * jsc#PED-15483 * jsc#PED-15782 Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains two features can now be installed. ## Description: This update for valgrind fixes the following issues: * update to 3.27.1 (jsc#PED-15483): * valgrind 3.27 "\--fair-sched=yes" does not work * Valgrind incorrectly unpacks the result of sys_port (port_getn) * on error, leading to a ~60s wallclock time delay on every call * n-i-bz Update vg-lifespan (copyright) years * n-i-bz Use SSizeT for VG_(readlink) result in VG_(realpath) * update to 3.27.0: * VALGRIND_REPLACES_MALLOC Returns 1 if the tool replaces malloc. * VALGRIND_GET_TOOLNAME Get the running tool name as a string. Takes two arguments, an input buffer pointer and the length of that buffer. * linux lightweight guard pages (madvise MADV_GUARD_INSTALL) supported * glibc 2.42+ (with linux 6.13+) uses MADV_GUARD_INSTALL to setup stack guard pages. These lightweight guard pages are now supported under valgrind. * If --max-guard-pages is not set explicitly, then it will default to the --max-threads setting. * \--num-callers now has a minimum value of 2. * x86: Support for SSE4.1 instructions has been ported from AMD64 to (32bit) x86. * s390x: Machine models older than z196 are no longer supported. * s390x: Support new z/Architecture features from the 15th edition. * remove 32bit for all SLES 16 based products (jsc#PED-15782) * update to 3.26.0: * Upgrade to the GNU General Public License version 3. * Control building documentation. When using make dist set the Makefile BUILD_DOCS to none, all or html. none, does not build any documentation. * New VEX API function LibVEX_set_VexControl * The deprecated IROps: Iop_Clz32/64 and Iop_Ctz32/64 have been removed * The Linux Test Project (LTP) integration has been updated to v20250930. * \--modify-fds=yes has been added. It acts like --modify-fds=high (the highest available file descriptor is returned first) except when when the lowers stdin/stdout/stderr (file descriptors 0, 1, 2) are available. * With --xml=yes log output protocol 6 is now always used. * Add "bad" option for --track-fds. When --track-fds=bad is specified, do not produce errors about unclosed file descriptors at program exit. * vgdb will now handle the qExecAndArgs packet. * DWARF inlined subroutine handling has been rewritten to work cross compile units. * updated keyring from https://www.klomp.org/mark/gnupg-pub.txt ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3142=1 ## Package List: * Development Tools Module 15-SP7 (noarch) * valgrind-client-headers-3.27.1-150700.3.6.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * valgrind-devel-3.27.1-150700.3.6.1 * valgrind-3.27.1-150700.3.6.1 * valgrind-debugsource-3.27.1-150700.3.6.1 * valgrind-debuginfo-3.27.1-150700.3.6.1 ## References: * https://jira.suse.com/browse/PED-15483 * https://jira.suse.com/browse/PED-15782 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 12:30:34 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 12:30:34 -0000 Subject: SUSE-RU-2026:3141-1: important: Recommended update for shadow Message-ID: <178463703442.1897.15126794701638353011@ddd703581f31> # Recommended update for shadow Announcement ID: SUSE-RU-2026:3141-1 Release Date: 2026-07-21T07:04:43Z Rating: important References: * bsc#1270393 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for shadow fixes the following issues: * Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3141=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3141=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsubid5-debuginfo-4.17.2-150600.17.21.1 * shadow-debuginfo-4.17.2-150600.17.21.1 * libsubid5-4.17.2-150600.17.21.1 * shadow-debugsource-4.17.2-150600.17.21.1 * libsubid-devel-4.17.2-150600.17.21.1 * shadow-4.17.2-150600.17.21.1 * Basesystem Module 15-SP7 (noarch) * login_defs-4.17.2-150600.17.21.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libsubid5-debuginfo-4.17.2-150600.17.21.1 * libsubid5-4.17.2-150600.17.21.1 * shadow-debuginfo-4.17.2-150600.17.21.1 * shadow-debugsource-4.17.2-150600.17.21.1 * libsubid-devel-4.17.2-150600.17.21.1 * shadow-4.17.2-150600.17.21.1 * openSUSE Leap 15.6 (noarch) * login_defs-4.17.2-150600.17.21.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270393 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 16:30:06 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 16:30:06 -0000 Subject: SUSE-RU-2026:3146-1: low: Recommended update for llvm19 Message-ID: <178465140609.1576.1301555862997235672@77cbb66263f9> # Recommended update for llvm19 Announcement ID: SUSE-RU-2026:3146-1 Release Date: 2026-07-21T08:49:36Z Rating: low References: Affected Products: * openSUSE Leap 15.4 An update that can now be installed. ## Description: This update provides llvm19 for building Firefox. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3146=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le x86_64) * libc++1-debuginfo-19.1.7-150400.9.3.1 * libc++abi1-debuginfo-19.1.7-150400.9.3.1 * libc++abi-devel-19.1.7-150400.9.3.1 * libc++-devel-19.1.7-150400.9.3.1 * libc++abi1-19.1.7-150400.9.3.1 * libc++1-19.1.7-150400.9.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libLLVM19-debuginfo-19.1.7-150400.9.3.1 * libLTO19-debuginfo-19.1.7-150400.9.3.1 * libclang-cpp19-19.1.7-150400.9.3.1 * libLLVM19-19.1.7-150400.9.3.1 * libclang13-debuginfo-19.1.7-150400.9.3.1 * llvm19-devel-19.1.7-150400.9.3.1 * llvm19-gold-debuginfo-19.1.7-150400.9.3.1 * llvm19-debuginfo-19.1.7-150400.9.3.1 * libLTO19-19.1.7-150400.9.3.1 * clang19-19.1.7-150400.9.3.1 * llvm19-polly-19.1.7-150400.9.3.1 * clang-tools-debuginfo-19.1.7-150400.9.3.1 * llvm19-devel-debuginfo-19.1.7-150400.9.3.1 * llvm19-gold-19.1.7-150400.9.3.1 * lld19-debuginfo-19.1.7-150400.9.3.1 * libclang-cpp19-debuginfo-19.1.7-150400.9.3.1 * llvm19-19.1.7-150400.9.3.1 * clang19-debuginfo-19.1.7-150400.9.3.1 * libclang_rt19-19.1.7-150400.9.3.1 * llvm19-polly-debuginfo-19.1.7-150400.9.3.1 * llvm19-polly-devel-19.1.7-150400.9.3.1 * clang-tools-19.1.7-150400.9.3.1 * clang19-devel-19.1.7-150400.9.3.1 * libclang_rt19-debuginfo-19.1.7-150400.9.3.1 * libclang13-19.1.7-150400.9.3.1 * lld19-19.1.7-150400.9.3.1 * openSUSE Leap 15.4 (x86_64) * libLLVM19-32bit-debuginfo-19.1.7-150400.9.3.1 * libLLVM19-32bit-19.1.7-150400.9.3.1 * libclang-cpp19-32bit-19.1.7-150400.9.3.1 * libclang-cpp19-32bit-debuginfo-19.1.7-150400.9.3.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libclang-cpp19-64bit-debuginfo-19.1.7-150400.9.3.1 * libclang-cpp19-64bit-19.1.7-150400.9.3.1 * libLLVM19-64bit-19.1.7-150400.9.3.1 * libLLVM19-64bit-debuginfo-19.1.7-150400.9.3.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * lldb19-devel-19.1.7-150400.9.3.1 * liblldb19-debuginfo-19.1.7-150400.9.3.1 * lldb19-19.1.7-150400.9.3.1 * liblldb19-19.1.7-150400.9.3.1 * lldb19-debuginfo-19.1.7-150400.9.3.1 * openSUSE Leap 15.4 (noarch) * clang19-doc-19.1.7-150400.9.3.1 * llvm19-doc-19.1.7-150400.9.3.1 * python3-clang19-19.1.7-150400.9.3.1 * llvm19-opt-viewer-19.1.7-150400.9.3.1 * llvm19-vim-plugins-19.1.7-150400.9.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le x86_64) * libomp19-devel-19.1.7-150400.9.3.1 * libomp19-devel-debuginfo-19.1.7-150400.9.3.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 16:30:10 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 16:30:10 -0000 Subject: SUSE-RU-2026:3145-1: important: Recommended update for log4j Message-ID: <178465141013.1576.2129201818882134131@77cbb66263f9> # Recommended update for log4j Announcement ID: SUSE-RU-2026:3145-1 Release Date: 2026-07-21T08:39:04Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for log4j fixes the following issues: log4j was updated and includes fixes and improvements from versions 2.21.0 through 2.26.0: * Bugs fixed: * Fixed crashes when logging errors with stack traces modified by other threads * Fixed FATAL-level log messages being silently discarded * Fixed memory leaks in several components * Fixed log file headers not being written correctly when files are recreated * Fixed log file rotation failures * Fixed configuration file loading from HTTP sources * Fixed date and time formatting issues in logs * Fixed problems when multiple threads modify logger settings simultaneously * Fixed MongoDB appender connection issues * New Features Added: * Support for ZStandard compression for log files * Support for LMAX Disruptor 4.x (high-performance logging) * Better support for GraalVM environments * Java 8 users now get sub-millisecond precision timestamps * Features Removed: * JMX GUI tool (moved to separate release) * Flume Appender (moved to separate release) * Kubernetes lookup feature (users should migrate to io.fabric8:kubernetes- log4j) * JAnsi library support (Windows 10+ has built-in color support) * Important Changes: * JMX monitoring is now DISABLED by default (set log4j2.disableJmx=false to enable) * Default log format has changed * Configuration scripts now require explicit names * Deprecations (features to be removed in the future): * MongoDB4 module (use standard MongoDB module instead) * EventLogger class * Some builder methods (replaced with setter methods) New Runtime Dependencies: * jackson-dataformat-xml * stax2-api * woodstox-core New and Updated Build Dependencies: * aalto-xml (updated from version 1.3.3 to 1.4.0) * jakarta-annotations (new) * jakarta-messaging (new) * jspecify (new) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3145=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3145=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3145=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3145=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3145=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3145=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3145=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3145=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3145=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3145=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3145=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * log4j-2.26.0-150200.4.36.1 * log4j-slf4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * log4j-2.26.0-150200.4.36.1 * log4j-slf4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * log4j-slf4j-2.26.0-150200.4.36.1 * log4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * Basesystem Module 15-SP7 (noarch) * log4j-2.26.0-150200.4.36.1 * log4j-slf4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * log4j-slf4j-2.26.0-150200.4.36.1 * log4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * log4j-slf4j-2.26.0-150200.4.36.1 * log4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * log4j-2.26.0-150200.4.36.1 * log4j-slf4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * log4j-slf4j-2.26.0-150200.4.36.1 * log4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * log4j-slf4j-2.26.0-150200.4.36.1 * log4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * log4j-2.26.0-150200.4.36.1 * log4j-slf4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * log4j-2.26.0-150200.4.36.1 * log4j-slf4j-2.26.0-150200.4.36.1 * stax2-api-4.3.0-150200.3.8.1 * log4j-javadoc-2.26.0-150200.4.36.1 * woodstox-core-7.2.1-150200.3.10.1 * jackson-dataformat-xml-2.18.8-150200.5.5.1 * log4j-jcl-2.26.0-150200.4.36.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:30:07 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:30:07 -0000 Subject: SUSE-SU-2026:3165-1: moderate: Security update for php7 Message-ID: <178466580794.146.9313005481276688876@1958684a8af1> # Security update for php7 Announcement ID: SUSE-SU-2026:3165-1 Release Date: 2026-07-21T14:55:01Z Rating: moderate References: * bsc#1270351 Cross-References: * CVE-2026-14355 CVSS scores: * CVE-2026-14355 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-14355 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14355 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14355 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for php7 fixes the following issue * CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3165=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3165=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3165=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * php7-sockets-debuginfo-7.4.33-150400.4.63.1 * php7-pdo-7.4.33-150400.4.63.1 * php7-tokenizer-7.4.33-150400.4.63.1 * php7-exif-7.4.33-150400.4.63.1 * php7-pgsql-7.4.33-150400.4.63.1 * php7-embed-debugsource-7.4.33-150400.4.63.1 * php7-posix-debuginfo-7.4.33-150400.4.63.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.63.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.63.1 * php7-mysql-7.4.33-150400.4.63.1 * php7-openssl-debuginfo-7.4.33-150400.4.63.1 * php7-sodium-7.4.33-150400.4.63.1 * php7-embed-7.4.33-150400.4.63.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.63.1 * php7-xsl-7.4.33-150400.4.63.1 * php7-fpm-debugsource-7.4.33-150400.4.63.1 * php7-curl-debuginfo-7.4.33-150400.4.63.1 * php7-zip-debuginfo-7.4.33-150400.4.63.1 * php7-devel-7.4.33-150400.4.63.1 * php7-readline-debuginfo-7.4.33-150400.4.63.1 * php7-sodium-debuginfo-7.4.33-150400.4.63.1 * php7-ftp-debuginfo-7.4.33-150400.4.63.1 * php7-snmp-debuginfo-7.4.33-150400.4.63.1 * php7-tidy-7.4.33-150400.4.63.1 * php7-snmp-7.4.33-150400.4.63.1 * php7-phar-7.4.33-150400.4.63.1 * php7-pcntl-debuginfo-7.4.33-150400.4.63.1 * php7-fastcgi-7.4.33-150400.4.63.1 * php7-cli-debuginfo-7.4.33-150400.4.63.1 * php7-debugsource-7.4.33-150400.4.63.1 * php7-pdo-debuginfo-7.4.33-150400.4.63.1 * php7-zip-7.4.33-150400.4.63.1 * php7-debuginfo-7.4.33-150400.4.63.1 * php7-ftp-7.4.33-150400.4.63.1 * php7-xmlwriter-7.4.33-150400.4.63.1 * php7-gd-7.4.33-150400.4.63.1 * php7-soap-7.4.33-150400.4.63.1 * php7-curl-7.4.33-150400.4.63.1 * php7-dom-debuginfo-7.4.33-150400.4.63.1 * php7-odbc-7.4.33-150400.4.63.1 * php7-dba-debuginfo-7.4.33-150400.4.63.1 * php7-gettext-debuginfo-7.4.33-150400.4.63.1 * php7-dom-7.4.33-150400.4.63.1 * php7-mysql-debuginfo-7.4.33-150400.4.63.1 * php7-opcache-debuginfo-7.4.33-150400.4.63.1 * php7-iconv-debuginfo-7.4.33-150400.4.63.1 * php7-tidy-debuginfo-7.4.33-150400.4.63.1 * php7-phar-debuginfo-7.4.33-150400.4.63.1 * php7-sysvshm-7.4.33-150400.4.63.1 * php7-calendar-7.4.33-150400.4.63.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.63.1 * php7-ldap-debuginfo-7.4.33-150400.4.63.1 * php7-fastcgi-debugsource-7.4.33-150400.4.63.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.63.1 * php7-calendar-debuginfo-7.4.33-150400.4.63.1 * php7-sysvsem-7.4.33-150400.4.63.1 * php7-gettext-7.4.33-150400.4.63.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.63.1 * php7-test-7.4.33-150400.4.63.1 * php7-mbstring-7.4.33-150400.4.63.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.63.1 * php7-shmop-7.4.33-150400.4.63.1 * php7-bcmath-7.4.33-150400.4.63.1 * php7-pcntl-7.4.33-150400.4.63.1 * php7-sockets-7.4.33-150400.4.63.1 * php7-sysvmsg-7.4.33-150400.4.63.1 * php7-zlib-debuginfo-7.4.33-150400.4.63.1 * php7-cli-7.4.33-150400.4.63.1 * php7-bz2-7.4.33-150400.4.63.1 * php7-ldap-7.4.33-150400.4.63.1 * php7-readline-7.4.33-150400.4.63.1 * php7-posix-7.4.33-150400.4.63.1 * php7-bz2-debuginfo-7.4.33-150400.4.63.1 * php7-gmp-debuginfo-7.4.33-150400.4.63.1 * php7-json-7.4.33-150400.4.63.1 * php7-7.4.33-150400.4.63.1 * php7-zlib-7.4.33-150400.4.63.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.63.1 * php7-odbc-debuginfo-7.4.33-150400.4.63.1 * php7-mbstring-debuginfo-7.4.33-150400.4.63.1 * php7-fpm-7.4.33-150400.4.63.1 * php7-intl-debuginfo-7.4.33-150400.4.63.1 * php7-gd-debuginfo-7.4.33-150400.4.63.1 * php7-opcache-7.4.33-150400.4.63.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.63.1 * php7-pgsql-debuginfo-7.4.33-150400.4.63.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.63.1 * php7-openssl-7.4.33-150400.4.63.1 * php7-ctype-7.4.33-150400.4.63.1 * php7-fileinfo-7.4.33-150400.4.63.1 * php7-xmlreader-7.4.33-150400.4.63.1 * php7-enchant-debuginfo-7.4.33-150400.4.63.1 * php7-gmp-7.4.33-150400.4.63.1 * php7-ctype-debuginfo-7.4.33-150400.4.63.1 * php7-xsl-debuginfo-7.4.33-150400.4.63.1 * php7-dba-7.4.33-150400.4.63.1 * php7-enchant-7.4.33-150400.4.63.1 * php7-sqlite-debuginfo-7.4.33-150400.4.63.1 * php7-json-debuginfo-7.4.33-150400.4.63.1 * php7-shmop-debuginfo-7.4.33-150400.4.63.1 * php7-fpm-debuginfo-7.4.33-150400.4.63.1 * php7-xmlrpc-7.4.33-150400.4.63.1 * php7-soap-debuginfo-7.4.33-150400.4.63.1 * php7-intl-7.4.33-150400.4.63.1 * php7-bcmath-debuginfo-7.4.33-150400.4.63.1 * php7-embed-debuginfo-7.4.33-150400.4.63.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.63.1 * php7-exif-debuginfo-7.4.33-150400.4.63.1 * apache2-mod_php7-7.4.33-150400.4.63.1 * php7-iconv-7.4.33-150400.4.63.1 * php7-sqlite-7.4.33-150400.4.63.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * php7-pdo-7.4.33-150400.4.63.1 * php7-sockets-debuginfo-7.4.33-150400.4.63.1 * php7-tokenizer-7.4.33-150400.4.63.1 * php7-exif-7.4.33-150400.4.63.1 * php7-pgsql-7.4.33-150400.4.63.1 * php7-embed-debugsource-7.4.33-150400.4.63.1 * php7-posix-debuginfo-7.4.33-150400.4.63.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.63.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.63.1 * php7-mysql-7.4.33-150400.4.63.1 * php7-openssl-debuginfo-7.4.33-150400.4.63.1 * php7-sodium-7.4.33-150400.4.63.1 * php7-embed-7.4.33-150400.4.63.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.63.1 * php7-xsl-7.4.33-150400.4.63.1 * php7-fpm-debugsource-7.4.33-150400.4.63.1 * php7-curl-debuginfo-7.4.33-150400.4.63.1 * php7-zip-debuginfo-7.4.33-150400.4.63.1 * php7-readline-debuginfo-7.4.33-150400.4.63.1 * php7-sodium-debuginfo-7.4.33-150400.4.63.1 * php7-ftp-debuginfo-7.4.33-150400.4.63.1 * php7-snmp-debuginfo-7.4.33-150400.4.63.1 * php7-tidy-7.4.33-150400.4.63.1 * php7-snmp-7.4.33-150400.4.63.1 * php7-fastcgi-7.4.33-150400.4.63.1 * php7-phar-7.4.33-150400.4.63.1 * php7-pcntl-debuginfo-7.4.33-150400.4.63.1 * php7-cli-debuginfo-7.4.33-150400.4.63.1 * php7-debugsource-7.4.33-150400.4.63.1 * php7-pdo-debuginfo-7.4.33-150400.4.63.1 * php7-zip-7.4.33-150400.4.63.1 * php7-debuginfo-7.4.33-150400.4.63.1 * php7-ftp-7.4.33-150400.4.63.1 * php7-xmlwriter-7.4.33-150400.4.63.1 * php7-gd-7.4.33-150400.4.63.1 * php7-soap-7.4.33-150400.4.63.1 * php7-curl-7.4.33-150400.4.63.1 * php7-dom-debuginfo-7.4.33-150400.4.63.1 * php7-odbc-7.4.33-150400.4.63.1 * php7-dba-debuginfo-7.4.33-150400.4.63.1 * php7-gettext-debuginfo-7.4.33-150400.4.63.1 * php7-dom-7.4.33-150400.4.63.1 * php7-mysql-debuginfo-7.4.33-150400.4.63.1 * php7-opcache-debuginfo-7.4.33-150400.4.63.1 * php7-iconv-debuginfo-7.4.33-150400.4.63.1 * php7-tidy-debuginfo-7.4.33-150400.4.63.1 * php7-phar-debuginfo-7.4.33-150400.4.63.1 * php7-sysvshm-7.4.33-150400.4.63.1 * php7-calendar-7.4.33-150400.4.63.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.63.1 * php7-ldap-debuginfo-7.4.33-150400.4.63.1 * php7-fastcgi-debugsource-7.4.33-150400.4.63.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.63.1 * php7-calendar-debuginfo-7.4.33-150400.4.63.1 * php7-sysvsem-7.4.33-150400.4.63.1 * php7-gettext-7.4.33-150400.4.63.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.63.1 * php7-test-7.4.33-150400.4.63.1 * php7-mbstring-7.4.33-150400.4.63.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.63.1 * php7-shmop-7.4.33-150400.4.63.1 * php7-bcmath-7.4.33-150400.4.63.1 * php7-pcntl-7.4.33-150400.4.63.1 * php7-sockets-7.4.33-150400.4.63.1 * php7-sysvmsg-7.4.33-150400.4.63.1 * php7-zlib-debuginfo-7.4.33-150400.4.63.1 * php7-cli-7.4.33-150400.4.63.1 * php7-bz2-7.4.33-150400.4.63.1 * php7-ldap-7.4.33-150400.4.63.1 * php7-readline-7.4.33-150400.4.63.1 * php7-posix-7.4.33-150400.4.63.1 * php7-bz2-debuginfo-7.4.33-150400.4.63.1 * php7-gmp-debuginfo-7.4.33-150400.4.63.1 * php7-json-7.4.33-150400.4.63.1 * php7-7.4.33-150400.4.63.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.63.1 * php7-zlib-7.4.33-150400.4.63.1 * php7-odbc-debuginfo-7.4.33-150400.4.63.1 * php7-mbstring-debuginfo-7.4.33-150400.4.63.1 * php7-intl-debuginfo-7.4.33-150400.4.63.1 * php7-fpm-7.4.33-150400.4.63.1 * php7-gd-debuginfo-7.4.33-150400.4.63.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.63.1 * php7-opcache-7.4.33-150400.4.63.1 * php7-pgsql-debuginfo-7.4.33-150400.4.63.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.63.1 * php7-openssl-7.4.33-150400.4.63.1 * php7-ctype-7.4.33-150400.4.63.1 * php7-fileinfo-7.4.33-150400.4.63.1 * php7-xmlreader-7.4.33-150400.4.63.1 * php7-enchant-debuginfo-7.4.33-150400.4.63.1 * php7-gmp-7.4.33-150400.4.63.1 * php7-ctype-debuginfo-7.4.33-150400.4.63.1 * php7-xsl-debuginfo-7.4.33-150400.4.63.1 * php7-dba-7.4.33-150400.4.63.1 * php7-enchant-7.4.33-150400.4.63.1 * php7-sqlite-debuginfo-7.4.33-150400.4.63.1 * php7-json-debuginfo-7.4.33-150400.4.63.1 * php7-shmop-debuginfo-7.4.33-150400.4.63.1 * php7-fpm-debuginfo-7.4.33-150400.4.63.1 * php7-xmlrpc-7.4.33-150400.4.63.1 * php7-soap-debuginfo-7.4.33-150400.4.63.1 * php7-intl-7.4.33-150400.4.63.1 * php7-bcmath-debuginfo-7.4.33-150400.4.63.1 * php7-embed-debuginfo-7.4.33-150400.4.63.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.63.1 * php7-exif-debuginfo-7.4.33-150400.4.63.1 * apache2-mod_php7-7.4.33-150400.4.63.1 * php7-iconv-7.4.33-150400.4.63.1 * php7-sqlite-7.4.33-150400.4.63.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * php7-debuginfo-7.4.33-150400.4.63.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.63.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.63.1 * php7-debugsource-7.4.33-150400.4.63.1 * apache2-mod_php7-7.4.33-150400.4.63.1 * php7-7.4.33-150400.4.63.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14355.html * https://bugzilla.suse.com/show_bug.cgi?id=1270351 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:30:16 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:30:16 -0000 Subject: SUSE-SU-2026:3164-1: moderate: Security update for php8 Message-ID: <178466581627.146.10466541413856004361@1958684a8af1> # Security update for php8 Announcement ID: SUSE-SU-2026:3164-1 Release Date: 2026-07-21T14:54:32Z Rating: moderate References: * bsc#1270351 * bsc#1270712 Cross-References: * CVE-2026-12184 * CVE-2026-14355 CVSS scores: * CVE-2026-12184 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14355 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-14355 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14355 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14355 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for php8 fixes the following issues * Update to version 8.3.32. * CVE-2026-12184: Failure to setup TLS with a remote server can result in a remote DoS (bsc#1270712). * CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3164=1 ## Package List: * Web and Scripting Module 15-SP7 (aarch64 ppc64le s390x x86_64) * php8-snmp-debuginfo-8.3.32-150700.3.15.1 * php8-gettext-debuginfo-8.3.32-150700.3.15.1 * php8-zlib-debuginfo-8.3.32-150700.3.15.1 * php8-cli-debuginfo-8.3.32-150700.3.15.1 * php8-posix-debuginfo-8.3.32-150700.3.15.1 * php8-embed-debuginfo-8.3.32-150700.3.15.1 * php8-dom-8.3.32-150700.3.15.1 * php8-xsl-debuginfo-8.3.32-150700.3.15.1 * php8-gettext-8.3.32-150700.3.15.1 * php8-mysql-debuginfo-8.3.32-150700.3.15.1 * php8-tidy-debuginfo-8.3.32-150700.3.15.1 * php8-pgsql-8.3.32-150700.3.15.1 * php8-bcmath-debuginfo-8.3.32-150700.3.15.1 * php8-phar-8.3.32-150700.3.15.1 * php8-shmop-8.3.32-150700.3.15.1 * php8-sockets-debuginfo-8.3.32-150700.3.15.1 * php8-tokenizer-8.3.32-150700.3.15.1 * php8-ftp-debuginfo-8.3.32-150700.3.15.1 * php8-pcntl-debuginfo-8.3.32-150700.3.15.1 * php8-fastcgi-debugsource-8.3.32-150700.3.15.1 * php8-fastcgi-debuginfo-8.3.32-150700.3.15.1 * php8-fpm-debugsource-8.3.32-150700.3.15.1 * php8-curl-debuginfo-8.3.32-150700.3.15.1 * php8-soap-8.3.32-150700.3.15.1 * php8-zip-debuginfo-8.3.32-150700.3.15.1 * php8-ldap-8.3.32-150700.3.15.1 * php8-sockets-8.3.32-150700.3.15.1 * php8-embed-8.3.32-150700.3.15.1 * php8-gd-debuginfo-8.3.32-150700.3.15.1 * php8-sysvmsg-debuginfo-8.3.32-150700.3.15.1 * php8-xmlreader-8.3.32-150700.3.15.1 * php8-pcntl-8.3.32-150700.3.15.1 * php8-sysvsem-8.3.32-150700.3.15.1 * php8-sysvshm-debuginfo-8.3.32-150700.3.15.1 * php8-iconv-debuginfo-8.3.32-150700.3.15.1 * php8-fileinfo-debuginfo-8.3.32-150700.3.15.1 * php8-gmp-debuginfo-8.3.32-150700.3.15.1 * php8-mbstring-8.3.32-150700.3.15.1 * php8-fpm-8.3.32-150700.3.15.1 * apache2-mod_php8-debuginfo-8.3.32-150700.3.15.1 * php8-odbc-debuginfo-8.3.32-150700.3.15.1 * php8-openssl-8.3.32-150700.3.15.1 * php8-dba-debuginfo-8.3.32-150700.3.15.1 * php8-intl-8.3.32-150700.3.15.1 * php8-fastcgi-8.3.32-150700.3.15.1 * php8-bcmath-8.3.32-150700.3.15.1 * php8-exif-8.3.32-150700.3.15.1 * php8-gmp-8.3.32-150700.3.15.1 * apache2-mod_php8-8.3.32-150700.3.15.1 * php8-tokenizer-debuginfo-8.3.32-150700.3.15.1 * php8-calendar-debuginfo-8.3.32-150700.3.15.1 * php8-readline-debuginfo-8.3.32-150700.3.15.1 * php8-sqlite-debuginfo-8.3.32-150700.3.15.1 * php8-phar-debuginfo-8.3.32-150700.3.15.1 * php8-mbstring-debuginfo-8.3.32-150700.3.15.1 * php8-exif-debuginfo-8.3.32-150700.3.15.1 * php8-curl-8.3.32-150700.3.15.1 * php8-sysvshm-8.3.32-150700.3.15.1 * php8-xmlreader-debuginfo-8.3.32-150700.3.15.1 * php8-sqlite-8.3.32-150700.3.15.1 * php8-8.3.32-150700.3.15.1 * php8-ldap-debuginfo-8.3.32-150700.3.15.1 * php8-cli-8.3.32-150700.3.15.1 * php8-intl-debuginfo-8.3.32-150700.3.15.1 * php8-readline-8.3.32-150700.3.15.1 * php8-posix-8.3.32-150700.3.15.1 * apache2-mod_php8-debugsource-8.3.32-150700.3.15.1 * php8-gd-8.3.32-150700.3.15.1 * php8-devel-8.3.32-150700.3.15.1 * php8-fileinfo-8.3.32-150700.3.15.1 * php8-test-8.3.32-150700.3.15.1 * php8-calendar-8.3.32-150700.3.15.1 * php8-opcache-debuginfo-8.3.32-150700.3.15.1 * php8-sysvmsg-8.3.32-150700.3.15.1 * php8-sodium-debuginfo-8.3.32-150700.3.15.1 * php8-embed-debugsource-8.3.32-150700.3.15.1 * php8-mysql-8.3.32-150700.3.15.1 * php8-opcache-8.3.32-150700.3.15.1 * php8-ftp-8.3.32-150700.3.15.1 * php8-snmp-8.3.32-150700.3.15.1 * php8-sysvsem-debuginfo-8.3.32-150700.3.15.1 * php8-bz2-8.3.32-150700.3.15.1 * php8-bz2-debuginfo-8.3.32-150700.3.15.1 * php8-zip-8.3.32-150700.3.15.1 * php8-dba-8.3.32-150700.3.15.1 * php8-enchant-8.3.32-150700.3.15.1 * php8-openssl-debuginfo-8.3.32-150700.3.15.1 * php8-xmlwriter-8.3.32-150700.3.15.1 * php8-debugsource-8.3.32-150700.3.15.1 * php8-dom-debuginfo-8.3.32-150700.3.15.1 * php8-soap-debuginfo-8.3.32-150700.3.15.1 * php8-pgsql-debuginfo-8.3.32-150700.3.15.1 * php8-shmop-debuginfo-8.3.32-150700.3.15.1 * php8-pdo-debuginfo-8.3.32-150700.3.15.1 * php8-debuginfo-8.3.32-150700.3.15.1 * php8-odbc-8.3.32-150700.3.15.1 * php8-xsl-8.3.32-150700.3.15.1 * php8-sodium-8.3.32-150700.3.15.1 * php8-zlib-8.3.32-150700.3.15.1 * php8-ctype-debuginfo-8.3.32-150700.3.15.1 * php8-pdo-8.3.32-150700.3.15.1 * php8-ctype-8.3.32-150700.3.15.1 * php8-xmlwriter-debuginfo-8.3.32-150700.3.15.1 * php8-enchant-debuginfo-8.3.32-150700.3.15.1 * php8-tidy-8.3.32-150700.3.15.1 * php8-fpm-debuginfo-8.3.32-150700.3.15.1 * php8-iconv-8.3.32-150700.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12184.html * https://www.suse.com/security/cve/CVE-2026-14355.html * https://bugzilla.suse.com/show_bug.cgi?id=1270351 * https://bugzilla.suse.com/show_bug.cgi?id=1270712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:30:24 -0000 Subject: SUSE-SU-2026:3163-1: moderate: Security update for pam Message-ID: <178466582485.146.17006797221871945954@1958684a8af1> # Security update for pam Announcement ID: SUSE-SU-2026:3163-1 Release Date: 2026-07-21T14:51:10Z Rating: moderate References: * bsc#1268290 Cross-References: * CVE-2026-54411 CVSS scores: * CVE-2026-54411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-54411 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X * CVE-2026-54411 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for pam fixes the following issue * CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext- password comparison (bsc#1268290). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3163=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3163=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3163=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3163=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3163=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3163=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3163=1 ## Package List: * Development Tools Module 15-SP7 (x86_64) * pam-32bit-debuginfo-1.3.0-150000.6.89.1 * pam-devel-32bit-1.3.0-150000.6.89.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * pam-1.3.0-150000.6.89.1 * pam-extra-debuginfo-1.3.0-150000.6.89.1 * pam-devel-1.3.0-150000.6.89.1 * pam-debugsource-1.3.0-150000.6.89.1 * pam-debuginfo-1.3.0-150000.6.89.1 * pam-extra-1.3.0-150000.6.89.1 * Basesystem Module 15-SP7 (noarch) * pam-doc-1.3.0-150000.6.89.1 * Basesystem Module 15-SP7 (x86_64) * pam-extra-32bit-1.3.0-150000.6.89.1 * pam-32bit-1.3.0-150000.6.89.1 * pam-32bit-debuginfo-1.3.0-150000.6.89.1 * pam-extra-32bit-debuginfo-1.3.0-150000.6.89.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * pam-1.3.0-150000.6.89.1 * pam-debugsource-1.3.0-150000.6.89.1 * pam-debuginfo-1.3.0-150000.6.89.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * pam-1.3.0-150000.6.89.1 * pam-debugsource-1.3.0-150000.6.89.1 * pam-debuginfo-1.3.0-150000.6.89.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * pam-1.3.0-150000.6.89.1 * pam-debugsource-1.3.0-150000.6.89.1 * pam-debuginfo-1.3.0-150000.6.89.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * pam-1.3.0-150000.6.89.1 * pam-debugsource-1.3.0-150000.6.89.1 * pam-debuginfo-1.3.0-150000.6.89.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * pam-1.3.0-150000.6.89.1 * pam-debugsource-1.3.0-150000.6.89.1 * pam-debuginfo-1.3.0-150000.6.89.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54411.html * https://bugzilla.suse.com/show_bug.cgi?id=1268290 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:30:30 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:30:30 -0000 Subject: SUSE-SU-2026:3162-1: moderate: Security update for pam Message-ID: <178466583055.146.17784215965053791685@1958684a8af1> # Security update for pam Announcement ID: SUSE-SU-2026:3162-1 Release Date: 2026-07-21T14:50:38Z Rating: moderate References: * bsc#1268290 Cross-References: * CVE-2026-54411 CVSS scores: * CVE-2026-54411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-54411 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X * CVE-2026-54411 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for pam fixes the following issue * CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext- password comparison (bsc#1268290). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3162=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * pam-extra-debuginfo-1.1.8-24.80.1 * pam-debuginfo-32bit-1.1.8-24.80.1 * pam-extra-debuginfo-32bit-1.1.8-24.80.1 * pam-1.1.8-24.80.1 * pam-devel-1.1.8-24.80.1 * pam-extra-32bit-1.1.8-24.80.1 * pam-32bit-1.1.8-24.80.1 * pam-debuginfo-1.1.8-24.80.1 * pam-extra-1.1.8-24.80.1 * pam-debugsource-1.1.8-24.80.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * pam-doc-1.1.8-24.80.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54411.html * https://bugzilla.suse.com/show_bug.cgi?id=1268290 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:30:38 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:30:38 -0000 Subject: SUSE-SU-2026:3161-1: low: Security update for patch Message-ID: <178466583823.146.14841071816756282958@1958684a8af1> # Security update for patch Announcement ID: SUSE-SU-2026:3161-1 Release Date: 2026-07-21T14:30:37Z Rating: low References: * bsc#1271166 * bsc#1271167 Cross-References: * CVE-2026-56288 * CVE-2026-56289 CVSS scores: * CVE-2026-56288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56288 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56288 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56289 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2026-56289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56289 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56289 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for patch fixes the following issues * CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167). * CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3161=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * patch-2.7.6-150000.5.12.1 * patch-debugsource-2.7.6-150000.5.12.1 * patch-debuginfo-2.7.6-150000.5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56288.html * https://www.suse.com/security/cve/CVE-2026-56289.html * https://bugzilla.suse.com/show_bug.cgi?id=1271166 * https://bugzilla.suse.com/show_bug.cgi?id=1271167 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:30:44 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:30:44 -0000 Subject: SUSE-SU-2026:3160-1: moderate: Security update for python-tornado Message-ID: <178466584439.146.1696557888247033453@1958684a8af1> # Security update for python-tornado Announcement ID: SUSE-SU-2026:3160-1 Release Date: 2026-07-21T14:29:42Z Rating: moderate References: * bsc#1269012 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for python-tornado fixes the following issues: * GHSA-pw6j-qg29-8w7f: `CurlAsyncHTTPClient` leaks per-request credentials on handle reuse (bsc#1269012). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3160=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3160=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3160=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3160=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3160=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3160=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-tornado-debuginfo-4.5.3-150000.3.25.1 * python-tornado-debuginfo-4.5.3-150000.3.25.1 * python3-tornado-4.5.3-150000.3.25.1 * python-tornado-debugsource-4.5.3-150000.3.25.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python3-tornado-debuginfo-4.5.3-150000.3.25.1 * python-tornado-debuginfo-4.5.3-150000.3.25.1 * python3-tornado-4.5.3-150000.3.25.1 * python-tornado-debugsource-4.5.3-150000.3.25.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python3-tornado-debuginfo-4.5.3-150000.3.25.1 * python-tornado-debuginfo-4.5.3-150000.3.25.1 * python3-tornado-4.5.3-150000.3.25.1 * python-tornado-debugsource-4.5.3-150000.3.25.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python3-tornado-debuginfo-4.5.3-150000.3.25.1 * python-tornado-debuginfo-4.5.3-150000.3.25.1 * python3-tornado-4.5.3-150000.3.25.1 * python-tornado-debugsource-4.5.3-150000.3.25.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python3-tornado-debuginfo-4.5.3-150000.3.25.1 * python-tornado-debuginfo-4.5.3-150000.3.25.1 * python3-tornado-4.5.3-150000.3.25.1 * python-tornado-debugsource-4.5.3-150000.3.25.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python3-tornado-debuginfo-4.5.3-150000.3.25.1 * python-tornado-debuginfo-4.5.3-150000.3.25.1 * python3-tornado-4.5.3-150000.3.25.1 * python-tornado-debugsource-4.5.3-150000.3.25.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269012 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:30:50 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:30:50 -0000 Subject: SUSE-SU-2026:3159-1: low: Security update for wpa_supplicant Message-ID: <178466585005.146.16111256468056383790@1958684a8af1> # Security update for wpa_supplicant Announcement ID: SUSE-SU-2026:3159-1 Release Date: 2026-07-21T14:27:38Z Rating: low References: * bsc#1239461 Cross-References: * CVE-2025-24912 CVSS scores: * CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for wpa_supplicant fixes the following issue: * CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3159=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * wpa_supplicant-2.9-23.23.1 * wpa_supplicant-debugsource-2.9-23.23.1 * wpa_supplicant-debuginfo-2.9-23.23.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24912.html * https://bugzilla.suse.com/show_bug.cgi?id=1239461 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:31:01 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:31:01 -0000 Subject: SUSE-RU-2026:3158-1: important: Recommended update for release-notes-sles Message-ID: <178466586187.146.9464557727980055063@1958684a8af1> # Recommended update for release-notes-sles Announcement ID: SUSE-RU-2026:3158-1 Release Date: 2026-07-21T13:59:49Z Rating: important References: * bsc#1236034 * bsc#1247000 * bsc#1252131 * bsc#1254182 * bsc#933411 * jsc#PED-14183 * jsc#PED-15725 * jsc#PED-15955 * jsc#TEAM-2049 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that contains four features and has five fixes can now be installed. ## Description: This update for release-notes-sles fixes the following issues: * Update to version 15.6.20260709 (bsc#933411): * Added overlapping support and deprecation of python3-salt (jsc#PED-14183) * Upgrade Apache HTTP Server to 2.4.66 to resolve HTTP/2 crashes (bsc#1254182, jsc#PED-15955) * Added chronological upgrade action checklist (jsc#DOCTEAM-2049) * Added note about MS SQL Server 2025 legacy hashing algorithms (jsc#PED-15725) * Added Slurm 24.11 release notes (bsc#1236034) * Added note about increased minimum RAM requirement for installation (bsc#1247000) * Added timezone-java deprecation note (bsc#1252131) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3158=1 * SUSE Linux Enterprise Server 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3158=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3158=1 * SUSE Linux Enterprise Desktop 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3158=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3158=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3158=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * release-notes-sles-15.6.20260709-150600.3.22.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * release-notes-sles-15.6.20260709-150600.3.22.1 * SUSE Linux Enterprise High Performance Computing 15 SP6 (noarch) * release-notes-sles-15.6.20260709-150600.3.22.1 * SUSE Linux Enterprise Desktop 15 SP6 (noarch) * release-notes-sles-15.6.20260709-150600.3.22.1 * SUSE Linux Enterprise Server 15 SP6 (noarch) * release-notes-sles-15.6.20260709-150600.3.22.1 * openSUSE Leap 15.6 (noarch) * release-notes-sles-15.6.20260709-150600.3.22.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1236034 * https://bugzilla.suse.com/show_bug.cgi?id=1247000 * https://bugzilla.suse.com/show_bug.cgi?id=1252131 * https://bugzilla.suse.com/show_bug.cgi?id=1254182 * https://bugzilla.suse.com/show_bug.cgi?id=933411 * https://jira.suse.com/browse/PED-14183 * https://jira.suse.com/browse/PED-15725 * https://jira.suse.com/browse/PED-15955 * https://jira.suse.com/browse/TEAM-2049 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:31:17 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:31:17 -0000 Subject: SUSE-RU-2026:3157-1: important: Recommended update for release-notes-sles Message-ID: <178466587736.146.3522759693487299784@1958684a8af1> # Recommended update for release-notes-sles Announcement ID: SUSE-RU-2026:3157-1 Release Date: 2026-07-21T13:58:56Z Rating: important References: * bsc#1219730 * bsc#1246838 * bsc#1247000 * bsc#1254182 * bsc#1256789 * bsc#1257500 * bsc#933411 * jsc#PED-11278 * jsc#PED-11943 * jsc#PED-11986 * jsc#PED-12762 * jsc#PED-12797 * jsc#PED-13323 * jsc#PED-13777 * jsc#PED-13827 * jsc#PED-15725 * jsc#PED-15955 * jsc#PED-9144 * jsc#TEAM-2049 Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains 12 features and has seven fixes can now be installed. ## Description: This update for release-notes-sles fixes the following issues: * Update to version 15.7.20260704 (bsc#933411): * Added note about Apache HTTP Server 2.4.66 to resolve HTTP/2 crashes (bsc#1254182, jsc#PED-15955) * Added chronological upgrade action checklist (jsc#DOCTEAM-2049) * Added note about MS SQL Server 2025 legacy hashing algorithms (jsc#PED-15725) * Added note about increased minimum RAM requirement for installation (bsc#1247000) * Added note about Intel Clearwater Forest CPU (jsc#PED-9144) * Added note about SSSD unprivileged user support (jsc#PED-11986) * Update to version 15.7.20260227 (bsc#933411): * Added note about GFS2 support (bsc#1257500) * Added note about KubeVirt support (bsc#1219730) * Added note about supported nodejs versions (jsc#PED-11943) * Added note about firewalld (jsc#PED-13827) * Added note about python3-ovs renaming (jsc#PED-13323) * Added note about MS Entra ID (jsc#PED-11278) * Added note about PostgreSQL 14 (jsc#PED-13777) * Added note about RMT supporting SLE 16.0 clients (jsc#PED-12797) * Updated kernel limits (bsc#1256789) * Updated Python 3 information (jsc#PED-12762) * Re-added ceph client packages move note (bsc#1246838) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3157=1 SUSE-SLE-Product- SLES-15-SP7-2026-3157=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3157=1 * SUSE Linux Enterprise High Performance Computing 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3157=1 * SUSE Linux Enterprise Desktop 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3157=1 ## Package List: * SUSE Linux Enterprise Server 15 SP7 (noarch) * release-notes-sles-15.7.20260704-150700.3.19.1 * SUSE Linux Enterprise High Performance Computing 15 SP7 (noarch) * release-notes-sles-15.7.20260704-150700.3.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 (noarch) * release-notes-sles-15.7.20260704-150700.3.19.1 * SUSE Linux Enterprise Desktop 15 SP7 (noarch) * release-notes-sles-15.7.20260704-150700.3.19.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1219730 * https://bugzilla.suse.com/show_bug.cgi?id=1246838 * https://bugzilla.suse.com/show_bug.cgi?id=1247000 * https://bugzilla.suse.com/show_bug.cgi?id=1254182 * https://bugzilla.suse.com/show_bug.cgi?id=1256789 * https://bugzilla.suse.com/show_bug.cgi?id=1257500 * https://bugzilla.suse.com/show_bug.cgi?id=933411 * https://jira.suse.com/browse/PED-11278 * https://jira.suse.com/browse/PED-11943 * https://jira.suse.com/browse/PED-11986 * https://jira.suse.com/browse/PED-12762 * https://jira.suse.com/browse/PED-12797 * https://jira.suse.com/browse/PED-13323 * https://jira.suse.com/browse/PED-13777 * https://jira.suse.com/browse/PED-13827 * https://jira.suse.com/browse/PED-15725 * https://jira.suse.com/browse/PED-15955 * https://jira.suse.com/browse/PED-9144 * https://jira.suse.com/browse/TEAM-2049 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:32:38 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:32:38 -0000 Subject: SUSE-SU-2026:3156-1: important: Security update for the Linux Kernel Message-ID: <178466595899.146.6833990226104146398@1958684a8af1> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:3156-1 Release Date: 2026-07-21T13:34:56Z Rating: important References: * bsc#1264484 * bsc#1265421 * bsc#1267365 * bsc#1267369 * bsc#1267494 * bsc#1267567 * bsc#1267591 * bsc#1267618 * bsc#1267635 * bsc#1267684 * bsc#1267722 * bsc#1267918 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268049 * bsc#1268237 * bsc#1268335 * bsc#1268660 * bsc#1268989 * bsc#1269022 * bsc#1269033 * bsc#1269036 * bsc#1269090 * bsc#1269100 * bsc#1269159 * bsc#1269172 * bsc#1269174 * bsc#1269184 * bsc#1269193 * bsc#1269195 * bsc#1269310 * bsc#1269314 * bsc#1269398 * bsc#1269493 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269795 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1269986 * bsc#1269993 * bsc#1270022 * bsc#1270059 * bsc#1270257 * bsc#1271050 * bsc#1271366 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2026-43109 * CVE-2026-46052 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46116 * CVE-2026-46173 * CVE-2026-46229 * CVE-2026-46242 * CVE-2026-46253 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46330 * CVE-2026-46331 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52943 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-52993 * CVE-2026-53016 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53133 * CVE-2026-53178 * CVE-2026-53182 * CVE-2026-53196 * CVE-2026-53253 * CVE-2026-53256 * CVE-2026-53357 * CVE-2026-53359 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46330 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46330 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46330 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 44 vulnerabilities, contains two features and has five security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46330: Revert "net/smc: Introduce TCP ULP support" (bsc#1268049). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271366). The following non security issues were fixed: * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * ipv4: account for fraggap on the paged allocation path (git-fixes). * ipv6: account for fraggap on the paged allocation path (git-fixes). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3156=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3156=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3156=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3156=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3156=1 ## Package List: * openSUSE Leap 15.6 (aarch64) * dtb-apm-6.4.0-150600.23.125.1 * dtb-lg-6.4.0-150600.23.125.1 * kernel-64kb-optional-debuginfo-6.4.0-150600.23.125.1 * kselftests-kmp-64kb-debuginfo-6.4.0-150600.23.125.1 * dlm-kmp-64kb-6.4.0-150600.23.125.1 * dtb-amazon-6.4.0-150600.23.125.1 * cluster-md-kmp-64kb-debuginfo-6.4.0-150600.23.125.1 * dtb-amlogic-6.4.0-150600.23.125.1 * dtb-amd-6.4.0-150600.23.125.1 * kernel-64kb-debuginfo-6.4.0-150600.23.125.1 * dtb-sprd-6.4.0-150600.23.125.1 * kernel-64kb-extra-debuginfo-6.4.0-150600.23.125.1 * dtb-nvidia-6.4.0-150600.23.125.1 * dtb-xilinx-6.4.0-150600.23.125.1 * dtb-mediatek-6.4.0-150600.23.125.1 * kernel-64kb-extra-6.4.0-150600.23.125.1 * ocfs2-kmp-64kb-6.4.0-150600.23.125.1 * reiserfs-kmp-64kb-debuginfo-6.4.0-150600.23.125.1 * ocfs2-kmp-64kb-debuginfo-6.4.0-150600.23.125.1 * kernel-64kb-debugsource-6.4.0-150600.23.125.1 * dtb-renesas-6.4.0-150600.23.125.1 * dtb-arm-6.4.0-150600.23.125.1 * kernel-64kb-devel-debuginfo-6.4.0-150600.23.125.1 * dtb-broadcom-6.4.0-150600.23.125.1 * dtb-altera-6.4.0-150600.23.125.1 * kselftests-kmp-64kb-6.4.0-150600.23.125.1 * kernel-64kb-optional-6.4.0-150600.23.125.1 * dtb-qcom-6.4.0-150600.23.125.1 * cluster-md-kmp-64kb-6.4.0-150600.23.125.1 * dtb-hisilicon-6.4.0-150600.23.125.1 * gfs2-kmp-64kb-debuginfo-6.4.0-150600.23.125.1 * dtb-allwinner-6.4.0-150600.23.125.1 * dtb-exynos-6.4.0-150600.23.125.1 * dtb-apple-6.4.0-150600.23.125.1 * dtb-marvell-6.4.0-150600.23.125.1 * kernel-64kb-devel-6.4.0-150600.23.125.1 * dtb-cavium-6.4.0-150600.23.125.1 * reiserfs-kmp-64kb-6.4.0-150600.23.125.1 * dtb-freescale-6.4.0-150600.23.125.1 * dtb-rockchip-6.4.0-150600.23.125.1 * dlm-kmp-64kb-debuginfo-6.4.0-150600.23.125.1 * gfs2-kmp-64kb-6.4.0-150600.23.125.1 * dtb-socionext-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * kernel-default-livepatch-6.4.0-150600.23.125.1 * kernel-default-extra-debuginfo-6.4.0-150600.23.125.1 * kernel-default-optional-debuginfo-6.4.0-150600.23.125.1 * kselftests-kmp-default-6.4.0-150600.23.125.1 * kernel-default-devel-6.4.0-150600.23.125.1 * kernel-default-debuginfo-6.4.0-150600.23.125.1 * dlm-kmp-default-6.4.0-150600.23.125.1 * reiserfs-kmp-default-6.4.0-150600.23.125.1 * kernel-obs-build-debugsource-6.4.0-150600.23.125.1 * kernel-default-debugsource-6.4.0-150600.23.125.1 * kernel-obs-build-6.4.0-150600.23.125.1 * cluster-md-kmp-default-debuginfo-6.4.0-150600.23.125.1 * ocfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1 * kselftests-kmp-default-debuginfo-6.4.0-150600.23.125.1 * kernel-syms-6.4.0-150600.23.125.1 * kernel-default-optional-6.4.0-150600.23.125.1 * dlm-kmp-default-debuginfo-6.4.0-150600.23.125.1 * cluster-md-kmp-default-6.4.0-150600.23.125.1 * ocfs2-kmp-default-6.4.0-150600.23.125.1 * reiserfs-kmp-default-debuginfo-6.4.0-150600.23.125.1 * kernel-default-devel-debuginfo-6.4.0-150600.23.125.1 * gfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1 * kernel-obs-qa-6.4.0-150600.23.125.1 * kernel-default-extra-6.4.0-150600.23.125.1 * gfs2-kmp-default-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (aarch64 ppc64le x86_64) * kernel-kvmsmall-devel-debuginfo-6.4.0-150600.23.125.1 * kernel-kvmsmall-devel-6.4.0-150600.23.125.1 * kernel-kvmsmall-debuginfo-6.4.0-150600.23.125.1 * kernel-default-base-6.4.0-150600.23.125.1.150600.12.58.3 * kernel-default-base-rebuild-6.4.0-150600.23.125.1.150600.12.58.3 * kernel-kvmsmall-debugsource-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (noarch) * kernel-source-vanilla-6.4.0-150600.23.125.1 * kernel-macros-6.4.0-150600.23.125.1 * kernel-devel-6.4.0-150600.23.125.1 * kernel-docs-html-6.4.0-150600.23.125.1 * kernel-source-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (nosrc s390x) * kernel-zfcpdump-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_29-debugsource-1-150600.13.7.1 * kernel-livepatch-6_4_0-150600_23_125-default-1-150600.13.7.1 * kernel-livepatch-6_4_0-150600_23_125-default-debuginfo-1-150600.13.7.1 * kernel-default-livepatch-devel-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (aarch64 nosrc ppc64le x86_64) * kernel-kvmsmall-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (ppc64le x86_64) * kernel-debug-debugsource-6.4.0-150600.23.125.1 * kernel-debug-devel-debuginfo-6.4.0-150600.23.125.1 * kernel-debug-devel-6.4.0-150600.23.125.1 * kernel-debug-debuginfo-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (nosrc) * dtb-aarch64-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (noarch nosrc) * kernel-docs-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (aarch64 nosrc) * kernel-64kb-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (nosrc ppc64le x86_64) * kernel-debug-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (s390x) * kernel-zfcpdump-debuginfo-6.4.0-150600.23.125.1 * kernel-zfcpdump-debugsource-6.4.0-150600.23.125.1 * openSUSE Leap 15.6 (x86_64) * kernel-debug-vdso-debuginfo-6.4.0-150600.23.125.1 * kernel-kvmsmall-vdso-6.4.0-150600.23.125.1 * kernel-kvmsmall-vdso-debuginfo-6.4.0-150600.23.125.1 * kernel-default-vdso-6.4.0-150600.23.125.1 * kernel-debug-vdso-6.4.0-150600.23.125.1 * kernel-default-vdso-debuginfo-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch nosrc) * kernel-docs-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * kernel-syms-6.4.0-150600.23.125.1 * kernel-default-devel-6.4.0-150600.23.125.1 * kernel-default-debuginfo-6.4.0-150600.23.125.1 * dlm-kmp-default-6.4.0-150600.23.125.1 * reiserfs-kmp-default-6.4.0-150600.23.125.1 * kernel-obs-build-debugsource-6.4.0-150600.23.125.1 * cluster-md-kmp-default-6.4.0-150600.23.125.1 * dlm-kmp-default-debuginfo-6.4.0-150600.23.125.1 * kernel-default-debugsource-6.4.0-150600.23.125.1 * kernel-obs-build-6.4.0-150600.23.125.1 * reiserfs-kmp-default-debuginfo-6.4.0-150600.23.125.1 * ocfs2-kmp-default-6.4.0-150600.23.125.1 * cluster-md-kmp-default-debuginfo-6.4.0-150600.23.125.1 * gfs2-kmp-default-6.4.0-150600.23.125.1 * ocfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1 * kernel-default-devel-debuginfo-6.4.0-150600.23.125.1 * gfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * kernel-macros-6.4.0-150600.23.125.1 * kernel-devel-6.4.0-150600.23.125.1 * kernel-source-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 nosrc) * kernel-64kb-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64) * kernel-64kb-debugsource-6.4.0-150600.23.125.1 * kernel-64kb-debuginfo-6.4.0-150600.23.125.1 * kernel-64kb-devel-6.4.0-150600.23.125.1 * kernel-64kb-devel-debuginfo-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-150600.23.125.1.150600.12.58.3 * SUSE Linux Enterprise Server 15 SP6 LTSS (s390x) * kernel-zfcpdump-debuginfo-6.4.0-150600.23.125.1 * kernel-zfcpdump-debugsource-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (nosrc s390x) * kernel-zfcpdump-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (nosrc ppc64le x86_64) * kernel-default-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * kernel-syms-6.4.0-150600.23.125.1 * kernel-default-devel-6.4.0-150600.23.125.1 * kernel-default-debuginfo-6.4.0-150600.23.125.1 * dlm-kmp-default-6.4.0-150600.23.125.1 * reiserfs-kmp-default-6.4.0-150600.23.125.1 * kernel-obs-build-debugsource-6.4.0-150600.23.125.1 * dlm-kmp-default-debuginfo-6.4.0-150600.23.125.1 * cluster-md-kmp-default-6.4.0-150600.23.125.1 * kernel-default-debugsource-6.4.0-150600.23.125.1 * kernel-obs-build-6.4.0-150600.23.125.1 * reiserfs-kmp-default-debuginfo-6.4.0-150600.23.125.1 * ocfs2-kmp-default-6.4.0-150600.23.125.1 * cluster-md-kmp-default-debuginfo-6.4.0-150600.23.125.1 * gfs2-kmp-default-6.4.0-150600.23.125.1 * ocfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1 * kernel-default-base-6.4.0-150600.23.125.1.150600.12.58.3 * kernel-default-devel-debuginfo-6.4.0-150600.23.125.1 * gfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * kernel-macros-6.4.0-150600.23.125.1 * kernel-devel-6.4.0-150600.23.125.1 * kernel-source-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch nosrc) * kernel-docs-6.4.0-150600.23.125.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-default-debuginfo-6.4.0-150600.23.125.1 * kernel-default-livepatch-6.4.0-150600.23.125.1 * kernel-livepatch-6_4_0-150600_23_125-default-debuginfo-1-150600.13.7.1 * kernel-default-debugsource-6.4.0-150600.23.125.1 * kernel-default-livepatch-devel-6.4.0-150600.23.125.1 * kernel-livepatch-SLE15-SP6_Update_29-debugsource-1-150600.13.7.1 * kernel-livepatch-6_4_0-150600_23_125-default-1-150600.13.7.1 * SUSE Linux Enterprise Live Patching 15-SP6 (nosrc) * kernel-default-6.4.0-150600.23.125.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150600.23.125.1 * kernel-default-debuginfo-6.4.0-150600.23.125.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (nosrc) * kernel-default-6.4.0-150600.23.125.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46330.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268049 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:32:47 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:32:47 -0000 Subject: SUSE-SU-2026:3155-1: moderate: Security update for python-tornado6 Message-ID: <178466596711.146.7744539616394576454@1958684a8af1> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:3155-1 Release Date: 2026-07-21T12:58:53Z Rating: moderate References: * bsc#1269012 Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for python-tornado6 fixes the following issue * GHSA-pw6j-qg29-8w7f: `CurlAsyncHTTPClient` leaks per-request credentials on handle reuse (bsc#1269012). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3155=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3155=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.21.1 * python-tornado6-debugsource-6.3.2-150400.9.21.1 * python311-tornado6-6.3.2-150400.9.21.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-tornado6-6.3.2-150400.9.21.1 * python311-tornado6-debuginfo-6.3.2-150400.9.21.1 * python-tornado6-debugsource-6.3.2-150400.9.21.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269012 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:32:53 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:32:53 -0000 Subject: SUSE-SU-2026:3154-1: moderate: Security update for nghttp2 Message-ID: <178466597346.146.16079380685139888594@1958684a8af1> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:3154-1 Release Date: 2026-07-21T12:55:40Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3154=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libnghttp2-devel-1.39.2-3.26.1 * nghttp2-debuginfo-1.39.2-3.26.1 * nghttp2-debugsource-1.39.2-3.26.1 * libnghttp2-14-debuginfo-32bit-1.39.2-3.26.1 * libnghttp2-14-32bit-1.39.2-3.26.1 * libnghttp2-14-1.39.2-3.26.1 * libnghttp2-14-debuginfo-1.39.2-3.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:32:59 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:32:59 -0000 Subject: SUSE-SU-2026:3153-1: moderate: Security update for nghttp2 Message-ID: <178466597954.146.9531374003067939497@1958684a8af1> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:3153-1 Release Date: 2026-07-21T12:54:31Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3153=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3153=1 ## Package List: * openSUSE Leap 15.6 (x86_64) * libnghttp2-14-32bit-1.40.0-150600.25.8.1 * libnghttp2_asio1-32bit-1.40.0-150600.25.8.1 * libnghttp2_asio1-32bit-debuginfo-1.40.0-150600.25.8.1 * libnghttp2-14-32bit-debuginfo-1.40.0-150600.25.8.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * nghttp2-1.40.0-150600.25.8.1 * python3-nghttp2-1.40.0-150600.25.8.1 * libnghttp2-14-debuginfo-1.40.0-150600.25.8.1 * nghttp2-debuginfo-1.40.0-150600.25.8.1 * libnghttp2-devel-1.40.0-150600.25.8.1 * libnghttp2_asio1-1.40.0-150600.25.8.1 * libnghttp2-14-1.40.0-150600.25.8.1 * libnghttp2_asio1-debuginfo-1.40.0-150600.25.8.1 * python3-nghttp2-debuginfo-1.40.0-150600.25.8.1 * nghttp2-python-debugsource-1.40.0-150600.25.8.1 * nghttp2-debugsource-1.40.0-150600.25.8.1 * libnghttp2_asio-devel-1.40.0-150600.25.8.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libnghttp2_asio1-64bit-debuginfo-1.40.0-150600.25.8.1 * libnghttp2-14-64bit-debuginfo-1.40.0-150600.25.8.1 * libnghttp2_asio1-64bit-1.40.0-150600.25.8.1 * libnghttp2-14-64bit-1.40.0-150600.25.8.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * nghttp2-debuginfo-1.40.0-150600.25.8.1 * libnghttp2_asio1-1.40.0-150600.25.8.1 * libnghttp2_asio1-debuginfo-1.40.0-150600.25.8.1 * nghttp2-debugsource-1.40.0-150600.25.8.1 * libnghttp2_asio-devel-1.40.0-150600.25.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:33:17 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:33:17 -0000 Subject: SUSE-SU-2026:3152-1: important: Security update for aws-nitro-enclaves-cli Message-ID: <178466599712.146.14470280052739872182@1958684a8af1> # Security update for aws-nitro-enclaves-cli Announcement ID: SUSE-SU-2026:3152-1 Release Date: 2026-07-21T12:51:48Z Rating: important References: * bsc#1270492 * bsc#1270542 * bsc#1270705 * bsc#1270747 * bsc#1270839 * bsc#1270932 * bsc#1270952 Cross-References: * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for aws-nitro-enclaves-cli fixes the following issues * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270542). * CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270705). * CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()` writing past caller buffer with no length check (bsc#1270747). * CVE-2026-41898: openssl: information leak to network peers due to unchecked callback-returned length in PSK and cookie generate trampolines (bsc#1270839). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270492). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270932). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffers (bsc#1270952). Changes for aws-nitro-enclaves-cli: * Update to version 1.4.5. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3152=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3152=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3152=1 ## Package List: * Public Cloud Module 15-SP7 (aarch64 x86_64) * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-150600.10.12.1 * system-group-ne-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1 * openSUSE Leap 15.6 (aarch64 x86_64) * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-150600.10.12.1 * system-group-ne-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1 * Public Cloud Module 15-SP6 (aarch64 x86_64) * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-150600.10.12.1 * system-group-ne-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-150600.10.12.1 * aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270492 * https://bugzilla.suse.com/show_bug.cgi?id=1270542 * https://bugzilla.suse.com/show_bug.cgi?id=1270705 * https://bugzilla.suse.com/show_bug.cgi?id=1270747 * https://bugzilla.suse.com/show_bug.cgi?id=1270839 * https://bugzilla.suse.com/show_bug.cgi?id=1270932 * https://bugzilla.suse.com/show_bug.cgi?id=1270952 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:33:42 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:33:42 -0000 Subject: SUSE-SU-2026:3151-1: important: Security update for go1.25-openssl Message-ID: <178466602232.146.9758839107302846815@1958684a8af1> # Security update for go1.25-openssl Announcement ID: SUSE-SU-2026:3151-1 Release Date: 2026-07-21T12:48:54Z Rating: important References: * bsc#1244485 * bsc#1245878 * bsc#1259264 * bsc#1259265 * bsc#1259268 * bsc#1264394 * bsc#1267442 * bsc#1267444 * bsc#1267450 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-25679 * CVE-2026-27139 * CVE-2026-27142 * CVE-2026-27145 * CVE-2026-39822 * CVE-2026-42504 * CVE-2026-42505 * CVE-2026-42507 CVSS scores: * CVE-2026-25679 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27139 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27142 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities, contains two features and has three security fixes can now be installed. ## Description: This update for go1.25-openssl fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). * CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3151=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3151=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3151=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3151=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * go1.25-openssl-1.25.12-150600.13.21.1 * go1.25-openssl-debuginfo-1.25.12-150600.13.21.1 * go1.25-openssl-doc-1.25.12-150600.13.21.1 * go1.25-openssl-race-1.25.12-150600.13.21.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * go1.25-openssl-1.25.12-150600.13.21.1 * go1.25-openssl-debuginfo-1.25.12-150600.13.21.1 * go1.25-openssl-doc-1.25.12-150600.13.21.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * go1.25-openssl-race-1.25.12-150600.13.21.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-openssl-1.25.12-150600.13.21.1 * go1.25-openssl-debuginfo-1.25.12-150600.13.21.1 * go1.25-openssl-doc-1.25.12-150600.13.21.1 * go1.25-openssl-race-1.25.12-150600.13.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * go1.25-openssl-1.25.12-150600.13.21.1 * go1.25-openssl-debuginfo-1.25.12-150600.13.21.1 * go1.25-openssl-doc-1.25.12-150600.13.21.1 * go1.25-openssl-race-1.25.12-150600.13.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25679.html * https://www.suse.com/security/cve/CVE-2026-27139.html * https://www.suse.com/security/cve/CVE-2026-27142.html * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1259264 * https://bugzilla.suse.com/show_bug.cgi?id=1259265 * https://bugzilla.suse.com/show_bug.cgi?id=1259268 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:33:54 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:33:54 -0000 Subject: SUSE-SU-2026:3150-1: low: Security update for iproute2 Message-ID: <178466603492.146.7270572802638584037@1958684a8af1> # Security update for iproute2 Announcement ID: SUSE-SU-2026:3150-1 Release Date: 2026-07-21T12:46:50Z Rating: low References: * bsc#1254324 Cross-References: * CVE-2024-58251 CVSS scores: * CVE-2024-58251 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-58251 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-58251 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for iproute2 fixes the following issue * CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254324). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3150=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * iproute2-4.12-16.9.1 * iproute2-debuginfo-4.12-16.9.1 * iproute2-debugsource-4.12-16.9.1 * libnetlink-devel-4.12-16.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-58251.html * https://bugzilla.suse.com/show_bug.cgi?id=1254324 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:34:01 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:34:01 -0000 Subject: SUSE-SU-2026:3149-1: moderate: Security update for ffmpeg Message-ID: <178466604108.146.6320054957489747540@1958684a8af1> # Security update for ffmpeg Announcement ID: SUSE-SU-2026:3149-1 Release Date: 2026-07-21T12:46:41Z Rating: moderate References: * bsc#1249431 Cross-References: * CVE-2025-10256 CVSS scores: * CVE-2025-10256 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-10256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-10256 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-10256 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for ffmpeg fixes the following issue * CVE-2025-10256: NULL pointer dereference in Firequalizer filter (bsc#1249431). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3149=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3149=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3149=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libavdevice57-3.4.2-150200.11.70.1 * ffmpeg-3.4.2-150200.11.70.1 * libavformat57-debuginfo-3.4.2-150200.11.70.1 * libavdevice57-debuginfo-3.4.2-150200.11.70.1 * libavfilter6-3.4.2-150200.11.70.1 * ffmpeg-debuginfo-3.4.2-150200.11.70.1 * libavresample3-3.4.2-150200.11.70.1 * libavresample3-debuginfo-3.4.2-150200.11.70.1 * ffmpeg-debugsource-3.4.2-150200.11.70.1 * libavformat57-3.4.2-150200.11.70.1 * libavfilter6-debuginfo-3.4.2-150200.11.70.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libavutil55-3.4.2-150200.11.70.1 * libpostproc54-debuginfo-3.4.2-150200.11.70.1 * libavutil55-debuginfo-3.4.2-150200.11.70.1 * libswscale4-3.4.2-150200.11.70.1 * libpostproc54-3.4.2-150200.11.70.1 * libswscale-devel-3.4.2-150200.11.70.1 * libswresample2-debuginfo-3.4.2-150200.11.70.1 * libavcodec57-3.4.2-150200.11.70.1 * libswresample-devel-3.4.2-150200.11.70.1 * libavcodec57-debuginfo-3.4.2-150200.11.70.1 * ffmpeg-debuginfo-3.4.2-150200.11.70.1 * libavutil-devel-3.4.2-150200.11.70.1 * libswscale4-debuginfo-3.4.2-150200.11.70.1 * libswresample2-3.4.2-150200.11.70.1 * libpostproc-devel-3.4.2-150200.11.70.1 * ffmpeg-debugsource-3.4.2-150200.11.70.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * libavcodec-devel-3.4.2-150200.11.70.1 * libavformat57-debuginfo-3.4.2-150200.11.70.1 * ffmpeg-debuginfo-3.4.2-150200.11.70.1 * libavformat-devel-3.4.2-150200.11.70.1 * libavresample3-debuginfo-3.4.2-150200.11.70.1 * libavresample3-3.4.2-150200.11.70.1 * ffmpeg-debugsource-3.4.2-150200.11.70.1 * libavresample-devel-3.4.2-150200.11.70.1 * libavformat57-3.4.2-150200.11.70.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10256.html * https://bugzilla.suse.com/show_bug.cgi?id=1249431 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 21 20:34:13 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 21 Jul 2026 20:34:13 -0000 Subject: SUSE-SU-2026:3148-1: important: Security update for wget Message-ID: <178466605372.146.15131838221457884467@1958684a8af1> # Security update for wget Announcement ID: SUSE-SU-2026:3148-1 Release Date: 2026-07-21T12:45:02Z Rating: important References: * bsc#1233773 * bsc#1271033 * bsc#1271034 * bsc#1271035 * bsc#1271036 * bsc#1271320 Cross-References: * CVE-2024-10524 * CVE-2026-15146 * CVE-2026-58469 * CVE-2026-58470 * CVE-2026-58471 * CVE-2026-58472 CVSS scores: * CVE-2024-10524 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2024-10524 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2024-10524 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2026-15146 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-15146 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-15146 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58469 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58469 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58470 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58470 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58470 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58470 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58471 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-58471 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58471 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58471 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58471 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58472 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-58472 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58472 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58472 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58472 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for wget fixes the following issues: * CVE-2026-15146: unvalidated IP address in an FTP PASV response can lead to server-side request forgery (bsc#1271320). * CVE-2026-58469: Metalink document containing a whitespace-only URL can cause a heap buffer underread (bsc#1271033). * CVE-2026-58470: server-controlled values can cause an integer overflow in parse_content_range() (bsc#1271034). * CVE-2026-58471: server-supplied filenames requiring character set conversion could lead to heap memory corruption (bsc#1271035). * CVE-2026-58472: crafted HTML attribute with a large number of characters can lead to a heap buffer overflow (bsc#1271036). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3148=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * wget-1.24.5-150700.3.3.1 * wget-debuginfo-1.24.5-150700.3.3.1 * wget-debugsource-1.24.5-150700.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-10524.html * https://www.suse.com/security/cve/CVE-2026-15146.html * https://www.suse.com/security/cve/CVE-2026-58469.html * https://www.suse.com/security/cve/CVE-2026-58470.html * https://www.suse.com/security/cve/CVE-2026-58471.html * https://www.suse.com/security/cve/CVE-2026-58472.html * https://bugzilla.suse.com/show_bug.cgi?id=1233773 * https://bugzilla.suse.com/show_bug.cgi?id=1271033 * https://bugzilla.suse.com/show_bug.cgi?id=1271034 * https://bugzilla.suse.com/show_bug.cgi?id=1271035 * https://bugzilla.suse.com/show_bug.cgi?id=1271036 * https://bugzilla.suse.com/show_bug.cgi?id=1271320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 08:43:45 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 08:43:45 -0000 Subject: SUSE-SU-2026:3166-1: important: Security update for the Linux Kernel Message-ID: <178470982540.55.7599216053524187310@cbbac00f79c6> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:3166-1 Release Date: 2026-07-21T17:09:31Z Rating: important References: * bsc#1204315 * bsc#1243603 * bsc#1251942 * bsc#1256564 * bsc#1257605 * bsc#1257777 * bsc#1260012 * bsc#1260593 * bsc#1261250 * bsc#1261562 * bsc#1262391 * bsc#1262603 * bsc#1262605 * bsc#1262614 * bsc#1262637 * bsc#1262639 * bsc#1262649 * bsc#1262653 * bsc#1262658 * bsc#1262659 * bsc#1262678 * bsc#1262723 * bsc#1262751 * bsc#1262757 * bsc#1262765 * bsc#1262768 * bsc#1262992 * bsc#1263008 * bsc#1263011 * bsc#1263013 * bsc#1263014 * bsc#1263016 * bsc#1263017 * bsc#1263020 * bsc#1263025 * bsc#1263030 * bsc#1263031 * bsc#1263045 * bsc#1263055 * bsc#1263059 * bsc#1263068 * bsc#1263073 * bsc#1263075 * bsc#1263077 * bsc#1263097 * bsc#1263111 * bsc#1263128 * bsc#1263134 * bsc#1263139 * bsc#1263142 * bsc#1263145 * bsc#1263167 * bsc#1263173 * bsc#1263175 * bsc#1263491 * bsc#1263493 * bsc#1263495 * bsc#1263539 * bsc#1263562 * bsc#1263598 * bsc#1263657 * bsc#1263776 * bsc#1263777 * bsc#1263778 * bsc#1263780 * bsc#1263782 * bsc#1263785 * bsc#1263786 * bsc#1263806 * bsc#1263876 * bsc#1263904 * bsc#1263905 * bsc#1263911 * bsc#1263923 * bsc#1263975 * bsc#1263999 * bsc#1264003 * bsc#1264006 * bsc#1264008 * bsc#1264009 * bsc#1264019 * bsc#1264030 * bsc#1264032 * bsc#1264033 * bsc#1264035 * bsc#1264039 * bsc#1264041 * bsc#1264044 * bsc#1264048 * bsc#1264056 * bsc#1264065 * bsc#1264070 * bsc#1264071 * bsc#1264073 * bsc#1264074 * bsc#1264075 * bsc#1264079 * bsc#1264088 * bsc#1264100 * bsc#1264101 * bsc#1264110 * bsc#1264121 * bsc#1264122 * bsc#1264125 * bsc#1264129 * bsc#1264142 * bsc#1264180 * bsc#1264188 * bsc#1264189 * bsc#1264190 * bsc#1264197 * bsc#1264237 * bsc#1264247 * bsc#1264257 * bsc#1264270 * bsc#1264296 * bsc#1264302 * bsc#1264304 * bsc#1264308 * bsc#1264313 * bsc#1264315 * bsc#1264317 * bsc#1264321 * bsc#1264322 * bsc#1264328 * bsc#1264331 * bsc#1264336 * bsc#1264338 * bsc#1264339 * bsc#1264340 * bsc#1264365 * bsc#1264377 * bsc#1264379 * bsc#1264386 * bsc#1264387 * bsc#1264388 * bsc#1264414 * bsc#1264416 * bsc#1264417 * bsc#1264419 * bsc#1264423 * bsc#1264424 * bsc#1264425 * bsc#1264429 * bsc#1264431 * bsc#1264436 * bsc#1264442 * bsc#1264451 * bsc#1264473 * bsc#1264477 * bsc#1264479 * bsc#1264480 * bsc#1264520 * bsc#1264526 * bsc#1264531 * bsc#1264538 * bsc#1264540 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264553 * bsc#1264556 * bsc#1264560 * bsc#1264564 * bsc#1264580 * bsc#1264584 * bsc#1264590 * bsc#1264592 * bsc#1264594 * bsc#1264598 * bsc#1264600 * bsc#1264613 * bsc#1264615 * bsc#1264616 * bsc#1264618 * bsc#1264620 * bsc#1264624 * bsc#1264626 * bsc#1264630 * bsc#1264633 * bsc#1264637 * bsc#1264640 * bsc#1264642 * bsc#1264644 * bsc#1264645 * bsc#1264668 * bsc#1264677 * bsc#1264731 * bsc#1264739 * bsc#1264744 * bsc#1264746 * bsc#1264758 * bsc#1264768 * bsc#1264780 * bsc#1264781 * bsc#1264782 * bsc#1264783 * bsc#1264785 * bsc#1264788 * bsc#1264790 * bsc#1264791 * bsc#1264794 * bsc#1264803 * bsc#1264809 * bsc#1264815 * bsc#1264816 * bsc#1264819 * bsc#1264821 * bsc#1264822 * bsc#1264826 * bsc#1264830 * bsc#1264835 * bsc#1264837 * bsc#1264844 * bsc#1264846 * bsc#1264853 * bsc#1264978 * bsc#1264987 * bsc#1264988 * bsc#1264991 * bsc#1264993 * bsc#1264997 * bsc#1265019 * bsc#1265023 * bsc#1265032 * bsc#1265037 * bsc#1265041 * bsc#1265047 * bsc#1265054 * bsc#1265074 * bsc#1265078 * bsc#1265079 * bsc#1265080 * bsc#1265089 * bsc#1265092 * bsc#1265093 * bsc#1265096 * bsc#1265100 * bsc#1265101 * bsc#1265102 * bsc#1265105 * bsc#1265112 * bsc#1265133 * bsc#1265138 * bsc#1265142 * bsc#1265249 * bsc#1265257 * bsc#1265264 * bsc#1265627 * bsc#1266000 * bsc#1266003 * bsc#1266399 * bsc#1266411 * bsc#1266412 * bsc#1266458 * bsc#1266467 * bsc#1266468 * bsc#1266677 * bsc#1266679 * bsc#1266684 * bsc#1266686 * bsc#1266688 * bsc#1266692 * bsc#1266703 * bsc#1266707 * bsc#1266721 * bsc#1266722 * bsc#1266726 * bsc#1266729 * bsc#1266732 * bsc#1266739 * bsc#1266740 * bsc#1266741 * bsc#1266743 * bsc#1266744 * bsc#1266751 * bsc#1266755 * bsc#1266762 * bsc#1266773 * bsc#1266774 * bsc#1266775 * bsc#1266777 * bsc#1266780 * bsc#1266805 * bsc#1266806 * bsc#1266831 * bsc#1266832 * bsc#1266834 * bsc#1266836 * bsc#1266838 * bsc#1266839 * bsc#1266841 * bsc#1266842 * bsc#1266846 * bsc#1266854 * bsc#1266855 * bsc#1266863 * bsc#1266864 * bsc#1266870 * bsc#1266872 * bsc#1266879 * bsc#1266883 * bsc#1266884 * bsc#1266886 * bsc#1266893 * bsc#1266894 * bsc#1266898 * bsc#1266908 * bsc#1266910 * bsc#1266917 * bsc#1266920 * bsc#1266925 * bsc#1266934 * bsc#1266935 * bsc#1266939 * bsc#1266947 * bsc#1267021 * bsc#1267027 * bsc#1267198 * bsc#1267204 * bsc#1267213 * bsc#1267226 * bsc#1267234 * bsc#1267251 * bsc#1267360 * bsc#1267367 * bsc#1267380 * bsc#1267432 * bsc#1267435 * bsc#1267436 * bsc#1267445 * bsc#1267448 * bsc#1267449 * bsc#1267466 * bsc#1267472 * bsc#1267473 * bsc#1267479 * bsc#1267491 * bsc#1267493 * bsc#1267494 * bsc#1267495 * bsc#1267496 * bsc#1267497 * bsc#1267502 * bsc#1267524 * bsc#1267555 * bsc#1267565 * bsc#1267571 * bsc#1267583 * bsc#1267592 * bsc#1267595 * bsc#1267611 * bsc#1267615 * bsc#1267616 * bsc#1267618 * bsc#1267623 * bsc#1267627 * bsc#1267630 * bsc#1267632 * bsc#1267636 * bsc#1267638 * bsc#1267643 * bsc#1267646 * bsc#1267649 * bsc#1267658 * bsc#1267661 * bsc#1267666 * bsc#1267667 * bsc#1267669 * bsc#1267676 * bsc#1267677 * bsc#1267680 * bsc#1267683 * bsc#1267690 * bsc#1267691 * bsc#1267693 * bsc#1267701 * bsc#1267702 * bsc#1267704 * bsc#1267712 * bsc#1267719 * bsc#1267725 * bsc#1267728 * bsc#1267922 * bsc#1267932 * bsc#1267939 * bsc#1267948 * bsc#1267968 * bsc#1267987 * bsc#1267990 * bsc#1267991 * bsc#1267992 * bsc#1267994 * bsc#1268024 * bsc#1268049 * bsc#1268051 * bsc#1268220 * bsc#1268221 * bsc#1268223 * bsc#1268981 * bsc#1268986 * bsc#1268989 * bsc#1269001 * bsc#1269002 * bsc#1269008 * bsc#1269025 * bsc#1269030 * bsc#1269031 * bsc#1269036 * bsc#1269081 * bsc#1269095 * bsc#1269098 * bsc#1269106 * bsc#1269111 * bsc#1269116 * bsc#1269124 * bsc#1269125 * bsc#1269129 * bsc#1269131 * bsc#1269133 * bsc#1269141 * bsc#1269151 * bsc#1269153 * bsc#1269159 * bsc#1269164 * bsc#1269172 * bsc#1269174 * bsc#1269177 * bsc#1269178 * bsc#1269187 * bsc#1269188 * bsc#1269190 * bsc#1269193 * bsc#1269230 * bsc#1269236 * bsc#1269239 * bsc#1269245 * bsc#1269254 * bsc#1269255 * bsc#1269257 * bsc#1269258 * bsc#1269262 * bsc#1269273 * bsc#1269283 * bsc#1269304 * bsc#1269364 * bsc#1269378 * bsc#1269385 * bsc#1269386 * bsc#1269389 * bsc#1269392 * bsc#1269403 * bsc#1269404 * bsc#1269410 * bsc#1269414 * bsc#1269493 * bsc#1269505 * bsc#1269527 * bsc#1269532 * bsc#1269537 * bsc#1269556 * bsc#1269587 * bsc#1269637 * bsc#1269644 * bsc#1269645 * bsc#1269646 * bsc#1269651 * bsc#1269652 * bsc#1269654 * bsc#1269661 * bsc#1269663 * bsc#1269669 * bsc#1269670 * bsc#1269674 * bsc#1269675 * bsc#1269677 * bsc#1269680 * bsc#1269682 * bsc#1269684 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269709 * bsc#1269710 * bsc#1269711 * bsc#1269719 * bsc#1269726 * bsc#1269733 * bsc#1269768 * bsc#1269770 * bsc#1269772 * bsc#1269786 * bsc#1269795 * bsc#1269796 * bsc#1269799 * bsc#1269809 * bsc#1269811 * bsc#1269814 * bsc#1269817 * bsc#1269826 * bsc#1269877 * bsc#1269886 * bsc#1269889 * bsc#1269898 * bsc#1269899 * bsc#1269904 * bsc#1269976 * bsc#1269984 * bsc#1269986 * bsc#1269988 * bsc#1269989 * bsc#1269992 * bsc#1269993 * bsc#1269996 * bsc#1269997 * bsc#1269998 * bsc#1270022 * bsc#1270042 * bsc#1270058 * bsc#1270059 * bsc#1270112 * bsc#1270226 * bsc#1270241 * bsc#1270244 * bsc#1270248 * bsc#1270249 * bsc#1270257 * bsc#1270260 * bsc#1270263 * bsc#1270268 * bsc#1270302 * bsc#1270396 * bsc#1271040 * bsc#1271050 * bsc#1271248 * bsc#1271249 * bsc#1271287 * bsc#1271366 * bsc#1271402 * jsc#PED-15897 Cross-References: * CVE-2023-20585 * CVE-2025-71274 * CVE-2025-71286 * CVE-2025-71291 * CVE-2025-71297 * CVE-2025-71302 * CVE-2025-71305 * CVE-2025-71314 * CVE-2026-23276 * CVE-2026-31430 * CVE-2026-31439 * CVE-2026-31440 * CVE-2026-31441 * CVE-2026-31447 * CVE-2026-31474 * CVE-2026-31479 * CVE-2026-31485 * CVE-2026-31497 * CVE-2026-31498 * CVE-2026-31503 * CVE-2026-31509 * CVE-2026-31510 * CVE-2026-31511 * CVE-2026-31513 * CVE-2026-31520 * CVE-2026-31522 * CVE-2026-31523 * CVE-2026-31524 * CVE-2026-31532 * CVE-2026-31540 * CVE-2026-31545 * CVE-2026-31548 * CVE-2026-31549 * CVE-2026-31551 * CVE-2026-31552 * CVE-2026-31561 * CVE-2026-31566 * CVE-2026-31568 * CVE-2026-31576 * CVE-2026-31578 * CVE-2026-31581 * CVE-2026-31583 * CVE-2026-31585 * CVE-2026-31587 * CVE-2026-31599 * CVE-2026-31603 * CVE-2026-31604 * CVE-2026-31605 * CVE-2026-31615 * CVE-2026-31616 * CVE-2026-31617 * CVE-2026-31618 * CVE-2026-31619 * CVE-2026-31623 * CVE-2026-31624 * CVE-2026-31625 * CVE-2026-31626 * CVE-2026-31627 * CVE-2026-31651 * CVE-2026-31657 * CVE-2026-31659 * CVE-2026-31660 * CVE-2026-31661 * CVE-2026-31667 * CVE-2026-31672 * CVE-2026-31678 * CVE-2026-31687 * CVE-2026-31701 * CVE-2026-31720 * CVE-2026-31726 * CVE-2026-31727 * CVE-2026-31728 * CVE-2026-31730 * CVE-2026-31747 * CVE-2026-31748 * CVE-2026-31749 * CVE-2026-31751 * CVE-2026-31754 * CVE-2026-31755 * CVE-2026-31756 * CVE-2026-31761 * CVE-2026-31762 * CVE-2026-31763 * CVE-2026-31765 * CVE-2026-31768 * CVE-2026-31770 * CVE-2026-31773 * CVE-2026-31776 * CVE-2026-31778 * CVE-2026-31779 * CVE-2026-31780 * CVE-2026-31781 * CVE-2026-43007 * CVE-2026-43011 * CVE-2026-43017 * CVE-2026-43018 * CVE-2026-43019 * CVE-2026-43020 * CVE-2026-43032 * CVE-2026-43043 * CVE-2026-43047 * CVE-2026-43051 * CVE-2026-43057 * CVE-2026-43058 * CVE-2026-43061 * CVE-2026-43062 * CVE-2026-43064 * CVE-2026-43069 * CVE-2026-43072 * CVE-2026-43092 * CVE-2026-43098 * CVE-2026-43104 * CVE-2026-43105 * CVE-2026-43111 * CVE-2026-43113 * CVE-2026-43117 * CVE-2026-43118 * CVE-2026-43123 * CVE-2026-43124 * CVE-2026-43129 * CVE-2026-43133 * CVE-2026-43134 * CVE-2026-43135 * CVE-2026-43136 * CVE-2026-43137 * CVE-2026-43140 * CVE-2026-43141 * CVE-2026-43143 * CVE-2026-43147 * CVE-2026-43149 * CVE-2026-43152 * CVE-2026-43156 * CVE-2026-43157 * CVE-2026-43159 * CVE-2026-43162 * CVE-2026-43167 * CVE-2026-43169 * CVE-2026-43177 * CVE-2026-43180 * CVE-2026-43182 * CVE-2026-43183 * CVE-2026-43189 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43196 * CVE-2026-43199 * CVE-2026-43200 * CVE-2026-43202 * CVE-2026-43203 * CVE-2026-43204 * CVE-2026-43205 * CVE-2026-43207 * CVE-2026-43211 * CVE-2026-43215 * CVE-2026-43218 * CVE-2026-43220 * CVE-2026-43221 * CVE-2026-43222 * CVE-2026-43223 * CVE-2026-43225 * CVE-2026-43226 * CVE-2026-43231 * CVE-2026-43232 * CVE-2026-43236 * CVE-2026-43240 * CVE-2026-43241 * CVE-2026-43242 * CVE-2026-43243 * CVE-2026-43244 * CVE-2026-43246 * CVE-2026-43248 * CVE-2026-43251 * CVE-2026-43253 * CVE-2026-43255 * CVE-2026-43256 * CVE-2026-43257 * CVE-2026-43260 * CVE-2026-43264 * CVE-2026-43269 * CVE-2026-43270 * CVE-2026-43277 * CVE-2026-43278 * CVE-2026-43279 * CVE-2026-43287 * CVE-2026-43291 * CVE-2026-43294 * CVE-2026-43295 * CVE-2026-43300 * CVE-2026-43302 * CVE-2026-43304 * CVE-2026-43312 * CVE-2026-43313 * CVE-2026-43314 * CVE-2026-43316 * CVE-2026-43318 * CVE-2026-43319 * CVE-2026-43320 * CVE-2026-43324 * CVE-2026-43327 * CVE-2026-43337 * CVE-2026-43340 * CVE-2026-43342 * CVE-2026-43343 * CVE-2026-43346 * CVE-2026-43353 * CVE-2026-43357 * CVE-2026-43370 * CVE-2026-43373 * CVE-2026-43380 * CVE-2026-43381 * CVE-2026-43382 * CVE-2026-43383 * CVE-2026-43387 * CVE-2026-43395 * CVE-2026-43397 * CVE-2026-43412 * CVE-2026-43425 * CVE-2026-43426 * CVE-2026-43427 * CVE-2026-43428 * CVE-2026-43429 * CVE-2026-43430 * CVE-2026-43432 * CVE-2026-43436 * CVE-2026-43443 * CVE-2026-43444 * CVE-2026-43445 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43459 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43467 * CVE-2026-43468 * CVE-2026-43473 * CVE-2026-43476 * CVE-2026-43480 * CVE-2026-43488 * CVE-2026-43493 * CVE-2026-43496 * CVE-2026-43497 * CVE-2026-45834 * CVE-2026-45835 * CVE-2026-45839 * CVE-2026-45851 * CVE-2026-45853 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45867 * CVE-2026-45868 * CVE-2026-45869 * CVE-2026-45871 * CVE-2026-45875 * CVE-2026-45877 * CVE-2026-45879 * CVE-2026-45880 * CVE-2026-45881 * CVE-2026-45883 * CVE-2026-45885 * CVE-2026-45899 * CVE-2026-45902 * CVE-2026-45911 * CVE-2026-45914 * CVE-2026-45916 * CVE-2026-45919 * CVE-2026-45920 * CVE-2026-45921 * CVE-2026-45922 * CVE-2026-45923 * CVE-2026-45928 * CVE-2026-45936 * CVE-2026-45941 * CVE-2026-45946 * CVE-2026-45947 * CVE-2026-45954 * CVE-2026-45958 * CVE-2026-45963 * CVE-2026-45969 * CVE-2026-45976 * CVE-2026-45981 * CVE-2026-45982 * CVE-2026-45986 * CVE-2026-45987 * CVE-2026-45994 * CVE-2026-45996 * CVE-2026-45997 * CVE-2026-46006 * CVE-2026-46009 * CVE-2026-46011 * CVE-2026-46016 * CVE-2026-46018 * CVE-2026-46019 * CVE-2026-46023 * CVE-2026-46027 * CVE-2026-46033 * CVE-2026-46040 * CVE-2026-46046 * CVE-2026-46048 * CVE-2026-46049 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46052 * CVE-2026-46056 * CVE-2026-46058 * CVE-2026-46059 * CVE-2026-46064 * CVE-2026-46068 * CVE-2026-46075 * CVE-2026-46077 * CVE-2026-46082 * CVE-2026-46086 * CVE-2026-46088 * CVE-2026-46089 * CVE-2026-46092 * CVE-2026-46099 * CVE-2026-46102 * CVE-2026-46103 * CVE-2026-46108 * CVE-2026-46122 * CVE-2026-46125 * CVE-2026-46128 * CVE-2026-46131 * CVE-2026-46132 * CVE-2026-46136 * CVE-2026-46138 * CVE-2026-46140 * CVE-2026-46143 * CVE-2026-46146 * CVE-2026-46151 * CVE-2026-46152 * CVE-2026-46161 * CVE-2026-46163 * CVE-2026-46165 * CVE-2026-46166 * CVE-2026-46167 * CVE-2026-46177 * CVE-2026-46178 * CVE-2026-46179 * CVE-2026-46184 * CVE-2026-46186 * CVE-2026-46187 * CVE-2026-46190 * CVE-2026-46191 * CVE-2026-46198 * CVE-2026-46199 * CVE-2026-46201 * CVE-2026-46204 * CVE-2026-46205 * CVE-2026-46206 * CVE-2026-46207 * CVE-2026-46211 * CVE-2026-46212 * CVE-2026-46216 * CVE-2026-46218 * CVE-2026-46219 * CVE-2026-46220 * CVE-2026-46225 * CVE-2026-46230 * CVE-2026-46231 * CVE-2026-46232 * CVE-2026-46233 * CVE-2026-46235 * CVE-2026-46236 * CVE-2026-46238 * CVE-2026-46242 * CVE-2026-46247 * CVE-2026-46249 * CVE-2026-46252 * CVE-2026-46261 * CVE-2026-46263 * CVE-2026-46267 * CVE-2026-46270 * CVE-2026-46275 * CVE-2026-46276 * CVE-2026-46285 * CVE-2026-46286 * CVE-2026-46294 * CVE-2026-46307 * CVE-2026-46312 * CVE-2026-46313 * CVE-2026-46314 * CVE-2026-46321 * CVE-2026-46322 * CVE-2026-46330 * CVE-2026-52904 * CVE-2026-52914 * CVE-2026-52915 * CVE-2026-52916 * CVE-2026-52919 * CVE-2026-52922 * CVE-2026-52924 * CVE-2026-52926 * CVE-2026-52931 * CVE-2026-52933 * CVE-2026-52936 * CVE-2026-52948 * CVE-2026-52951 * CVE-2026-52953 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52961 * CVE-2026-52963 * CVE-2026-52964 * CVE-2026-52976 * CVE-2026-52981 * CVE-2026-52982 * CVE-2026-52989 * CVE-2026-52993 * CVE-2026-52995 * CVE-2026-53003 * CVE-2026-53004 * CVE-2026-53009 * CVE-2026-53013 * CVE-2026-53021 * CVE-2026-53022 * CVE-2026-53035 * CVE-2026-53036 * CVE-2026-53037 * CVE-2026-53039 * CVE-2026-53045 * CVE-2026-53047 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53056 * CVE-2026-53058 * CVE-2026-53060 * CVE-2026-53065 * CVE-2026-53066 * CVE-2026-53068 * CVE-2026-53070 * CVE-2026-53073 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53080 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53093 * CVE-2026-53098 * CVE-2026-53112 * CVE-2026-53135 * CVE-2026-53136 * CVE-2026-53137 * CVE-2026-53139 * CVE-2026-53140 * CVE-2026-53143 * CVE-2026-53144 * CVE-2026-53146 * CVE-2026-53147 * CVE-2026-53148 * CVE-2026-53149 * CVE-2026-53150 * CVE-2026-53158 * CVE-2026-53159 * CVE-2026-53160 * CVE-2026-53161 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53181 * CVE-2026-53186 * CVE-2026-53190 * CVE-2026-53192 * CVE-2026-53194 * CVE-2026-53195 * CVE-2026-53196 * CVE-2026-53202 * CVE-2026-53203 * CVE-2026-53208 * CVE-2026-53209 * CVE-2026-53213 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53218 * CVE-2026-53224 * CVE-2026-53225 * CVE-2026-53227 * CVE-2026-53229 * CVE-2026-53237 * CVE-2026-53239 * CVE-2026-53241 * CVE-2026-53242 * CVE-2026-53245 * CVE-2026-53246 * CVE-2026-53249 * CVE-2026-53254 * CVE-2026-53255 * CVE-2026-53256 * CVE-2026-53258 * CVE-2026-53268 * CVE-2026-53272 * CVE-2026-53274 * CVE-2026-53279 * CVE-2026-53285 * CVE-2026-53293 * CVE-2026-53306 * CVE-2026-53313 * CVE-2026-53325 * CVE-2026-53329 * CVE-2026-53339 * CVE-2026-53347 * CVE-2026-53350 * CVE-2026-53355 * CVE-2026-53356 * CVE-2026-53357 * CVE-2026-53358 * CVE-2026-53359 * CVE-2026-53360 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2023-20585 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-20585 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2023-20585 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-71274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71274 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71286 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71291 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71297 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71297 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71302 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71302 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71302 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71305 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71305 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71305 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23276 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23276 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31430 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31430 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31430 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31439 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31439 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31439 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31440 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31440 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31440 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31441 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31441 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31441 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31447 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31447 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31447 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-31474 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31474 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31474 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31474 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31479 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31479 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31485 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31485 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31485 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31497 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31497 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31498 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31498 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31498 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31503 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31503 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31503 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31509 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31509 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31509 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31510 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31510 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31510 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31511 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31513 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31513 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-31513 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31520 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31520 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31520 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31522 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31522 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31522 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31523 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31523 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31524 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31524 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31524 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31532 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31532 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31532 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31532 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31540 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31540 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31540 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31545 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31545 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31545 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31548 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31549 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31549 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31551 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31551 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31551 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31552 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31552 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31552 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31561 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31561 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31561 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31566 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31566 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31566 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31566 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31568 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31568 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31568 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31576 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31576 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31576 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31578 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31578 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31578 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31581 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31583 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31583 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31585 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31585 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31585 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31587 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31587 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31587 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31599 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31599 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31603 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31603 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31603 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31604 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31604 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31604 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31605 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31605 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31605 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31615 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31615 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31615 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31616 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31616 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31616 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31617 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31617 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31617 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31617 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31618 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31618 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31618 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31619 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31619 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31619 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31623 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-31623 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-31623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31624 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31624 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31624 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31625 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31625 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31625 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31626 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31626 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-31626 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31627 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31627 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31627 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31651 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31651 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31651 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31657 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31657 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31657 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31659 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-31659 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-31659 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31660 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31660 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31660 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31661 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31661 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31661 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31667 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31667 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31667 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31672 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31672 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-31672 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31678 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31687 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31687 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31687 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31701 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31701 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31701 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31720 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31720 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31720 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31726 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31726 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31726 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31727 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31727 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31727 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31728 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31728 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31728 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31730 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31730 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31730 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31730 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31747 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31747 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31747 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31748 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31748 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31748 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31749 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31749 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31749 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31751 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31751 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31754 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31754 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31754 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31755 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31755 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31755 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31756 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31756 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-31756 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31761 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31761 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31761 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31762 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31762 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31763 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31763 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31763 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31765 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31765 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31765 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31768 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31768 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-31768 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31770 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31770 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31770 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31773 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31773 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31776 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31776 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31778 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31778 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31778 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31779 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31779 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31780 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31780 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31781 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31781 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43007 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43007 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43011 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43011 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43017 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43017 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43018 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43018 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43020 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43020 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43032 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43032 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43043 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43043 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43043 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43047 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43047 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43051 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43058 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43058 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43058 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43061 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43061 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43062 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43062 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-43064 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43064 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43069 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43072 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43072 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43072 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43098 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43098 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43104 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43105 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43105 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43111 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43111 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43113 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43113 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43117 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43117 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43117 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43118 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-43118 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-43118 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43123 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43123 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43129 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43129 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43133 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-43133 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-43134 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43134 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-43135 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43135 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43136 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43136 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43137 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43137 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43137 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43140 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43140 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43140 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43141 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43141 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43141 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43143 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43143 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43147 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43147 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43149 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43149 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43152 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43152 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43156 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43156 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43156 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43159 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43159 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43162 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43169 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43180 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43180 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43182 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43183 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43183 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43183 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43189 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43189 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43189 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43196 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43200 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43200 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43202 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43202 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43203 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43203 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43207 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43211 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43211 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43215 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43215 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43215 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43218 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43221 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43221 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43223 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43223 ( SUSE ): 4.3 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43223 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43225 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43231 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43231 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43232 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43232 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43241 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43241 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43241 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43242 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43242 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43243 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43246 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43246 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43251 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43255 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43255 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43255 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43256 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43256 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43256 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43257 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43264 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43264 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43264 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43269 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43269 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43270 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43270 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43277 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43279 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43279 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43291 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43295 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43295 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43295 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43300 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43302 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43302 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43312 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43313 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43313 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43316 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43316 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43318 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43324 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43327 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43327 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43340 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43340 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43340 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43342 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43342 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43343 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43346 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43346 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43353 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43353 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43353 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43357 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-43357 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-43357 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43370 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43380 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43380 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43380 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43381 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43381 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43382 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43387 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43387 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43395 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43397 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43397 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43397 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43412 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43412 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43425 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43425 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43426 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43426 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43427 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43428 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43428 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43428 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43430 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43430 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43430 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43432 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43436 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43443 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43459 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43459 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43467 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43476 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43476 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43480 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43488 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43488 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43488 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43493 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43493 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43493 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43496 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43496 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43497 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43497 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43497 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-45834 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45834 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45834 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45835 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45835 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45835 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45839 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45839 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45839 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45851 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45853 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45853 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45853 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45867 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-45867 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45868 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45868 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45869 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45869 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45869 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45871 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45871 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45875 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45875 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45875 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45877 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45877 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45877 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45879 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45879 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45880 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45880 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45881 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45881 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45881 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45883 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45883 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45885 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45885 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45902 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45902 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45902 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45911 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45914 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45914 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45914 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45916 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45916 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45919 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45919 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45919 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45921 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45921 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45921 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45922 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45922 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45922 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45923 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45923 ( SUSE ): 4.9 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45923 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45928 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45936 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45936 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45936 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45941 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45941 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45941 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45946 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45946 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45947 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45947 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45954 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45954 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45954 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45958 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45958 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45958 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45963 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45963 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45969 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45976 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45976 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45981 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45982 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45982 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45982 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45986 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45986 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45994 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45996 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45996 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46006 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46006 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46009 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46009 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46011 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46016 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46016 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46018 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46018 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46019 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46023 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46023 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46027 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46027 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46033 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46033 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46033 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46040 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46040 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46048 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46048 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46049 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46056 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46056 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46058 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46058 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46064 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46064 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46068 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46068 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46068 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46075 ( SUSE ): 5.6 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46082 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46082 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46086 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46088 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46088 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46088 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46092 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46102 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46102 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46103 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46103 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46108 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46108 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46122 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46122 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46122 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46125 ( NVD ): 6.8 CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46131 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46132 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46136 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46136 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46138 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46138 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46140 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46140 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46140 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46143 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46143 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46143 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46146 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46146 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46146 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46151 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46151 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46151 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46152 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46152 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46152 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46163 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46165 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46165 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46166 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46166 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46177 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46179 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46179 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46184 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46184 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46186 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46186 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46187 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46187 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46190 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46190 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46191 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46191 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46198 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46198 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46199 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46201 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46201 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46207 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46207 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-46207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46211 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46211 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46211 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46212 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46212 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46212 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46216 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46216 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46218 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46219 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46225 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46230 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46230 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46231 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46231 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46232 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46232 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46233 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46233 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46233 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46235 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46235 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46235 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46236 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46238 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46247 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46252 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46263 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46267 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46267 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46270 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46270 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46275 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46276 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46276 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46285 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46286 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-46286 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46294 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46294 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46307 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-46307 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-46307 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46312 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46312 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46313 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46313 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46321 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46321 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46330 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46330 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46330 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52904 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52904 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52904 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52914 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52914 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52914 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52915 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52915 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52915 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52916 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52916 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52916 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52919 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52919 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52922 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52922 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52922 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52926 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52931 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52931 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52936 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52936 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52951 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52951 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52951 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52953 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52953 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52961 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52963 ( SUSE ): 5.9 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52963 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52964 ( SUSE ): 4.3 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-52964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52976 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52976 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52976 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52981 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52981 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52982 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52982 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52989 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52989 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52989 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52995 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52995 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53003 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53003 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53004 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53009 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53009 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53009 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53013 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53013 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53037 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53037 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53037 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53045 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53045 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53047 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53047 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53056 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53056 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53056 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53058 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53058 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53065 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53065 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53066 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53066 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53066 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53068 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53068 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53068 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53070 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53070 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53073 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53073 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53080 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53080 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53093 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53093 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53098 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53135 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53135 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53136 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53136 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53136 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53137 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53137 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53140 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53140 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53140 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53143 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53143 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53144 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53146 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53146 ( SUSE ): 5.2 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53146 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-53147 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53147 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53148 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53148 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53148 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53148 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53149 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53149 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53150 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53150 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53150 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53158 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53158 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53158 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53159 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53159 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53160 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53161 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53181 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53181 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53186 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53190 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53190 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53192 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53194 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53194 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53194 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53195 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53195 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53195 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53202 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53202 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53202 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53203 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53203 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53203 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53203 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53208 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53208 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53208 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53213 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53218 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53225 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53227 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53227 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53227 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53237 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53237 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53239 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53241 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53241 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53241 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53242 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53254 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53254 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53254 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53255 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53268 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53268 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53272 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53272 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53272 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53279 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53279 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53293 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53293 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53313 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53313 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53325 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53325 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53325 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53329 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53339 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53347 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53347 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53355 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53355 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-53355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53356 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53356 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53356 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53358 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53358 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * Legacy Module 15-SP7 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves 513 vulnerabilities, contains one feature and has 26 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). * CVE-2025-71302: drm/panthor: fix for dma-fence safe access rules (bsc#1264837). * CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765). * CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). * CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). * CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593 bsc#1264419). * CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429). * CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). * CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). * CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). * CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112). * CVE-2026-43353: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue (bsc#1265089). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). * CVE-2026-43496: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1266000). * CVE-2026-45839: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (bsc#1266399). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805). * CVE-2026-45981: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() (bsc#1267204). * CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). * CVE-2026-45994: ibmasm: fix OOB reads in command_file_write due to missing size checks (bsc#1267432). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-46023: dm mirror: fix integer overflow in create_dirty_log() (bsc#1267449). * CVE-2026-46027: net/smc: avoid early lgr access in smc_clc_wait_msg (bsc#1266744). * CVE-2026-46040: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (bsc#1267472). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). * CVE-2026-46064: ibmasm: fix heap over-read in ibmasm_send_i2o_message() (bsc#1267497). * CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (bsc#1267592). * CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524). * CVE-2026-46089: zram: do not forget to endio for partial discard requests (bsc#1267445). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46102: net: strparser: fix skb_head leak in strp_abort_strp() (bsc#1267502). * CVE-2026-46132: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (bsc#1267616). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690). * CVE-2026-46207: vsock/virtio: fix length and offset in tap skb for split packets (bsc#1267691). * CVE-2026-46216: drm/xe/hdcp: Add NULL check for media_gt in (bsc#1267234). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46249: octeontx2-af: Fix PF driver crash with kexec kernel booting (bsc#1267683). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one() (bsc#1268024). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52953: iommu/vt-d: Fix oops due to out of scope access (bsc#1269133). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). * CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124). * CVE-2026-53003: pppoe: drop PFC frames (bsc#1269111). * CVE-2026-53004: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (bsc#1269106). * CVE-2026-53009: ice: fix double-free of tx_buf skb (bsc#1269098). * CVE-2026-53013: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (bsc#1269095). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). * CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (bsc#1269273). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). * CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (bsc#1269711). * CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR (bsc#1269877). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (bsc#1269677). * CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257). * CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress (bsc#1269809). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). * CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270302). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271366). The following non security issues were fixed: * ALSA: hda: conexant: Remove mic bias threshold override (git-fixes). * ALSA: hda: Fix cached processing coefficient verbs (git-fixes). * ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (git-fixes). * ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (git- fixes). * ASoC: cs42l43: Correct report for forced microphone jack (git-fixes). * ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (git-fixes). * ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (git-fixes). * batman-adv: access unicast_ttvn skb->data only after skb realloc (git- fixes). * batman-adv: bla: reacquire gw address after skb realloc (git-fixes). * batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). * batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). * batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). * bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). * bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). * bnxt_en: Add TX timestamp completion logic (bsc#1264180). * bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). * bnxt_en: fix module unload sequence (bsc#1264180). * bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). * bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). * bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). * bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). * bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). * bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). * bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). * bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). * bnxt_en: silence clang build warning (bsc#1264180). * bpf: Disambiguate SCALAR register state output in verifier logs (bsc#1271249). * crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). * crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable- fixes). * drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). * drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git- fixes). * drm/amd/pm: fix amdgpu_pm_info power display units (git-fixes). * drm/amd/pm: fix smu13 power limit range calculation (git-fixes). * drm/amdgpu: fix aperture mapping leak (git-fixes). * drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). * drm/gfx10: Program DB_RING_CONTROL (git-fixes). * drm/i915/bios: range check LFP Data Block panel_type2 (git-fixes). * drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). * drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). * drm/i915: Return NULL on error in active_instance (git-fixes). * drm/imagination: Fix double call to drm_sched_entity_fini() (git-fixes). * drm/imagination: fix error checking of pvr_vm_context_lookup() (git-fixes). * drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY (git-fixes). * drm/imagination: Fix user array stride in pvr_set_uobj_array() (git-fixes). * drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() (git-fixes). * drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced (git-fixes). * drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() (git-fixes). * drm/panthor: Interrupt group start/resumption if group_bind_locked() fails (git-fixes). * drm/v3d: Reject invalid indirect BO handle in indirect CSD setup (git- fixes). * drm/virtio: bound EDID block reads to the response buffer (git-fixes). * drm/xe/hw_engine: Fix double-free of managed BO in error path (git-fixes). * drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays (git-fixes). * drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() (git- fixes). * drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (git- fixes). * drm/xe: remove duplicate include (git-fixes). * fbdev: efifb: fix memory leak in efifb_probe() (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes). * git_sort: Add workqueue maintainer tree. * git_sort: Update nf-next branch. * gpio-f7188x: Add support for NCT6126D version B (git-fixes). * gpio: htc-egpio: use managed gpiochip registration (git-fixes). * gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). * gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git- fixes). * gpios: palmas: add .get_direction() op (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue (git- fixes). * i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring (git-fixes). * iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). * iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git- fixes). * iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). * iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). * iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). * iio: event: Fix event FIFO reset race (git-fixes). * iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). * iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). * iio: light: al3010: fix incorrect scale for the highest gain range (git- fixes). * iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). * iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). * Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). * Input: mms114 - fix multi-touch slot corruption (git-fixes). * io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF (bsc#1261250). * io_uring/kbuf: propagate BUF_MORE through early buffer commit path (bsc#1261250). * io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git- fixes bsc#1261250 bsc#1271287). * iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). * ipvs: Move defense_work to system_dfl_long_wq (bsc#1257605). * ixgbe: reduce number of reads when getting OROM data (bsc#1269637). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042 bsc#1270396). * mm: Do not allocate shrinker info with cgroup.memory=nokmem (bsc#1256564). * net/handshake: do not send request when the socket is closed (bsc#1251942). * net: mana: Sync page pool RX frags for CPU (git-fixes). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562). * pinctrl: meson: restore non-sleeping GPIO access (git-fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). * s390/ap: Externalize AP bus specific bitmap reading function (jsc#PED-15897). * s390/pkey: Check length in pkey_pckmo handler implementation (bsc#1270268). * s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (bsc#1270263). * s390/vfio-ap: Add sysfs attr, ap_config, to export mdev state (jsc#PED-15897). * s390/vfio-ap: Add write support to sysfs attr ap_config (jsc#PED-15897). * s390/vfio-ap: Driver feature advertisement (jsc#PED-15897). * s390/vfio-ap: Ignore duplicate link requests in vfio_ap_mdev_link_queue (jsc#PED-15897). * scripts/submit_branch: do submission right after upload. * sctp: validate embedded address parameter length (git-fixes). * selftests/alsa: Fix memory leak in find_controls error path (git-fixes). * selftests/bpf: Add uprobe_multi to gen_tar target (bsc#1271248). * selftests/bpf: Make align selftests more robust (bsc#1271249). * serial: 8250_omap: clear rx_running on zero-length DMA completes (git- fixes). * serial: msm: Disable DMA for kernel console UART (git-fixes). * staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). * staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git- fixes). * staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). * staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). * staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). * staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git- fixes). * tools: hv: Fix cross-compilation (git-fixes). * tpm: Make the TPM character devices non-seekable (git-fixes). * usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git- fixes). * USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). * usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git- fixes). * usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). * usb: free iso schedules on failed submit (git-fixes). * usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git- fixes). * usb: gadget: f_printer: take kref only for successful open (git-fixes). * USB: idmouse: fix use-after-free on disconnect race (git-fixes). * USB: iowarrior: fix use-after-free on disconnect (git-fixes). * USB: ldusb: fix use-after-free on disconnect race (git-fixes). * USB: legousbtower: fix use-after-free on disconnect race (git-fixes). * USB: misc: uss720: unregister parport on probe failure (git-fixes). * usb: mtu3: unmap request DMA on queue failure (git-fixes). * USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). * USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). * USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). * USB: serial: keyspan_pda: fix information leak (git-fixes). * usb: sl811-hcd: disable controller wakeup on remove (git-fixes). * USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). * usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). * usb: typec: class: drop PD lookup reference (git-fixes). * usb: typec: tcpm: Fix VDM type for Enter Mode commands (git-fixes). * usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). * usb: typec: ucsi: cancel pending work on system suspend (git-fixes). * usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). * usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). * usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). * USB: ulpi: fix memory leak on registration failure (git-fixes). * USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). * usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). * usbip: tools: support SuperSpeedPlus devices (git-fixes). * usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). * wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3166=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3166=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3166=1 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-3166=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3166=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3166=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3166=1 Please note that this is the initial kernel livepatch without fixes itself, this package is later updated by separate standalone kernel livepatch updates. ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.73.2 * kernel-default-debuginfo-6.4.0-150700.53.73.2 * kernel-default-devel-6.4.0-150700.53.73.2 * kernel-default-devel-debuginfo-6.4.0-150700.53.73.2 * Basesystem Module 15-SP7 (noarch) * kernel-macros-6.4.0-150700.53.73.1 * kernel-devel-6.4.0-150700.53.73.1 * Basesystem Module 15-SP7 (aarch64 nosrc) * kernel-64kb-6.4.0-150700.53.73.2 * Basesystem Module 15-SP7 (aarch64) * kernel-64kb-debugsource-6.4.0-150700.53.73.2 * kernel-64kb-devel-6.4.0-150700.53.73.2 * kernel-64kb-devel-debuginfo-6.4.0-150700.53.73.2 * kernel-64kb-debuginfo-6.4.0-150700.53.73.2 * Basesystem Module 15-SP7 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-150700.53.73.2 * Basesystem Module 15-SP7 (s390x) * kernel-zfcpdump-debugsource-6.4.0-150700.53.73.2 * kernel-zfcpdump-debuginfo-6.4.0-150700.53.73.2 * Basesystem Module 15-SP7 (nosrc s390x) * kernel-zfcpdump-6.4.0-150700.53.73.2 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-150700.53.73.2.150700.17.41.4 * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * ocfs2-kmp-default-6.4.0-150700.53.73.2 * dlm-kmp-default-debuginfo-6.4.0-150700.53.73.2 * cluster-md-kmp-default-debuginfo-6.4.0-150700.53.73.2 * dlm-kmp-default-6.4.0-150700.53.73.2 * cluster-md-kmp-default-6.4.0-150700.53.73.2 * kernel-default-debugsource-6.4.0-150700.53.73.2 * gfs2-kmp-default-6.4.0-150700.53.73.2 * gfs2-kmp-default-debuginfo-6.4.0-150700.53.73.2 * ocfs2-kmp-default-debuginfo-6.4.0-150700.53.73.2 * kernel-default-debuginfo-6.4.0-150700.53.73.2 * SUSE Linux Enterprise High Availability Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.73.2 * Development Tools Module 15-SP7 (noarch) * kernel-source-6.4.0-150700.53.73.1 * Development Tools Module 15-SP7 (noarch nosrc) * kernel-docs-6.4.0-150700.53.73.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-150700.53.73.2 * kernel-obs-build-debugsource-6.4.0-150700.53.73.2 * kernel-syms-6.4.0-150700.53.73.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.73.2 * kernel-default-debuginfo-6.4.0-150700.53.73.2 * reiserfs-kmp-default-6.4.0-150700.53.73.2 * reiserfs-kmp-default-debuginfo-6.4.0-150700.53.73.2 * Legacy Module 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.73.2 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * kernel-default-debugsource-6.4.0-150700.53.73.2 * kernel-default-debuginfo-6.4.0-150700.53.73.2 * kernel-default-extra-debuginfo-6.4.0-150700.53.73.2 * kernel-default-extra-6.4.0-150700.53.73.2 * SUSE Linux Enterprise Workstation Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.73.2 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_19-debugsource-1-150700.15.3.4 * kernel-default-livepatch-devel-6.4.0-150700.53.73.2 * kernel-livepatch-6_4_0-150700_53_73-default-1-150700.15.3.4 * kernel-livepatch-6_4_0-150700_53_73-default-debuginfo-1-150700.15.3.4 * kernel-default-livepatch-6.4.0-150700.53.73.2 * kernel-default-debugsource-6.4.0-150700.53.73.2 * kernel-default-debuginfo-6.4.0-150700.53.73.2 * SUSE Linux Enterprise Live Patching 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.73.2 * Public Cloud Module 15-SP7 (aarch64 nosrc x86_64) * kernel-azure-6.4.0-150700.53.73.2 * Public Cloud Module 15-SP7 (aarch64 x86_64) * kernel-azure-debuginfo-6.4.0-150700.53.73.2 * kernel-azure-devel-debuginfo-6.4.0-150700.53.73.2 * kernel-azure-devel-6.4.0-150700.53.73.2 * kernel-azure-debugsource-6.4.0-150700.53.73.2 ## References: * https://www.suse.com/security/cve/CVE-2023-20585.html * https://www.suse.com/security/cve/CVE-2025-71274.html * https://www.suse.com/security/cve/CVE-2025-71286.html * https://www.suse.com/security/cve/CVE-2025-71291.html * https://www.suse.com/security/cve/CVE-2025-71297.html * https://www.suse.com/security/cve/CVE-2025-71302.html * https://www.suse.com/security/cve/CVE-2025-71305.html * https://www.suse.com/security/cve/CVE-2025-71314.html * https://www.suse.com/security/cve/CVE-2026-23276.html * https://www.suse.com/security/cve/CVE-2026-31430.html * https://www.suse.com/security/cve/CVE-2026-31439.html * https://www.suse.com/security/cve/CVE-2026-31440.html * https://www.suse.com/security/cve/CVE-2026-31441.html * https://www.suse.com/security/cve/CVE-2026-31447.html * https://www.suse.com/security/cve/CVE-2026-31474.html * https://www.suse.com/security/cve/CVE-2026-31479.html * https://www.suse.com/security/cve/CVE-2026-31485.html * https://www.suse.com/security/cve/CVE-2026-31497.html * https://www.suse.com/security/cve/CVE-2026-31498.html * https://www.suse.com/security/cve/CVE-2026-31503.html * https://www.suse.com/security/cve/CVE-2026-31509.html * https://www.suse.com/security/cve/CVE-2026-31510.html * https://www.suse.com/security/cve/CVE-2026-31511.html * https://www.suse.com/security/cve/CVE-2026-31513.html * https://www.suse.com/security/cve/CVE-2026-31520.html * https://www.suse.com/security/cve/CVE-2026-31522.html * https://www.suse.com/security/cve/CVE-2026-31523.html * https://www.suse.com/security/cve/CVE-2026-31524.html * https://www.suse.com/security/cve/CVE-2026-31532.html * https://www.suse.com/security/cve/CVE-2026-31540.html * https://www.suse.com/security/cve/CVE-2026-31545.html * https://www.suse.com/security/cve/CVE-2026-31548.html * https://www.suse.com/security/cve/CVE-2026-31549.html * https://www.suse.com/security/cve/CVE-2026-31551.html * https://www.suse.com/security/cve/CVE-2026-31552.html * https://www.suse.com/security/cve/CVE-2026-31561.html * https://www.suse.com/security/cve/CVE-2026-31566.html * https://www.suse.com/security/cve/CVE-2026-31568.html * https://www.suse.com/security/cve/CVE-2026-31576.html * https://www.suse.com/security/cve/CVE-2026-31578.html * https://www.suse.com/security/cve/CVE-2026-31581.html * https://www.suse.com/security/cve/CVE-2026-31583.html * https://www.suse.com/security/cve/CVE-2026-31585.html * https://www.suse.com/security/cve/CVE-2026-31587.html * https://www.suse.com/security/cve/CVE-2026-31599.html * https://www.suse.com/security/cve/CVE-2026-31603.html * https://www.suse.com/security/cve/CVE-2026-31604.html * https://www.suse.com/security/cve/CVE-2026-31605.html * https://www.suse.com/security/cve/CVE-2026-31615.html * https://www.suse.com/security/cve/CVE-2026-31616.html * https://www.suse.com/security/cve/CVE-2026-31617.html * https://www.suse.com/security/cve/CVE-2026-31618.html * https://www.suse.com/security/cve/CVE-2026-31619.html * https://www.suse.com/security/cve/CVE-2026-31623.html * https://www.suse.com/security/cve/CVE-2026-31624.html * https://www.suse.com/security/cve/CVE-2026-31625.html * https://www.suse.com/security/cve/CVE-2026-31626.html * https://www.suse.com/security/cve/CVE-2026-31627.html * https://www.suse.com/security/cve/CVE-2026-31651.html * https://www.suse.com/security/cve/CVE-2026-31657.html * https://www.suse.com/security/cve/CVE-2026-31659.html * https://www.suse.com/security/cve/CVE-2026-31660.html * https://www.suse.com/security/cve/CVE-2026-31661.html * https://www.suse.com/security/cve/CVE-2026-31667.html * https://www.suse.com/security/cve/CVE-2026-31672.html * https://www.suse.com/security/cve/CVE-2026-31678.html * https://www.suse.com/security/cve/CVE-2026-31687.html * https://www.suse.com/security/cve/CVE-2026-31701.html * https://www.suse.com/security/cve/CVE-2026-31720.html * https://www.suse.com/security/cve/CVE-2026-31726.html * https://www.suse.com/security/cve/CVE-2026-31727.html * https://www.suse.com/security/cve/CVE-2026-31728.html * https://www.suse.com/security/cve/CVE-2026-31730.html * https://www.suse.com/security/cve/CVE-2026-31747.html * https://www.suse.com/security/cve/CVE-2026-31748.html * https://www.suse.com/security/cve/CVE-2026-31749.html * https://www.suse.com/security/cve/CVE-2026-31751.html * https://www.suse.com/security/cve/CVE-2026-31754.html * https://www.suse.com/security/cve/CVE-2026-31755.html * https://www.suse.com/security/cve/CVE-2026-31756.html * https://www.suse.com/security/cve/CVE-2026-31761.html * https://www.suse.com/security/cve/CVE-2026-31762.html * https://www.suse.com/security/cve/CVE-2026-31763.html * https://www.suse.com/security/cve/CVE-2026-31765.html * https://www.suse.com/security/cve/CVE-2026-31768.html * https://www.suse.com/security/cve/CVE-2026-31770.html * https://www.suse.com/security/cve/CVE-2026-31773.html * https://www.suse.com/security/cve/CVE-2026-31776.html * https://www.suse.com/security/cve/CVE-2026-31778.html * https://www.suse.com/security/cve/CVE-2026-31779.html * https://www.suse.com/security/cve/CVE-2026-31780.html * https://www.suse.com/security/cve/CVE-2026-31781.html * https://www.suse.com/security/cve/CVE-2026-43007.html * https://www.suse.com/security/cve/CVE-2026-43011.html * https://www.suse.com/security/cve/CVE-2026-43017.html * https://www.suse.com/security/cve/CVE-2026-43018.html * https://www.suse.com/security/cve/CVE-2026-43019.html * https://www.suse.com/security/cve/CVE-2026-43020.html * https://www.suse.com/security/cve/CVE-2026-43032.html * https://www.suse.com/security/cve/CVE-2026-43043.html * https://www.suse.com/security/cve/CVE-2026-43047.html * https://www.suse.com/security/cve/CVE-2026-43051.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43058.html * https://www.suse.com/security/cve/CVE-2026-43061.html * https://www.suse.com/security/cve/CVE-2026-43062.html * https://www.suse.com/security/cve/CVE-2026-43064.html * https://www.suse.com/security/cve/CVE-2026-43069.html * https://www.suse.com/security/cve/CVE-2026-43072.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43098.html * https://www.suse.com/security/cve/CVE-2026-43104.html * https://www.suse.com/security/cve/CVE-2026-43105.html * https://www.suse.com/security/cve/CVE-2026-43111.html * https://www.suse.com/security/cve/CVE-2026-43113.html * https://www.suse.com/security/cve/CVE-2026-43117.html * https://www.suse.com/security/cve/CVE-2026-43118.html * https://www.suse.com/security/cve/CVE-2026-43123.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43129.html * https://www.suse.com/security/cve/CVE-2026-43133.html * https://www.suse.com/security/cve/CVE-2026-43134.html * https://www.suse.com/security/cve/CVE-2026-43135.html * https://www.suse.com/security/cve/CVE-2026-43136.html * https://www.suse.com/security/cve/CVE-2026-43137.html * https://www.suse.com/security/cve/CVE-2026-43140.html * https://www.suse.com/security/cve/CVE-2026-43141.html * https://www.suse.com/security/cve/CVE-2026-43143.html * https://www.suse.com/security/cve/CVE-2026-43147.html * https://www.suse.com/security/cve/CVE-2026-43149.html * https://www.suse.com/security/cve/CVE-2026-43152.html * https://www.suse.com/security/cve/CVE-2026-43156.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43159.html * https://www.suse.com/security/cve/CVE-2026-43162.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43169.html * https://www.suse.com/security/cve/CVE-2026-43177.html * https://www.suse.com/security/cve/CVE-2026-43180.html * https://www.suse.com/security/cve/CVE-2026-43182.html * https://www.suse.com/security/cve/CVE-2026-43183.html * https://www.suse.com/security/cve/CVE-2026-43189.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43196.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43200.html * https://www.suse.com/security/cve/CVE-2026-43202.html * https://www.suse.com/security/cve/CVE-2026-43203.html * https://www.suse.com/security/cve/CVE-2026-43204.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43207.html * https://www.suse.com/security/cve/CVE-2026-43211.html * https://www.suse.com/security/cve/CVE-2026-43215.html * https://www.suse.com/security/cve/CVE-2026-43218.html * https://www.suse.com/security/cve/CVE-2026-43220.html * https://www.suse.com/security/cve/CVE-2026-43221.html * https://www.suse.com/security/cve/CVE-2026-43222.html * https://www.suse.com/security/cve/CVE-2026-43223.html * https://www.suse.com/security/cve/CVE-2026-43225.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43231.html * https://www.suse.com/security/cve/CVE-2026-43232.html * https://www.suse.com/security/cve/CVE-2026-43236.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43241.html * https://www.suse.com/security/cve/CVE-2026-43242.html * https://www.suse.com/security/cve/CVE-2026-43243.html * https://www.suse.com/security/cve/CVE-2026-43244.html * https://www.suse.com/security/cve/CVE-2026-43246.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43251.html * https://www.suse.com/security/cve/CVE-2026-43253.html * https://www.suse.com/security/cve/CVE-2026-43255.html * https://www.suse.com/security/cve/CVE-2026-43256.html * https://www.suse.com/security/cve/CVE-2026-43257.html * https://www.suse.com/security/cve/CVE-2026-43260.html * https://www.suse.com/security/cve/CVE-2026-43264.html * https://www.suse.com/security/cve/CVE-2026-43269.html * https://www.suse.com/security/cve/CVE-2026-43270.html * https://www.suse.com/security/cve/CVE-2026-43277.html * https://www.suse.com/security/cve/CVE-2026-43278.html * https://www.suse.com/security/cve/CVE-2026-43279.html * https://www.suse.com/security/cve/CVE-2026-43287.html * https://www.suse.com/security/cve/CVE-2026-43291.html * https://www.suse.com/security/cve/CVE-2026-43294.html * https://www.suse.com/security/cve/CVE-2026-43295.html * https://www.suse.com/security/cve/CVE-2026-43300.html * https://www.suse.com/security/cve/CVE-2026-43302.html * https://www.suse.com/security/cve/CVE-2026-43304.html * https://www.suse.com/security/cve/CVE-2026-43312.html * https://www.suse.com/security/cve/CVE-2026-43313.html * https://www.suse.com/security/cve/CVE-2026-43314.html * https://www.suse.com/security/cve/CVE-2026-43316.html * https://www.suse.com/security/cve/CVE-2026-43318.html * https://www.suse.com/security/cve/CVE-2026-43319.html * https://www.suse.com/security/cve/CVE-2026-43320.html * https://www.suse.com/security/cve/CVE-2026-43324.html * https://www.suse.com/security/cve/CVE-2026-43327.html * https://www.suse.com/security/cve/CVE-2026-43337.html * https://www.suse.com/security/cve/CVE-2026-43340.html * https://www.suse.com/security/cve/CVE-2026-43342.html * https://www.suse.com/security/cve/CVE-2026-43343.html * https://www.suse.com/security/cve/CVE-2026-43346.html * https://www.suse.com/security/cve/CVE-2026-43353.html * https://www.suse.com/security/cve/CVE-2026-43357.html * https://www.suse.com/security/cve/CVE-2026-43370.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43380.html * https://www.suse.com/security/cve/CVE-2026-43381.html * https://www.suse.com/security/cve/CVE-2026-43382.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43387.html * https://www.suse.com/security/cve/CVE-2026-43395.html * https://www.suse.com/security/cve/CVE-2026-43397.html * https://www.suse.com/security/cve/CVE-2026-43412.html * https://www.suse.com/security/cve/CVE-2026-43425.html * https://www.suse.com/security/cve/CVE-2026-43426.html * https://www.suse.com/security/cve/CVE-2026-43427.html * https://www.suse.com/security/cve/CVE-2026-43428.html * https://www.suse.com/security/cve/CVE-2026-43429.html * https://www.suse.com/security/cve/CVE-2026-43430.html * https://www.suse.com/security/cve/CVE-2026-43432.html * https://www.suse.com/security/cve/CVE-2026-43436.html * https://www.suse.com/security/cve/CVE-2026-43443.html * https://www.suse.com/security/cve/CVE-2026-43444.html * https://www.suse.com/security/cve/CVE-2026-43445.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43459.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43467.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43473.html * https://www.suse.com/security/cve/CVE-2026-43476.html * https://www.suse.com/security/cve/CVE-2026-43480.html * https://www.suse.com/security/cve/CVE-2026-43488.html * https://www.suse.com/security/cve/CVE-2026-43493.html * https://www.suse.com/security/cve/CVE-2026-43496.html * https://www.suse.com/security/cve/CVE-2026-43497.html * https://www.suse.com/security/cve/CVE-2026-45834.html * https://www.suse.com/security/cve/CVE-2026-45835.html * https://www.suse.com/security/cve/CVE-2026-45839.html * https://www.suse.com/security/cve/CVE-2026-45851.html * https://www.suse.com/security/cve/CVE-2026-45853.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45867.html * https://www.suse.com/security/cve/CVE-2026-45868.html * https://www.suse.com/security/cve/CVE-2026-45869.html * https://www.suse.com/security/cve/CVE-2026-45871.html * https://www.suse.com/security/cve/CVE-2026-45875.html * https://www.suse.com/security/cve/CVE-2026-45877.html * https://www.suse.com/security/cve/CVE-2026-45879.html * https://www.suse.com/security/cve/CVE-2026-45880.html * https://www.suse.com/security/cve/CVE-2026-45881.html * https://www.suse.com/security/cve/CVE-2026-45883.html * https://www.suse.com/security/cve/CVE-2026-45885.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45902.html * https://www.suse.com/security/cve/CVE-2026-45911.html * https://www.suse.com/security/cve/CVE-2026-45914.html * https://www.suse.com/security/cve/CVE-2026-45916.html * https://www.suse.com/security/cve/CVE-2026-45919.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45921.html * https://www.suse.com/security/cve/CVE-2026-45922.html * https://www.suse.com/security/cve/CVE-2026-45923.html * https://www.suse.com/security/cve/CVE-2026-45928.html * https://www.suse.com/security/cve/CVE-2026-45936.html * https://www.suse.com/security/cve/CVE-2026-45941.html * https://www.suse.com/security/cve/CVE-2026-45946.html * https://www.suse.com/security/cve/CVE-2026-45947.html * https://www.suse.com/security/cve/CVE-2026-45954.html * https://www.suse.com/security/cve/CVE-2026-45958.html * https://www.suse.com/security/cve/CVE-2026-45963.html * https://www.suse.com/security/cve/CVE-2026-45969.html * https://www.suse.com/security/cve/CVE-2026-45976.html * https://www.suse.com/security/cve/CVE-2026-45981.html * https://www.suse.com/security/cve/CVE-2026-45982.html * https://www.suse.com/security/cve/CVE-2026-45986.html * https://www.suse.com/security/cve/CVE-2026-45987.html * https://www.suse.com/security/cve/CVE-2026-45994.html * https://www.suse.com/security/cve/CVE-2026-45996.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-46006.html * https://www.suse.com/security/cve/CVE-2026-46009.html * https://www.suse.com/security/cve/CVE-2026-46011.html * https://www.suse.com/security/cve/CVE-2026-46016.html * https://www.suse.com/security/cve/CVE-2026-46018.html * https://www.suse.com/security/cve/CVE-2026-46019.html * https://www.suse.com/security/cve/CVE-2026-46023.html * https://www.suse.com/security/cve/CVE-2026-46027.html * https://www.suse.com/security/cve/CVE-2026-46033.html * https://www.suse.com/security/cve/CVE-2026-46040.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46048.html * https://www.suse.com/security/cve/CVE-2026-46049.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46056.html * https://www.suse.com/security/cve/CVE-2026-46058.html * https://www.suse.com/security/cve/CVE-2026-46059.html * https://www.suse.com/security/cve/CVE-2026-46064.html * https://www.suse.com/security/cve/CVE-2026-46068.html * https://www.suse.com/security/cve/CVE-2026-46075.html * https://www.suse.com/security/cve/CVE-2026-46077.html * https://www.suse.com/security/cve/CVE-2026-46082.html * https://www.suse.com/security/cve/CVE-2026-46086.html * https://www.suse.com/security/cve/CVE-2026-46088.html * https://www.suse.com/security/cve/CVE-2026-46089.html * https://www.suse.com/security/cve/CVE-2026-46092.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46102.html * https://www.suse.com/security/cve/CVE-2026-46103.html * https://www.suse.com/security/cve/CVE-2026-46108.html * https://www.suse.com/security/cve/CVE-2026-46122.html * https://www.suse.com/security/cve/CVE-2026-46125.html * https://www.suse.com/security/cve/CVE-2026-46128.html * https://www.suse.com/security/cve/CVE-2026-46131.html * https://www.suse.com/security/cve/CVE-2026-46132.html * https://www.suse.com/security/cve/CVE-2026-46136.html * https://www.suse.com/security/cve/CVE-2026-46138.html * https://www.suse.com/security/cve/CVE-2026-46140.html * https://www.suse.com/security/cve/CVE-2026-46143.html * https://www.suse.com/security/cve/CVE-2026-46146.html * https://www.suse.com/security/cve/CVE-2026-46151.html * https://www.suse.com/security/cve/CVE-2026-46152.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46163.html * https://www.suse.com/security/cve/CVE-2026-46165.html * https://www.suse.com/security/cve/CVE-2026-46166.html * https://www.suse.com/security/cve/CVE-2026-46167.html * https://www.suse.com/security/cve/CVE-2026-46177.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46179.html * https://www.suse.com/security/cve/CVE-2026-46184.html * https://www.suse.com/security/cve/CVE-2026-46186.html * https://www.suse.com/security/cve/CVE-2026-46187.html * https://www.suse.com/security/cve/CVE-2026-46190.html * https://www.suse.com/security/cve/CVE-2026-46191.html * https://www.suse.com/security/cve/CVE-2026-46198.html * https://www.suse.com/security/cve/CVE-2026-46199.html * https://www.suse.com/security/cve/CVE-2026-46201.html * https://www.suse.com/security/cve/CVE-2026-46204.html * https://www.suse.com/security/cve/CVE-2026-46205.html * https://www.suse.com/security/cve/CVE-2026-46206.html * https://www.suse.com/security/cve/CVE-2026-46207.html * https://www.suse.com/security/cve/CVE-2026-46211.html * https://www.suse.com/security/cve/CVE-2026-46212.html * https://www.suse.com/security/cve/CVE-2026-46216.html * https://www.suse.com/security/cve/CVE-2026-46218.html * https://www.suse.com/security/cve/CVE-2026-46219.html * https://www.suse.com/security/cve/CVE-2026-46220.html * https://www.suse.com/security/cve/CVE-2026-46225.html * https://www.suse.com/security/cve/CVE-2026-46230.html * https://www.suse.com/security/cve/CVE-2026-46231.html * https://www.suse.com/security/cve/CVE-2026-46232.html * https://www.suse.com/security/cve/CVE-2026-46233.html * https://www.suse.com/security/cve/CVE-2026-46235.html * https://www.suse.com/security/cve/CVE-2026-46236.html * https://www.suse.com/security/cve/CVE-2026-46238.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46247.html * https://www.suse.com/security/cve/CVE-2026-46249.html * https://www.suse.com/security/cve/CVE-2026-46252.html * https://www.suse.com/security/cve/CVE-2026-46261.html * https://www.suse.com/security/cve/CVE-2026-46263.html * https://www.suse.com/security/cve/CVE-2026-46267.html * https://www.suse.com/security/cve/CVE-2026-46270.html * https://www.suse.com/security/cve/CVE-2026-46275.html * https://www.suse.com/security/cve/CVE-2026-46276.html * https://www.suse.com/security/cve/CVE-2026-46285.html * https://www.suse.com/security/cve/CVE-2026-46286.html * https://www.suse.com/security/cve/CVE-2026-46294.html * https://www.suse.com/security/cve/CVE-2026-46307.html * https://www.suse.com/security/cve/CVE-2026-46312.html * https://www.suse.com/security/cve/CVE-2026-46313.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46321.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-46330.html * https://www.suse.com/security/cve/CVE-2026-52904.html * https://www.suse.com/security/cve/CVE-2026-52914.html * https://www.suse.com/security/cve/CVE-2026-52915.html * https://www.suse.com/security/cve/CVE-2026-52916.html * https://www.suse.com/security/cve/CVE-2026-52919.html * https://www.suse.com/security/cve/CVE-2026-52922.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52926.html * https://www.suse.com/security/cve/CVE-2026-52931.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52936.html * https://www.suse.com/security/cve/CVE-2026-52948.html * https://www.suse.com/security/cve/CVE-2026-52951.html * https://www.suse.com/security/cve/CVE-2026-52953.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52961.html * https://www.suse.com/security/cve/CVE-2026-52963.html * https://www.suse.com/security/cve/CVE-2026-52964.html * https://www.suse.com/security/cve/CVE-2026-52976.html * https://www.suse.com/security/cve/CVE-2026-52981.html * https://www.suse.com/security/cve/CVE-2026-52982.html * https://www.suse.com/security/cve/CVE-2026-52989.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-52995.html * https://www.suse.com/security/cve/CVE-2026-53003.html * https://www.suse.com/security/cve/CVE-2026-53004.html * https://www.suse.com/security/cve/CVE-2026-53009.html * https://www.suse.com/security/cve/CVE-2026-53013.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53022.html * https://www.suse.com/security/cve/CVE-2026-53035.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53037.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53045.html * https://www.suse.com/security/cve/CVE-2026-53047.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53056.html * https://www.suse.com/security/cve/CVE-2026-53058.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53065.html * https://www.suse.com/security/cve/CVE-2026-53066.html * https://www.suse.com/security/cve/CVE-2026-53068.html * https://www.suse.com/security/cve/CVE-2026-53070.html * https://www.suse.com/security/cve/CVE-2026-53073.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53080.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53093.html * https://www.suse.com/security/cve/CVE-2026-53098.html * https://www.suse.com/security/cve/CVE-2026-53112.html * https://www.suse.com/security/cve/CVE-2026-53135.html * https://www.suse.com/security/cve/CVE-2026-53136.html * https://www.suse.com/security/cve/CVE-2026-53137.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53140.html * https://www.suse.com/security/cve/CVE-2026-53143.html * https://www.suse.com/security/cve/CVE-2026-53144.html * https://www.suse.com/security/cve/CVE-2026-53146.html * https://www.suse.com/security/cve/CVE-2026-53147.html * https://www.suse.com/security/cve/CVE-2026-53148.html * https://www.suse.com/security/cve/CVE-2026-53149.html * https://www.suse.com/security/cve/CVE-2026-53150.html * https://www.suse.com/security/cve/CVE-2026-53158.html * https://www.suse.com/security/cve/CVE-2026-53159.html * https://www.suse.com/security/cve/CVE-2026-53160.html * https://www.suse.com/security/cve/CVE-2026-53161.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53181.html * https://www.suse.com/security/cve/CVE-2026-53186.html * https://www.suse.com/security/cve/CVE-2026-53190.html * https://www.suse.com/security/cve/CVE-2026-53192.html * https://www.suse.com/security/cve/CVE-2026-53194.html * https://www.suse.com/security/cve/CVE-2026-53195.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53202.html * https://www.suse.com/security/cve/CVE-2026-53203.html * https://www.suse.com/security/cve/CVE-2026-53208.html * https://www.suse.com/security/cve/CVE-2026-53209.html * https://www.suse.com/security/cve/CVE-2026-53213.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53218.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53225.html * https://www.suse.com/security/cve/CVE-2026-53227.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53237.html * https://www.suse.com/security/cve/CVE-2026-53239.html * https://www.suse.com/security/cve/CVE-2026-53241.html * https://www.suse.com/security/cve/CVE-2026-53242.html * https://www.suse.com/security/cve/CVE-2026-53245.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53254.html * https://www.suse.com/security/cve/CVE-2026-53255.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53268.html * https://www.suse.com/security/cve/CVE-2026-53272.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53279.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53293.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53313.html * https://www.suse.com/security/cve/CVE-2026-53325.html * https://www.suse.com/security/cve/CVE-2026-53329.html * https://www.suse.com/security/cve/CVE-2026-53339.html * https://www.suse.com/security/cve/CVE-2026-53347.html * https://www.suse.com/security/cve/CVE-2026-53350.html * https://www.suse.com/security/cve/CVE-2026-53355.html * https://www.suse.com/security/cve/CVE-2026-53356.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53358.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1204315 * https://bugzilla.suse.com/show_bug.cgi?id=1243603 * https://bugzilla.suse.com/show_bug.cgi?id=1251942 * https://bugzilla.suse.com/show_bug.cgi?id=1256564 * https://bugzilla.suse.com/show_bug.cgi?id=1257605 * https://bugzilla.suse.com/show_bug.cgi?id=1257777 * https://bugzilla.suse.com/show_bug.cgi?id=1260012 * https://bugzilla.suse.com/show_bug.cgi?id=1260593 * https://bugzilla.suse.com/show_bug.cgi?id=1261250 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1262391 * https://bugzilla.suse.com/show_bug.cgi?id=1262603 * https://bugzilla.suse.com/show_bug.cgi?id=1262605 * https://bugzilla.suse.com/show_bug.cgi?id=1262614 * https://bugzilla.suse.com/show_bug.cgi?id=1262637 * https://bugzilla.suse.com/show_bug.cgi?id=1262639 * https://bugzilla.suse.com/show_bug.cgi?id=1262649 * https://bugzilla.suse.com/show_bug.cgi?id=1262653 * https://bugzilla.suse.com/show_bug.cgi?id=1262658 * https://bugzilla.suse.com/show_bug.cgi?id=1262659 * https://bugzilla.suse.com/show_bug.cgi?id=1262678 * https://bugzilla.suse.com/show_bug.cgi?id=1262723 * https://bugzilla.suse.com/show_bug.cgi?id=1262751 * https://bugzilla.suse.com/show_bug.cgi?id=1262757 * https://bugzilla.suse.com/show_bug.cgi?id=1262765 * https://bugzilla.suse.com/show_bug.cgi?id=1262768 * https://bugzilla.suse.com/show_bug.cgi?id=1262992 * https://bugzilla.suse.com/show_bug.cgi?id=1263008 * https://bugzilla.suse.com/show_bug.cgi?id=1263011 * https://bugzilla.suse.com/show_bug.cgi?id=1263013 * https://bugzilla.suse.com/show_bug.cgi?id=1263014 * https://bugzilla.suse.com/show_bug.cgi?id=1263016 * https://bugzilla.suse.com/show_bug.cgi?id=1263017 * https://bugzilla.suse.com/show_bug.cgi?id=1263020 * https://bugzilla.suse.com/show_bug.cgi?id=1263025 * https://bugzilla.suse.com/show_bug.cgi?id=1263030 * https://bugzilla.suse.com/show_bug.cgi?id=1263031 * https://bugzilla.suse.com/show_bug.cgi?id=1263045 * https://bugzilla.suse.com/show_bug.cgi?id=1263055 * https://bugzilla.suse.com/show_bug.cgi?id=1263059 * https://bugzilla.suse.com/show_bug.cgi?id=1263068 * https://bugzilla.suse.com/show_bug.cgi?id=1263073 * https://bugzilla.suse.com/show_bug.cgi?id=1263075 * https://bugzilla.suse.com/show_bug.cgi?id=1263077 * https://bugzilla.suse.com/show_bug.cgi?id=1263097 * https://bugzilla.suse.com/show_bug.cgi?id=1263111 * https://bugzilla.suse.com/show_bug.cgi?id=1263128 * https://bugzilla.suse.com/show_bug.cgi?id=1263134 * https://bugzilla.suse.com/show_bug.cgi?id=1263139 * https://bugzilla.suse.com/show_bug.cgi?id=1263142 * https://bugzilla.suse.com/show_bug.cgi?id=1263145 * https://bugzilla.suse.com/show_bug.cgi?id=1263167 * https://bugzilla.suse.com/show_bug.cgi?id=1263173 * https://bugzilla.suse.com/show_bug.cgi?id=1263175 * https://bugzilla.suse.com/show_bug.cgi?id=1263491 * https://bugzilla.suse.com/show_bug.cgi?id=1263493 * https://bugzilla.suse.com/show_bug.cgi?id=1263495 * https://bugzilla.suse.com/show_bug.cgi?id=1263539 * https://bugzilla.suse.com/show_bug.cgi?id=1263562 * https://bugzilla.suse.com/show_bug.cgi?id=1263598 * https://bugzilla.suse.com/show_bug.cgi?id=1263657 * https://bugzilla.suse.com/show_bug.cgi?id=1263776 * https://bugzilla.suse.com/show_bug.cgi?id=1263777 * https://bugzilla.suse.com/show_bug.cgi?id=1263778 * https://bugzilla.suse.com/show_bug.cgi?id=1263780 * https://bugzilla.suse.com/show_bug.cgi?id=1263782 * https://bugzilla.suse.com/show_bug.cgi?id=1263785 * https://bugzilla.suse.com/show_bug.cgi?id=1263786 * https://bugzilla.suse.com/show_bug.cgi?id=1263806 * https://bugzilla.suse.com/show_bug.cgi?id=1263876 * https://bugzilla.suse.com/show_bug.cgi?id=1263904 * https://bugzilla.suse.com/show_bug.cgi?id=1263905 * https://bugzilla.suse.com/show_bug.cgi?id=1263911 * https://bugzilla.suse.com/show_bug.cgi?id=1263923 * https://bugzilla.suse.com/show_bug.cgi?id=1263975 * https://bugzilla.suse.com/show_bug.cgi?id=1263999 * https://bugzilla.suse.com/show_bug.cgi?id=1264003 * https://bugzilla.suse.com/show_bug.cgi?id=1264006 * https://bugzilla.suse.com/show_bug.cgi?id=1264008 * https://bugzilla.suse.com/show_bug.cgi?id=1264009 * https://bugzilla.suse.com/show_bug.cgi?id=1264019 * https://bugzilla.suse.com/show_bug.cgi?id=1264030 * https://bugzilla.suse.com/show_bug.cgi?id=1264032 * https://bugzilla.suse.com/show_bug.cgi?id=1264033 * https://bugzilla.suse.com/show_bug.cgi?id=1264035 * https://bugzilla.suse.com/show_bug.cgi?id=1264039 * https://bugzilla.suse.com/show_bug.cgi?id=1264041 * https://bugzilla.suse.com/show_bug.cgi?id=1264044 * https://bugzilla.suse.com/show_bug.cgi?id=1264048 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264065 * https://bugzilla.suse.com/show_bug.cgi?id=1264070 * https://bugzilla.suse.com/show_bug.cgi?id=1264071 * https://bugzilla.suse.com/show_bug.cgi?id=1264073 * https://bugzilla.suse.com/show_bug.cgi?id=1264074 * https://bugzilla.suse.com/show_bug.cgi?id=1264075 * https://bugzilla.suse.com/show_bug.cgi?id=1264079 * https://bugzilla.suse.com/show_bug.cgi?id=1264088 * https://bugzilla.suse.com/show_bug.cgi?id=1264100 * https://bugzilla.suse.com/show_bug.cgi?id=1264101 * https://bugzilla.suse.com/show_bug.cgi?id=1264110 * https://bugzilla.suse.com/show_bug.cgi?id=1264121 * https://bugzilla.suse.com/show_bug.cgi?id=1264122 * https://bugzilla.suse.com/show_bug.cgi?id=1264125 * https://bugzilla.suse.com/show_bug.cgi?id=1264129 * https://bugzilla.suse.com/show_bug.cgi?id=1264142 * https://bugzilla.suse.com/show_bug.cgi?id=1264180 * https://bugzilla.suse.com/show_bug.cgi?id=1264188 * https://bugzilla.suse.com/show_bug.cgi?id=1264189 * https://bugzilla.suse.com/show_bug.cgi?id=1264190 * https://bugzilla.suse.com/show_bug.cgi?id=1264197 * https://bugzilla.suse.com/show_bug.cgi?id=1264237 * https://bugzilla.suse.com/show_bug.cgi?id=1264247 * https://bugzilla.suse.com/show_bug.cgi?id=1264257 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264296 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264308 * https://bugzilla.suse.com/show_bug.cgi?id=1264313 * https://bugzilla.suse.com/show_bug.cgi?id=1264315 * https://bugzilla.suse.com/show_bug.cgi?id=1264317 * https://bugzilla.suse.com/show_bug.cgi?id=1264321 * https://bugzilla.suse.com/show_bug.cgi?id=1264322 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264331 * https://bugzilla.suse.com/show_bug.cgi?id=1264336 * https://bugzilla.suse.com/show_bug.cgi?id=1264338 * https://bugzilla.suse.com/show_bug.cgi?id=1264339 * https://bugzilla.suse.com/show_bug.cgi?id=1264340 * https://bugzilla.suse.com/show_bug.cgi?id=1264365 * https://bugzilla.suse.com/show_bug.cgi?id=1264377 * https://bugzilla.suse.com/show_bug.cgi?id=1264379 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264387 * https://bugzilla.suse.com/show_bug.cgi?id=1264388 * https://bugzilla.suse.com/show_bug.cgi?id=1264414 * https://bugzilla.suse.com/show_bug.cgi?id=1264416 * https://bugzilla.suse.com/show_bug.cgi?id=1264417 * https://bugzilla.suse.com/show_bug.cgi?id=1264419 * https://bugzilla.suse.com/show_bug.cgi?id=1264423 * https://bugzilla.suse.com/show_bug.cgi?id=1264424 * https://bugzilla.suse.com/show_bug.cgi?id=1264425 * https://bugzilla.suse.com/show_bug.cgi?id=1264429 * https://bugzilla.suse.com/show_bug.cgi?id=1264431 * https://bugzilla.suse.com/show_bug.cgi?id=1264436 * https://bugzilla.suse.com/show_bug.cgi?id=1264442 * https://bugzilla.suse.com/show_bug.cgi?id=1264451 * https://bugzilla.suse.com/show_bug.cgi?id=1264473 * https://bugzilla.suse.com/show_bug.cgi?id=1264477 * https://bugzilla.suse.com/show_bug.cgi?id=1264479 * https://bugzilla.suse.com/show_bug.cgi?id=1264480 * https://bugzilla.suse.com/show_bug.cgi?id=1264520 * https://bugzilla.suse.com/show_bug.cgi?id=1264526 * https://bugzilla.suse.com/show_bug.cgi?id=1264531 * https://bugzilla.suse.com/show_bug.cgi?id=1264538 * https://bugzilla.suse.com/show_bug.cgi?id=1264540 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264553 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264560 * https://bugzilla.suse.com/show_bug.cgi?id=1264564 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264584 * https://bugzilla.suse.com/show_bug.cgi?id=1264590 * https://bugzilla.suse.com/show_bug.cgi?id=1264592 * https://bugzilla.suse.com/show_bug.cgi?id=1264594 * https://bugzilla.suse.com/show_bug.cgi?id=1264598 * https://bugzilla.suse.com/show_bug.cgi?id=1264600 * https://bugzilla.suse.com/show_bug.cgi?id=1264613 * https://bugzilla.suse.com/show_bug.cgi?id=1264615 * https://bugzilla.suse.com/show_bug.cgi?id=1264616 * https://bugzilla.suse.com/show_bug.cgi?id=1264618 * https://bugzilla.suse.com/show_bug.cgi?id=1264620 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264626 * https://bugzilla.suse.com/show_bug.cgi?id=1264630 * https://bugzilla.suse.com/show_bug.cgi?id=1264633 * https://bugzilla.suse.com/show_bug.cgi?id=1264637 * https://bugzilla.suse.com/show_bug.cgi?id=1264640 * https://bugzilla.suse.com/show_bug.cgi?id=1264642 * https://bugzilla.suse.com/show_bug.cgi?id=1264644 * https://bugzilla.suse.com/show_bug.cgi?id=1264645 * https://bugzilla.suse.com/show_bug.cgi?id=1264668 * https://bugzilla.suse.com/show_bug.cgi?id=1264677 * https://bugzilla.suse.com/show_bug.cgi?id=1264731 * https://bugzilla.suse.com/show_bug.cgi?id=1264739 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264746 * https://bugzilla.suse.com/show_bug.cgi?id=1264758 * https://bugzilla.suse.com/show_bug.cgi?id=1264768 * https://bugzilla.suse.com/show_bug.cgi?id=1264780 * https://bugzilla.suse.com/show_bug.cgi?id=1264781 * https://bugzilla.suse.com/show_bug.cgi?id=1264782 * https://bugzilla.suse.com/show_bug.cgi?id=1264783 * https://bugzilla.suse.com/show_bug.cgi?id=1264785 * https://bugzilla.suse.com/show_bug.cgi?id=1264788 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264791 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264803 * https://bugzilla.suse.com/show_bug.cgi?id=1264809 * https://bugzilla.suse.com/show_bug.cgi?id=1264815 * https://bugzilla.suse.com/show_bug.cgi?id=1264816 * https://bugzilla.suse.com/show_bug.cgi?id=1264819 * https://bugzilla.suse.com/show_bug.cgi?id=1264821 * https://bugzilla.suse.com/show_bug.cgi?id=1264822 * https://bugzilla.suse.com/show_bug.cgi?id=1264826 * https://bugzilla.suse.com/show_bug.cgi?id=1264830 * https://bugzilla.suse.com/show_bug.cgi?id=1264835 * https://bugzilla.suse.com/show_bug.cgi?id=1264837 * https://bugzilla.suse.com/show_bug.cgi?id=1264844 * https://bugzilla.suse.com/show_bug.cgi?id=1264846 * https://bugzilla.suse.com/show_bug.cgi?id=1264853 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264987 * https://bugzilla.suse.com/show_bug.cgi?id=1264988 * https://bugzilla.suse.com/show_bug.cgi?id=1264991 * https://bugzilla.suse.com/show_bug.cgi?id=1264993 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265019 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265032 * https://bugzilla.suse.com/show_bug.cgi?id=1265037 * https://bugzilla.suse.com/show_bug.cgi?id=1265041 * https://bugzilla.suse.com/show_bug.cgi?id=1265047 * https://bugzilla.suse.com/show_bug.cgi?id=1265054 * https://bugzilla.suse.com/show_bug.cgi?id=1265074 * https://bugzilla.suse.com/show_bug.cgi?id=1265078 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265080 * https://bugzilla.suse.com/show_bug.cgi?id=1265089 * https://bugzilla.suse.com/show_bug.cgi?id=1265092 * https://bugzilla.suse.com/show_bug.cgi?id=1265093 * https://bugzilla.suse.com/show_bug.cgi?id=1265096 * https://bugzilla.suse.com/show_bug.cgi?id=1265100 * https://bugzilla.suse.com/show_bug.cgi?id=1265101 * https://bugzilla.suse.com/show_bug.cgi?id=1265102 * https://bugzilla.suse.com/show_bug.cgi?id=1265105 * https://bugzilla.suse.com/show_bug.cgi?id=1265112 * https://bugzilla.suse.com/show_bug.cgi?id=1265133 * https://bugzilla.suse.com/show_bug.cgi?id=1265138 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1265249 * https://bugzilla.suse.com/show_bug.cgi?id=1265257 * https://bugzilla.suse.com/show_bug.cgi?id=1265264 * https://bugzilla.suse.com/show_bug.cgi?id=1265627 * https://bugzilla.suse.com/show_bug.cgi?id=1266000 * https://bugzilla.suse.com/show_bug.cgi?id=1266003 * https://bugzilla.suse.com/show_bug.cgi?id=1266399 * https://bugzilla.suse.com/show_bug.cgi?id=1266411 * https://bugzilla.suse.com/show_bug.cgi?id=1266412 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266467 * https://bugzilla.suse.com/show_bug.cgi?id=1266468 * https://bugzilla.suse.com/show_bug.cgi?id=1266677 * https://bugzilla.suse.com/show_bug.cgi?id=1266679 * https://bugzilla.suse.com/show_bug.cgi?id=1266684 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266688 * https://bugzilla.suse.com/show_bug.cgi?id=1266692 * https://bugzilla.suse.com/show_bug.cgi?id=1266703 * https://bugzilla.suse.com/show_bug.cgi?id=1266707 * https://bugzilla.suse.com/show_bug.cgi?id=1266721 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266729 * https://bugzilla.suse.com/show_bug.cgi?id=1266732 * https://bugzilla.suse.com/show_bug.cgi?id=1266739 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266741 * https://bugzilla.suse.com/show_bug.cgi?id=1266743 * https://bugzilla.suse.com/show_bug.cgi?id=1266744 * https://bugzilla.suse.com/show_bug.cgi?id=1266751 * https://bugzilla.suse.com/show_bug.cgi?id=1266755 * https://bugzilla.suse.com/show_bug.cgi?id=1266762 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266774 * https://bugzilla.suse.com/show_bug.cgi?id=1266775 * https://bugzilla.suse.com/show_bug.cgi?id=1266777 * https://bugzilla.suse.com/show_bug.cgi?id=1266780 * https://bugzilla.suse.com/show_bug.cgi?id=1266805 * https://bugzilla.suse.com/show_bug.cgi?id=1266806 * https://bugzilla.suse.com/show_bug.cgi?id=1266831 * https://bugzilla.suse.com/show_bug.cgi?id=1266832 * https://bugzilla.suse.com/show_bug.cgi?id=1266834 * https://bugzilla.suse.com/show_bug.cgi?id=1266836 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266839 * https://bugzilla.suse.com/show_bug.cgi?id=1266841 * https://bugzilla.suse.com/show_bug.cgi?id=1266842 * https://bugzilla.suse.com/show_bug.cgi?id=1266846 * https://bugzilla.suse.com/show_bug.cgi?id=1266854 * https://bugzilla.suse.com/show_bug.cgi?id=1266855 * https://bugzilla.suse.com/show_bug.cgi?id=1266863 * https://bugzilla.suse.com/show_bug.cgi?id=1266864 * https://bugzilla.suse.com/show_bug.cgi?id=1266870 * https://bugzilla.suse.com/show_bug.cgi?id=1266872 * https://bugzilla.suse.com/show_bug.cgi?id=1266879 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266884 * https://bugzilla.suse.com/show_bug.cgi?id=1266886 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1266894 * https://bugzilla.suse.com/show_bug.cgi?id=1266898 * https://bugzilla.suse.com/show_bug.cgi?id=1266908 * https://bugzilla.suse.com/show_bug.cgi?id=1266910 * https://bugzilla.suse.com/show_bug.cgi?id=1266917 * https://bugzilla.suse.com/show_bug.cgi?id=1266920 * https://bugzilla.suse.com/show_bug.cgi?id=1266925 * https://bugzilla.suse.com/show_bug.cgi?id=1266934 * https://bugzilla.suse.com/show_bug.cgi?id=1266935 * https://bugzilla.suse.com/show_bug.cgi?id=1266939 * https://bugzilla.suse.com/show_bug.cgi?id=1266947 * https://bugzilla.suse.com/show_bug.cgi?id=1267021 * https://bugzilla.suse.com/show_bug.cgi?id=1267027 * https://bugzilla.suse.com/show_bug.cgi?id=1267198 * https://bugzilla.suse.com/show_bug.cgi?id=1267204 * https://bugzilla.suse.com/show_bug.cgi?id=1267213 * https://bugzilla.suse.com/show_bug.cgi?id=1267226 * https://bugzilla.suse.com/show_bug.cgi?id=1267234 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267367 * https://bugzilla.suse.com/show_bug.cgi?id=1267380 * https://bugzilla.suse.com/show_bug.cgi?id=1267432 * https://bugzilla.suse.com/show_bug.cgi?id=1267435 * https://bugzilla.suse.com/show_bug.cgi?id=1267436 * https://bugzilla.suse.com/show_bug.cgi?id=1267445 * https://bugzilla.suse.com/show_bug.cgi?id=1267448 * https://bugzilla.suse.com/show_bug.cgi?id=1267449 * https://bugzilla.suse.com/show_bug.cgi?id=1267466 * https://bugzilla.suse.com/show_bug.cgi?id=1267472 * https://bugzilla.suse.com/show_bug.cgi?id=1267473 * https://bugzilla.suse.com/show_bug.cgi?id=1267479 * https://bugzilla.suse.com/show_bug.cgi?id=1267491 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267495 * https://bugzilla.suse.com/show_bug.cgi?id=1267496 * https://bugzilla.suse.com/show_bug.cgi?id=1267497 * https://bugzilla.suse.com/show_bug.cgi?id=1267502 * https://bugzilla.suse.com/show_bug.cgi?id=1267524 * https://bugzilla.suse.com/show_bug.cgi?id=1267555 * https://bugzilla.suse.com/show_bug.cgi?id=1267565 * https://bugzilla.suse.com/show_bug.cgi?id=1267571 * https://bugzilla.suse.com/show_bug.cgi?id=1267583 * https://bugzilla.suse.com/show_bug.cgi?id=1267592 * https://bugzilla.suse.com/show_bug.cgi?id=1267595 * https://bugzilla.suse.com/show_bug.cgi?id=1267611 * https://bugzilla.suse.com/show_bug.cgi?id=1267615 * https://bugzilla.suse.com/show_bug.cgi?id=1267616 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267623 * https://bugzilla.suse.com/show_bug.cgi?id=1267627 * https://bugzilla.suse.com/show_bug.cgi?id=1267630 * https://bugzilla.suse.com/show_bug.cgi?id=1267632 * https://bugzilla.suse.com/show_bug.cgi?id=1267636 * https://bugzilla.suse.com/show_bug.cgi?id=1267638 * https://bugzilla.suse.com/show_bug.cgi?id=1267643 * https://bugzilla.suse.com/show_bug.cgi?id=1267646 * https://bugzilla.suse.com/show_bug.cgi?id=1267649 * https://bugzilla.suse.com/show_bug.cgi?id=1267658 * https://bugzilla.suse.com/show_bug.cgi?id=1267661 * https://bugzilla.suse.com/show_bug.cgi?id=1267666 * https://bugzilla.suse.com/show_bug.cgi?id=1267667 * https://bugzilla.suse.com/show_bug.cgi?id=1267669 * https://bugzilla.suse.com/show_bug.cgi?id=1267676 * https://bugzilla.suse.com/show_bug.cgi?id=1267677 * https://bugzilla.suse.com/show_bug.cgi?id=1267680 * https://bugzilla.suse.com/show_bug.cgi?id=1267683 * https://bugzilla.suse.com/show_bug.cgi?id=1267690 * https://bugzilla.suse.com/show_bug.cgi?id=1267691 * https://bugzilla.suse.com/show_bug.cgi?id=1267693 * https://bugzilla.suse.com/show_bug.cgi?id=1267701 * https://bugzilla.suse.com/show_bug.cgi?id=1267702 * https://bugzilla.suse.com/show_bug.cgi?id=1267704 * https://bugzilla.suse.com/show_bug.cgi?id=1267712 * https://bugzilla.suse.com/show_bug.cgi?id=1267719 * https://bugzilla.suse.com/show_bug.cgi?id=1267725 * https://bugzilla.suse.com/show_bug.cgi?id=1267728 * https://bugzilla.suse.com/show_bug.cgi?id=1267922 * https://bugzilla.suse.com/show_bug.cgi?id=1267932 * https://bugzilla.suse.com/show_bug.cgi?id=1267939 * https://bugzilla.suse.com/show_bug.cgi?id=1267948 * https://bugzilla.suse.com/show_bug.cgi?id=1267968 * https://bugzilla.suse.com/show_bug.cgi?id=1267987 * https://bugzilla.suse.com/show_bug.cgi?id=1267990 * https://bugzilla.suse.com/show_bug.cgi?id=1267991 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268024 * https://bugzilla.suse.com/show_bug.cgi?id=1268049 * https://bugzilla.suse.com/show_bug.cgi?id=1268051 * https://bugzilla.suse.com/show_bug.cgi?id=1268220 * https://bugzilla.suse.com/show_bug.cgi?id=1268221 * https://bugzilla.suse.com/show_bug.cgi?id=1268223 * https://bugzilla.suse.com/show_bug.cgi?id=1268981 * https://bugzilla.suse.com/show_bug.cgi?id=1268986 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269001 * https://bugzilla.suse.com/show_bug.cgi?id=1269002 * https://bugzilla.suse.com/show_bug.cgi?id=1269008 * https://bugzilla.suse.com/show_bug.cgi?id=1269025 * https://bugzilla.suse.com/show_bug.cgi?id=1269030 * https://bugzilla.suse.com/show_bug.cgi?id=1269031 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269081 * https://bugzilla.suse.com/show_bug.cgi?id=1269095 * https://bugzilla.suse.com/show_bug.cgi?id=1269098 * https://bugzilla.suse.com/show_bug.cgi?id=1269106 * https://bugzilla.suse.com/show_bug.cgi?id=1269111 * https://bugzilla.suse.com/show_bug.cgi?id=1269116 * https://bugzilla.suse.com/show_bug.cgi?id=1269124 * https://bugzilla.suse.com/show_bug.cgi?id=1269125 * https://bugzilla.suse.com/show_bug.cgi?id=1269129 * https://bugzilla.suse.com/show_bug.cgi?id=1269131 * https://bugzilla.suse.com/show_bug.cgi?id=1269133 * https://bugzilla.suse.com/show_bug.cgi?id=1269141 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269153 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269177 * https://bugzilla.suse.com/show_bug.cgi?id=1269178 * https://bugzilla.suse.com/show_bug.cgi?id=1269187 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269190 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269236 * https://bugzilla.suse.com/show_bug.cgi?id=1269239 * https://bugzilla.suse.com/show_bug.cgi?id=1269245 * https://bugzilla.suse.com/show_bug.cgi?id=1269254 * https://bugzilla.suse.com/show_bug.cgi?id=1269255 * https://bugzilla.suse.com/show_bug.cgi?id=1269257 * https://bugzilla.suse.com/show_bug.cgi?id=1269258 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269273 * https://bugzilla.suse.com/show_bug.cgi?id=1269283 * https://bugzilla.suse.com/show_bug.cgi?id=1269304 * https://bugzilla.suse.com/show_bug.cgi?id=1269364 * https://bugzilla.suse.com/show_bug.cgi?id=1269378 * https://bugzilla.suse.com/show_bug.cgi?id=1269385 * https://bugzilla.suse.com/show_bug.cgi?id=1269386 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269403 * https://bugzilla.suse.com/show_bug.cgi?id=1269404 * https://bugzilla.suse.com/show_bug.cgi?id=1269410 * https://bugzilla.suse.com/show_bug.cgi?id=1269414 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269505 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269556 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269637 * https://bugzilla.suse.com/show_bug.cgi?id=1269644 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269652 * https://bugzilla.suse.com/show_bug.cgi?id=1269654 * https://bugzilla.suse.com/show_bug.cgi?id=1269661 * https://bugzilla.suse.com/show_bug.cgi?id=1269663 * https://bugzilla.suse.com/show_bug.cgi?id=1269669 * https://bugzilla.suse.com/show_bug.cgi?id=1269670 * https://bugzilla.suse.com/show_bug.cgi?id=1269674 * https://bugzilla.suse.com/show_bug.cgi?id=1269675 * https://bugzilla.suse.com/show_bug.cgi?id=1269677 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269682 * https://bugzilla.suse.com/show_bug.cgi?id=1269684 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269709 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269711 * https://bugzilla.suse.com/show_bug.cgi?id=1269719 * https://bugzilla.suse.com/show_bug.cgi?id=1269726 * https://bugzilla.suse.com/show_bug.cgi?id=1269733 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269770 * https://bugzilla.suse.com/show_bug.cgi?id=1269772 * https://bugzilla.suse.com/show_bug.cgi?id=1269786 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269796 * https://bugzilla.suse.com/show_bug.cgi?id=1269799 * https://bugzilla.suse.com/show_bug.cgi?id=1269809 * https://bugzilla.suse.com/show_bug.cgi?id=1269811 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269817 * https://bugzilla.suse.com/show_bug.cgi?id=1269826 * https://bugzilla.suse.com/show_bug.cgi?id=1269877 * https://bugzilla.suse.com/show_bug.cgi?id=1269886 * https://bugzilla.suse.com/show_bug.cgi?id=1269889 * https://bugzilla.suse.com/show_bug.cgi?id=1269898 * https://bugzilla.suse.com/show_bug.cgi?id=1269899 * https://bugzilla.suse.com/show_bug.cgi?id=1269904 * https://bugzilla.suse.com/show_bug.cgi?id=1269976 * https://bugzilla.suse.com/show_bug.cgi?id=1269984 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269988 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1269996 * https://bugzilla.suse.com/show_bug.cgi?id=1269997 * https://bugzilla.suse.com/show_bug.cgi?id=1269998 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270042 * https://bugzilla.suse.com/show_bug.cgi?id=1270058 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270112 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1270241 * https://bugzilla.suse.com/show_bug.cgi?id=1270244 * https://bugzilla.suse.com/show_bug.cgi?id=1270248 * https://bugzilla.suse.com/show_bug.cgi?id=1270249 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1270260 * https://bugzilla.suse.com/show_bug.cgi?id=1270263 * https://bugzilla.suse.com/show_bug.cgi?id=1270268 * https://bugzilla.suse.com/show_bug.cgi?id=1270302 * https://bugzilla.suse.com/show_bug.cgi?id=1270396 * https://bugzilla.suse.com/show_bug.cgi?id=1271040 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271248 * https://bugzilla.suse.com/show_bug.cgi?id=1271249 * https://bugzilla.suse.com/show_bug.cgi?id=1271287 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271402 * https://jira.suse.com/browse/PED-15897 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 08:43:56 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 08:43:56 -0000 Subject: SUSE-SU-2026:3169-1: moderate: Security update for openexr Message-ID: <178470983611.55.7534928109275440499@cbbac00f79c6> # Security update for openexr Announcement ID: SUSE-SU-2026:3169-1 Release Date: 2026-07-21T18:45:13Z Rating: moderate References: * bsc#1269701 * bsc#1269702 * bsc#1269703 Cross-References: * CVE-2026-54920 * CVE-2026-55059 * CVE-2026-55373 CVSS scores: * CVE-2026-54920 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55059 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-55373 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for openexr fixes the following issues * CVE-2026-54920: unchecked integer overflows in Image::resize() followed by an exception can lead to an invalid delete via uninitialized pointers (bsc#1269703). * CVE-2026-55059: row setter utilizing dataWindow.min.x instead of min.y can lead to a heap out-of-bounds write (bsc#1269702). * CVE-2026-55373: integer overflow in roundListSizeUp() wrapping a 32-bit unsigned value to zero can lead to an infinite loop (bsc#1269701). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3169=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libIlmImfUtil-2_2-23-2.2.1-150000.3.52.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.52.1 * libIlmImf-2_2-23-2.2.1-150000.3.52.1 * openexr-debugsource-2.2.1-150000.3.52.1 * openexr-devel-2.2.1-150000.3.52.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.52.1 * openexr-debuginfo-2.2.1-150000.3.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54920.html * https://www.suse.com/security/cve/CVE-2026-55059.html * https://www.suse.com/security/cve/CVE-2026-55373.html * https://bugzilla.suse.com/show_bug.cgi?id=1269701 * https://bugzilla.suse.com/show_bug.cgi?id=1269702 * https://bugzilla.suse.com/show_bug.cgi?id=1269703 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 08:44:03 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 08:44:03 -0000 Subject: SUSE-SU-2026:3168-1: moderate: Security update for openexr Message-ID: <178470984308.55.16869648311530066275@cbbac00f79c6> # Security update for openexr Announcement ID: SUSE-SU-2026:3168-1 Release Date: 2026-07-21T18:44:49Z Rating: moderate References: * bsc#1269703 Cross-References: * CVE-2026-54920 CVSS scores: * CVE-2026-54920 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for openexr fixes the following issue * CVE-2026-54920: unchecked integer overflows in Image::resize() followed by an exception can lead to an invalid delete via uninitialized pointers (bsc#1269703). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3168=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libIlmImf-Imf_2_1-21-debuginfo-2.1.0-6.48.1 * openexr-2.1.0-6.48.1 * libIlmImf-Imf_2_1-21-2.1.0-6.48.1 * openexr-debuginfo-2.1.0-6.48.1 * openexr-debugsource-2.1.0-6.48.1 * openexr-devel-2.1.0-6.48.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54920.html * https://bugzilla.suse.com/show_bug.cgi?id=1269703 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 08:44:16 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 08:44:16 -0000 Subject: SUSE-SU-2026:3167-1: moderate: Security update for tomcat Message-ID: <178470985679.55.15725748660085079124@cbbac00f79c6> # Security update for tomcat Announcement ID: SUSE-SU-2026:3167-1 Release Date: 2026-07-21T18:33:27Z Rating: moderate References: * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues Update to Tomcat 9.0.119. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Tomcat 9.0.119 * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This is a breaking change for the EncryptInterceptor. (markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Wrong references to jakarta instead of javax. (remm) * Fix: Restore default authenticator to nullafter executing an Ant task. (remm) * Update: Update Commons Daemon to 1.6.1. (markt) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update Tomcat Native to 1.3.8. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3167=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * tomcat-docs-webapp-9.0.119-3.169.1 * tomcat-webapps-9.0.119-3.169.1 * tomcat-el-3_0-api-9.0.119-3.169.1 * tomcat-jsp-2_3-api-9.0.119-3.169.1 * tomcat-servlet-4_0-api-9.0.119-3.169.1 * tomcat-javadoc-9.0.119-3.169.1 * tomcat-admin-webapps-9.0.119-3.169.1 * tomcat-9.0.119-3.169.1 * tomcat-lib-9.0.119-3.169.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:30:10 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:30:10 -0000 Subject: SUSE-SU-2026:22737-1: moderate: Security update for s390-tools Message-ID: <178473781061.189.17533490911362458822@cbbac00f79c6> # Security update for s390-tools Announcement ID: SUSE-SU-2026:22737-1 Release Date: 2026-07-09T07:32:43Z Rating: moderate References: * bsc#1270185 Cross-References: * CVE-2026-41676 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for s390-tools fixes the following issue * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270185). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-789=1 ## Package List: * SUSE Linux Micro 6.0 (s390x) * libkmipclient1-debuginfo-2.31.0-4.1 * s390-tools-debuginfo-2.31.0-4.1 * libekmfweb1-2.31.0-4.1 * libekmfweb1-debuginfo-2.31.0-4.1 * libkmipclient1-2.31.0-4.1 * s390-tools-debugsource-2.31.0-4.1 * s390-tools-2.31.0-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270185 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:30:29 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:30:29 -0000 Subject: SUSE-SU-2026:22736-1: important: Security update for systemd Message-ID: <178473782937.189.15241786884008754847@cbbac00f79c6> # Security update for systemd Announcement ID: SUSE-SU-2026:22736-1 Release Date: 2026-07-16T12:25:57Z Rating: important References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1262305 * bsc#1267644 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has five fixes can now be installed. ## Description: This update for systemd fixes the following issues: Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Import commit 260e668bfa (bsc#1267647 bsc#1262305 bsc#1267644). * Import commit 58e5d2e21e (bsc#1261982). * Import commit 4bd91117cc (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-794=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libsystemd0-254.27-4.1 * udev-254.27-4.1 * systemd-experimental-254.27-4.1 * systemd-experimental-debuginfo-254.27-4.1 * systemd-portable-debuginfo-254.27-4.1 * libsystemd0-debuginfo-254.27-4.1 * systemd-debugsource-254.27-4.1 * libudev1-254.27-4.1 * libudev1-debuginfo-254.27-4.1 * systemd-container-debuginfo-254.27-4.1 * systemd-coredump-254.27-4.1 * systemd-journal-remote-254.27-4.1 * systemd-journal-remote-debuginfo-254.27-4.1 * systemd-254.27-4.1 * systemd-coredump-debuginfo-254.27-4.1 * systemd-debuginfo-254.27-4.1 * systemd-container-254.27-4.1 * systemd-portable-254.27-4.1 * udev-debuginfo-254.27-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1262305 * https://bugzilla.suse.com/show_bug.cgi?id=1267644 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:31:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:31:02 -0000 Subject: SUSE-SU-2026:22735-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473786224.189.3761333068078075462@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22735-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-529=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-45-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-45-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_22-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:31:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:31:42 -0000 Subject: SUSE-SU-2026:22734-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473790233.189.14734094229612928977@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22734-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-528=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-3-1.1 * kernel-livepatch-6_4_0-43-default-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:32:16 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:32:16 -0000 Subject: SUSE-SU-2026:22733-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473793606.189.9427445275146615828@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22733-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-527=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-42-default-debuginfo-4-1.1 * kernel-livepatch-MICRO-6-0_Update_19-debugsource-4-1.1 * kernel-livepatch-6_4_0-42-default-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:32:53 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:32:53 -0000 Subject: SUSE-SU-2026:22732-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473797329.189.14754231956790425584@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22732-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-526=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_18-debugsource-6-1.1 * kernel-livepatch-6_4_0-41-default-6-1.1 * kernel-livepatch-6_4_0-41-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:33:29 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:33:29 -0000 Subject: SUSE-SU-2026:22731-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473800973.189.206163861296867478@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22731-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-525=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_17-debugsource-7-1.1 * kernel-livepatch-6_4_0-40-default-7-1.1 * kernel-livepatch-6_4_0-40-default-debuginfo-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:34:08 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:34:08 -0000 Subject: SUSE-SU-2026:22730-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473804857.189.16234952621288183822@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22730-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-524=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_14-debugsource-9-1.2 * kernel-livepatch-6_4_0-38-default-9-1.2 * kernel-livepatch-6_4_0-38-default-debuginfo-9-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:34:47 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:34:47 -0000 Subject: SUSE-SU-2026:22729-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473808701.189.8292728490529902991@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22729-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-523=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-31-default-20-1.2 * kernel-livepatch-MICRO-6-0_Update_9-debugsource-20-1.2 * kernel-livepatch-6_4_0-31-default-debuginfo-20-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:35:26 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:35:26 -0000 Subject: SUSE-SU-2026:22728-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473812658.189.9816877002873376309@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22728-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-30.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-522=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-20-1.2 * kernel-livepatch-6_4_0-30-default-debuginfo-20-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-20-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:35:43 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:35:43 -0000 Subject: SUSE-SU-2026:22727-1: important: Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473814367.189.13204166015551942373@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22727-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-521=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-47-rt-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_24-debugsource-2-1.1 * kernel-livepatch-6_4_0-47-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:36:17 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:36:17 -0000 Subject: SUSE-SU-2026:22726-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473817731.189.7314562077715071551@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22726-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-520=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-46-rt-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-3-1.1 * kernel-livepatch-6_4_0-46-rt-debuginfo-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:36:56 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:36:56 -0000 Subject: SUSE-SU-2026:22725-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473821616.189.8371715278981186188@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22725-1 Release Date: 2026-07-16T08:59:27Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-519=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-38-rt-debuginfo-9-1.1 * kernel-livepatch-6_4_0-38-rt-9-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:37:13 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:37:13 -0000 Subject: SUSE-SU-2026:22724-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473823312.189.604801957342052952@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22724-1 Release Date: 2026-07-16T08:57:28Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-518=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-46-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_23-debugsource-3-1.1 * kernel-livepatch-6_4_0-46-default-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:37:46 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:37:46 -0000 Subject: SUSE-SU-2026:22723-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473826624.189.16664705636345540050@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22723-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-517=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-44-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_21-debugsource-3-1.1 * kernel-livepatch-6_4_0-44-default-debuginfo-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:38:22 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:38:22 -0000 Subject: SUSE-SU-2026:22722-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473830280.189.10466441422548520513@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22722-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-516=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-39-default-8-1.1 * kernel-livepatch-6_4_0-39-default-debuginfo-8-1.1 * kernel-livepatch-MICRO-6-0_Update_16-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:39:01 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:39:01 -0000 Subject: SUSE-SU-2026:22721-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473834123.189.734064869464727738@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22721-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-515=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-36-default-11-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-11-1.1 * kernel-livepatch-MICRO-6-0_Update_13-debugsource-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:39:46 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:39:46 -0000 Subject: SUSE-SU-2026:22720-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473838604.189.15982398527259593962@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22720-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-514=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-debuginfo-13-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-13-1.1 * kernel-livepatch-6_4_0-35-default-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:40:25 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:40:25 -0000 Subject: SUSE-SU-2026:22719-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473842504.189.11359165531245053121@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22719-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-513=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_11-debugsource-13-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-13-1.1 * kernel-livepatch-6_4_0-34-default-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:41:03 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:41:03 -0000 Subject: SUSE-SU-2026:22718-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473846349.189.17822137058659560878@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22718-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-512=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-14-1.1 * kernel-livepatch-6_4_0-32-default-debuginfo-14-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:41:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:41:36 -0000 Subject: SUSE-SU-2026:22717-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473849644.189.15851935882276269488@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22717-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-511=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-3-1.2 * kernel-livepatch-6_4_0-45-rt-debuginfo-3-1.2 * kernel-livepatch-6_4_0-45-rt-3-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:42:10 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:42:10 -0000 Subject: SUSE-SU-2026:22716-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473853004.189.2560893962148254809@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22716-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-510=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-43-rt-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-3-1.1 * kernel-livepatch-6_4_0-43-rt-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:42:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:42:42 -0000 Subject: SUSE-SU-2026:22715-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473856263.189.17086759201014091269@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22715-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-509=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-4-1.1 * kernel-livepatch-6_4_0-42-rt-debuginfo-4-1.1 * kernel-livepatch-6_4_0-42-rt-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:43:15 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:43:15 -0000 Subject: SUSE-SU-2026:22714-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473859552.189.15671015087362111@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22714-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-508=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-6-1.1 * kernel-livepatch-6_4_0-41-rt-6-1.1 * kernel-livepatch-6_4_0-41-rt-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:43:54 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:43:54 -0000 Subject: SUSE-SU-2026:22713-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473863487.189.14390548144448655997@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22713-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-507=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-7-1.1 * kernel-livepatch-6_4_0-40-rt-debuginfo-7-1.1 * kernel-livepatch-6_4_0-40-rt-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:44:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:44:36 -0000 Subject: SUSE-SU-2026:22712-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473867602.189.8931958714447569829@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22712-1 Release Date: 2026-07-16T08:24:10Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-506=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-39-rt-8-1.1 * kernel-livepatch-6_4_0-39-rt-debuginfo-8-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:45:20 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:45:20 -0000 Subject: SUSE-SU-2026:22711-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473872046.189.16552702800526741718@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22711-1 Release Date: 2026-07-16T08:21:48Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-504=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-37-rt-9-1.1 * kernel-livepatch-6_4_0-37-rt-debuginfo-9-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:45:37 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:45:37 -0000 Subject: SUSE-SU-2026:22710-1: important: Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178473873759.189.3884170726105139162@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22710-1 Release Date: 2026-07-16T08:20:26Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-505=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_24-debugsource-2-1.1 * kernel-livepatch-6_4_0-47-default-2-1.1 * kernel-livepatch-6_4_0-47-default-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:45:55 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:45:55 -0000 Subject: SUSE-SU-2026:22709-1: important: Security update for curl Message-ID: <178473875573.189.8825382326267746419@cbbac00f79c6> # Security update for curl Announcement ID: SUSE-SU-2026:22709-1 Release Date: 2026-07-14T12:49:24Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-793=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * curl-debugsource-8.14.1-7.1 * curl-debuginfo-8.14.1-7.1 * curl-8.14.1-7.1 * libcurl4-8.14.1-7.1 * libcurl4-debuginfo-8.14.1-7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:46:01 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:46:01 -0000 Subject: SUSE-SU-2026:22708-1: moderate: Security update for python-tornado6 Message-ID: <178473876150.189.18310975050050918108@cbbac00f79c6> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:22708-1 Release Date: 2026-07-14T12:34:12Z Rating: moderate References: * bsc#1269012 Affected Products: * SUSE Linux Micro 6.0 An update that has one fix can now be installed. ## Description: This update for python-tornado6 fixes the following issue * GHSA-pw6j-qg29-8w7f: `CurlAsyncHTTPClient` leaks per-request credentials on handle reuse (bsc#1269012). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-792=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * python311-tornado6-debuginfo-6.4-7.1 * python-tornado6-debugsource-6.4-7.1 * python311-tornado6-6.4-7.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269012 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:46:07 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:46:07 -0000 Subject: SUSE-SU-2026:22707-1: moderate: Security update for nghttp2 Message-ID: <178473876717.189.8250738972589167668@cbbac00f79c6> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:22707-1 Release Date: 2026-07-10T08:06:26Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-791=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libnghttp2-14-debuginfo-1.52.0-7.1 * libnghttp2-14-1.52.0-7.1 * nghttp2-debugsource-1.52.0-7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:46:15 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:46:15 -0000 Subject: SUSE-SU-2026:22706-1: important: Security update for dnsmasq Message-ID: <178473877551.189.14139320762582427239@cbbac00f79c6> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:22706-1 Release Date: 2026-07-10T08:06:26Z Rating: important References: * bsc#1268764 * bsc#1268882 Cross-References: * CVE-2026-12725 * CVE-2026-12969 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12969 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). * CVE-2026-12969: out-of-bounds read in `find_soa()` due to missing extrabytes validation (bsc#1268882). Changes for dnsmasq: * Update to 2.93: * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-790=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * dnsmasq-2.93-1.1 * dnsmasq-debuginfo-2.93-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-12969.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 * https://bugzilla.suse.com/show_bug.cgi?id=1268882 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:46:31 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:46:31 -0000 Subject: SUSE-SU-2026:22705-1: moderate: Security update for jq Message-ID: <178473879162.189.8910683734284625322@cbbac00f79c6> # Security update for jq Announcement ID: SUSE-SU-2026:22705-1 Release Date: 2026-07-08T11:04:34Z Rating: moderate References: * bsc#1248600 * bsc#1262043 * bsc#1262044 * bsc#1262069 * bsc#1262070 * bsc#1262071 * bsc#1262072 Cross-References: * CVE-2025-9403 * CVE-2026-32316 * CVE-2026-33947 * CVE-2026-33948 * CVE-2026-39956 * CVE-2026-39979 * CVE-2026-40164 CVSS scores: * CVE-2025-9403 ( SUSE ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-9403 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-9403 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-9403 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-9403 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32316 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-32316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32316 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-33947 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33947 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33948 ( SUSE ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-33948 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-39956 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39956 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39956 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39979 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39979 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-39979 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40164 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues Security issues fixed: * CVE-2025-9403: reacheable assertion in `run_jq_tests` can lead to program termination when processing malformed JSON input containing invalid Unicode escape sequences (bsc#1248600). * CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). * CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). * CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). * CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). * CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). * CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre- computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). Other updates and bugfixes: * spec: add `--enable-pthread-tls` to configure invocation. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-788=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * jq-1.6-6.1 * libjq1-1.6-6.1 * jq-debuginfo-1.6-6.1 * libjq1-debuginfo-1.6-6.1 * jq-debugsource-1.6-6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9403.html * https://www.suse.com/security/cve/CVE-2026-32316.html * https://www.suse.com/security/cve/CVE-2026-33947.html * https://www.suse.com/security/cve/CVE-2026-33948.html * https://www.suse.com/security/cve/CVE-2026-39956.html * https://www.suse.com/security/cve/CVE-2026-39979.html * https://www.suse.com/security/cve/CVE-2026-40164.html * https://bugzilla.suse.com/show_bug.cgi?id=1248600 * https://bugzilla.suse.com/show_bug.cgi?id=1262043 * https://bugzilla.suse.com/show_bug.cgi?id=1262044 * https://bugzilla.suse.com/show_bug.cgi?id=1262069 * https://bugzilla.suse.com/show_bug.cgi?id=1262070 * https://bugzilla.suse.com/show_bug.cgi?id=1262071 * https://bugzilla.suse.com/show_bug.cgi?id=1262072 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:46:37 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:46:37 -0000 Subject: SUSE-SU-2026:22704-1: important: Security update for python-msgpack Message-ID: <178473879744.189.3861522083297974836@cbbac00f79c6> # Security update for python-msgpack Announcement ID: SUSE-SU-2026:22704-1 Release Date: 2026-07-08T10:56:09Z Rating: important References: * bsc#1269947 Cross-References: * CVE-2026-57585 CVSS scores: * CVE-2026-57585 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57585 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-msgpack fixes the following issue * CVE-2026-57585: reusing an Unpacker instance after an error has been caught can lead to an out-of-bounds read (bsc#1269947). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-787=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * python-msgpack-debugsource-1.0.5-2.1 * python311-msgpack-1.0.5-2.1 * python311-msgpack-debuginfo-1.0.5-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57585.html * https://bugzilla.suse.com/show_bug.cgi?id=1269947 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:46:47 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:46:47 -0000 Subject: SUSE-SU-2026:22703-1: important: Security update for docker-compose Message-ID: <178473880714.189.2930416945982816338@cbbac00f79c6> # Security update for docker-compose Announcement ID: SUSE-SU-2026:22703-1 Release Date: 2026-07-07T11:59:53Z Rating: important References: * bsc#1239340 * bsc#1239766 * bsc#1265782 * bsc#1266625 Cross-References: * CVE-2025-0495 * CVE-2025-22869 * CVE-2026-33814 * CVE-2026-39821 CVSS scores: * CVE-2025-0495 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-0495 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N * CVE-2025-0495 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker-compose fixes the following issues * CVE-2025-0495: buildx: credential leakage to telemetry endpoints when credentials allowed to be set as attribute values in cache-to/cache-from configuration (bsc#1239766). * CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239340). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-786=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * docker-compose-2.33.1-5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0495.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1239340 * https://bugzilla.suse.com/show_bug.cgi?id=1239766 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:46:53 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:46:53 -0000 Subject: SUSE-SU-2026:22702-1: important: Security update for krb5 Message-ID: <178473881303.189.5405874674529338878@cbbac00f79c6> # Security update for krb5 Announcement ID: SUSE-SU-2026:22702-1 Release Date: 2026-07-07T11:59:53Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-785=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * krb5-client-debuginfo-1.20.1-9.1 * krb5-client-1.20.1-9.1 * krb5-debugsource-1.20.1-9.1 * krb5-debuginfo-1.20.1-9.1 * krb5-1.20.1-9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:06 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:06 -0000 Subject: SUSE-SU-2026:22701-1: important: Security update for systemd Message-ID: <178473882603.189.4860676470826618182@cbbac00f79c6> # Security update for systemd Announcement ID: SUSE-SU-2026:22701-1 Release Date: 2026-07-16T12:29:13Z Rating: important References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1262305 * bsc#1267644 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves one vulnerability and has five fixes can now be installed. ## Description: This update for systemd fixes the following issues: Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Import commit 260e668bfa (bsc#1267647 bsc#1262305 bsc#1267644). * Import commit 58e5d2e21e (bsc#1261982). * Import commit 4bd91117cc (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-794=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * systemd-devel-254.27-4.1 * systemd-debugsource-254.27-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1262305 * https://bugzilla.suse.com/show_bug.cgi?id=1267644 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:11 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:11 -0000 Subject: SUSE-SU-2026:22700-1: important: Security update for krb5 Message-ID: <178473883160.189.2006819201476764905@cbbac00f79c6> # Security update for krb5 Announcement ID: SUSE-SU-2026:22700-1 Release Date: 2026-07-07T12:04:16Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-785=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * krb5-mini-debugsource-1.20.1-9.1 * krb5-mini-debuginfo-1.20.1-9.1 * krb5-mini-1.20.1-9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:16 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:16 -0000 Subject: SUSE-OU-2026:3190-1: low: Optional update for zypp-plugin Message-ID: <178473883634.189.13882519761214088972@cbbac00f79c6> # Optional update for zypp-plugin Announcement ID: SUSE-OU-2026:3190-1 Release Date: 2026-07-22T09:25:17Z Rating: low References: * jsc#PED-15591 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Public Cloud Module 15-SP6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains one feature can now be installed. ## Description: This update for zypp-plugin fixes the following issue: * Add python311-zypp-plugin to Public Cloud Modules. No source change. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3190=1 * SUSE Linux Enterprise High Performance Computing 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3190=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3190=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3190=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3190=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3190=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3190=1 * SUSE Linux Enterprise Desktop 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-3190=1 ## Package List: * Public Cloud Module 15-SP6 (noarch) * python311-zypp-plugin-0.6.5-150600.18.10.1 * Basesystem Module 15-SP7 (noarch) * python3-zypp-plugin-0.6.5-150600.18.10.1 * SUSE Linux Enterprise Server 15 SP6 (noarch) * python3-zypp-plugin-0.6.5-150600.18.10.1 * SUSE Linux Enterprise High Performance Computing 15 SP6 (noarch) * python3-zypp-plugin-0.6.5-150600.18.10.1 * Python 3 Module 15-SP7 (noarch) * python311-zypp-plugin-0.6.5-150600.18.10.1 * openSUSE Leap 15.6 (noarch) * python311-zypp-plugin-0.6.5-150600.18.10.1 * python3-zypp-plugin-0.6.5-150600.18.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python3-zypp-plugin-0.6.5-150600.18.10.1 * SUSE Linux Enterprise Desktop 15 SP6 (noarch) * python3-zypp-plugin-0.6.5-150600.18.10.1 ## References: * https://jira.suse.com/browse/PED-15591 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:20 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:20 -0000 Subject: SUSE-OU-2026:3189-1: low: Optional update for zypp-plugin Message-ID: <178473884051.189.15076953947984184296@cbbac00f79c6> # Optional update for zypp-plugin Announcement ID: SUSE-OU-2026:3189-1 Release Date: 2026-07-22T09:24:42Z Rating: low References: * jsc#PED-15591 Affected Products: * openSUSE Leap 15.5 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that contains one feature can now be installed. ## Description: This update for zypp-plugin fixes the following issue: * Add python311-zypp-plugin to Public Cloud Modules. No source change. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3189=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3189=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3189=1 ## Package List: * Public Cloud Module 15-SP5 (noarch) * python311-zypp-plugin-0.6.5-150500.16.9.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-zypp-plugin-0.6.5-150500.16.9.1 * openSUSE Leap 15.5 (noarch) * python311-zypp-plugin-0.6.5-150500.16.9.1 * python3-zypp-plugin-0.6.5-150500.16.9.1 ## References: * https://jira.suse.com/browse/PED-15591 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:24 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:24 -0000 Subject: SUSE-OU-2026:3188-1: low: Optional update for zypp-plugin Message-ID: <178473884437.189.15157380331171182349@cbbac00f79c6> # Optional update for zypp-plugin Announcement ID: SUSE-OU-2026:3188-1 Release Date: 2026-07-22T09:24:17Z Rating: low References: * jsc#PED-15591 Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that contains one feature can now be installed. ## Description: This update for zypp-plugin fixes the following issue: * Add python311-zypp-plugin to Public Cloud Modules. No source change. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3188=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3188=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3188=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3188=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3188=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3188=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-zypp-plugin-0.6.5-150400.13.12.2 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-zypp-plugin-0.6.5-150400.13.12.2 * Public Cloud Module 15-SP4 (noarch) * python311-zypp-plugin-0.6.5-150400.13.12.2 * openSUSE Leap 15.4 (noarch) * python311-zypp-plugin-0.6.5-150400.13.12.2 * python3-zypp-plugin-0.6.5-150400.13.12.2 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-zypp-plugin-0.6.5-150400.13.12.2 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-zypp-plugin-0.6.5-150400.13.12.2 ## References: * https://jira.suse.com/browse/PED-15591 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:29 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:29 -0000 Subject: SUSE-RU-2026:3186-1: important: Recommended update for cryptctl Message-ID: <178473884993.189.1561849295765119141@cbbac00f79c6> # Recommended update for cryptctl Announcement ID: SUSE-RU-2026:3186-1 Release Date: 2026-07-22T07:28:44Z Rating: important References: * bsc#1268070 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for cryptctl fixes the following issues: * Add configuration option to enforce minimum TLS version (bsc#1268070) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3186=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3186=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3186=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3186=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3186=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3186=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3186=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3186=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3186=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3186=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3186=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (ppc64le x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * Basesystem Module 15-SP7 (ppc64le x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (ppc64le x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * cryptctl-debuginfo-2.4-150000.4.8.1 * cryptctl-2.4-150000.4.8.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268070 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:36 -0000 Subject: SUSE-SU-2026:3184-1: moderate: Security update for multipath-tools Message-ID: <178473885664.189.1863469662216123208@cbbac00f79c6> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:3184-1 Release Date: 2026-07-22T07:26:21Z Rating: moderate References: * bsc#1268144 * bsc#1268145 Affected Products: * openSUSE Leap 15.6 An update that has two security fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: Update to version 0.9.8+292+suse.c0523c1. * kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device or disk image(bsc#1268145). * kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256 consecutive format labels (bsc#1268144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3184=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * multipath-tools-devel-0.9.8+292+suse.c0523c1-150600.3.12.1 * multipath-tools-debugsource-0.9.8+292+suse.c0523c1-150600.3.12.1 * multipath-tools-debuginfo-0.9.8+292+suse.c0523c1-150600.3.12.1 * multipath-tools-0.9.8+292+suse.c0523c1-150600.3.12.1 * kpartx-0.9.8+292+suse.c0523c1-150600.3.12.1 * libmpath0-debuginfo-0.9.8+292+suse.c0523c1-150600.3.12.1 * libdmmp0_2_0-debuginfo-0.9.8+292+suse.c0523c1-150600.3.12.1 * kpartx-debuginfo-0.9.8+292+suse.c0523c1-150600.3.12.1 * libmpath0-0.9.8+292+suse.c0523c1-150600.3.12.1 * libdmmp-devel-0.9.8+292+suse.c0523c1-150600.3.12.1 * libdmmp0_2_0-0.9.8+292+suse.c0523c1-150600.3.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268144 * https://bugzilla.suse.com/show_bug.cgi?id=1268145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:43 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:43 -0000 Subject: SUSE-SU-2026:3182-1: moderate: Security update for libgcrypt Message-ID: <178473886334.189.14116960960757922062@cbbac00f79c6> # Security update for libgcrypt Announcement ID: SUSE-SU-2026:3182-1 Release Date: 2026-07-22T07:25:47Z Rating: moderate References: * bsc#1262684 Cross-References: * CVE-2026-41989 CVSS scores: * CVE-2026-41989 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue * CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3182=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libgcrypt20-debuginfo-1.11.0-150700.5.10.1 * libgcrypt-devel-1.11.0-150700.5.10.1 * libgcrypt-debugsource-1.11.0-150700.5.10.1 * libgcrypt20-1.11.0-150700.5.10.1 * libgcrypt-devel-debuginfo-1.11.0-150700.5.10.1 * Basesystem Module 15-SP7 (x86_64) * libgcrypt20-32bit-1.11.0-150700.5.10.1 * libgcrypt20-32bit-debuginfo-1.11.0-150700.5.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41989.html * https://bugzilla.suse.com/show_bug.cgi?id=1262684 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:48 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:48 -0000 Subject: SUSE-SU-2026:3181-1: moderate: Security update for python3-sqlparse Message-ID: <178473886894.189.4449321106851119261@cbbac00f79c6> # Security update for python3-sqlparse Announcement ID: SUSE-SU-2026:3181-1 Release Date: 2026-07-22T07:25:38Z Rating: moderate References: * bsc#1268597 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for python3-sqlparse fixes the following issue * Fixed an issue where formatting list of tuples leads to denial of service (bsc#1268597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3181=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3181=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * python3-sqlparse-0.4.2-150300.17.1 * openSUSE Leap 15.3 (noarch) * python3-sqlparse-0.4.2-150300.17.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:47:54 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:47:54 -0000 Subject: SUSE-SU-2026:3180-1: moderate: Security update for python-sqlparse Message-ID: <178473887469.189.10114282673787464515@cbbac00f79c6> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:3180-1 Release Date: 2026-07-22T07:25:23Z Rating: moderate References: * bsc#1268597 Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for python-sqlparse fixes the following issue * Fixed a bug where formatting list of tuples leads to denial of service (bsc#1268597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3180=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3180=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3180=1 ## Package List: * Public Cloud Module 15-SP6 (noarch) * python311-sqlparse-0.4.4-150600.3.3.1 * Python 3 Module 15-SP7 (noarch) * python311-sqlparse-0.4.4-150600.3.3.1 * openSUSE Leap 15.6 (noarch) * python311-sqlparse-0.4.4-150600.3.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:48:00 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:48:00 -0000 Subject: SUSE-SU-2026:3179-1: moderate: Security update for python-sqlparse Message-ID: <178473888085.189.12010635570955719056@cbbac00f79c6> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:3179-1 Release Date: 2026-07-22T07:25:06Z Rating: moderate References: * bsc#1268597 Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has one security fix can now be installed. ## Description: This update for python-sqlparse fixes the following issue * Fixed a bug where formatting list of tuples leads to denial of service (bsc#1268597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3179=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3179=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3179=1 ## Package List: * Public Cloud Module 15-SP4 (noarch) * python311-sqlparse-0.4.4-150400.6.10.1 * Public Cloud Module 15-SP5 (noarch) * python311-sqlparse-0.4.4-150400.6.10.1 * openSUSE Leap 15.4 (noarch) * python311-sqlparse-0.4.4-150400.6.10.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:48:08 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:48:08 -0000 Subject: SUSE-SU-2026:3178-1: low: Security update for nasm Message-ID: <178473888825.189.8121996531044052625@cbbac00f79c6> # Security update for nasm Announcement ID: SUSE-SU-2026:3178-1 Release Date: 2026-07-22T07:24:33Z Rating: low References: * bsc#1261985 * bsc#1261986 Cross-References: * CVE-2026-6067 * CVE-2026-6068 CVSS scores: * CVE-2026-6067 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-6067 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-6067 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6067 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6068 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-6068 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-6068 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-6068 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for nasm fixes the following issues * CVE-2026-6067: heap buffer overflow vulnerability due to a lack of bounds checking in the obj_directive() function (bsc#1261986). * CVE-2026-6068: heap use after free vulnerability in response file processing (bsc#1261985). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3178=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * nasm-2.16.03-150700.3.3.1 * nasm-debuginfo-2.16.03-150700.3.3.1 * nasm-debugsource-2.16.03-150700.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6067.html * https://www.suse.com/security/cve/CVE-2026-6068.html * https://bugzilla.suse.com/show_bug.cgi?id=1261985 * https://bugzilla.suse.com/show_bug.cgi?id=1261986 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:48:13 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:48:13 -0000 Subject: SUSE-RU-2026:3177-1: moderate: Recommended update for python-gcemetadata Message-ID: <178473889392.189.11230347925745461142@cbbac00f79c6> # Recommended update for python-gcemetadata Announcement ID: SUSE-RU-2026:3177-1 Release Date: 2026-07-22T07:11:49Z Rating: moderate References: * bsc#1269423 Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has one fix can now be installed. ## Description: This update for python-gcemetadata fixes the following issues: * Update to version 1.1.1: * Fix UnboundLocalError when using --xml with --query (bsc#1269423) * Update comments ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3177=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3177=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3177=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3177=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3177=1 ## Package List: * Public Cloud Module 15-SP6 (noarch) * python-gcemetadata-1.1.1-150400.9.8.1 * Public Cloud Module 15-SP7 (noarch) * python-gcemetadata-1.1.1-150400.9.8.1 * openSUSE Leap 15.4 (noarch) * python-gcemetadata-1.1.1-150400.9.8.1 * Public Cloud Module 15-SP5 (noarch) * python-gcemetadata-1.1.1-150400.9.8.1 * Public Cloud Module 15-SP4 (noarch) * python-gcemetadata-1.1.1-150400.9.8.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269423 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:48:19 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:48:19 -0000 Subject: SUSE-RU-2026:3176-1: moderate: Recommended update for libnvme Message-ID: <178473889949.189.1111435243983879897@cbbac00f79c6> # Recommended update for libnvme Announcement ID: SUSE-RU-2026:3176-1 Release Date: 2026-07-22T07:09:55Z Rating: moderate References: * bsc#1262707 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for libnvme fixes the following issues: * fabrics: permit bi-auth with secure concat TLS (bsc#1262707) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3176=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libnvme-devel-1.11+28.gfdbd3dfa-150700.4.23.1 * libnvme-debuginfo-1.11+28.gfdbd3dfa-150700.4.23.1 * libnvme-mi1-1.11+28.gfdbd3dfa-150700.4.23.1 * libnvme1-debuginfo-1.11+28.gfdbd3dfa-150700.4.23.1 * libnvme-debugsource-1.11+28.gfdbd3dfa-150700.4.23.1 * python3-libnvme-debuginfo-1.11+28.gfdbd3dfa-150700.4.23.1 * libnvme-mi1-debuginfo-1.11+28.gfdbd3dfa-150700.4.23.1 * python3-libnvme-1.11+28.gfdbd3dfa-150700.4.23.1 * libnvme1-1.11+28.gfdbd3dfa-150700.4.23.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1262707 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:48:26 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:48:26 -0000 Subject: SUSE-RU-2026:3175-1: moderate: Recommended update for release-notes-sles Message-ID: <178473890615.189.15085503974600181246@cbbac00f79c6> # Recommended update for release-notes-sles Announcement ID: SUSE-RU-2026:3175-1 Release Date: 2026-07-22T07:09:42Z Rating: moderate References: * bsc#1217483 * bsc#933411 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has two fixes can now be installed. ## Description: This update for release-notes-sles fixes the following issues: * Update to version 15.5.20260709 (bsc#933411): * Added note about PostgreSQL 13 being removed (bsc#1217483) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3175=1 * SUSE Linux Enterprise Server 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3175=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3175=1 * SUSE Linux Enterprise High Performance Computing 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3175=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3175=1 * SUSE Linux Enterprise Desktop 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3175=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 (noarch) * release-notes-sles-15.5.20260709-150500.3.35.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * release-notes-sles-15.5.20260709-150500.3.35.1 * SUSE Linux Enterprise High Performance Computing 15 SP5 (noarch) * release-notes-sles-15.5.20260709-150500.3.35.1 * SUSE Linux Enterprise Desktop 15 SP5 (noarch) * release-notes-sles-15.5.20260709-150500.3.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * release-notes-sles-15.5.20260709-150500.3.35.1 * openSUSE Leap 15.5 (noarch) * release-notes-sles-15.5.20260709-150500.3.35.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1217483 * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:48:37 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:48:37 -0000 Subject: SUSE-RU-2026:3174-1: important: Recommended update for release-notes-sles Message-ID: <178473891704.189.8213131243976480669@cbbac00f79c6> # Recommended update for release-notes-sles Announcement ID: SUSE-RU-2026:3174-1 Release Date: 2026-07-22T07:09:18Z Rating: important References: * bsc#1200759 * bsc#1201981 * bsc#1212186 * bsc#1219730 * bsc#933411 * jsc#PED-10574 * jsc#SLE-21484 * jsc#TEAM-815 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that contains three features and has five fixes can now be installed. ## Description: This update for release-notes-sles fixes the following issues: * Update to version 15.4.20260709 (bsc#933411) * Document removal of scsi_mod.use_blk_mq (bsc#1201981) * Provide documentation link for Python 3 module lifecycle (bsc#1200759) * Update to version 15.4.20260227 (bsc#933411) * Updated note to say that AArch64 supports both 4K and 64K block sizes (bsc#1212186) * Added note about KubeVirt support (bsc#1219730) * Added note about cronie minute change (jsc#DOCTEAM-815) * Added note about libmfx being removed (jsc#PED-10574) * Added note about Vagrant 2.2.18 (jsc#SLE-21484) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3174=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3174=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3174=1 * SUSE Linux Enterprise High Performance Computing 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3174=1 * SUSE Linux Enterprise Desktop 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3174=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3174=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3174=1 * SUSE Linux Enterprise Server 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3174=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3174=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * release-notes-sles-15.4.20260709-150400.3.35.3 * SUSE Linux Enterprise High Performance Computing 15 SP4 (noarch) * release-notes-sles-15.4.20260709-150400.3.35.3 * SUSE Linux Enterprise Server 15 SP4 (noarch) * release-notes-sles-15.4.20260709-150400.3.35.3 * SUSE Manager Server 4.3 (noarch) * release-notes-sles-15.4.20260709-150400.3.35.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * release-notes-sles-15.4.20260709-150400.3.35.3 * SUSE Linux Enterprise Desktop 15 SP4 (noarch) * release-notes-sles-15.4.20260709-150400.3.35.3 * SUSE Manager Retail Branch Server 4.3 (noarch) * release-notes-sles-15.4.20260709-150400.3.35.3 * SUSE Manager Proxy 4.3 (noarch) * release-notes-sles-15.4.20260709-150400.3.35.3 * openSUSE Leap 15.4 (noarch) * release-notes-sles-15.4.20260709-150400.3.35.3 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1200759 * https://bugzilla.suse.com/show_bug.cgi?id=1201981 * https://bugzilla.suse.com/show_bug.cgi?id=1212186 * https://bugzilla.suse.com/show_bug.cgi?id=1219730 * https://bugzilla.suse.com/show_bug.cgi?id=933411 * https://jira.suse.com/browse/PED-10574 * https://jira.suse.com/browse/SLE-21484 * https://jira.suse.com/browse/TEAM-815 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:48:44 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:48:44 -0000 Subject: SUSE-RU-2026:3173-1: moderate: Recommended update for release-notes-sle_hpc Message-ID: <178473892440.189.8479732775778740818@cbbac00f79c6> # Recommended update for release-notes-sle_hpc Announcement ID: SUSE-RU-2026:3173-1 Release Date: 2026-07-22T07:07:21Z Rating: moderate References: * bsc#1236930 * bsc#933411 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 An update that has two fixes can now be installed. ## Description: This update for release-notes-sle_hpc fixes the following issues: * Update to version 15.5.20260709 (bsc#933411): * Slurm: Updated to version 24.11.1 (bsc#1236930) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3173=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3173=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3173=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * release-notes-sle_hpc-15.500000000.20260709-150500.3.12.1 * openSUSE Leap 15.5 (noarch) * release-notes-sle_hpc-15.500000000.20260709-150500.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * release-notes-sle_hpc-15.500000000.20260709-150500.3.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1236930 * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:48:54 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:48:54 -0000 Subject: SUSE-RU-2026:3172-1: moderate: Recommended update for release-notes-sle_hpc Message-ID: <178473893420.189.948444484023429852@cbbac00f79c6> # Recommended update for release-notes-sle_hpc Announcement ID: SUSE-RU-2026:3172-1 Release Date: 2026-07-22T07:07:07Z Rating: moderate References: * bsc#1235732 * bsc#1236034 * bsc#1236930 * bsc#933411 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 An update that has four fixes can now be installed. ## Description: This update for release-notes-sle_hpc fixes the following issues: * Update to version 15.4.20260709 (bsc#933411): * Slurm: Updated to version 24.11.1 (bsc#1236930) * Added Slurm 24.11 release notes (bsc#1236034) * Added Spack 0.23 release notes (bsc#1235732) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3172=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3172=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3172=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * release-notes-sle_hpc-15.400000000.20260709-150400.3.20.1 * openSUSE Leap 15.4 (noarch) * release-notes-sle_hpc-15.400000000.20260709-150400.3.20.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * release-notes-sle_hpc-15.400000000.20260709-150400.3.20.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1235732 * https://bugzilla.suse.com/show_bug.cgi?id=1236034 * https://bugzilla.suse.com/show_bug.cgi?id=1236930 * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:49:01 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:49:01 -0000 Subject: SUSE-RU-2026:3171-1: moderate: Recommended update for release-notes-sle_hpc Message-ID: <178473894143.189.644861889493860144@cbbac00f79c6> # Recommended update for release-notes-sle_hpc Announcement ID: SUSE-RU-2026:3171-1 Release Date: 2026-07-22T07:06:18Z Rating: moderate References: * bsc#1235732 * bsc#933411 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS An update that has two fixes can now be installed. ## Description: This update for release-notes-sle_hpc fixes the following issues: * Update to version 15.6.20260709 (bsc#933411) * Added Spack 0.23 release notes (bsc#1235732) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3171=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3171=1 ## Package List: * openSUSE Leap 15.6 (noarch) * release-notes-sle_hpc-15.600000000.20260709-150600.3.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * release-notes-sle_hpc-15.600000000.20260709-150600.3.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1235732 * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 16:49:05 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 16:49:05 -0000 Subject: SUSE-RU-2026:3170-1: moderate: Recommended update for rust Message-ID: <178473894554.189.1556251466115262087@cbbac00f79c6> # Recommended update for rust Announcement ID: SUSE-RU-2026:3170-1 Release Date: 2026-07-21T21:16:19Z Rating: moderate References: * jsc#PED-11411 * jsc#SLE-18626 Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.3 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains two features can now be installed. ## Description: This update for rust fixes the following issues: Update to rust1.97.1: * Release notes can be found externally: https://github.com/rust- lang/rust/releases/tag/1.97.1 Changes in rust: * Update to version 1.97.0 - for details see the rust1.97 package ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3170=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3170=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3170=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3170=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3170=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3170=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3170=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3170=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3170=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3170=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3170=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3170=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3170=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3170=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 nosrc ppc64le s390x x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * rust1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * rust-1.97.0-150500.27.74.1 * cargo1.97-1.97.1-150300.7.5.1 * cargo-1.97.0-150500.27.74.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-1.97.1-150300.7.5.1 * rust1.97-debuginfo-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * rust-1.97.0-150400.24.83.1 * cargo-1.97.0-150400.24.83.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64) * cargo-1.97.0-150400.24.81.1 * rust-1.97.0-150400.24.81.1 * Development Tools Module 15-SP7 (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rust1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-1.97.1-150300.7.5.1 * rust-1.97.0-150500.27.74.1 * cargo-1.97.0-150500.27.74.1 * Development Tools Module 15-SP7 (aarch64 nosrc ppc64le s390x x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rust1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * rust-1.97.0-150500.27.74.1 * cargo1.97-1.97.1-150300.7.5.1 * cargo-1.97.0-150500.27.74.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 nosrc ppc64le s390x x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (nosrc ppc64le x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * rust1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-1.97.1-150300.7.5.1 * rust-1.97.0-150500.27.74.1 * cargo-1.97.0-150500.27.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rust1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-1.97.1-150300.7.5.1 * rust-1.97.0-150500.27.74.1 * cargo-1.97.0-150500.27.74.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 nosrc x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-1.97.1-150300.7.5.1 * rust1.97-debuginfo-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc ppc64le s390x x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x) * cargo-1.97.0-150400.24.81.1 * rust-1.97.0-150400.24.81.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * rust-1.97.0-150400.24.83.1 * cargo-1.97.0-150400.24.83.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * cargo-1.97.0-150500.27.74.1 * rust-1.97.0-150500.27.74.1 * rust-src-1.97.0-150500.27.74.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x) * cargo-1.97.0-150400.24.81.1 * rust-src-1.97.0-150400.24.81.1 * rust-1.97.0-150400.24.81.1 * openSUSE Leap 15.4 (i586 x86_64) * rust-src-1.97.0-150400.24.83.1 * rust-1.97.0-150400.24.83.1 * cargo-1.97.0-150400.24.83.1 * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * rust-1.97.0-150300.21.100.1 * rust1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * cargo-1.97.0-150300.21.100.1 * cargo1.97-1.97.1-150300.7.5.1 * rust-src-1.97.0-150300.21.100.1 * openSUSE Leap 15.3 (aarch64 i586 nosrc ppc64le s390x x86_64) * rust1.97-1.97.1-150300.7.5.1 * openSUSE Leap 15.3 (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * openSUSE Leap 15.3 (nosrc) * rust1.97-test-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 nosrc x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rust1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * rust-1.97.0-150500.27.74.1 * cargo1.97-1.97.1-150300.7.5.1 * cargo-1.97.0-150500.27.74.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * rust-1.97.0-150400.24.83.1 * cargo-1.97.0-150400.24.83.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le) * cargo-1.97.0-150400.24.81.1 * rust-1.97.0-150400.24.81.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-1.97.1-150300.7.5.1 * rust1.97-debuginfo-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rust1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-1.97.1-150300.7.5.1 * rust-1.97.0-150500.27.74.1 * cargo-1.97.0-150500.27.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (nosrc ppc64le x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cargo1.97-debuginfo-1.97.1-150300.7.5.1 * cargo1.97-1.97.1-150300.7.5.1 * rust1.97-debuginfo-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc x86_64) * rust1.97-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * rust1.97-src-1.97.1-150300.7.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * rust-1.97.0-150400.24.83.1 * cargo-1.97.0-150400.24.83.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64) * cargo-1.97.0-150400.24.81.1 * rust-1.97.0-150400.24.81.1 ## References: * https://jira.suse.com/browse/PED-11411 * https://jira.suse.com/browse/SLE-18626 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:30:10 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:30:10 -0000 Subject: SUSE-RU-2026:22772-1: important: Recommended update for s390-tools Message-ID: <178475221014.245.1033129822882364897@c3e054a4ce29> # Recommended update for s390-tools Announcement ID: SUSE-RU-2026:22772-1 Release Date: 2026-07-21T07:58:47Z Rating: important References: * bsc#1266436 * bsc#1268516 Affected Products: * SUSE Linux Micro 6.2 An update that has two fixes can now be installed. ## Description: This update for s390-tools fixes the following issues: * Upgrade to version 2.43.0: * Fix: [QE][Build 39.11] sel-ebc-paes-enforce.service:23: Failed to parse output specifier, ignoring: console (bsc#1268516) * Fix: SCSI LUN for reboot not set ant the end of installation (bsc#1266436) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1308=1 ## Package List: * SUSE Linux Micro 6.2 (s390x) * libkmipclient1-debuginfo-2.43.0-160000.2.1 * libkmipclient1-2.43.0-160000.2.1 * s390-tools-debugsource-2.43.0-160000.2.1 * libekmfweb1-2.43.0-160000.2.1 * s390-tools-2.43.0-160000.2.1 * s390-tools-debuginfo-2.43.0-160000.2.1 * libekmfweb1-debuginfo-2.43.0-160000.2.1 * SUSE Linux Micro 6.2 (noarch) * s390-tools-genprotimg-data-2.43.0-160000.2.1 * s390-tools-chreipl-fcp-mpath-2.43.0-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1266436 * https://bugzilla.suse.com/show_bug.cgi?id=1268516 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:30:18 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:30:18 -0000 Subject: SUSE-RU-2026:22771-1: important: Recommended update for openCryptoki Message-ID: <178475221833.245.14804527522878864576@c3e054a4ce29> # Recommended update for openCryptoki Announcement ID: SUSE-RU-2026:22771-1 Release Date: 2026-07-20T17:31:56Z Rating: important References: * bsc#1268745 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for openCryptoki fixes the following issues: * Fix pkcsslotd directory creation failures on immutable/transactional systems (bsc#1268745): * Added systemd service drop-in to allow dynamic token slot path creation via ReadWritePaths ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1307=1 ## Package List: * SUSE Linux Micro 6.2 (s390x) * openCryptoki-3.27.0-160000.2.1 * openCryptoki-debugsource-3.27.0-160000.2.1 * openCryptoki-debuginfo-3.27.0-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268745 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:30:45 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:30:45 -0000 Subject: SUSE-SU-2026:22770-1: critical: Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions Message-ID: <178475224511.245.17695475494592964768@c3e054a4ce29> # Security update for cockpit, cockpit-machines, cockpit-packages, cockpit- podman, cockpit-repos, cockpit-subscriptions Announcement ID: SUSE-SU-2026:22770-1 Release Date: 2026-07-21T16:05:47Z Rating: critical References: * bsc#1236149 * bsc#1257033 * bsc#1257325 * bsc#1257698 * bsc#1257836 * bsc#1257838 * bsc#1257840 * bsc#1258040 * bsc#1258637 * bsc#1258640 * bsc#1258641 * bsc#1259010 * bsc#1259013 * bsc#1259015 * bsc#1259210 * bsc#1259774 * bsc#1261829 * jsc#PED-15706 * jsc#PED-15820 Cross-References: * CVE-2025-13465 * CVE-2026-25547 * CVE-2026-26996 * CVE-2026-27904 * CVE-2026-4631 * CVE-2026-4802 CVSS scores: * CVE-2025-13465 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-13465 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-13465 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13465 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13465 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-25547 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25547 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25547 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-26996 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27904 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27904 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27904 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4631 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4631 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4802 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4802 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4802 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4802 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities, contains two features and has 11 fixes can now be installed. ## Description: This update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions fixes the following issues: Security issues fixed: * CVE-2025-13465: lodash: prototype pollution in the _.unset and_.omit functions can lead to deletion of methods from global prototypes (bsc#1257325). * CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829). * CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840). * CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637 bsc#1258640 bsc#1258641). * CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking complexity and a ReDoS (bsc#1259010 bsc#1259013 bsc#1259015). Non security issues fixed: * cockpit webUI - 'Software updates - install all updates' got an unexpected internal error (bsc#1259210). * cockpit-machines does not work out of the box, missing libvirt daemon (bsc#1236149). Changes for cockpit: * Update to 364. * Update to 361 (jsc#PED-15706/jsc#CPT-183): * Remove all "Mount" actions in Anaconda mode * Dependency updates * Update to 360: * ws: be more explicit when handling hostnames on cli bsc#1261829/CVE-2026-4631 * ws: support loading a custom login page * Update to 358: * Networking: Add Wi-Fi support * Cockpit Client updated to GTK 4 * Bugfixes and translation updates * Update to 357: * lib: Use browser context menu on shift * bridge: support Python 3.14 on old kernels (RHEL 8) * Update to 356: * systemd: Allow editing timers created by Cockpit * Convert license headers to SPDX format * Update to 355: * ws: Remove obsolete pam_cockpit_cert module * shell: add StartTransientUnit as a sudo alternative Changes for cockpit-machines: * Update to 354. * Update to 352: * Improvements to the "Add disk" and "Create Volume" dialogs. * Update suse_version requirement to function with the planned bump (jsc#PED-15820). * Drop explict dependency on libvirt (bsc#1258040, bsc#1236149). * Update to 348: * Translation updates * Convert license headers to SPDX format * Now requires cockpit-devel 356 due to the replacement of xterm/addon-canvas with xterm/addon-webgl * Update to 347: * Bug fixes and translation updates * Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-packages: * Update to version 5: * Support transactional systems * Improve error/success messages * Translation updates * Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-podman: * Update to 128. * Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-repos: * Update to 4.8. * Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-subscriptions: * Update to version 16.2 (bsc#1257033). * Patch esbuild to use native runtime on ppc64 (bsc#1257698). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1309=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * cockpit-podman-128-160000.1.1 * cockpit-networkmanager-364-160000.1.1 * cockpit-machines-354-160000.1.1 * cockpit-firewalld-364-160000.1.1 * cockpit-system-364-160000.1.1 * cockpit-kdump-364-160000.1.1 * cockpit-selinux-364-160000.1.1 * cockpit-repos-4.8-160000.1.1 * cockpit-subscriptions-16.2-160000.1.1 * cockpit-bridge-364-160000.1.1 * cockpit-storaged-364-160000.1.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * cockpit-ws-debuginfo-364-160000.1.1 * cockpit-debugsource-364-160000.1.1 * cockpit-364-160000.1.1 * cockpit-ws-selinux-364-160000.1.1 * cockpit-ws-364-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13465.html * https://www.suse.com/security/cve/CVE-2026-25547.html * https://www.suse.com/security/cve/CVE-2026-26996.html * https://www.suse.com/security/cve/CVE-2026-27904.html * https://www.suse.com/security/cve/CVE-2026-4631.html * https://www.suse.com/security/cve/CVE-2026-4802.html * https://bugzilla.suse.com/show_bug.cgi?id=1236149 * https://bugzilla.suse.com/show_bug.cgi?id=1257033 * https://bugzilla.suse.com/show_bug.cgi?id=1257325 * https://bugzilla.suse.com/show_bug.cgi?id=1257698 * https://bugzilla.suse.com/show_bug.cgi?id=1257836 * https://bugzilla.suse.com/show_bug.cgi?id=1257838 * https://bugzilla.suse.com/show_bug.cgi?id=1257840 * https://bugzilla.suse.com/show_bug.cgi?id=1258040 * https://bugzilla.suse.com/show_bug.cgi?id=1258637 * https://bugzilla.suse.com/show_bug.cgi?id=1258640 * https://bugzilla.suse.com/show_bug.cgi?id=1258641 * https://bugzilla.suse.com/show_bug.cgi?id=1259010 * https://bugzilla.suse.com/show_bug.cgi?id=1259013 * https://bugzilla.suse.com/show_bug.cgi?id=1259015 * https://bugzilla.suse.com/show_bug.cgi?id=1259210 * https://bugzilla.suse.com/show_bug.cgi?id=1259774 * https://bugzilla.suse.com/show_bug.cgi?id=1261829 * https://jira.suse.com/browse/PED-15706 * https://jira.suse.com/browse/PED-15820 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:37:11 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:37:11 -0000 Subject: SUSE-SU-2026:22769-1: important: Security update for the Linux Kernel Message-ID: <178475263188.245.16157623058141010034@c3e054a4ce29> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22769-1 Release Date: 2026-07-21T08:27:34Z Rating: important References: * bsc#1149651 * bsc#1204315 * bsc#1236743 * bsc#1255029 * bsc#1257506 * bsc#1258538 * bsc#1259800 * bsc#1260565 * bsc#1261250 * bsc#1261256 * bsc#1261562 * bsc#1261604 * bsc#1262085 * bsc#1262392 * bsc#1262430 * bsc#1262618 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262765 * bsc#1262798 * bsc#1263057 * bsc#1263072 * bsc#1263133 * bsc#1263137 * bsc#1263143 * bsc#1263169 * bsc#1263178 * bsc#1263319 * bsc#1263563 * bsc#1263568 * bsc#1263573 * bsc#1263578 * bsc#1263581 * bsc#1263796 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1263998 * bsc#1264001 * bsc#1264007 * bsc#1264010 * bsc#1264012 * bsc#1264015 * bsc#1264045 * bsc#1264056 * bsc#1264067 * bsc#1264084 * bsc#1264145 * bsc#1264230 * bsc#1264231 * bsc#1264236 * bsc#1264239 * bsc#1264241 * bsc#1264250 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264263 * bsc#1264266 * bsc#1264270 * bsc#1264286 * bsc#1264294 * bsc#1264295 * bsc#1264302 * bsc#1264304 * bsc#1264320 * bsc#1264328 * bsc#1264333 * bsc#1264337 * bsc#1264372 * bsc#1264386 * bsc#1264429 * bsc#1264449 * bsc#1264532 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264549 * bsc#1264556 * bsc#1264561 * bsc#1264580 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264612 * bsc#1264614 * bsc#1264624 * bsc#1264643 * bsc#1264734 * bsc#1264740 * bsc#1264741 * bsc#1264744 * bsc#1264763 * bsc#1264789 * bsc#1264790 * bsc#1264794 * bsc#1264852 * bsc#1264974 * bsc#1264978 * bsc#1264997 * bsc#1265000 * bsc#1265005 * bsc#1265020 * bsc#1265023 * bsc#1265073 * bsc#1265079 * bsc#1265082 * bsc#1265084 * bsc#1265091 * bsc#1265097 * bsc#1265103 * bsc#1265112 * bsc#1265113 * bsc#1265123 * bsc#1265128 * bsc#1265129 * bsc#1265142 * bsc#1265143 * bsc#1265628 * bsc#1265629 * bsc#1266008 * bsc#1266214 * bsc#1266283 * bsc#1266284 * bsc#1266290 * bsc#1266390 * bsc#1266396 * bsc#1266397 * bsc#1266398 * bsc#1266452 * bsc#1266458 * bsc#1266686 * bsc#1266693 * bsc#1266697 * bsc#1266698 * bsc#1266700 * bsc#1266704 * bsc#1266705 * bsc#1266717 * bsc#1266718 * bsc#1266722 * bsc#1266726 * bsc#1266734 * bsc#1266740 * bsc#1266750 * bsc#1266754 * bsc#1266761 * bsc#1266773 * bsc#1266805 * bsc#1266830 * bsc#1266838 * bsc#1266840 * bsc#1266847 * bsc#1266878 * bsc#1266883 * bsc#1266892 * bsc#1266893 * bsc#1266895 * bsc#1266899 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266925 * bsc#1266929 * bsc#1266933 * bsc#1267208 * bsc#1267218 * bsc#1267228 * bsc#1267238 * bsc#1267251 * bsc#1267360 * bsc#1267361 * bsc#1267365 * bsc#1267369 * bsc#1267387 * bsc#1267419 * bsc#1267427 * bsc#1267431 * bsc#1267437 * bsc#1267458 * bsc#1267493 * bsc#1267505 * bsc#1267548 * bsc#1267582 * bsc#1267591 * bsc#1267600 * bsc#1267618 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267635 * bsc#1267637 * bsc#1267640 * bsc#1267654 * bsc#1267682 * bsc#1267684 * bsc#1267685 * bsc#1267697 * bsc#1267717 * bsc#1267722 * bsc#1267732 * bsc#1267744 * bsc#1267816 * bsc#1267824 * bsc#1267825 * bsc#1267937 * bsc#1267966 * bsc#1267992 * bsc#1267993 * bsc#1267994 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268238 * bsc#1268276 * bsc#1268307 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1268989 * bsc#1269022 * bsc#1269031 * bsc#1269033 * bsc#1269036 * bsc#1269087 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269188 * bsc#1269193 * bsc#1269199 * bsc#1269230 * bsc#1269234 * bsc#1269252 * bsc#1269262 * bsc#1269288 * bsc#1269310 * bsc#1269389 * bsc#1269392 * bsc#1269397 * bsc#1269398 * bsc#1269416 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269527 * bsc#1269531 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269617 * bsc#1269645 * bsc#1269646 * bsc#1269647 * bsc#1269651 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269708 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269798 * bsc#1269809 * bsc#1269814 * bsc#1269821 * bsc#1269904 * bsc#1269982 * bsc#1269989 * bsc#1269992 * bsc#1270000 * bsc#1270022 * bsc#1270042 * bsc#1270059 * bsc#1270226 * bsc#1271366 * jsc#PED-10906 * jsc#PED-15986 * jsc#PED-16390 * jsc#SLE-8615 Cross-References: * CVE-2025-10263 * CVE-2025-39894 * CVE-2025-40341 * CVE-2026-23248 * CVE-2026-23394 * CVE-2026-23451 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31438 * CVE-2026-31450 * CVE-2026-31452 * CVE-2026-31466 * CVE-2026-31469 * CVE-2026-31479 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31502 * CVE-2026-31555 * CVE-2026-31560 * CVE-2026-31580 * CVE-2026-31596 * CVE-2026-31646 * CVE-2026-31647 * CVE-2026-31663 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31670 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31743 * CVE-2026-31752 * CVE-2026-31771 * CVE-2026-43010 * CVE-2026-43014 * CVE-2026-43015 * CVE-2026-43016 * CVE-2026-43022 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43034 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43053 * CVE-2026-43057 * CVE-2026-43074 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43083 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43090 * CVE-2026-43092 * CVE-2026-43093 * CVE-2026-43094 * CVE-2026-43101 * CVE-2026-43107 * CVE-2026-43119 * CVE-2026-43124 * CVE-2026-43128 * CVE-2026-43130 * CVE-2026-43132 * CVE-2026-43139 * CVE-2026-43145 * CVE-2026-43157 * CVE-2026-43158 * CVE-2026-43161 * CVE-2026-43167 * CVE-2026-43171 * CVE-2026-43175 * CVE-2026-43187 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43198 * CVE-2026-43199 * CVE-2026-43205 * CVE-2026-43213 * CVE-2026-43226 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43260 * CVE-2026-43283 * CVE-2026-43284 * CVE-2026-43298 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43337 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43351 * CVE-2026-43373 * CVE-2026-43374 * CVE-2026-43383 * CVE-2026-43384 * CVE-2026-43386 * CVE-2026-43403 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43415 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43456 * CVE-2026-43457 * CVE-2026-43458 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43471 * CVE-2026-43491 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45837 * CVE-2026-45838 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45848 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45861 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45884 * CVE-2026-45888 * CVE-2026-45891 * CVE-2026-45894 * CVE-2026-45899 * CVE-2026-45901 * CVE-2026-45912 * CVE-2026-45920 * CVE-2026-45922 * CVE-2026-45933 * CVE-2026-45940 * CVE-2026-45948 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45985 * CVE-2026-45997 * CVE-2026-45999 * CVE-2026-46005 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46078 * CVE-2026-46079 * CVE-2026-46091 * CVE-2026-46093 * CVE-2026-46099 * CVE-2026-46101 * CVE-2026-46111 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46124 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46161 * CVE-2026-46162 * CVE-2026-46172 * CVE-2026-46173 * CVE-2026-46178 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46227 * CVE-2026-46242 * CVE-2026-46244 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46259 * CVE-2026-46266 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46314 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46322 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52919 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52955 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52975 * CVE-2026-52980 * CVE-2026-52993 * CVE-2026-53015 * CVE-2026-53021 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53053 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53081 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53103 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53139 * CVE-2026-53156 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53194 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53249 * CVE-2026-53258 * CVE-2026-53262 * CVE-2026-53263 * CVE-2026-53266 * CVE-2026-53272 * CVE-2026-53274 * CVE-2026-53281 * CVE-2026-53285 * CVE-2026-53286 * CVE-2026-53287 * CVE-2026-53306 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-39894 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-39894 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23248 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23394 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23394 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31479 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31479 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31560 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31580 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31646 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31646 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31646 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31647 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31743 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31743 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43016 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43090 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43090 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43094 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43130 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43130 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43132 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43145 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43145 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43145 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43175 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43213 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43260 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43283 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43283 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43298 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43298 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43298 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43374 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43384 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43384 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-43384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43403 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43403 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43415 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43415 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43415 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43457 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43457 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43458 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43458 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43471 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45837 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45837 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45837 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45861 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45861 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45884 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45884 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45884 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45888 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45888 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45888 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45901 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45901 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45901 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45922 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45922 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45922 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45999 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45999 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46078 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46078 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46093 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52919 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52962 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52980 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52980 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53015 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53103 ( SUSE ): 5.9 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53103 ( SUSE ): 4.8 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53103 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53156 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53156 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53194 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53194 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53194 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53262 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53262 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53263 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53272 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53272 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53272 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53286 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 255 vulnerabilities, contains four features and has 30 fixes can now be installed. ## Description: The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-10263: arm64: cputype: Add C1-Premium definitions (bsc#1266290). * CVE-2025-39894: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm (bsc#1262430). * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2026-23248: perf: Make perf_pmu_unregister() useable (bsc#1259800). * CVE-2026-23394: Revert: "af_unix: Remove lock dance in unix_peek_fds()." (bsc#1260565). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31438: netfs: Fix kernel BUG in netfs_limit_iter() for ITER_KVEC iterators (bsc#1267824). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). * CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31646: net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() (bsc#1263796). * CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578). * CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31743: nvmem: zynqmp_nvmem: Fix buffer size in DMA and memcpy (bsc#1264067). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43014,CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal (bsc#1264010 bsc#1264012). * CVE-2026-43016: bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready() (bsc#1264007). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084). * CVE-2026-43057: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback (bsc#1264056). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43090: xfrm: fix refcount leak in xfrm_migrate_policy_find (bsc#1264250). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43130: iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode (bsc#1264532). * CVE-2026-43132: dm-verity: correctly handle dm_bufio_client_create() failure (bsc#1264614). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43145: remoteproc: imx_rproc: Fix invalid loaded resource table detection (bsc#1265091). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43161: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode (bsc#1264333). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549). * CVE-2026-43175: clk: rs9: Reserve 8 struct clk_hw slots for for 9FGV0841 (bsc#1264372). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43213: wifi: rtw89: pci: validate sequence number of TX release report (bsc#1264643). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429). * CVE-2026-43283: net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle (bsc#1264295). * CVE-2026-43298: drm/amdgpu: Skip vcn poison irq release on VF (bsc#1264852). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43351: KVM: arm64: gic: Set vgic_model before initing private IRQs (bsc#1265082). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43374: net: nexthop: fix percpu use-after-free in remove_nh_grp_entry (bsc#1265084). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43384: net/tcp-ao: Fix MAC comparison to be constant-time (bsc#1265097). * CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (bsc#1264740). * CVE-2026-43403: nsfs: tighten permission checks for ns iteration ioctls (bsc#1265129). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43415: scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend (bsc#1265123). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43457: mctp: i2c: fix skb memory leak in receive path (bsc#1265000). * CVE-2026-43458: serial: caif: hold tty->link reference in ldisc_open and ser_release (bsc#1265005). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43471: scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_trace() (bsc#1264789). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45837: Require (reasonably) normal mappings for MADV_DOFORK (bsc#1266398). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 (bsc#1266773). * CVE-2026-45861: gfs2: Fix slab-use-after-free in qd_put (bsc#1266754). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45884: apparmor: avoid per-cpu hold underflow in aa_get_buffer (bsc#1266718). * CVE-2026-45888: md/raid1: fix memory leak in raid1_run() (bsc#1266761). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45901: netfilter: nf_tables: revert commit_mutex usage in reset path (bsc#1266892). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805). * CVE-2026-45933: bpf: Preserve id of register in sync_linked_regs() (bsc#1266693). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-45999: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (bsc#1266750). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents (bsc#1267505). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46093: mm/vmalloc: take vmap_purge_lock in shrinker (bsc#1267548). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: printk: add print_hex_dump_devel() (bsc#1267937). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52919: batman-adv: fix tp_meter counter underflow during shutdown (bsc#1269031). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52975: bonding: 3ad: implement proper RCU rules for port->aggregator (bsc#1269234). * CVE-2026-52980: sched/fair: Clear rel_deadline when initializing forked entities (bsc#1269252). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53015: erofs: unify lcn as u64 for 32-bit platforms (bsc#1269087). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53081: bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars (bsc#1269708). * CVE-2026-53086: net: bcmgenet: move DESC_INDEX flow to ring 0 (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53103: wifi: mt76: mt7925: fix potential deadlock in mt7925_roc_abort_sync (bsc#1269416). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53156: nvmem: core: fix use-after-free bugs in error paths (bsc#1269288). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000). * CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression (bsc#1269647). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress (bsc#1269809). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53286: idpf: fix double free and use-after-free in aux device error paths (bsc#1269531). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). The following non security issues were fixed: * accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: scarlett2: Allow flash writes ending at segment boundary (git-fixes). * ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes (stable- fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: timer: Forcibly close timer instances at closing (git-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: virtio: Validate control metadata from the device (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64 (bsc#1267600). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: amd: acp-sdw-sof: Bound DAI link iteration (git-fixes). * ASoC: codecs: aw88261: fix incorrect masks for boost regs (git-fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git- fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). * ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_core: Fix UAF in hci_unregister_dev() (git-fixes). * Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non- serdev device (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls (git- fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: ISO: Fix not using bc_sid as advertisement SID (stable-fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * Bluetooth: sco: Fix a race condition in sco_sock_timeout() (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * bpf: Free reuseport cBPF prog after RCU grace period (git-fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * crypto/hmac: reject keys shorter than 128 bits in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow ffdhe2048 in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow plain ecb() usage in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow sha224 + sha3-224 in fips mode (bsc#1266284 jsc#PED-15986). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) (git-fixes). * crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) (git-fixes). * crypto: ccp - Do not initialize SNP for SEV ioctls (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * crypto: tegra - Fix dma_free_coherent size error (git-fixes). * crypto: tegra - fix refcount leak in tegra_se_host1x_submit() (git-fixes). * crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm (git-fixes). * dm init: ensure device probing has finished in dm-mod.waitfor= (git-fixes). * dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc (git-fixes). * dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). * drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). * drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git- fixes). * drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: always resume_all after suspend_all (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/gpuvm: Do not prepare NULL objects (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). * drm/imagination: Count paired job fence as dependency in prepare_job() (git- fixes). * drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/rockchip: Test for imported buffers with drm_gem_is_imported() (git- fixes). * drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). * drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * ftrace: Check against is_kernel_text() instead of kaslr_offset() (bsc#1267600). * ftrace: Do not over-allocate ftrace memory (bsc#1267600). * ftrace: Have ftrace pages output reflect freed pages (bsc#1267600). * ftrace: Test mcount_loc addr before calling ftrace_call_addr() (bsc#1267600). * ftrace: Update the mcount_loc check of skipped entries (bsc#1267600). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpio: mxc: fix irq_high handling (git-fixes). * gpio: rockchip: convert bank->clk to devm_clk_get_enabled() (git-fixes). * gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write() (git-fixes). * gpio: zynq: fix runtime PM leak on remove (git-fixes). * gpiolib: Extract gpiochip_choose_fwnode() for wider use (stable-fixes). * gpiolib: Remove redundant assignment of return variable (stable-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * HID: core: Add printk_ratelimited variants to hid_warn() etc (stable-fixes). * HID: hid-goodix-spi: validate report size to prevent stack buffer overflow (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: rate-limit hid_warn to prevent log flooding (stable-fixes). * HID: remove duplicate hid_warn_ratelimited definition (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hv: utils: replace deprecated strcpy with strscpy in kvp_register (git- fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (git-fixes). * hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (max1619) add missing 'select REGMAP' to Kconfig (git-fixes). * hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: disable runtime PM on adapter registration failure (git-fixes). * i2c: core: fix adapter debugfs creation (git-fixes). * i2c: core: fix adapter deregistration race (git-fixes). * i2c: core: fix adapter probe deferral loop (git-fixes). * i2c: core: fix adapter registration race (git-fixes). * i2c: core: fix hang on adapter registration failure (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: core: fix NULL-deref on adapter registration failure (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: imx-lpi2c: mark I2C adapter when hardware is powered down (git-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: riic: fix refcount leak in riic_i2c_resume_noirq() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock (git- fixes). * ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: ti-ads1298: add bounds check to pga_settings index (stable-fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: backend: fix uninitialized data in debugfs (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: light: veml6075: add bounds check to veml6075_it_ms index (stable- fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: resolver: ad2s1210: notify trigger and clear state on fault read error (git-fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * io_uring/cancel: de-unionize file and user_data in struct io_cancel_data (git-fixes bsc#1261250). * io_uring/filetable: clamp alloc_hint to the configured alloc range (git- fixes bsc#1261250). * io_uring/io-wq: fix incorrect io_wq_for_each_worker() termination logic (git-fixes bsc#1261250). * io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git- fixes bsc#1261250). * io_uring/wait: fix min_timeout behavior (git-fixes bsc#1261250). * io_uring/waitid: clear waitid info before copying it to userspace (git- fixes). * io_uring: fix min_wait wakeups for SQPOLL (git-fixes bsc#1261250). * ipv4: account for fraggap on the paged allocation path (git-fixes). * ipv6: account for fraggap on the paged allocation path (git-fixes). * KEYS: fix overflow in keyctl_pkey_params_get_2() (git-fixes). * KEYS: Use acquire when reading state in keyring search (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: vgic: Free private_irqs when init fails after allocation (git- fixes). * KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (git-fixes). * KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (git- fixes). * KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2 (git-fixes). * KVM: nVMX: Immediately refresh APICv controls as needed on nested VM-Exit (git-fixes). * KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (git-fixes). * KVM: SEV: Add an anonymous "psc" struct to track current PSC metadata (git- fixes). * KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA (git-fixes). * KVM: SEV: Don't terminate SNP VMs on #VMGEXIT without a registered GHCB (git-fixes). * KVM: SEV: Make it more obvious when KVM is writing back the current PSC index (git-fixes). * KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() (git-fixes). * KVM: SEV: Read start/end indices of PSC requests exactly once per #VMGEXIT (git-fixes). * KVM: SEV: Return INVALID_EVENT for SNP-only #VMGEXIT from non-SNP guest (git-fixes). * KVM: SEV: Return INVALID_INPUT, not MISSING_INPUT, for bad GUEST_REQUEST input(s) (git-fixes). * KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: Use vCPU specific memslots in __kvm_vcpu_map() (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: VMX: Read 32-bit GPR values for ENCLS instructions outside of 64-bit mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86/xen: Bug the VM if 32-bit KVM observes a 64-bit mode hypercall (git-fixes). * KVM: x86/xen: Don't truncate RAX when handling hypercall from protected guest (git-fixes). * KVM: x86: Consolidate CPUID fault handling for emulator and interception logic (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Prioritize CPUID faulting over CPUID VM-exits in nested VMX (git- fixes). * KVM: x86: Trace hypercall register _after_ truncating values for 32-bit (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() (git-fixes). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: Pause continuous reads at block boundaries (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program (stable-fixes). * mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g (stable-fixes). * mtd: spi-nor: spansion: use die erase for multi-die devices only (git- fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Cache MANA_QUERY_LINK_CONFIG result to avoid repeated HWC queries (bsc#1268238). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Sync page pool RX frags for CPU (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * packaging: Add nvidia kernel description. * packaging: compute-PATCHVERSION.sh -> compute-PATCHVERSION. * page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562). * page_pool: Move pp_magic check into helper functions (bsc#1261562). * page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). * PCI: Update saved_config_space upon resource assignment (git-fixes). * perf/x86/intel/uncore: Fix die ID init and look up bugs (bsc#1267419). * perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1267419). * platform/x86: dell-laptop: fix missing cleanups in init error path (git- fixes). * platform/x86: intel-hid: Protect ACPI notify handler against recursion (git- fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git- fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * pwm: imx27: Fix variable truncation in .apply() (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (git- fixes). * Revert "fs: don't block i_writecount during exec" (bsc#1269982). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scripts/sorttable: Add helper functions for Elf_Ehdr (bsc#1267600). * scripts/sorttable: Add helper functions for Elf_Shdr (bsc#1267600). * scripts/sorttable: Add helper functions for Elf_Sym (bsc#1267600). * scripts/sorttable: Allow matches to functions before function entry (bsc#1267600). * scripts/sorttable: Always use an array for the mcount_loc sorting (bsc#1267600). * scripts/sorttable: Convert Elf_Ehdr to union (bsc#1267600). * scripts/sorttable: Convert Elf_Sym MACRO over to a union (bsc#1267600). * scripts/sorttable: Fix endianness handling in build-time mcount sort (bsc#1267600). * scripts/sorttable: Get start/stop_mcount_loc from ELF file directly (bsc#1267600). * scripts/sorttable: Have mcount rela sort use direct values (bsc#1267600). * scripts/sorttable: Have the ORC code use the _r() functions to read (bsc#1267600). * scripts/sorttable: Make compare_extable() into two functions (bsc#1267600). * scripts/sorttable: Move code from sorttable.h into sorttable.c (bsc#1267600). * scripts/sorttable: Remove unneeded Elf_Rel (bsc#1267600). * scripts/sorttable: Remove unused macro defines (bsc#1267600). * scripts/sorttable: Remove unused write functions (bsc#1267600). * scripts/sorttable: Replace Elf_Shdr Macro with a union (bsc#1267600). * scripts/sorttable: Use a structure of function pointers for elf helpers (bsc#1267600). * scripts/sorttable: Use normal sort if theres no relocs in the mcount section (bsc#1267600). * scripts/sorttable: Use uint64_t for mcount sorting (bsc#1267600). * scripts/sorttable: Zero out weak functions in mcount_loc table (bsc#1267600). * scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (bsc#1257506). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * selftests/bpf: Add BPF_STRICT_BUILD toggle (poo#202224). * selftests/bpf: Allow test_progs to link with a partial object set (poo#202224). * selftests/bpf: Avoid rebuilds when running emit_tests (poo#202224). * selftests/bpf: Consolidate kernel modules into common directory (poo#202224). * selftests/bpf: Copy test_kmods when installing selftest (poo#202224). * selftests/bpf: Fix runqslower cross-endian build (poo#202224). * selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (poo#202224). * selftests/bpf: make BPF_TARGET_ENDIAN non-recursive to speed up *.bpf.o build (poo#202224). * selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (poo#202224). * selftests/bpf: Provide weak definitions for cross-test functions (poo#202224). * selftests/bpf: Skip tests whose objects were not built (poo#202224). * selftests/bpf: Support cross-endian building (poo#202224). * selftests/bpf: Tolerate benchmark build failures (poo#202224). * selftests/bpf: Tolerate BPF and skeleton generation failures (poo#202224). * selftests/bpf: Tolerate missing files during install (poo#202224). * selftests/bpf: Tolerate test file compilation failures (poo#202224). * serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git- fixes). * serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git- fixes). * serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero (git- fixes). * slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (git-fixes). * slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (git-fixes). * slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * slimbus: qcom-ngd-ctrl: Fix probe error path ordering (git-fixes). * slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (git-fixes). * slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (git- fixes). * slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (git- fixes). * soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() (git-fixes). * soc: qcom: ice: Return -ENODEV if the ICE platform device is not found (git- fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: hisi-kunpeng: Use dev_err_probe() for host registration failure (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * thermal: testing: reject missing command arguments (git-fixes). * thermal: testing: zone: Flush work items during cleanup (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: debugfs: Don't stop reading SB registers if just one fails (git-fixes). * thunderbolt: debugfs: Fix margining error counter buffer leak (git-fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * tools/power/x86/intel-speed-select: Harden daemon pidfile open (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt (git-fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (git-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (stable-fixes). * usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 (git- fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). * wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes). * wifi: mt76: mt7921: fix a potential scan no APs (stable-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer (git- fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links (git- fixes). * wifi: mt76: mt7925: keep TX BA state in the primary WCID (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * x86/cpu/amd: Correct the microcode table for Zenbleed (git-fixes). * x86/cpu: Disable FRED when PTI is forced on (git-fixes). * x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63 (git-fixes). * x86/cpu: Validate CPUID leaf 0x2 EDX output (git-fixes). * x86/irq: Ensure initial PIR loads are performed exactly once (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16390). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16390). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1295=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.12.0-160000.36.1 * SUSE Linux Micro 6.2 (aarch64 x86_64) * kernel-rt-debugsource-6.12.0-160000.36.1 * kernel-rt-debuginfo-6.12.0-160000.36.1 * kernel-rt-devel-6.12.0-160000.36.1 * SUSE Linux Micro 6.2 (noarch) * kernel-source-6.12.0-160000.36.1 * kernel-devel-6.12.0-160000.36.1 * kernel-macros-6.12.0-160000.36.1 * SUSE Linux Micro 6.2 (aarch64) * kernel-64kb-debugsource-6.12.0-160000.36.1 * kernel-default-base-6.12.0-160000.36.1.160000.2.18 * kernel-64kb-debuginfo-6.12.0-160000.36.1 * kernel-64kb-devel-6.12.0-160000.36.1 * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-default-livepatch-6.12.0-160000.36.1 * SUSE Linux Micro 6.2 (aarch64 nosrc x86_64) * kernel-rt-6.12.0-160000.36.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * kernel-default-debuginfo-6.12.0-160000.36.1 * kernel-default-debugsource-6.12.0-160000.36.1 * kernel-default-devel-6.12.0-160000.36.1 * kernel-default-extra-6.12.0-160000.36.1 * kernel-default-extra-debuginfo-6.12.0-160000.36.1 * SUSE Linux Micro 6.2 (aarch64 nosrc) * kernel-64kb-6.12.0-160000.36.1 * SUSE Linux Micro 6.2 (ppc64le x86_64) * kernel-default-base-6.12.0-160000.36.1.160000.2.17 * SUSE Linux Micro 6.2 (x86_64) * kernel-rt-livepatch-6.12.0-160000.36.1 * kernel-rt-devel-debuginfo-6.12.0-160000.36.1 * kernel-default-devel-debuginfo-6.12.0-160000.36.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-39894.html * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2026-23248.html * https://www.suse.com/security/cve/CVE-2026-23394.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31438.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31479.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31560.html * https://www.suse.com/security/cve/CVE-2026-31580.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31646.html * https://www.suse.com/security/cve/CVE-2026-31647.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31743.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43014.html * https://www.suse.com/security/cve/CVE-2026-43015.html * https://www.suse.com/security/cve/CVE-2026-43016.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43090.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43094.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43130.html * https://www.suse.com/security/cve/CVE-2026-43132.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43145.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43161.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43175.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43213.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43260.html * https://www.suse.com/security/cve/CVE-2026-43283.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43298.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43337.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43351.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43374.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43384.html * https://www.suse.com/security/cve/CVE-2026-43386.html * https://www.suse.com/security/cve/CVE-2026-43403.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43415.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43457.html * https://www.suse.com/security/cve/CVE-2026-43458.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43471.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45837.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45861.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45884.html * https://www.suse.com/security/cve/CVE-2026-45888.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45901.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45922.html * https://www.suse.com/security/cve/CVE-2026-45933.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-45999.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46078.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46093.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46162.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52919.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52980.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53015.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53081.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53103.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53156.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53194.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53262.html * https://www.suse.com/security/cve/CVE-2026-53263.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53272.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53286.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1149651 * https://bugzilla.suse.com/show_bug.cgi?id=1204315 * https://bugzilla.suse.com/show_bug.cgi?id=1236743 * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1257506 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1259800 * https://bugzilla.suse.com/show_bug.cgi?id=1260565 * https://bugzilla.suse.com/show_bug.cgi?id=1261250 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262430 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262765 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1263057 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263169 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263581 * https://bugzilla.suse.com/show_bug.cgi?id=1263796 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264007 * https://bugzilla.suse.com/show_bug.cgi?id=1264010 * https://bugzilla.suse.com/show_bug.cgi?id=1264012 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264067 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264231 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264250 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264295 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264333 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264372 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264429 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264532 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264614 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264643 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264740 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264789 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264852 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265000 * https://bugzilla.suse.com/show_bug.cgi?id=1265005 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265082 * https://bugzilla.suse.com/show_bug.cgi?id=1265084 * https://bugzilla.suse.com/show_bug.cgi?id=1265091 * https://bugzilla.suse.com/show_bug.cgi?id=1265097 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265112 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265123 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265129 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266283 * https://bugzilla.suse.com/show_bug.cgi?id=1266284 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266398 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266693 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266718 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266750 * https://bugzilla.suse.com/show_bug.cgi?id=1266754 * https://bugzilla.suse.com/show_bug.cgi?id=1266761 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266805 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266840 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266892 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266925 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267419 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267505 * https://bugzilla.suse.com/show_bug.cgi?id=1267548 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267600 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1267816 * https://bugzilla.suse.com/show_bug.cgi?id=1267824 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268238 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269031 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269087 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269199 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269252 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269288 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269416 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269531 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269617 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269647 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269708 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269809 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269904 * https://bugzilla.suse.com/show_bug.cgi?id=1269982 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1270000 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270042 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://jira.suse.com/browse/PED-10906 * https://jira.suse.com/browse/PED-15986 * https://jira.suse.com/browse/PED-16390 * https://jira.suse.com/browse/SLE-8615 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:37:18 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:37:18 -0000 Subject: SUSE-RU-2026:22768-1: important: Recommended update for container-selinux Message-ID: <178475263888.245.13989303611692245278@c3e054a4ce29> # Recommended update for container-selinux Announcement ID: SUSE-RU-2026:22768-1 Release Date: 2026-07-20T14:07:23Z Rating: important References: * bsc#1268490 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for container-selinux fixes the following issues: * Introduce container_can_execstack boolean for older Java applications and allow execmem (bsc#1268490) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1304=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * container-selinux-2.239.0-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268490 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:37:26 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:37:26 -0000 Subject: SUSE-SU-2026:22767-1: moderate: Security update for gawk Message-ID: <178475264671.245.548156438509852788@c3e054a4ce29> # Security update for gawk Announcement ID: SUSE-SU-2026:22767-1 Release Date: 2026-07-20T13:43:46Z Rating: moderate References: * bsc#1271351 * bsc#1271352 * bsc#1271354 Cross-References: * CVE-2026-40467 * CVE-2026-40468 * CVE-2026-40553 CVSS scores: * CVE-2026-40467 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40467 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40467 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40467 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40468 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L * CVE-2026-40468 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40468 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40468 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-40553 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-40553 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-40553 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40553 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for gawk fixes the following issues: * CVE-2026-40467: use-after-free vulnerability within the do_getline_redir() routine could lead to a program crash (bsc#1271351). * CVE-2026-40468: use-after-free vulnerability in gawk's "io.c" file could permit heap metadata manipulation and host memory exhaustion (bsc#1271352). * CVE-2026-40553: buffer overflow in the ftype() routine of the readdir extension could trigger a program crash (bsc#1271354). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1303=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * gawk-5.3.2-160000.3.1 * gawk-debuginfo-5.3.2-160000.3.1 * gawk-debugsource-5.3.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40467.html * https://www.suse.com/security/cve/CVE-2026-40468.html * https://www.suse.com/security/cve/CVE-2026-40553.html * https://bugzilla.suse.com/show_bug.cgi?id=1271351 * https://bugzilla.suse.com/show_bug.cgi?id=1271352 * https://bugzilla.suse.com/show_bug.cgi?id=1271354 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:37:40 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:37:40 -0000 Subject: SUSE-SU-2026:22766-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 16) Message-ID: <178475266083.245.3331675228732808466@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22766-1 Release Date: 2026-07-20T12:22:28Z Rating: important References: * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.34.1 fixes various security issues The following security issues were fixed: * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1302=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_34-default-debuginfo-2-160000.1.2 * kernel-livepatch-SLE16_Update_13-debugsource-2-160000.1.2 * kernel-livepatch-6_12_0-160000_34-default-2-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:37:49 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:37:49 -0000 Subject: SUSE-SU-2026:22765-1: important: Security update for python-pyasn1 Message-ID: <178475266914.245.3022360886160156053@c3e054a4ce29> # Security update for python-pyasn1 Announcement ID: SUSE-SU-2026:22765-1 Release Date: 2026-07-20T12:15:58Z Rating: important References: * bsc#1271464 * bsc#1271465 * bsc#1271466 Cross-References: * CVE-2026-59884 * CVE-2026-59885 * CVE-2026-59886 CVSS scores: * CVE-2026-59884 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59884 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59884 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59885 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59885 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59885 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59886 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59886 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59886 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-pyasn1 fixes the following issues: * CVE-2026-59884: BER/CER/DER decoder denial of service via unbounded long- form tag IDs (bsc#1271464). * CVE-2026-59885: quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service (bsc#1271465). * CVE-2026-59886: uncontrolled resource consumption when converting decoded REAL values (bsc#1271466). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1301=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * python313-pyasn1-0.6.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59884.html * https://www.suse.com/security/cve/CVE-2026-59885.html * https://www.suse.com/security/cve/CVE-2026-59886.html * https://bugzilla.suse.com/show_bug.cgi?id=1271464 * https://bugzilla.suse.com/show_bug.cgi?id=1271465 * https://bugzilla.suse.com/show_bug.cgi?id=1271466 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:37:53 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:37:53 -0000 Subject: SUSE-RU-2026:22764-1: important: Recommended update for the initial kernel livepatch Message-ID: <178475267318.245.15126522235174534535@c3e054a4ce29> # Recommended update for the initial kernel livepatch Announcement ID: SUSE-RU-2026:22764-1 Release Date: 2026-07-20T11:11:24Z Rating: important References: Affected Products: * SUSE Linux Micro 6.2 An update that can now be installed. ## Description: This update contains initial livepatches for the SUSE Linux Enterprise Server 16.0 and SUSE Linux Micro 6.2 kernel update. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1296=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_36-rt-1-160000.1.1 * kernel-livepatch-6_12_0-160000_36-rt-debuginfo-1-160000.1.1 * kernel-livepatch-SLE16-RT_Update_15-debugsource-1-160000.1.1 * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_36-default-1-160000.1.1 * kernel-livepatch-6_12_0-160000_36-default-debuginfo-1-160000.1.1 * kernel-livepatch-SLE16_Update_15-debugsource-1-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:38:25 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:38:25 -0000 Subject: SUSE-SU-2026:22763-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Message-ID: <178475270538.245.18349697105632568607@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22763-1 Release Date: 2026-07-20T09:52:57Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1297=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_32-default-debuginfo-4-160000.1.1 * kernel-livepatch-SLE16_Update_11-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_32-default-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:38:58 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:38:58 -0000 Subject: SUSE-SU-2026:22762-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178475273817.245.16191785776346997830@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22762-1 Release Date: 2026-07-20T09:27:51Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1291=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_29-default-debuginfo-5-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:39:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:39:36 -0000 Subject: SUSE-SU-2026:22761-1: important: Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Message-ID: <178475277697.245.13534909028815452942@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22761-1 Release Date: 2026-07-20T09:27:03Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.7.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1292=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_7-default-debuginfo-11-160000.1.1 * kernel-livepatch-SLE16_Update_2-debugsource-11-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:39:43 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:39:43 -0000 Subject: SUSE-SU-2026:22760-1: moderate: Security update for libgcrypt Message-ID: <178475278323.245.18202440597073212741@c3e054a4ce29> # Security update for libgcrypt Announcement ID: SUSE-SU-2026:22760-1 Release Date: 2026-07-20T09:26:19Z Rating: moderate References: * bsc#1262684 Cross-References: * CVE-2026-41989 CVSS scores: * CVE-2026-41989 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue * CVE-2026-41989: crafted ECDH ciphertext can lead denial of service (bsc#1262684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1294=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libgcrypt-debugsource-1.12.1-160000.3.1 * libgcrypt20-1.12.1-160000.3.1 * libgcrypt20-debuginfo-1.12.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41989.html * https://bugzilla.suse.com/show_bug.cgi?id=1262684 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:40:21 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:40:21 -0000 Subject: SUSE-SU-2026:22759-1: important: Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Message-ID: <178475282172.245.5431080631525843965@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22759-1 Release Date: 2026-07-20T07:46:18Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.26.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1290=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_26-default-8-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-8-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-debuginfo-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:40:59 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:40:59 -0000 Subject: SUSE-SU-2026:22758-1: important: Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Message-ID: <178475285951.245.16194403374419948913@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22758-1 Release Date: 2026-07-20T07:46:18Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.27.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1289=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_27-default-7-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-debuginfo-7-160000.1.1 * kernel-livepatch-SLE16_Update_6-debugsource-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:41:05 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:41:05 -0000 Subject: SUSE-SU-2026:22757-1: low: Security update for gpg2 Message-ID: <178475286510.245.6195850827108312607@c3e054a4ce29> # Security update for gpg2 Announcement ID: SUSE-SU-2026:22757-1 Release Date: 2026-07-20T03:15:09Z Rating: low References: * bsc#1269279 Cross-References: * CVE-2026-57062 CVSS scores: * CVE-2026-57062 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-57062 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-57062 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for gpg2 fixes the following issue: * CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1288=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * gpg2-2.5.5-160000.6.1 * gpg2-debugsource-2.5.5-160000.6.1 * gpg2-debuginfo-2.5.5-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57062.html * https://bugzilla.suse.com/show_bug.cgi?id=1269279 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:41:10 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:41:10 -0000 Subject: SUSE-RU-2026:22756-1: moderate: Recommended update for python-kiwi Message-ID: <178475287062.245.9343285930924427519@c3e054a4ce29> # Recommended update for python-kiwi Announcement ID: SUSE-RU-2026:22756-1 Release Date: 2026-07-18T13:40:31Z Rating: moderate References: * bsc#1263564 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for python-kiwi fixes the following issues: * Fix reading of runtime config files: * Make sure the reading of the runtime config files in the different locations is not an exclusive procedure. * Add support for sha512sum: * Allow to select between the default shasum size 256 and 512 via a new runtime config section named: shasum. * Fix system resize: * The filesystem check is not applied for btrfs prior resize. * Fix qemu-xxx requirement: * Do not require qemu variant packages for 32bit architectures. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1286=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * dracut-kiwi-oem-dump-10.2.33-160000.4.1 * dracut-kiwi-oem-repart-10.2.33-160000.4.1 * dracut-kiwi-lib-10.2.33-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1263564 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:41:54 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:41:54 -0000 Subject: SUSE-SU-2026:22755-1: important: Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Message-ID: <178475291405.245.4118594118255695754@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22755-1 Release Date: 2026-07-18T12:13:35Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1284=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_5-default-15-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-debuginfo-15-160000.4.3 * kernel-livepatch-SLE16_Update_0-debugsource-15-160000.4.3 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:42:02 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:42:02 -0000 Subject: SUSE-SU-2026:22754-1: important: Security update for vim Message-ID: <178475292230.245.14223087098340076770@c3e054a4ce29> # Security update for vim Announcement ID: SUSE-SU-2026:22754-1 Release Date: 2026-07-18T11:47:56Z Rating: important References: * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for vim fixes the following issues: Update to version 9.2.0780. Security issues fixed: * CVE-2026-59856: arbitrary code execution via PHP omni-completion due to improper escaping (bsc#1271194). * CVE-2026-59857: out-of-bounds write in SAL soundfolding due to improper bounds check (bsc#1271195). * CVE-2026-59858: arbitrary code execution via C omni-completion due to improper escaping (bsc#1271193). Other updates and bugfixes: * Version 9.2.0780 changelog: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * tests: test_popupwin fails with zsh because of the prompt (9.2.0757). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * tests: style issue in test_plugin_netrw (9.2.0763). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1283=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * vim-debuginfo-9.2.0780-160000.1.1 * vim-small-debuginfo-9.2.0780-160000.1.1 * vim-debugsource-9.2.0780-160000.1.1 * vim-small-9.2.0780-160000.1.1 * SUSE Linux Micro 6.2 (noarch) * vim-data-common-9.2.0780-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:42:07 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:42:07 -0000 Subject: SUSE-SU-2026:22753-1: important: Security update for gzip Message-ID: <178475292777.245.10548579858815881874@c3e054a4ce29> # Security update for gzip Announcement ID: SUSE-SU-2026:22753-1 Release Date: 2026-07-18T08:14:12Z Rating: important References: * bsc#1269622 Cross-References: * CVE-2026-41991 CVSS scores: * CVE-2026-41991 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41991 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41991 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41991 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for gzip fixes the following issue * CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1280=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * gzip-debuginfo-1.13-160000.3.1 * gzip-debugsource-1.13-160000.3.1 * gzip-1.13-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41991.html * https://bugzilla.suse.com/show_bug.cgi?id=1269622 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:42:24 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:42:24 -0000 Subject: SUSE-SU-2026:22752-1: important: Security update for gstreamer-plugins-bad Message-ID: <178475294404.245.12756613836715475374@c3e054a4ce29> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:22752-1 Release Date: 2026-07-18T06:19:25Z Rating: important References: * bsc#1268168 * bsc#1268172 * bsc#1268406 * bsc#1268408 * bsc#1268410 * bsc#1268872 * bsc#1268971 * bsc#1271051 * bsc#1271168 Cross-References: * CVE-2026-12891 * CVE-2026-12892 * CVE-2026-14935 * CVE-2026-52720 * CVE-2026-52721 * CVE-2026-52722 * CVE-2026-53701 * CVE-2026-53702 * CVE-2026-59692 CVSS scores: * CVE-2026-12891 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-12891 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-12892 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12892 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12892 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-14935 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-14935 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-14935 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-52720 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52721 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-52721 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53701 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53701 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53702 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53702 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59692 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves nine vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issues * CVE-2026-12891: unchecked aspect_ratio_idc value used as an array index in the H.266 parser could cause a global out- of-bounds read (bsc#1268872). * CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser (bsc#1268971). * CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check (bsc#1271051). * CVE-2026-52720: invalid check of total area instead of individual dimensions could trigger a heap out-of-bounds write (bsc#1268406). * CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could cause an out-of-bounds read (bsc#1268408). * CVE-2026-52722: crafted VMnc stream with large cursor dimensions can overflow signed integer (bsc#1268410). * CVE-2026-53701: multi-slice-in-tile partitions without slice index bounds checks could trigger an out-of-bounds write (bsc#1268172). * CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could result in a stack buffer overflow (bsc#1268168). * CVE-2026-59692: unvalidated peer certificate Subject DN printed during a DTLS handshake could cause a stack buffer overflow (bsc#1271168). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1279=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libgstplayer-1_0-0-1.26.7-160000.3.1 * gstreamer-plugins-bad-debugsource-1.26.7-160000.3.1 * libgstplayer-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstplay-1_0-0-1.26.7-160000.3.1 * libgstplay-1_0-0-debuginfo-1.26.7-160000.3.1 * gstreamer-plugins-bad-debuginfo-1.26.7-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12891.html * https://www.suse.com/security/cve/CVE-2026-12892.html * https://www.suse.com/security/cve/CVE-2026-14935.html * https://www.suse.com/security/cve/CVE-2026-52720.html * https://www.suse.com/security/cve/CVE-2026-52721.html * https://www.suse.com/security/cve/CVE-2026-52722.html * https://www.suse.com/security/cve/CVE-2026-53701.html * https://www.suse.com/security/cve/CVE-2026-53702.html * https://www.suse.com/security/cve/CVE-2026-59692.html * https://bugzilla.suse.com/show_bug.cgi?id=1268168 * https://bugzilla.suse.com/show_bug.cgi?id=1268172 * https://bugzilla.suse.com/show_bug.cgi?id=1268406 * https://bugzilla.suse.com/show_bug.cgi?id=1268408 * https://bugzilla.suse.com/show_bug.cgi?id=1268410 * https://bugzilla.suse.com/show_bug.cgi?id=1268872 * https://bugzilla.suse.com/show_bug.cgi?id=1268971 * https://bugzilla.suse.com/show_bug.cgi?id=1271051 * https://bugzilla.suse.com/show_bug.cgi?id=1271168 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:42:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:42:42 -0000 Subject: SUSE-SU-2026:22751-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 16) Message-ID: <178475296268.245.2075990001462198908@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22751-1 Release Date: 2026-07-16T21:48:13Z Rating: important References: * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.33.1 fixes various security issues The following security issues were fixed: * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1277=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_33-default-2-160000.1.1 * kernel-livepatch-6_12_0-160000_33-default-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16_Update_12-debugsource-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:42:51 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:42:51 -0000 Subject: SUSE-SU-2026:22750-1: moderate: Security update for freetype2 Message-ID: <178475297193.245.16193860771519158676@c3e054a4ce29> # Security update for freetype2 Announcement ID: SUSE-SU-2026:22750-1 Release Date: 2026-07-16T18:45:28Z Rating: moderate References: * bsc#1252148 * bsc#1259118 * bsc#1271045 Cross-References: * CVE-2026-23865 * CVE-2026-50811 CVSS scores: * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-50811 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-50811 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-50811 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for freetype2 fixes the following issues * Update to version 2.14.3 * CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118). * CVE-2026-50811: out-of-bounds read vulnerabilityin src/truetype/ttgxvar.c in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates (bsc#1271045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1276=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libfreetype6-debuginfo-2.14.3-160000.1.1 * libfreetype6-2.14.3-160000.1.1 * freetype2-debugsource-2.14.3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-50811.html * https://bugzilla.suse.com/show_bug.cgi?id=1252148 * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1271045 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:43:24 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:43:24 -0000 Subject: SUSE-SU-2026:22749-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Message-ID: <178475300441.245.580029361386589623@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22749-1 Release Date: 2026-07-16T11:44:00Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1274=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_31-default-4-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-debuginfo-4-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:44:03 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:44:03 -0000 Subject: SUSE-SU-2026:22748-1: important: Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Message-ID: <178475304329.245.4863667532971103968@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22748-1 Release Date: 2026-07-16T09:15:22Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1273=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_3-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-10-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:44:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:44:36 -0000 Subject: SUSE-SU-2026:22747-1: important: Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Message-ID: <178475307673.245.4987299819662907078@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22747-1 Release Date: 2026-07-16T06:12:55Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.28.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1272=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_28-default-debuginfo-6-160000.1.1 * kernel-livepatch-SLE16_Update_7-debugsource-6-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:45:17 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:45:17 -0000 Subject: SUSE-SU-2026:22746-1: important: Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Message-ID: <178475311761.245.4161497449498817213@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22746-1 Release Date: 2026-07-16T02:49:54Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1271=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_4-debugsource-9-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-9-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-debuginfo-9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:45:30 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:45:30 -0000 Subject: SUSE-SU-2026:22745-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Message-ID: <178475313080.245.2434616226568252867@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22745-1 Release Date: 2026-07-15T20:41:46Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.35.1 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1270=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_14-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-2-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-debuginfo-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:46:07 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:46:07 -0000 Subject: SUSE-SU-2026:22744-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Message-ID: <178475316791.245.8556034946795478133@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22744-1 Release Date: 2026-07-15T19:15:36Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.30.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1269=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_30-default-debuginfo-4-160000.1.1 * kernel-livepatch-SLE16_Update_9-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:47:09 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:47:09 -0000 Subject: SUSE-SU-2026:22743-1: important: Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Message-ID: <178475322929.245.3918015538143253820@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22743-1 Release Date: 2026-07-15T10:12:41Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.6.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1266=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_6-default-13-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-debuginfo-13-160000.1.1 * kernel-livepatch-SLE16_Update_1-debugsource-13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:54:13 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:54:13 -0000 Subject: SUSE-SU-2026:22742-1: important: Security update for the Linux Kernel Message-ID: <178475365308.245.11665480338746407984@c3e054a4ce29> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22742-1 Release Date: 2026-07-21T08:27:33Z Rating: important References: * bsc#1149651 * bsc#1204315 * bsc#1236743 * bsc#1255029 * bsc#1257506 * bsc#1258538 * bsc#1259800 * bsc#1260565 * bsc#1261250 * bsc#1261256 * bsc#1261562 * bsc#1261604 * bsc#1262085 * bsc#1262392 * bsc#1262430 * bsc#1262618 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262765 * bsc#1262798 * bsc#1263057 * bsc#1263072 * bsc#1263133 * bsc#1263137 * bsc#1263143 * bsc#1263169 * bsc#1263178 * bsc#1263319 * bsc#1263563 * bsc#1263568 * bsc#1263573 * bsc#1263578 * bsc#1263581 * bsc#1263796 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1263998 * bsc#1264001 * bsc#1264007 * bsc#1264010 * bsc#1264012 * bsc#1264015 * bsc#1264045 * bsc#1264056 * bsc#1264067 * bsc#1264084 * bsc#1264145 * bsc#1264230 * bsc#1264231 * bsc#1264236 * bsc#1264239 * bsc#1264241 * bsc#1264250 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264263 * bsc#1264266 * bsc#1264270 * bsc#1264286 * bsc#1264294 * bsc#1264295 * bsc#1264302 * bsc#1264304 * bsc#1264320 * bsc#1264328 * bsc#1264333 * bsc#1264337 * bsc#1264372 * bsc#1264386 * bsc#1264429 * bsc#1264449 * bsc#1264532 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264549 * bsc#1264556 * bsc#1264561 * bsc#1264580 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264612 * bsc#1264614 * bsc#1264624 * bsc#1264643 * bsc#1264734 * bsc#1264740 * bsc#1264741 * bsc#1264744 * bsc#1264763 * bsc#1264789 * bsc#1264790 * bsc#1264794 * bsc#1264852 * bsc#1264974 * bsc#1264978 * bsc#1264997 * bsc#1265000 * bsc#1265005 * bsc#1265020 * bsc#1265023 * bsc#1265073 * bsc#1265079 * bsc#1265082 * bsc#1265084 * bsc#1265091 * bsc#1265097 * bsc#1265103 * bsc#1265112 * bsc#1265113 * bsc#1265123 * bsc#1265128 * bsc#1265129 * bsc#1265142 * bsc#1265143 * bsc#1265628 * bsc#1265629 * bsc#1266008 * bsc#1266214 * bsc#1266283 * bsc#1266284 * bsc#1266290 * bsc#1266390 * bsc#1266396 * bsc#1266397 * bsc#1266398 * bsc#1266452 * bsc#1266458 * bsc#1266686 * bsc#1266693 * bsc#1266697 * bsc#1266698 * bsc#1266700 * bsc#1266704 * bsc#1266705 * bsc#1266717 * bsc#1266718 * bsc#1266722 * bsc#1266726 * bsc#1266734 * bsc#1266740 * bsc#1266750 * bsc#1266754 * bsc#1266761 * bsc#1266773 * bsc#1266805 * bsc#1266830 * bsc#1266838 * bsc#1266840 * bsc#1266847 * bsc#1266878 * bsc#1266883 * bsc#1266892 * bsc#1266893 * bsc#1266895 * bsc#1266899 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266925 * bsc#1266929 * bsc#1266933 * bsc#1267208 * bsc#1267218 * bsc#1267228 * bsc#1267238 * bsc#1267251 * bsc#1267360 * bsc#1267361 * bsc#1267365 * bsc#1267369 * bsc#1267387 * bsc#1267419 * bsc#1267427 * bsc#1267431 * bsc#1267437 * bsc#1267458 * bsc#1267493 * bsc#1267505 * bsc#1267548 * bsc#1267582 * bsc#1267591 * bsc#1267600 * bsc#1267618 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267635 * bsc#1267637 * bsc#1267640 * bsc#1267654 * bsc#1267682 * bsc#1267684 * bsc#1267685 * bsc#1267697 * bsc#1267717 * bsc#1267722 * bsc#1267732 * bsc#1267744 * bsc#1267816 * bsc#1267824 * bsc#1267825 * bsc#1267937 * bsc#1267966 * bsc#1267992 * bsc#1267993 * bsc#1267994 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268238 * bsc#1268276 * bsc#1268307 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1268989 * bsc#1269022 * bsc#1269031 * bsc#1269033 * bsc#1269036 * bsc#1269087 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269188 * bsc#1269193 * bsc#1269199 * bsc#1269230 * bsc#1269234 * bsc#1269252 * bsc#1269262 * bsc#1269288 * bsc#1269310 * bsc#1269389 * bsc#1269392 * bsc#1269397 * bsc#1269398 * bsc#1269416 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269527 * bsc#1269531 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269617 * bsc#1269645 * bsc#1269646 * bsc#1269647 * bsc#1269651 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269708 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269798 * bsc#1269809 * bsc#1269814 * bsc#1269821 * bsc#1269904 * bsc#1269982 * bsc#1269989 * bsc#1269992 * bsc#1270000 * bsc#1270022 * bsc#1270042 * bsc#1270059 * bsc#1270226 * bsc#1271366 * jsc#PED-10906 * jsc#PED-15986 * jsc#PED-16390 * jsc#SLE-8615 Cross-References: * CVE-2025-10263 * CVE-2025-39894 * CVE-2025-40341 * CVE-2026-23248 * CVE-2026-23394 * CVE-2026-23451 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31438 * CVE-2026-31450 * CVE-2026-31452 * CVE-2026-31466 * CVE-2026-31469 * CVE-2026-31479 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31502 * CVE-2026-31555 * CVE-2026-31560 * CVE-2026-31580 * CVE-2026-31596 * CVE-2026-31646 * CVE-2026-31647 * CVE-2026-31663 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31670 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31743 * CVE-2026-31752 * CVE-2026-31771 * CVE-2026-43010 * CVE-2026-43014 * CVE-2026-43015 * CVE-2026-43016 * CVE-2026-43022 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43034 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43053 * CVE-2026-43057 * CVE-2026-43074 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43083 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43090 * CVE-2026-43092 * CVE-2026-43093 * CVE-2026-43094 * CVE-2026-43101 * CVE-2026-43107 * CVE-2026-43119 * CVE-2026-43124 * CVE-2026-43128 * CVE-2026-43130 * CVE-2026-43132 * CVE-2026-43139 * CVE-2026-43145 * CVE-2026-43157 * CVE-2026-43158 * CVE-2026-43161 * CVE-2026-43167 * CVE-2026-43171 * CVE-2026-43175 * CVE-2026-43187 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43198 * CVE-2026-43199 * CVE-2026-43205 * CVE-2026-43213 * CVE-2026-43226 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43260 * CVE-2026-43283 * CVE-2026-43284 * CVE-2026-43298 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43337 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43351 * CVE-2026-43373 * CVE-2026-43374 * CVE-2026-43383 * CVE-2026-43384 * CVE-2026-43386 * CVE-2026-43403 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43415 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43456 * CVE-2026-43457 * CVE-2026-43458 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43471 * CVE-2026-43491 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45837 * CVE-2026-45838 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45848 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45861 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45884 * CVE-2026-45888 * CVE-2026-45891 * CVE-2026-45894 * CVE-2026-45899 * CVE-2026-45901 * CVE-2026-45912 * CVE-2026-45920 * CVE-2026-45922 * CVE-2026-45933 * CVE-2026-45940 * CVE-2026-45948 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45985 * CVE-2026-45997 * CVE-2026-45999 * CVE-2026-46005 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46078 * CVE-2026-46079 * CVE-2026-46091 * CVE-2026-46093 * CVE-2026-46099 * CVE-2026-46101 * CVE-2026-46111 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46124 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46161 * CVE-2026-46162 * CVE-2026-46172 * CVE-2026-46173 * CVE-2026-46178 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46227 * CVE-2026-46242 * CVE-2026-46244 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46259 * CVE-2026-46266 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46314 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46322 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52919 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52955 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52975 * CVE-2026-52980 * CVE-2026-52993 * CVE-2026-53015 * CVE-2026-53021 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53053 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53081 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53103 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53139 * CVE-2026-53156 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53194 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53249 * CVE-2026-53258 * CVE-2026-53262 * CVE-2026-53263 * CVE-2026-53266 * CVE-2026-53272 * CVE-2026-53274 * CVE-2026-53281 * CVE-2026-53285 * CVE-2026-53286 * CVE-2026-53287 * CVE-2026-53306 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-39894 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-39894 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23248 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23394 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23394 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31479 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31479 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31560 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31580 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31646 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31646 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31646 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31647 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31743 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31743 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43016 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43090 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43090 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43094 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43130 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43130 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43132 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43145 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43145 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43145 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43175 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43213 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43260 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43283 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43283 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43298 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43298 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43298 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43374 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43384 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43384 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-43384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43403 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43403 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43415 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43415 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43415 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43457 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43457 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43458 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43458 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43471 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45837 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45837 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45837 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45861 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45861 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45884 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45884 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45884 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45888 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45888 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45888 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45901 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45901 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45901 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45922 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45922 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45922 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45999 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45999 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46078 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46078 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46093 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52919 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52962 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52980 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52980 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53015 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53103 ( SUSE ): 5.9 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53103 ( SUSE ): 4.8 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53103 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53156 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53156 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53194 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53194 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53194 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53262 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53262 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53263 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53272 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53272 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53272 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53286 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves 255 vulnerabilities, contains four features and has 30 fixes can now be installed. ## Description: The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-10263: arm64: cputype: Add C1-Premium definitions (bsc#1266290). * CVE-2025-39894: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm (bsc#1262430). * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2026-23248: perf: Make perf_pmu_unregister() useable (bsc#1259800). * CVE-2026-23394: Revert: "af_unix: Remove lock dance in unix_peek_fds()." (bsc#1260565). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31438: netfs: Fix kernel BUG in netfs_limit_iter() for ITER_KVEC iterators (bsc#1267824). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). * CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31646: net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() (bsc#1263796). * CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578). * CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31743: nvmem: zynqmp_nvmem: Fix buffer size in DMA and memcpy (bsc#1264067). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43014,CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal (bsc#1264010 bsc#1264012). * CVE-2026-43016: bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready() (bsc#1264007). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084). * CVE-2026-43057: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback (bsc#1264056). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43090: xfrm: fix refcount leak in xfrm_migrate_policy_find (bsc#1264250). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43130: iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode (bsc#1264532). * CVE-2026-43132: dm-verity: correctly handle dm_bufio_client_create() failure (bsc#1264614). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43145: remoteproc: imx_rproc: Fix invalid loaded resource table detection (bsc#1265091). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43161: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode (bsc#1264333). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549). * CVE-2026-43175: clk: rs9: Reserve 8 struct clk_hw slots for for 9FGV0841 (bsc#1264372). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43213: wifi: rtw89: pci: validate sequence number of TX release report (bsc#1264643). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429). * CVE-2026-43283: net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle (bsc#1264295). * CVE-2026-43298: drm/amdgpu: Skip vcn poison irq release on VF (bsc#1264852). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43351: KVM: arm64: gic: Set vgic_model before initing private IRQs (bsc#1265082). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43374: net: nexthop: fix percpu use-after-free in remove_nh_grp_entry (bsc#1265084). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43384: net/tcp-ao: Fix MAC comparison to be constant-time (bsc#1265097). * CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (bsc#1264740). * CVE-2026-43403: nsfs: tighten permission checks for ns iteration ioctls (bsc#1265129). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43415: scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend (bsc#1265123). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43457: mctp: i2c: fix skb memory leak in receive path (bsc#1265000). * CVE-2026-43458: serial: caif: hold tty->link reference in ldisc_open and ser_release (bsc#1265005). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43471: scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_trace() (bsc#1264789). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45837: Require (reasonably) normal mappings for MADV_DOFORK (bsc#1266398). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 (bsc#1266773). * CVE-2026-45861: gfs2: Fix slab-use-after-free in qd_put (bsc#1266754). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45884: apparmor: avoid per-cpu hold underflow in aa_get_buffer (bsc#1266718). * CVE-2026-45888: md/raid1: fix memory leak in raid1_run() (bsc#1266761). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45901: netfilter: nf_tables: revert commit_mutex usage in reset path (bsc#1266892). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805). * CVE-2026-45933: bpf: Preserve id of register in sync_linked_regs() (bsc#1266693). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-45999: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (bsc#1266750). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents (bsc#1267505). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46093: mm/vmalloc: take vmap_purge_lock in shrinker (bsc#1267548). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: printk: add print_hex_dump_devel() (bsc#1267937). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52919: batman-adv: fix tp_meter counter underflow during shutdown (bsc#1269031). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52975: bonding: 3ad: implement proper RCU rules for port->aggregator (bsc#1269234). * CVE-2026-52980: sched/fair: Clear rel_deadline when initializing forked entities (bsc#1269252). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53015: erofs: unify lcn as u64 for 32-bit platforms (bsc#1269087). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53081: bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars (bsc#1269708). * CVE-2026-53086: net: bcmgenet: move DESC_INDEX flow to ring 0 (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53103: wifi: mt76: mt7925: fix potential deadlock in mt7925_roc_abort_sync (bsc#1269416). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53156: nvmem: core: fix use-after-free bugs in error paths (bsc#1269288). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000). * CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression (bsc#1269647). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress (bsc#1269809). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53286: idpf: fix double free and use-after-free in aux device error paths (bsc#1269531). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). The following non security issues were fixed: * accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: scarlett2: Allow flash writes ending at segment boundary (git-fixes). * ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes (stable- fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: timer: Forcibly close timer instances at closing (git-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: virtio: Validate control metadata from the device (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64 (bsc#1267600). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: amd: acp-sdw-sof: Bound DAI link iteration (git-fixes). * ASoC: codecs: aw88261: fix incorrect masks for boost regs (git-fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git- fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). * ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_core: Fix UAF in hci_unregister_dev() (git-fixes). * Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non- serdev device (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls (git- fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: ISO: Fix not using bc_sid as advertisement SID (stable-fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * Bluetooth: sco: Fix a race condition in sco_sock_timeout() (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * bpf: Free reuseport cBPF prog after RCU grace period (git-fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * crypto/hmac: reject keys shorter than 128 bits in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow ffdhe2048 in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow plain ecb() usage in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow sha224 + sha3-224 in fips mode (bsc#1266284 jsc#PED-15986). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) (git-fixes). * crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) (git-fixes). * crypto: ccp - Do not initialize SNP for SEV ioctls (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * crypto: tegra - Fix dma_free_coherent size error (git-fixes). * crypto: tegra - fix refcount leak in tegra_se_host1x_submit() (git-fixes). * crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm (git-fixes). * dm init: ensure device probing has finished in dm-mod.waitfor= (git-fixes). * dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc (git-fixes). * dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). * drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). * drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git- fixes). * drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: always resume_all after suspend_all (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/gpuvm: Do not prepare NULL objects (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). * drm/imagination: Count paired job fence as dependency in prepare_job() (git- fixes). * drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/rockchip: Test for imported buffers with drm_gem_is_imported() (git- fixes). * drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). * drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * ftrace: Check against is_kernel_text() instead of kaslr_offset() (bsc#1267600). * ftrace: Do not over-allocate ftrace memory (bsc#1267600). * ftrace: Have ftrace pages output reflect freed pages (bsc#1267600). * ftrace: Test mcount_loc addr before calling ftrace_call_addr() (bsc#1267600). * ftrace: Update the mcount_loc check of skipped entries (bsc#1267600). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpio: mxc: fix irq_high handling (git-fixes). * gpio: rockchip: convert bank->clk to devm_clk_get_enabled() (git-fixes). * gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write() (git-fixes). * gpio: zynq: fix runtime PM leak on remove (git-fixes). * gpiolib: Extract gpiochip_choose_fwnode() for wider use (stable-fixes). * gpiolib: Remove redundant assignment of return variable (stable-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * HID: core: Add printk_ratelimited variants to hid_warn() etc (stable-fixes). * HID: hid-goodix-spi: validate report size to prevent stack buffer overflow (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: rate-limit hid_warn to prevent log flooding (stable-fixes). * HID: remove duplicate hid_warn_ratelimited definition (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hv: utils: replace deprecated strcpy with strscpy in kvp_register (git- fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (git-fixes). * hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (max1619) add missing 'select REGMAP' to Kconfig (git-fixes). * hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: disable runtime PM on adapter registration failure (git-fixes). * i2c: core: fix adapter debugfs creation (git-fixes). * i2c: core: fix adapter deregistration race (git-fixes). * i2c: core: fix adapter probe deferral loop (git-fixes). * i2c: core: fix adapter registration race (git-fixes). * i2c: core: fix hang on adapter registration failure (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: core: fix NULL-deref on adapter registration failure (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: imx-lpi2c: mark I2C adapter when hardware is powered down (git-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: riic: fix refcount leak in riic_i2c_resume_noirq() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock (git- fixes). * ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: ti-ads1298: add bounds check to pga_settings index (stable-fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: backend: fix uninitialized data in debugfs (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: light: veml6075: add bounds check to veml6075_it_ms index (stable- fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: resolver: ad2s1210: notify trigger and clear state on fault read error (git-fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * io_uring/cancel: de-unionize file and user_data in struct io_cancel_data (git-fixes bsc#1261250). * io_uring/filetable: clamp alloc_hint to the configured alloc range (git- fixes bsc#1261250). * io_uring/io-wq: fix incorrect io_wq_for_each_worker() termination logic (git-fixes bsc#1261250). * io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git- fixes bsc#1261250). * io_uring/wait: fix min_timeout behavior (git-fixes bsc#1261250). * io_uring/waitid: clear waitid info before copying it to userspace (git- fixes). * io_uring: fix min_wait wakeups for SQPOLL (git-fixes bsc#1261250). * ipv4: account for fraggap on the paged allocation path (git-fixes). * ipv6: account for fraggap on the paged allocation path (git-fixes). * KEYS: fix overflow in keyctl_pkey_params_get_2() (git-fixes). * KEYS: Use acquire when reading state in keyring search (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: vgic: Free private_irqs when init fails after allocation (git- fixes). * KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (git-fixes). * KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (git- fixes). * KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2 (git-fixes). * KVM: nVMX: Immediately refresh APICv controls as needed on nested VM-Exit (git-fixes). * KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (git-fixes). * KVM: SEV: Add an anonymous "psc" struct to track current PSC metadata (git- fixes). * KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA (git-fixes). * KVM: SEV: Don't terminate SNP VMs on #VMGEXIT without a registered GHCB (git-fixes). * KVM: SEV: Make it more obvious when KVM is writing back the current PSC index (git-fixes). * KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() (git-fixes). * KVM: SEV: Read start/end indices of PSC requests exactly once per #VMGEXIT (git-fixes). * KVM: SEV: Return INVALID_EVENT for SNP-only #VMGEXIT from non-SNP guest (git-fixes). * KVM: SEV: Return INVALID_INPUT, not MISSING_INPUT, for bad GUEST_REQUEST input(s) (git-fixes). * KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: Use vCPU specific memslots in __kvm_vcpu_map() (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: VMX: Read 32-bit GPR values for ENCLS instructions outside of 64-bit mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86/xen: Bug the VM if 32-bit KVM observes a 64-bit mode hypercall (git-fixes). * KVM: x86/xen: Don't truncate RAX when handling hypercall from protected guest (git-fixes). * KVM: x86: Consolidate CPUID fault handling for emulator and interception logic (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Prioritize CPUID faulting over CPUID VM-exits in nested VMX (git- fixes). * KVM: x86: Trace hypercall register _after_ truncating values for 32-bit (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() (git-fixes). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: Pause continuous reads at block boundaries (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program (stable-fixes). * mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g (stable-fixes). * mtd: spi-nor: spansion: use die erase for multi-die devices only (git- fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Cache MANA_QUERY_LINK_CONFIG result to avoid repeated HWC queries (bsc#1268238). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Sync page pool RX frags for CPU (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * packaging: Add nvidia kernel description. * packaging: compute-PATCHVERSION.sh -> compute-PATCHVERSION. * page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562). * page_pool: Move pp_magic check into helper functions (bsc#1261562). * page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). * PCI: Update saved_config_space upon resource assignment (git-fixes). * perf/x86/intel/uncore: Fix die ID init and look up bugs (bsc#1267419). * perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1267419). * platform/x86: dell-laptop: fix missing cleanups in init error path (git- fixes). * platform/x86: intel-hid: Protect ACPI notify handler against recursion (git- fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git- fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * pwm: imx27: Fix variable truncation in .apply() (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (git- fixes). * Revert "fs: don't block i_writecount during exec" (bsc#1269982). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scripts/sorttable: Add helper functions for Elf_Ehdr (bsc#1267600). * scripts/sorttable: Add helper functions for Elf_Shdr (bsc#1267600). * scripts/sorttable: Add helper functions for Elf_Sym (bsc#1267600). * scripts/sorttable: Allow matches to functions before function entry (bsc#1267600). * scripts/sorttable: Always use an array for the mcount_loc sorting (bsc#1267600). * scripts/sorttable: Convert Elf_Ehdr to union (bsc#1267600). * scripts/sorttable: Convert Elf_Sym MACRO over to a union (bsc#1267600). * scripts/sorttable: Fix endianness handling in build-time mcount sort (bsc#1267600). * scripts/sorttable: Get start/stop_mcount_loc from ELF file directly (bsc#1267600). * scripts/sorttable: Have mcount rela sort use direct values (bsc#1267600). * scripts/sorttable: Have the ORC code use the _r() functions to read (bsc#1267600). * scripts/sorttable: Make compare_extable() into two functions (bsc#1267600). * scripts/sorttable: Move code from sorttable.h into sorttable.c (bsc#1267600). * scripts/sorttable: Remove unneeded Elf_Rel (bsc#1267600). * scripts/sorttable: Remove unused macro defines (bsc#1267600). * scripts/sorttable: Remove unused write functions (bsc#1267600). * scripts/sorttable: Replace Elf_Shdr Macro with a union (bsc#1267600). * scripts/sorttable: Use a structure of function pointers for elf helpers (bsc#1267600). * scripts/sorttable: Use normal sort if theres no relocs in the mcount section (bsc#1267600). * scripts/sorttable: Use uint64_t for mcount sorting (bsc#1267600). * scripts/sorttable: Zero out weak functions in mcount_loc table (bsc#1267600). * scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (bsc#1257506). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * selftests/bpf: Add BPF_STRICT_BUILD toggle (poo#202224). * selftests/bpf: Allow test_progs to link with a partial object set (poo#202224). * selftests/bpf: Avoid rebuilds when running emit_tests (poo#202224). * selftests/bpf: Consolidate kernel modules into common directory (poo#202224). * selftests/bpf: Copy test_kmods when installing selftest (poo#202224). * selftests/bpf: Fix runqslower cross-endian build (poo#202224). * selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (poo#202224). * selftests/bpf: make BPF_TARGET_ENDIAN non-recursive to speed up *.bpf.o build (poo#202224). * selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (poo#202224). * selftests/bpf: Provide weak definitions for cross-test functions (poo#202224). * selftests/bpf: Skip tests whose objects were not built (poo#202224). * selftests/bpf: Support cross-endian building (poo#202224). * selftests/bpf: Tolerate benchmark build failures (poo#202224). * selftests/bpf: Tolerate BPF and skeleton generation failures (poo#202224). * selftests/bpf: Tolerate missing files during install (poo#202224). * selftests/bpf: Tolerate test file compilation failures (poo#202224). * serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git- fixes). * serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git- fixes). * serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero (git- fixes). * slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (git-fixes). * slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (git-fixes). * slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * slimbus: qcom-ngd-ctrl: Fix probe error path ordering (git-fixes). * slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (git-fixes). * slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (git- fixes). * slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (git- fixes). * soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() (git-fixes). * soc: qcom: ice: Return -ENODEV if the ICE platform device is not found (git- fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: hisi-kunpeng: Use dev_err_probe() for host registration failure (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * thermal: testing: reject missing command arguments (git-fixes). * thermal: testing: zone: Flush work items during cleanup (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: debugfs: Don't stop reading SB registers if just one fails (git-fixes). * thunderbolt: debugfs: Fix margining error counter buffer leak (git-fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * tools/power/x86/intel-speed-select: Harden daemon pidfile open (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt (git-fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (git-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (stable-fixes). * usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 (git- fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). * wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes). * wifi: mt76: mt7921: fix a potential scan no APs (stable-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer (git- fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links (git- fixes). * wifi: mt76: mt7925: keep TX BA state in the primary WCID (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * x86/cpu/amd: Correct the microcode table for Zenbleed (git-fixes). * x86/cpu: Disable FRED when PTI is forced on (git-fixes). * x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63 (git-fixes). * x86/cpu: Validate CPUID leaf 0x2 EDX output (git-fixes). * x86/irq: Ensure initial PIR loads are performed exactly once (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16390). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16390). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1295=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * kernel-syms-6.12.0-160000.36.1 * kernel-obs-build-debugsource-6.12.0-160000.36.1 * kernel-obs-build-6.12.0-160000.36.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-39894.html * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2026-23248.html * https://www.suse.com/security/cve/CVE-2026-23394.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31438.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31479.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31560.html * https://www.suse.com/security/cve/CVE-2026-31580.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31646.html * https://www.suse.com/security/cve/CVE-2026-31647.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31743.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43014.html * https://www.suse.com/security/cve/CVE-2026-43015.html * https://www.suse.com/security/cve/CVE-2026-43016.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43090.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43094.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43130.html * https://www.suse.com/security/cve/CVE-2026-43132.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43145.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43161.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43175.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43213.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43260.html * https://www.suse.com/security/cve/CVE-2026-43283.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43298.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43337.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43351.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43374.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43384.html * https://www.suse.com/security/cve/CVE-2026-43386.html * https://www.suse.com/security/cve/CVE-2026-43403.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43415.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43457.html * https://www.suse.com/security/cve/CVE-2026-43458.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43471.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45837.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45861.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45884.html * https://www.suse.com/security/cve/CVE-2026-45888.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45901.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45922.html * https://www.suse.com/security/cve/CVE-2026-45933.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-45999.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46078.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46093.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46162.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52919.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52980.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53015.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53081.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53103.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53156.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53194.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53262.html * https://www.suse.com/security/cve/CVE-2026-53263.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53272.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53286.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1149651 * https://bugzilla.suse.com/show_bug.cgi?id=1204315 * https://bugzilla.suse.com/show_bug.cgi?id=1236743 * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1257506 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1259800 * https://bugzilla.suse.com/show_bug.cgi?id=1260565 * https://bugzilla.suse.com/show_bug.cgi?id=1261250 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262430 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262765 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1263057 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263169 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263581 * https://bugzilla.suse.com/show_bug.cgi?id=1263796 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264007 * https://bugzilla.suse.com/show_bug.cgi?id=1264010 * https://bugzilla.suse.com/show_bug.cgi?id=1264012 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264067 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264231 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264250 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264295 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264333 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264372 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264429 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264532 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264614 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264643 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264740 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264789 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264852 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265000 * https://bugzilla.suse.com/show_bug.cgi?id=1265005 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265082 * https://bugzilla.suse.com/show_bug.cgi?id=1265084 * https://bugzilla.suse.com/show_bug.cgi?id=1265091 * https://bugzilla.suse.com/show_bug.cgi?id=1265097 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265112 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265123 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265129 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266283 * https://bugzilla.suse.com/show_bug.cgi?id=1266284 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266398 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266693 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266718 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266750 * https://bugzilla.suse.com/show_bug.cgi?id=1266754 * https://bugzilla.suse.com/show_bug.cgi?id=1266761 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266805 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266840 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266892 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266925 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267419 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267505 * https://bugzilla.suse.com/show_bug.cgi?id=1267548 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267600 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1267816 * https://bugzilla.suse.com/show_bug.cgi?id=1267824 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268238 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269031 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269087 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269199 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269252 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269288 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269416 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269531 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269617 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269647 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269708 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269809 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269904 * https://bugzilla.suse.com/show_bug.cgi?id=1269982 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1270000 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270042 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://jira.suse.com/browse/PED-10906 * https://jira.suse.com/browse/PED-15986 * https://jira.suse.com/browse/PED-16390 * https://jira.suse.com/browse/SLE-8615 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:54:20 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:54:20 -0000 Subject: SUSE-RU-2026:22741-1: moderate: Recommended update for python-kiwi Message-ID: <178475366057.245.27942945291780615@c3e054a4ce29> # Recommended update for python-kiwi Announcement ID: SUSE-RU-2026:22741-1 Release Date: 2026-07-18T13:40:00Z Rating: moderate References: * bsc#1263564 Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that has one fix can now be installed. ## Description: This update for python-kiwi fixes the following issues: * Fix reading of runtime config files: * Make sure the reading of the runtime config files in the different locations is not an exclusive procedure. * Add support for sha512sum: * Allow to select between the default shasum size 256 and 512 via a new runtime config section named: shasum. * Fix system resize: * The filesystem check is not applied for btrfs prior resize. * Fix qemu-xxx requirement: * Do not require qemu variant packages for 32bit architectures. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1286=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * kiwi-systemdeps-core-10.2.33-160000.4.1 * python3-kiwi-10.2.33-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1263564 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:54:28 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:54:28 -0000 Subject: SUSE-SU-2026:22740-1: important: Security update for vim Message-ID: <178475366844.245.11263745706140958791@c3e054a4ce29> # Security update for vim Announcement ID: SUSE-SU-2026:22740-1 Release Date: 2026-07-18T11:52:07Z Rating: important References: * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for vim fixes the following issues: Update to version 9.2.0780. Security issues fixed: * CVE-2026-59856: arbitrary code execution via PHP omni-completion due to improper escaping (bsc#1271194). * CVE-2026-59857: out-of-bounds write in SAL soundfolding due to improper bounds check (bsc#1271195). * CVE-2026-59858: arbitrary code execution via C omni-completion due to improper escaping (bsc#1271193). Other updates and bugfixes: * Version 9.2.0780 changelog: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * tests: test_popupwin fails with zsh because of the prompt (9.2.0757). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * tests: style issue in test_plugin_netrw (9.2.0763). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1283=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * xxd-debuginfo-9.2.0780-160000.1.1 * vim-9.2.0780-160000.1.1 * vim-debuginfo-9.2.0780-160000.1.1 * xxd-9.2.0780-160000.1.1 * vim-debugsource-9.2.0780-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:54:33 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:54:33 -0000 Subject: SUSE-SU-2026:22739-1: moderate: Security update for nmap Message-ID: <178475367382.245.10789990075082870820@c3e054a4ce29> # Security update for nmap Announcement ID: SUSE-SU-2026:22739-1 Release Date: 2026-07-15T12:11:26Z Rating: moderate References: * bsc#1269570 Cross-References: * CVE-2026-58058 CVSS scores: * CVE-2026-58058 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58058 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58058 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for nmap fixes the following issue * CVE-2026-58058: crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash (bsc#1269570). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1267=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * nmap-debuginfo-7.92-160000.3.1 * nmap-7.92-160000.3.1 * nmap-debugsource-7.92-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58058.html * https://bugzilla.suse.com/show_bug.cgi?id=1269570 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:54:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:54:42 -0000 Subject: SUSE-RU-2026:22738-1: moderate: Recommended update for polkit-default-privs Message-ID: <178475368228.245.15238496175327744171@c3e054a4ce29> # Recommended update for polkit-default-privs Announcement ID: SUSE-RU-2026:22738-1 Release Date: 2026-07-15T08:56:19Z Rating: moderate References: * bsc#1235659 * bsc#1253111 * bsc#1267014 Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that has three fixes can now be installed. ## Description: This update for polkit-default-privs fixes the following issues: Changes in polkit-default-privs: Update to version 1550+20260709.b1b58aa: * profiles: fwupd new actions in 2.1.4 (bsc#1267014) * profiles: fwupd (bsc#1253111) * profiles: add left out emulation-load action for fwupd (bsc#1235659) * profiles: whitelist fwupd 2.0 major update actions (bsc#1235659) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1265=1 ## Package List: * SUSE Linux Micro Extras 6.2 (noarch) * polkit-default-privs-1550+20260709.b1b58aa-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1235659 * https://bugzilla.suse.com/show_bug.cgi?id=1253111 * https://bugzilla.suse.com/show_bug.cgi?id=1267014 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:54:47 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:54:47 -0000 Subject: SUSE-SU-2026:3198-1: important: Security update for terraform-provider-susepubliccloud Message-ID: <178475368761.245.10492677573417690749@c3e054a4ce29> # Security update for terraform-provider-susepubliccloud Announcement ID: SUSE-SU-2026:3198-1 Release Date: 2026-07-22T14:37:54Z Rating: important References: * bsc#1266477 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for terraform-provider-susepubliccloud fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266477). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3198=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3198=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-susepubliccloud-0.0.1-150100.3.17.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-susepubliccloud-0.0.1-150100.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266477 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:54:58 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:54:58 -0000 Subject: SUSE-SU-2026:3197-1: important: Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Message-ID: <178475369892.245.9059410633118859497@c3e054a4ce29> # Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Announcement ID: SUSE-SU-2026:3197-1 Release Date: 2026-07-22T14:37:32Z Rating: important References: * bsc#1266477 * bsc#1266482 * bsc#1266541 * bsc#1266547 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability and has three security fixes can now be installed. ## Description: This update for terraform-provider-aws, terraform-provider-azurerm, terraform- provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider- null, terraform-provider-random, terraform-provider-tls fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266477 bsc#1266482 bsc#1266541 bsc#1266547). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3197=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3197=1 ## Package List: * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-local-2.0.0-150200.6.20.1 * terraform-provider-null-3.0.0-150200.6.21.1 * terraform-provider-tls-3.0.0-150200.5.18.1 * terraform-provider-google-3.43.0-150200.6.15.1 * terraform-provider-random-3.0.0-150200.6.18.1 * terraform-provider-kubernetes-1.13.2-150200.6.15.1 * terraform-provider-external-2.0.0-150200.6.15.1 * terraform-provider-helm-2.9.0-150200.6.26.1 * terraform-provider-aws-3.11.0-150200.6.21.1 * terraform-provider-azurerm-2.32.0-150200.6.15.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.21.1 * terraform-provider-tls-3.0.0-150200.5.18.1 * terraform-provider-google-3.43.0-150200.6.15.1 * terraform-provider-random-3.0.0-150200.6.18.1 * terraform-provider-kubernetes-1.13.2-150200.6.15.1 * terraform-provider-helm-2.9.0-150200.6.26.1 * terraform-provider-external-2.0.0-150200.6.15.1 * terraform-provider-local-2.0.0-150200.6.20.1 * terraform-provider-aws-3.11.0-150200.6.21.1 * terraform-provider-azurerm-2.32.0-150200.6.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266477 * https://bugzilla.suse.com/show_bug.cgi?id=1266482 * https://bugzilla.suse.com/show_bug.cgi?id=1266541 * https://bugzilla.suse.com/show_bug.cgi?id=1266547 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:55:06 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:55:06 -0000 Subject: SUSE-SU-2026:3196-1: important: Security update for joe Message-ID: <178475370633.245.434465953139127384@c3e054a4ce29> # Security update for joe Announcement ID: SUSE-SU-2026:3196-1 Release Date: 2026-07-22T14:34:50Z Rating: important References: * bsc#1269379 Cross-References: * CVE-2026-13412 CVSS scores: * CVE-2026-13412 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-13412 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for joe fixes the following issue * CVE-2026-13412: arbitrary command execution via malicious tags file (bsc#1269379). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3196=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3196=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * joe-debugsource-3.7-30.3.1 * joe-3.7-30.3.1 * joe-debuginfo-3.7-30.3.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * joe-debugsource-3.7-30.3.1 * joe-3.7-30.3.1 * joe-debuginfo-3.7-30.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13412.html * https://bugzilla.suse.com/show_bug.cgi?id=1269379 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:55:14 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:55:14 -0000 Subject: SUSE-SU-2026:3195-1: important: Security update for sssd Message-ID: <178475371449.245.6589796321890046039@c3e054a4ce29> # Security update for sssd Announcement ID: SUSE-SU-2026:3195-1 Release Date: 2026-07-22T14:30:59Z Rating: important References: * bsc#1246196 * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3195=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3195=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3195=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3195=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3195=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3195=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * sssd-ipa-debuginfo-2.5.2-150500.10.44.1 * sssd-proxy-debuginfo-2.5.2-150500.10.44.1 * sssd-common-2.5.2-150500.10.44.1 * sssd-winbind-idmap-2.5.2-150500.10.44.1 * sssd-kcm-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-2.5.2-150500.10.44.1 * sssd-ldap-2.5.2-150500.10.44.1 * python3-sssd-config-debuginfo-2.5.2-150500.10.44.1 * libsss_certmap0-debuginfo-2.5.2-150500.10.44.1 * sssd-2.5.2-150500.10.44.1 * sssd-ad-2.5.2-150500.10.44.1 * python3-sss_nss_idmap-2.5.2-150500.10.44.1 * libsss_simpleifp0-2.5.2-150500.10.44.1 * sssd-tools-2.5.2-150500.10.44.1 * sssd-krb5-debuginfo-2.5.2-150500.10.44.1 * sssd-dbus-debuginfo-2.5.2-150500.10.44.1 * libsss_simpleifp0-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-debuginfo-2.5.2-150500.10.44.1 * libnfsidmap-sss-debuginfo-2.5.2-150500.10.44.1 * sssd-tools-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap0-2.5.2-150500.10.44.1 * libsss_nss_idmap0-debuginfo-2.5.2-150500.10.44.1 * python3-sss_nss_idmap-debuginfo-2.5.2-150500.10.44.1 * libsss_idmap0-2.5.2-150500.10.44.1 * python3-sss-murmur-debuginfo-2.5.2-150500.10.44.1 * libsss_idmap-devel-2.5.2-150500.10.44.1 * sssd-ipa-2.5.2-150500.10.44.1 * python3-ipa_hbac-debuginfo-2.5.2-150500.10.44.1 * sssd-ldap-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap-devel-2.5.2-150500.10.44.1 * python3-sssd-config-2.5.2-150500.10.44.1 * python3-ipa_hbac-2.5.2-150500.10.44.1 * libsss_certmap-devel-2.5.2-150500.10.44.1 * libipa_hbac-devel-2.5.2-150500.10.44.1 * sssd-kcm-2.5.2-150500.10.44.1 * sssd-krb5-2.5.2-150500.10.44.1 * libsss_simpleifp-devel-2.5.2-150500.10.44.1 * libsss_idmap0-debuginfo-2.5.2-150500.10.44.1 * sssd-common-debuginfo-2.5.2-150500.10.44.1 * sssd-winbind-idmap-debuginfo-2.5.2-150500.10.44.1 * libnfsidmap-sss-2.5.2-150500.10.44.1 * sssd-ad-debuginfo-2.5.2-150500.10.44.1 * sssd-krb5-common-debuginfo-2.5.2-150500.10.44.1 * sssd-krb5-common-2.5.2-150500.10.44.1 * sssd-debugsource-2.5.2-150500.10.44.1 * libsss_certmap0-2.5.2-150500.10.44.1 * sssd-proxy-2.5.2-150500.10.44.1 * python3-sss-murmur-2.5.2-150500.10.44.1 * sssd-dbus-2.5.2-150500.10.44.1 * openSUSE Leap 15.5 (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150500.10.44.1 * sssd-common-32bit-2.5.2-150500.10.44.1 * openSUSE Leap 15.5 (aarch64_ilp32) * sssd-common-64bit-2.5.2-150500.10.44.1 * sssd-common-64bit-debuginfo-2.5.2-150500.10.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * sssd-proxy-debuginfo-2.5.2-150500.10.44.1 * sssd-ipa-debuginfo-2.5.2-150500.10.44.1 * sssd-common-2.5.2-150500.10.44.1 * sssd-winbind-idmap-2.5.2-150500.10.44.1 * sssd-kcm-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-2.5.2-150500.10.44.1 * sssd-ldap-2.5.2-150500.10.44.1 * libsss_certmap0-debuginfo-2.5.2-150500.10.44.1 * python3-sssd-config-debuginfo-2.5.2-150500.10.44.1 * sssd-2.5.2-150500.10.44.1 * sssd-ad-2.5.2-150500.10.44.1 * libsss_simpleifp0-2.5.2-150500.10.44.1 * sssd-tools-2.5.2-150500.10.44.1 * sssd-krb5-debuginfo-2.5.2-150500.10.44.1 * sssd-dbus-debuginfo-2.5.2-150500.10.44.1 * libsss_simpleifp0-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-debuginfo-2.5.2-150500.10.44.1 * sssd-tools-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap0-2.5.2-150500.10.44.1 * libsss_nss_idmap0-debuginfo-2.5.2-150500.10.44.1 * libsss_idmap0-2.5.2-150500.10.44.1 * libsss_idmap-devel-2.5.2-150500.10.44.1 * sssd-ipa-2.5.2-150500.10.44.1 * sssd-ldap-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap-devel-2.5.2-150500.10.44.1 * python3-sssd-config-2.5.2-150500.10.44.1 * libsss_certmap-devel-2.5.2-150500.10.44.1 * libipa_hbac-devel-2.5.2-150500.10.44.1 * sssd-kcm-2.5.2-150500.10.44.1 * libsss_simpleifp-devel-2.5.2-150500.10.44.1 * sssd-krb5-2.5.2-150500.10.44.1 * libsss_idmap0-debuginfo-2.5.2-150500.10.44.1 * sssd-common-debuginfo-2.5.2-150500.10.44.1 * sssd-winbind-idmap-debuginfo-2.5.2-150500.10.44.1 * sssd-ad-debuginfo-2.5.2-150500.10.44.1 * sssd-krb5-common-2.5.2-150500.10.44.1 * sssd-krb5-common-debuginfo-2.5.2-150500.10.44.1 * sssd-debugsource-2.5.2-150500.10.44.1 * libsss_certmap0-2.5.2-150500.10.44.1 * sssd-proxy-2.5.2-150500.10.44.1 * sssd-dbus-2.5.2-150500.10.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150500.10.44.1 * sssd-common-32bit-2.5.2-150500.10.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * sssd-ipa-debuginfo-2.5.2-150500.10.44.1 * sssd-proxy-debuginfo-2.5.2-150500.10.44.1 * sssd-common-2.5.2-150500.10.44.1 * sssd-winbind-idmap-2.5.2-150500.10.44.1 * sssd-kcm-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-2.5.2-150500.10.44.1 * sssd-ldap-2.5.2-150500.10.44.1 * libsss_certmap0-debuginfo-2.5.2-150500.10.44.1 * python3-sssd-config-debuginfo-2.5.2-150500.10.44.1 * sssd-2.5.2-150500.10.44.1 * sssd-ad-2.5.2-150500.10.44.1 * libsss_simpleifp0-2.5.2-150500.10.44.1 * sssd-tools-2.5.2-150500.10.44.1 * sssd-krb5-debuginfo-2.5.2-150500.10.44.1 * sssd-dbus-debuginfo-2.5.2-150500.10.44.1 * libsss_simpleifp0-debuginfo-2.5.2-150500.10.44.1 * sssd-tools-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap0-2.5.2-150500.10.44.1 * libsss_nss_idmap0-debuginfo-2.5.2-150500.10.44.1 * libsss_idmap0-2.5.2-150500.10.44.1 * libsss_idmap-devel-2.5.2-150500.10.44.1 * sssd-ipa-2.5.2-150500.10.44.1 * sssd-ldap-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap-devel-2.5.2-150500.10.44.1 * python3-sssd-config-2.5.2-150500.10.44.1 * libsss_simpleifp-devel-2.5.2-150500.10.44.1 * libipa_hbac-devel-2.5.2-150500.10.44.1 * sssd-kcm-2.5.2-150500.10.44.1 * sssd-krb5-2.5.2-150500.10.44.1 * libsss_certmap-devel-2.5.2-150500.10.44.1 * libsss_idmap0-debuginfo-2.5.2-150500.10.44.1 * sssd-common-debuginfo-2.5.2-150500.10.44.1 * sssd-winbind-idmap-debuginfo-2.5.2-150500.10.44.1 * sssd-ad-debuginfo-2.5.2-150500.10.44.1 * sssd-krb5-common-2.5.2-150500.10.44.1 * sssd-krb5-common-debuginfo-2.5.2-150500.10.44.1 * sssd-debugsource-2.5.2-150500.10.44.1 * libsss_certmap0-2.5.2-150500.10.44.1 * sssd-proxy-2.5.2-150500.10.44.1 * sssd-dbus-2.5.2-150500.10.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150500.10.44.1 * sssd-common-32bit-2.5.2-150500.10.44.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * sssd-common-2.5.2-150500.10.44.1 * sssd-ldap-2.5.2-150500.10.44.1 * libsss_certmap0-debuginfo-2.5.2-150500.10.44.1 * sssd-2.5.2-150500.10.44.1 * sssd-ad-2.5.2-150500.10.44.1 * sssd-tools-2.5.2-150500.10.44.1 * sssd-krb5-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap0-2.5.2-150500.10.44.1 * libsss_nss_idmap0-debuginfo-2.5.2-150500.10.44.1 * libsss_idmap0-2.5.2-150500.10.44.1 * sssd-ldap-debuginfo-2.5.2-150500.10.44.1 * python3-sssd-config-2.5.2-150500.10.44.1 * sssd-krb5-2.5.2-150500.10.44.1 * libsss_idmap0-debuginfo-2.5.2-150500.10.44.1 * sssd-common-debuginfo-2.5.2-150500.10.44.1 * sssd-ad-debuginfo-2.5.2-150500.10.44.1 * sssd-krb5-common-2.5.2-150500.10.44.1 * sssd-krb5-common-debuginfo-2.5.2-150500.10.44.1 * sssd-debugsource-2.5.2-150500.10.44.1 * libsss_certmap0-2.5.2-150500.10.44.1 * sssd-dbus-2.5.2-150500.10.44.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * sssd-ipa-debuginfo-2.5.2-150500.10.44.1 * sssd-proxy-debuginfo-2.5.2-150500.10.44.1 * sssd-common-2.5.2-150500.10.44.1 * sssd-winbind-idmap-2.5.2-150500.10.44.1 * sssd-kcm-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-2.5.2-150500.10.44.1 * sssd-ldap-2.5.2-150500.10.44.1 * libsss_certmap0-debuginfo-2.5.2-150500.10.44.1 * python3-sssd-config-debuginfo-2.5.2-150500.10.44.1 * sssd-2.5.2-150500.10.44.1 * sssd-ad-2.5.2-150500.10.44.1 * libsss_simpleifp0-2.5.2-150500.10.44.1 * sssd-tools-2.5.2-150500.10.44.1 * sssd-krb5-debuginfo-2.5.2-150500.10.44.1 * sssd-dbus-debuginfo-2.5.2-150500.10.44.1 * libsss_simpleifp0-debuginfo-2.5.2-150500.10.44.1 * sssd-tools-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap0-2.5.2-150500.10.44.1 * libsss_nss_idmap0-debuginfo-2.5.2-150500.10.44.1 * libsss_idmap0-2.5.2-150500.10.44.1 * libsss_idmap-devel-2.5.2-150500.10.44.1 * sssd-ipa-2.5.2-150500.10.44.1 * sssd-ldap-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap-devel-2.5.2-150500.10.44.1 * python3-sssd-config-2.5.2-150500.10.44.1 * libsss_certmap-devel-2.5.2-150500.10.44.1 * libipa_hbac-devel-2.5.2-150500.10.44.1 * sssd-kcm-2.5.2-150500.10.44.1 * sssd-krb5-2.5.2-150500.10.44.1 * libsss_simpleifp-devel-2.5.2-150500.10.44.1 * libsss_idmap0-debuginfo-2.5.2-150500.10.44.1 * sssd-common-debuginfo-2.5.2-150500.10.44.1 * sssd-winbind-idmap-debuginfo-2.5.2-150500.10.44.1 * sssd-ad-debuginfo-2.5.2-150500.10.44.1 * sssd-krb5-common-2.5.2-150500.10.44.1 * sssd-krb5-common-debuginfo-2.5.2-150500.10.44.1 * sssd-debugsource-2.5.2-150500.10.44.1 * libsss_certmap0-2.5.2-150500.10.44.1 * sssd-proxy-2.5.2-150500.10.44.1 * sssd-dbus-2.5.2-150500.10.44.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150500.10.44.1 * sssd-common-32bit-2.5.2-150500.10.44.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * sssd-ipa-debuginfo-2.5.2-150500.10.44.1 * sssd-proxy-debuginfo-2.5.2-150500.10.44.1 * sssd-common-2.5.2-150500.10.44.1 * sssd-winbind-idmap-2.5.2-150500.10.44.1 * sssd-kcm-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-2.5.2-150500.10.44.1 * sssd-ldap-2.5.2-150500.10.44.1 * libsss_certmap0-debuginfo-2.5.2-150500.10.44.1 * python3-sssd-config-debuginfo-2.5.2-150500.10.44.1 * sssd-2.5.2-150500.10.44.1 * sssd-ad-2.5.2-150500.10.44.1 * libsss_simpleifp0-2.5.2-150500.10.44.1 * sssd-tools-2.5.2-150500.10.44.1 * sssd-krb5-debuginfo-2.5.2-150500.10.44.1 * sssd-dbus-debuginfo-2.5.2-150500.10.44.1 * libsss_simpleifp0-debuginfo-2.5.2-150500.10.44.1 * libipa_hbac0-debuginfo-2.5.2-150500.10.44.1 * sssd-tools-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap0-2.5.2-150500.10.44.1 * libsss_nss_idmap0-debuginfo-2.5.2-150500.10.44.1 * libsss_idmap0-2.5.2-150500.10.44.1 * libsss_idmap-devel-2.5.2-150500.10.44.1 * sssd-ipa-2.5.2-150500.10.44.1 * sssd-ldap-debuginfo-2.5.2-150500.10.44.1 * libsss_nss_idmap-devel-2.5.2-150500.10.44.1 * python3-sssd-config-2.5.2-150500.10.44.1 * libsss_simpleifp-devel-2.5.2-150500.10.44.1 * libsss_certmap-devel-2.5.2-150500.10.44.1 * sssd-kcm-2.5.2-150500.10.44.1 * libipa_hbac-devel-2.5.2-150500.10.44.1 * sssd-krb5-2.5.2-150500.10.44.1 * libsss_idmap0-debuginfo-2.5.2-150500.10.44.1 * sssd-common-debuginfo-2.5.2-150500.10.44.1 * sssd-winbind-idmap-debuginfo-2.5.2-150500.10.44.1 * sssd-ad-debuginfo-2.5.2-150500.10.44.1 * sssd-krb5-common-2.5.2-150500.10.44.1 * sssd-krb5-common-debuginfo-2.5.2-150500.10.44.1 * sssd-debugsource-2.5.2-150500.10.44.1 * libsss_certmap0-2.5.2-150500.10.44.1 * sssd-proxy-2.5.2-150500.10.44.1 * sssd-dbus-2.5.2-150500.10.44.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150500.10.44.1 * sssd-common-32bit-2.5.2-150500.10.44.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1246196 * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:55:54 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:55:54 -0000 Subject: SUSE-SU-2026:3194-1: moderate: Security update for ImageMagick Message-ID: <178475375446.245.834282717895469216@c3e054a4ce29> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3194-1 Release Date: 2026-07-22T14:28:17Z Rating: moderate References: * bsc#1268640 * bsc#1270006 * bsc#1270081 * bsc#1271100 * bsc#1271293 * bsc#1271294 * bsc#1271311 * bsc#1271312 * bsc#1271313 * bsc#1271314 * bsc#1271315 * bsc#1271316 * bsc#1271484 * bsc#1271485 * bsc#1271486 * bsc#1271487 * bsc#1271488 * bsc#1271489 * bsc#1271490 * bsc#1271491 * bsc#1271492 * bsc#1271493 * bsc#1271494 * bsc#1271495 * bsc#1271496 * bsc#1271497 Cross-References: * CVE-2026-55628 * CVE-2026-56362 * CVE-2026-56366 * CVE-2026-56372 * CVE-2026-56373 * CVE-2026-56375 * CVE-2026-56377 * CVE-2026-61464 * CVE-2026-61465 * CVE-2026-61857 * CVE-2026-61858 * CVE-2026-61859 * CVE-2026-61860 * CVE-2026-61861 * CVE-2026-61862 * CVE-2026-61863 * CVE-2026-61864 * CVE-2026-61865 * CVE-2026-61866 * CVE-2026-61867 * CVE-2026-61868 * CVE-2026-61869 * CVE-2026-61870 * CVE-2026-61871 * CVE-2026-61872 CVSS scores: * CVE-2026-55628 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55628 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56362 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56362 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56362 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56366 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56366 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56366 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56366 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56366 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56372 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56372 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56372 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56373 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56373 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56375 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56375 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56375 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56375 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56377 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-56377 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56377 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56377 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61464 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61464 ( NVD ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61464 ( NVD ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61465 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61465 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-61857 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61857 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61857 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61857 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61857 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61858 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61858 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61858 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61859 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-61859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61859 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61859 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61860 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61860 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61860 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61861 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61861 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61861 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61862 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61862 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61862 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61863 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61863 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61863 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61863 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61864 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61864 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61864 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61864 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61865 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61865 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61865 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61865 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61866 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61866 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61866 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61867 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61867 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61867 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61867 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61868 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61869 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61870 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61871 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61871 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61871 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61871 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61872 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61872 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61872 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 25 vulnerabilities and has one security fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495). * CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496). * CVE-2026-61859: policy bypass in script operation due to missing checks (bsc#1271497). * CVE-2026-61860: use-after-free when `freetype` initialization fails (bsc#1271494). * CVE-2026-61862: information disclosure when printing profiles with debug enabled (bsc#1271493). * CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not be created (bsc#1271492). * CVE-2026-61864: memory leak in color transformation to log colorspace when operation fails (bsc#1271491). * CVE-2026-61865: memory leak in hough lines operation when an operation fails (bsc#1271490). * CVE-2026-61866: memory leak in JNG encoder when a blob could not be opened (bsc#1271489). * CVE-2026-61867: memory leak in TIFF encoder when an allocation fails (bsc#1271488). * CVE-2026-61868: memory leak in YUV decoder when opening of blob fails (bsc#1271487). * CVE-2026-61869: memory leak in MIFF encoder when allocation fails (bsc#1271486). * CVE-2026-61871: memory leak in ICON decoder when allocation fails (bsc#1271485). * CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile- geometry` is specified (bsc#1271484). * CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). * CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). * CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). * CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314). * CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315). * CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006). * CVE-2026-61465: policy bypass possible with matrix-backed operations (bsc#1271313). * CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312). * CVE-2026-61858: policy bypass in APNG encoder and delegates due to a missing check (bsc#1271311). * CVE-2026-61861: use-after-free in `FormatMagickCaption` when memory allocation fails (bsc#1271294). * CVE-2026-61870: memory leak in VIFF encoder when allocation fails (bsc#1271293). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3194=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3194=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.1.43-150700.3.70.1 * perl-PerlMagick-debuginfo-7.1.1.43-150700.3.70.1 * perl-PerlMagick-7.1.1.43-150700.3.70.1 * ImageMagick-debugsource-7.1.1.43-150700.3.70.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.70.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.70.1 * libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.70.1 * ImageMagick-config-7-SUSE-7.1.1.43-150700.3.70.1 * libMagick++-devel-7.1.1.43-150700.3.70.1 * ImageMagick-7.1.1.43-150700.3.70.1 * libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.70.1 * ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.70.1 * ImageMagick-debuginfo-7.1.1.43-150700.3.70.1 * ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.70.1 * ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.70.1 * ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.70.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.43-150700.3.70.1 * ImageMagick-devel-7.1.1.43-150700.3.70.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.70.1 * ImageMagick-debugsource-7.1.1.43-150700.3.70.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55628.html * https://www.suse.com/security/cve/CVE-2026-56362.html * https://www.suse.com/security/cve/CVE-2026-56366.html * https://www.suse.com/security/cve/CVE-2026-56372.html * https://www.suse.com/security/cve/CVE-2026-56373.html * https://www.suse.com/security/cve/CVE-2026-56375.html * https://www.suse.com/security/cve/CVE-2026-56377.html * https://www.suse.com/security/cve/CVE-2026-61464.html * https://www.suse.com/security/cve/CVE-2026-61465.html * https://www.suse.com/security/cve/CVE-2026-61857.html * https://www.suse.com/security/cve/CVE-2026-61858.html * https://www.suse.com/security/cve/CVE-2026-61859.html * https://www.suse.com/security/cve/CVE-2026-61860.html * https://www.suse.com/security/cve/CVE-2026-61861.html * https://www.suse.com/security/cve/CVE-2026-61862.html * https://www.suse.com/security/cve/CVE-2026-61863.html * https://www.suse.com/security/cve/CVE-2026-61864.html * https://www.suse.com/security/cve/CVE-2026-61865.html * https://www.suse.com/security/cve/CVE-2026-61866.html * https://www.suse.com/security/cve/CVE-2026-61867.html * https://www.suse.com/security/cve/CVE-2026-61868.html * https://www.suse.com/security/cve/CVE-2026-61869.html * https://www.suse.com/security/cve/CVE-2026-61870.html * https://www.suse.com/security/cve/CVE-2026-61871.html * https://www.suse.com/security/cve/CVE-2026-61872.html * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1270006 * https://bugzilla.suse.com/show_bug.cgi?id=1270081 * https://bugzilla.suse.com/show_bug.cgi?id=1271100 * https://bugzilla.suse.com/show_bug.cgi?id=1271293 * https://bugzilla.suse.com/show_bug.cgi?id=1271294 * https://bugzilla.suse.com/show_bug.cgi?id=1271311 * https://bugzilla.suse.com/show_bug.cgi?id=1271312 * https://bugzilla.suse.com/show_bug.cgi?id=1271313 * https://bugzilla.suse.com/show_bug.cgi?id=1271314 * https://bugzilla.suse.com/show_bug.cgi?id=1271315 * https://bugzilla.suse.com/show_bug.cgi?id=1271316 * https://bugzilla.suse.com/show_bug.cgi?id=1271484 * https://bugzilla.suse.com/show_bug.cgi?id=1271485 * https://bugzilla.suse.com/show_bug.cgi?id=1271486 * https://bugzilla.suse.com/show_bug.cgi?id=1271487 * https://bugzilla.suse.com/show_bug.cgi?id=1271488 * https://bugzilla.suse.com/show_bug.cgi?id=1271489 * https://bugzilla.suse.com/show_bug.cgi?id=1271490 * https://bugzilla.suse.com/show_bug.cgi?id=1271491 * https://bugzilla.suse.com/show_bug.cgi?id=1271492 * https://bugzilla.suse.com/show_bug.cgi?id=1271493 * https://bugzilla.suse.com/show_bug.cgi?id=1271494 * https://bugzilla.suse.com/show_bug.cgi?id=1271495 * https://bugzilla.suse.com/show_bug.cgi?id=1271496 * https://bugzilla.suse.com/show_bug.cgi?id=1271497 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:56:31 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:56:31 -0000 Subject: SUSE-SU-2026:3193-1: moderate: Security update for ImageMagick Message-ID: <178475379124.245.1420899136546269781@c3e054a4ce29> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3193-1 Release Date: 2026-07-22T14:27:15Z Rating: moderate References: * bsc#1268640 * bsc#1270006 * bsc#1270081 * bsc#1271100 * bsc#1271293 * bsc#1271294 * bsc#1271311 * bsc#1271312 * bsc#1271313 * bsc#1271314 * bsc#1271315 * bsc#1271316 * bsc#1271484 * bsc#1271486 * bsc#1271487 * bsc#1271488 * bsc#1271489 * bsc#1271490 * bsc#1271491 * bsc#1271492 * bsc#1271493 * bsc#1271495 * bsc#1271496 * bsc#1271497 Cross-References: * CVE-2026-55628 * CVE-2026-56362 * CVE-2026-56366 * CVE-2026-56372 * CVE-2026-56373 * CVE-2026-56375 * CVE-2026-56377 * CVE-2026-61464 * CVE-2026-61465 * CVE-2026-61857 * CVE-2026-61858 * CVE-2026-61859 * CVE-2026-61861 * CVE-2026-61862 * CVE-2026-61863 * CVE-2026-61864 * CVE-2026-61865 * CVE-2026-61866 * CVE-2026-61867 * CVE-2026-61868 * CVE-2026-61869 * CVE-2026-61870 * CVE-2026-61872 CVSS scores: * CVE-2026-55628 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55628 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56362 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56362 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56362 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56366 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56366 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56366 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56366 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56366 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56372 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56372 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56372 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56373 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56373 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56375 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56375 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56375 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56375 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56377 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-56377 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56377 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56377 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61464 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61464 ( NVD ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61464 ( NVD ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61465 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61465 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-61857 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61857 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61857 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61857 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61857 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61858 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61858 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61858 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61859 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-61859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61859 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61859 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61861 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61861 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61861 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61862 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61862 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61862 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61863 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61863 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61863 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61863 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61864 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61864 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61864 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61864 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61865 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61865 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61865 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61865 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61866 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61866 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61867 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61867 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61867 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61867 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61868 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61869 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61870 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61870 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61872 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61872 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61872 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 23 vulnerabilities and has one security fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). * CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). * CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). * CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314). * CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315). * CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495). * CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006). * CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496). * CVE-2026-61465: policy bypass possible with matrix-backed operations (bsc#1271313). * CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312). * CVE-2026-61858: policy bypass in APNG encoder and delegates due to a missing check (bsc#1271311). * CVE-2026-61859: policy bypass in script operation due to missing checks (bsc#1271497). * CVE-2026-61861: use-after-free in `FormatMagickCaption` when memory allocation fails (bsc#1271294). * CVE-2026-61862: information disclosure when printing profiles with debug enabled (bsc#1271493). * CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not be created (bsc#1271492). * CVE-2026-61864: memory leak in color transformation to log colorspace when operation fails (bsc#1271491). * CVE-2026-61865: memory leak in hough lines operation when an operation fails (bsc#1271490). * CVE-2026-61866: memory leak in JNG encoder when a blob could not be opened (bsc#1271489). * CVE-2026-61867: memory leak in TIFF encoder when an allocation fails (bsc#1271488). * CVE-2026-61868: memory leak in YUV decoder when opening of blob fails (bsc#1271487). * CVE-2026-61869: memory leak in MIFF encoder when allocation fails (bsc#1271486). * CVE-2026-61870: memory leak in VIFF encoder when allocation fails (bsc#1271293). * CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile- geometry` is specified (bsc#1271484). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3193=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3193=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * ImageMagick-debugsource-7.1.0.9-150400.6.101.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.101.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.101.1 * ImageMagick-extra-7.1.0.9-150400.6.101.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.101.1 * ImageMagick-devel-7.1.0.9-150400.6.101.1 * libMagick++-devel-7.1.0.9-150400.6.101.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.101.1 * ImageMagick-7.1.0.9-150400.6.101.1 * perl-PerlMagick-7.1.0.9-150400.6.101.1 * ImageMagick-extra-debuginfo-7.1.0.9-150400.6.101.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.101.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.101.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.101.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.101.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.101.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.101.1 * openSUSE Leap 15.4 (x86_64) * libMagick++-devel-32bit-7.1.0.9-150400.6.101.1 * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.101.1 * ImageMagick-devel-32bit-7.1.0.9-150400.6.101.1 * libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.101.1 * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.101.1 * libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.101.1 * libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.101.1 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.101.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.101.1 * libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.101.1 * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.101.1 * libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.101.1 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.101.1 * libMagick++-devel-64bit-7.1.0.9-150400.6.101.1 * ImageMagick-devel-64bit-7.1.0.9-150400.6.101.1 * libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.101.1 * openSUSE Leap 15.4 (noarch) * ImageMagick-doc-7.1.0.9-150400.6.101.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.0.9-150400.6.101.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.101.1 * ImageMagick-debugsource-7.1.0.9-150400.6.101.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55628.html * https://www.suse.com/security/cve/CVE-2026-56362.html * https://www.suse.com/security/cve/CVE-2026-56366.html * https://www.suse.com/security/cve/CVE-2026-56372.html * https://www.suse.com/security/cve/CVE-2026-56373.html * https://www.suse.com/security/cve/CVE-2026-56375.html * https://www.suse.com/security/cve/CVE-2026-56377.html * https://www.suse.com/security/cve/CVE-2026-61464.html * https://www.suse.com/security/cve/CVE-2026-61465.html * https://www.suse.com/security/cve/CVE-2026-61857.html * https://www.suse.com/security/cve/CVE-2026-61858.html * https://www.suse.com/security/cve/CVE-2026-61859.html * https://www.suse.com/security/cve/CVE-2026-61861.html * https://www.suse.com/security/cve/CVE-2026-61862.html * https://www.suse.com/security/cve/CVE-2026-61863.html * https://www.suse.com/security/cve/CVE-2026-61864.html * https://www.suse.com/security/cve/CVE-2026-61865.html * https://www.suse.com/security/cve/CVE-2026-61866.html * https://www.suse.com/security/cve/CVE-2026-61867.html * https://www.suse.com/security/cve/CVE-2026-61868.html * https://www.suse.com/security/cve/CVE-2026-61869.html * https://www.suse.com/security/cve/CVE-2026-61870.html * https://www.suse.com/security/cve/CVE-2026-61872.html * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1270006 * https://bugzilla.suse.com/show_bug.cgi?id=1270081 * https://bugzilla.suse.com/show_bug.cgi?id=1271100 * https://bugzilla.suse.com/show_bug.cgi?id=1271293 * https://bugzilla.suse.com/show_bug.cgi?id=1271294 * https://bugzilla.suse.com/show_bug.cgi?id=1271311 * https://bugzilla.suse.com/show_bug.cgi?id=1271312 * https://bugzilla.suse.com/show_bug.cgi?id=1271313 * https://bugzilla.suse.com/show_bug.cgi?id=1271314 * https://bugzilla.suse.com/show_bug.cgi?id=1271315 * https://bugzilla.suse.com/show_bug.cgi?id=1271316 * https://bugzilla.suse.com/show_bug.cgi?id=1271484 * https://bugzilla.suse.com/show_bug.cgi?id=1271486 * https://bugzilla.suse.com/show_bug.cgi?id=1271487 * https://bugzilla.suse.com/show_bug.cgi?id=1271488 * https://bugzilla.suse.com/show_bug.cgi?id=1271489 * https://bugzilla.suse.com/show_bug.cgi?id=1271490 * https://bugzilla.suse.com/show_bug.cgi?id=1271491 * https://bugzilla.suse.com/show_bug.cgi?id=1271492 * https://bugzilla.suse.com/show_bug.cgi?id=1271493 * https://bugzilla.suse.com/show_bug.cgi?id=1271495 * https://bugzilla.suse.com/show_bug.cgi?id=1271496 * https://bugzilla.suse.com/show_bug.cgi?id=1271497 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:56:56 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:56:56 -0000 Subject: SUSE-SU-2026:3192-1: moderate: Security update for ImageMagick Message-ID: <178475381630.245.7177375563785680622@c3e054a4ce29> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3192-1 Release Date: 2026-07-22T14:26:04Z Rating: moderate References: * bsc#1268640 * bsc#1270006 * bsc#1270081 * bsc#1271100 * bsc#1271293 * bsc#1271312 * bsc#1271315 * bsc#1271316 * bsc#1271484 * bsc#1271486 * bsc#1271487 * bsc#1271492 * bsc#1271493 * bsc#1271496 Cross-References: * CVE-2026-55628 * CVE-2026-56362 * CVE-2026-56366 * CVE-2026-56373 * CVE-2026-56377 * CVE-2026-61464 * CVE-2026-61857 * CVE-2026-61862 * CVE-2026-61863 * CVE-2026-61868 * CVE-2026-61869 * CVE-2026-61870 * CVE-2026-61872 CVSS scores: * CVE-2026-55628 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55628 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56362 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56362 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56362 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56366 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56366 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56366 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56366 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56366 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56373 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56373 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56377 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-56377 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56377 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56377 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61464 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61464 ( NVD ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61464 ( NVD ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61857 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61857 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61857 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61857 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61857 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61862 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61862 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61862 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61863 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61863 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61863 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61863 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61868 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61869 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61870 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61870 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61872 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61872 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61872 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 13 vulnerabilities and has one security fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). * CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). * CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). * CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315). * CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006). * CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496). * CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312). * CVE-2026-61862: information disclosure when printing profiles with debug enabled (bsc#1271493). * CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not be created (bsc#1271492). * CVE-2026-61868: memory leak in YUV decoder when opening of blob fails (bsc#1271487). * CVE-2026-61869: memory leak in MIFF encoder when allocation fails (bsc#1271486). * CVE-2026-61870: memory leak in VIFF encoder when allocation fails (bsc#1271293). * CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile- geometry` is specified (bsc#1271484). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3192=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * ImageMagick-config-6-SUSE-6.8.8.1-71.264.1 * ImageMagick-config-6-upstream-6.8.8.1-71.264.1 * ImageMagick-debuginfo-6.8.8.1-71.264.1 * ImageMagick-devel-6.8.8.1-71.264.1 * libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.264.1 * ImageMagick-debugsource-6.8.8.1-71.264.1 * libMagickWand-6_Q16-1-6.8.8.1-71.264.1 * libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.264.1 * libMagickCore-6_Q16-1-6.8.8.1-71.264.1 * libMagick++-devel-6.8.8.1-71.264.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55628.html * https://www.suse.com/security/cve/CVE-2026-56362.html * https://www.suse.com/security/cve/CVE-2026-56366.html * https://www.suse.com/security/cve/CVE-2026-56373.html * https://www.suse.com/security/cve/CVE-2026-56377.html * https://www.suse.com/security/cve/CVE-2026-61464.html * https://www.suse.com/security/cve/CVE-2026-61857.html * https://www.suse.com/security/cve/CVE-2026-61862.html * https://www.suse.com/security/cve/CVE-2026-61863.html * https://www.suse.com/security/cve/CVE-2026-61868.html * https://www.suse.com/security/cve/CVE-2026-61869.html * https://www.suse.com/security/cve/CVE-2026-61870.html * https://www.suse.com/security/cve/CVE-2026-61872.html * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1270006 * https://bugzilla.suse.com/show_bug.cgi?id=1270081 * https://bugzilla.suse.com/show_bug.cgi?id=1271100 * https://bugzilla.suse.com/show_bug.cgi?id=1271293 * https://bugzilla.suse.com/show_bug.cgi?id=1271312 * https://bugzilla.suse.com/show_bug.cgi?id=1271315 * https://bugzilla.suse.com/show_bug.cgi?id=1271316 * https://bugzilla.suse.com/show_bug.cgi?id=1271484 * https://bugzilla.suse.com/show_bug.cgi?id=1271486 * https://bugzilla.suse.com/show_bug.cgi?id=1271487 * https://bugzilla.suse.com/show_bug.cgi?id=1271492 * https://bugzilla.suse.com/show_bug.cgi?id=1271493 * https://bugzilla.suse.com/show_bug.cgi?id=1271496 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 22 20:57:01 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 22 Jul 2026 20:57:01 -0000 Subject: SUSE-RU-2026:3191-1: moderate: Recommended update for adcli Message-ID: <178475382186.245.2926555298511024841@c3e054a4ce29> # Recommended update for adcli Announcement ID: SUSE-RU-2026:3191-1 Release Date: 2026-07-22T14:08:43Z Rating: moderate References: * bsc#1183870 * jsc#PED-13768 * jsc#PED-16503 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains two features and has one fix can now be installed. ## Description: This update for adcli fixes the following issues: Update to 0.9.3.1; (jsc#PED-13768); * enroll: check if AD accepts new password * enroll: allow to add SPNs to manages service accounts * enroll: add new SPNs from AD to keytab during update * conn: use 10s timeout for connect() * enroll: restore SELinux file context of keytab files * enroll: remove USE_DES_KEY_ONLY during join * entry: check user and group names for illegal characters * tools: add --recursive option to delete-computer * tools: testjoin, use realm from keytab as domain name * enroll: use realm form the HOST$ entry in the keytab * Tests: initial framework and tests for adcli based on sssd-test-framework * krb5: add adcli_krb5_get_error_message() * Various fixes for issues found by static code scanners * enroll: Populate Samba's secrets database using offline domain join Update to 0.9.2: * adenroll: set password via LDAP instead Kerberos * disco: fall back to LDAPS if CLDAP ping was not successful * tools: replace getpass() * adenroll: write SID before secret to Samba's db * doc: add clarification to add-member command on doc/adcli.xml * tools: Set umask before calling mkdtemp() * Avoid undefined behaviour in short option parsing * library: include endian.h for le32toh * man: Fix typos and use consistent upper case for some keywords * configure: check for ns_get16 and ns_get32 as well * Add setattr and delattr options * entry: add passwd-user sub-command * Add dont-expire-password option Update to 0.9.1: * tools: add show-computer command * add description option to join and update * Use GSS-SPNEGO if available * add option use-ldaps * tools: disable SSSD's locator plugin * doc: explain required AD permissions * computer: add create-msa sub-command * Add account-disable option * fix coredump in discovery (boo#1183870) Update to 0.9.0: * doc: add missing samba_data_tool_path.xml(.in) to EXTRA_DIST * doc: explain how to force password reset * Do not use arcfour-hmac-md5 when discovering the salt * Fix for issue found by Coverity * adenroll: use only enctypes permitted by Kerberos config * adenroll: add adcli_enroll_get_permitted_keytab_enctypes with tests * adconn: add adcli_conn_set_krb5_context * adenroll: make sure only allowed enctypes are used in FIPS mode * tools: computer - remove errx from parse_option ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3191=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3191=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3191=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3191=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * adcli-debuginfo-0.9.3.1-150600.22.8.1 * adcli-0.9.3.1-150600.22.8.1 * adcli-debugsource-0.9.3.1-150600.22.8.1 * adcli-doc-0.9.3.1-150600.22.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * adcli-debuginfo-0.9.3.1-150600.22.8.1 * adcli-0.9.3.1-150600.22.8.1 * adcli-debugsource-0.9.3.1-150600.22.8.1 * adcli-doc-0.9.3.1-150600.22.8.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * adcli-debuginfo-0.9.3.1-150600.22.8.1 * adcli-0.9.3.1-150600.22.8.1 * adcli-debugsource-0.9.3.1-150600.22.8.1 * adcli-doc-0.9.3.1-150600.22.8.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * adcli-doc-0.9.3.1-150600.22.8.1 * adcli-0.9.3.1-150600.22.8.1 * adcli-debugsource-0.9.3.1-150600.22.8.1 * adcli-debuginfo-0.9.3.1-150600.22.8.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1183870 * https://jira.suse.com/browse/PED-13768 * https://jira.suse.com/browse/PED-16503 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:30:09 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:30:09 -0000 Subject: SUSE-RU-2026:22788-1: important: Recommended update for pcr-oracle Message-ID: <178479540992.359.362570655016258116@91cb4ee470e0> # Recommended update for pcr-oracle Announcement ID: SUSE-RU-2026:22788-1 Release Date: 2026-07-20T17:29:51Z Rating: important References: * bsc#1270265 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for pcr-oracle fixes the following issues: * Update to 0.6.4: * Support TPM PCR snapshot on PowerPC 64 platform * Fix SBAT string length calculations (bsc#1270265) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1306=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 x86_64) * pcr-oracle-debuginfo-0.6.4-160000.1.1 * pcr-oracle-0.6.4-160000.1.1 * pcr-oracle-debugsource-0.6.4-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270265 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:30:30 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:30:30 -0000 Subject: SUSE-SU-2026:22787-1: important: Security update for afterburn Message-ID: <178479543048.359.3367402852875094057@91cb4ee470e0> # Security update for afterburn Announcement ID: SUSE-SU-2026:22787-1 Release Date: 2026-07-20T09:39:37Z Rating: important References: * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.2 An update that solves nine vulnerabilities can now be installed. ## Description: This update for afterburn fixes the following issues: Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ? * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1293=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 x86_64) * afterburn-5.10.0.git73.b97f772-160000.1.1 * afterburn-debugsource-5.10.0.git73.b97f772-160000.1.1 * afterburn-debuginfo-5.10.0.git73.b97f772-160000.1.1 * SUSE Linux Micro 6.2 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:31:36 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:31:36 -0000 Subject: SUSE-SU-2026:22786-1: important: Security update for the Linux Kernel RT (Live Patch 3 for SUSE Linux Enterprise 16) Message-ID: <178479549665.359.8472864117405093281@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22786-1 Release Date: 2026-07-14T19:40:44Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1264=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_8-rt-9-160000.1.1 * kernel-livepatch-6_12_0-160000_8-rt-debuginfo-9-160000.1.1 * kernel-livepatch-SLE16-RT_Update_3-debugsource-9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:32:21 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:32:21 -0000 Subject: SUSE-SU-2026:22785-1: important: Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 16) Message-ID: <178479554121.359.17070453452095462661@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22785-1 Release Date: 2026-07-14T16:21:17Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1263=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_0-debugsource-13-160000.3.4 * kernel-livepatch-6_12_0-160000_5-rt-13-160000.3.4 * kernel-livepatch-6_12_0-160000_5-rt-debuginfo-13-160000.3.4 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:33:11 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:33:11 -0000 Subject: SUSE-SU-2026:22784-1: important: Security update for the Linux Kernel RT (Live Patch 1 for SUSE Linux Enterprise 16) Message-ID: <178479559182.359.6069181788242605472@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22784-1 Release Date: 2026-07-14T16:21:16Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.6.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1262=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_1-debugsource-12-160000.1.1 * kernel-livepatch-6_12_0-160000_6-rt-12-160000.1.1 * kernel-livepatch-6_12_0-160000_6-rt-debuginfo-12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:33:52 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:33:52 -0000 Subject: SUSE-SU-2026:22783-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 16) Message-ID: <178479563257.359.3400578728374142896@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22783-1 Release Date: 2026-07-14T16:20:18Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.7.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1261=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_7-rt-10-160000.1.1 * kernel-livepatch-SLE16-RT_Update_2-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_7-rt-debuginfo-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:34:34 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:34:34 -0000 Subject: SUSE-SU-2026:22782-1: important: Security update for the Linux Kernel RT (Live Patch 4 for SUSE Linux Enterprise 16) Message-ID: <178479567485.359.6678443492052872281@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22782-1 Release Date: 2026-07-14T16:20:18Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1260=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_9-rt-debuginfo-9-160000.1.1 * kernel-livepatch-6_12_0-160000_9-rt-9-160000.1.1 * kernel-livepatch-SLE16-RT_Update_4-debugsource-9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:35:06 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:35:06 -0000 Subject: SUSE-SU-2026:22781-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178479570605.359.5933787655839581177@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22781-1 Release Date: 2026-07-14T16:20:02Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1256=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_29-rt-5-160000.1.1 * kernel-livepatch-6_12_0-160000_29-rt-debuginfo-5-160000.1.1 * kernel-livepatch-SLE16-RT_Update_8-debugsource-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:35:38 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:35:38 -0000 Subject: SUSE-SU-2026:22780-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise 16) Message-ID: <178479573888.359.5240869176208595262@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22780-1 Release Date: 2026-07-14T16:20:02Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1254=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_32-rt-debuginfo-4-160000.1.1 * kernel-livepatch-6_12_0-160000_32-rt-4-160000.1.1 * kernel-livepatch-SLE16-RT_Update_11-debugsource-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:35:54 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:35:54 -0000 Subject: SUSE-SU-2026:22779-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise 16) Message-ID: <178479575488.359.1322020296758613598@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22779-1 Release Date: 2026-07-14T16:20:02Z Rating: important References: * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.33.1 fixes various security issues The following security issues were fixed: * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1253=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_33-rt-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16-RT_Update_12-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_33-rt-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:36:35 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:36:35 -0000 Subject: SUSE-SU-2026:22778-1: important: Security update for the Linux Kernel RT (Live Patch 5 for SUSE Linux Enterprise 16) Message-ID: <178479579522.359.5752103665509997840@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 5 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22778-1 Release Date: 2026-07-14T16:18:36Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.26.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1259=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_26-rt-debuginfo-8-160000.1.1 * kernel-livepatch-6_12_0-160000_26-rt-8-160000.1.1 * kernel-livepatch-SLE16-RT_Update_5-debugsource-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:37:14 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:37:14 -0000 Subject: SUSE-SU-2026:22777-1: important: Security update for the Linux Kernel RT (Live Patch 6 for SUSE Linux Enterprise 16) Message-ID: <178479583491.359.5711912861078278@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 6 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22777-1 Release Date: 2026-07-14T16:18:36Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.27.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1258=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_6-debugsource-7-160000.1.1 * kernel-livepatch-6_12_0-160000_27-rt-7-160000.1.1 * kernel-livepatch-6_12_0-160000_27-rt-debuginfo-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:37:47 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:37:47 -0000 Subject: SUSE-SU-2026:22776-1: important: Security update for the Linux Kernel RT (Live Patch 7 for SUSE Linux Enterprise 16) Message-ID: <178479586782.359.7945436591871922719@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 7 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22776-1 Release Date: 2026-07-14T16:17:09Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.28.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1257=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_28-rt-6-160000.1.1 * kernel-livepatch-SLE16-RT_Update_7-debugsource-6-160000.1.1 * kernel-livepatch-6_12_0-160000_28-rt-debuginfo-6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:38:21 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:38:21 -0000 Subject: SUSE-SU-2026:22775-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 16) Message-ID: <178479590140.359.14625951389857238938@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22775-1 Release Date: 2026-07-14T16:17:09Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1255=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_31-rt-4-160000.1.1 * kernel-livepatch-SLE16-RT_Update_10-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_31-rt-debuginfo-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:38:35 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:38:35 -0000 Subject: SUSE-SU-2026:22774-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 16) Message-ID: <178479591576.359.2839685012730287300@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22774-1 Release Date: 2026-07-14T16:17:09Z Rating: important References: * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.34.1 fixes various security issues The following security issues were fixed: * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1252=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_34-rt-2-160000.1.1 * kernel-livepatch-6_12_0-160000_34-rt-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16-RT_Update_13-debugsource-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:38:48 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:38:48 -0000 Subject: SUSE-SU-2026:22773-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 16) Message-ID: <178479592894.359.16534357080720215897@91cb4ee470e0> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22773-1 Release Date: 2026-07-14T16:17:09Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.35.1 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1251=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_35-rt-2-160000.1.1 * kernel-livepatch-6_12_0-160000_35-rt-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16-RT_Update_14-debugsource-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:38:54 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:38:54 -0000 Subject: SUSE-SU-2026:3201-1: low: Security update for GraphicsMagick Message-ID: <178479593474.359.4164664182972838593@91cb4ee470e0> # Security update for GraphicsMagick Announcement ID: SUSE-SU-2026:3201-1 Release Date: 2026-07-22T18:53:49Z Rating: low References: * bsc#1271293 Cross-References: * CVE-2026-61870 CVSS scores: * CVE-2026-61870 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61870 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for GraphicsMagick fixes the following issue * CVE-2026-61870: Memory leak in VIFF encoder when allocation fails (bsc#1271293). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3201=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3201=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.36.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.36.1 * libGraphicsMagick3-config-1.3.42-150600.3.36.1 * GraphicsMagick-debugsource-1.3.42-150600.3.36.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.36.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.36.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.36.1 * perl-GraphicsMagick-1.3.42-150600.3.36.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.36.1 * GraphicsMagick-1.3.42-150600.3.36.1 * GraphicsMagick-devel-1.3.42-150600.3.36.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.36.1 * libGraphicsMagick++-devel-1.3.42-150600.3.36.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.36.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.36.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.36.1 * libGraphicsMagick3-config-1.3.42-150600.3.36.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.36.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.36.1 * GraphicsMagick-debugsource-1.3.42-150600.3.36.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.36.1 * GraphicsMagick-1.3.42-150600.3.36.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.36.1 * perl-GraphicsMagick-1.3.42-150600.3.36.1 * GraphicsMagick-devel-1.3.42-150600.3.36.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.36.1 * libGraphicsMagick++-devel-1.3.42-150600.3.36.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.36.1 ## References: * https://www.suse.com/security/cve/CVE-2026-61870.html * https://bugzilla.suse.com/show_bug.cgi?id=1271293 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:39:00 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:39:00 -0000 Subject: SUSE-SU-2026:3200-1: critical: Security update for MozillaFirefox Message-ID: <178479594084.359.17299721258217123930@91cb4ee470e0> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:3200-1 Release Date: 2026-07-22T18:48:43Z Rating: critical References: * bsc#1271649 Cross-References: * CVE-2026-15718 * CVE-2026-15719 * CVE-2026-16349 * CVE-2026-16350 * CVE-2026-16351 * CVE-2026-16352 * CVE-2026-16353 * CVE-2026-16354 * CVE-2026-16355 * CVE-2026-16356 * CVE-2026-16357 * CVE-2026-16358 * CVE-2026-16359 * CVE-2026-16360 * CVE-2026-16361 * CVE-2026-16362 * CVE-2026-16363 * CVE-2026-16368 * CVE-2026-16369 * CVE-2026-16371 * CVE-2026-16374 * CVE-2026-16375 * CVE-2026-16377 * CVE-2026-16379 * CVE-2026-16381 * CVE-2026-16383 * CVE-2026-16387 * CVE-2026-16390 * CVE-2026-16391 * CVE-2026-16396 * CVE-2026-16405 * CVE-2026-16412 CVSS scores: * CVE-2026-15718 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15719 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-16349 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16350 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16351 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16352 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16353 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16354 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16356 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16358 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16359 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16360 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16361 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16362 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16363 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16368 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16369 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16371 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16374 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16375 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16377 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16379 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16381 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16390 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16396 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16412 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 32 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: * Firefox Extended Support Release 140.13.0 ESR (MFSA 2026-70, bsc#1271649): * CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component. * CVE-2026-15719: Site isolation issue in the DOM: Navigation component. * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component. * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component. * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component. * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component. * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component. * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component. * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component. * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component. * CVE-2026-16357: Incorrect boundary conditions in the Graphics component. * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component. * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component. * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153. * CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13. * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component. * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component. * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component. * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component. * CVE-2026-16371: Privilege escalation in the DOM: Navigation component. * CVE-2026-16374: Information disclosure in the Framework component in DevTools. * CVE-2026-16375: Site isolation issue in the Networking: HTTP component. * CVE-2026-16377: Mitigation bypass in the PDF Viewer component. * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component. * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component. * CVE-2026-16383: Mitigation bypass in the DOM: Networking component. * CVE-2026-16387: Site isolation issue in the Networking component. * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component. * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component. * CVE-2026-16396: Privilege escalation in WebExtensions. * CVE-2026-16405: Information disclosure in the Networking: WebSockets component. * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3200=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3200=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-140.13.0-112.324.2 * MozillaFirefox-140.13.0-112.324.2 * MozillaFirefox-debuginfo-140.13.0-112.324.2 * MozillaFirefox-debugsource-140.13.0-112.324.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * MozillaFirefox-devel-140.13.0-112.324.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * MozillaFirefox-translations-common-140.13.0-112.324.2 * MozillaFirefox-140.13.0-112.324.2 * MozillaFirefox-debuginfo-140.13.0-112.324.2 * MozillaFirefox-debugsource-140.13.0-112.324.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * MozillaFirefox-devel-140.13.0-112.324.2 ## References: * https://www.suse.com/security/cve/CVE-2026-15718.html * https://www.suse.com/security/cve/CVE-2026-15719.html * https://www.suse.com/security/cve/CVE-2026-16349.html * https://www.suse.com/security/cve/CVE-2026-16350.html * https://www.suse.com/security/cve/CVE-2026-16351.html * https://www.suse.com/security/cve/CVE-2026-16352.html * https://www.suse.com/security/cve/CVE-2026-16353.html * https://www.suse.com/security/cve/CVE-2026-16354.html * https://www.suse.com/security/cve/CVE-2026-16355.html * https://www.suse.com/security/cve/CVE-2026-16356.html * https://www.suse.com/security/cve/CVE-2026-16357.html * https://www.suse.com/security/cve/CVE-2026-16358.html * https://www.suse.com/security/cve/CVE-2026-16359.html * https://www.suse.com/security/cve/CVE-2026-16360.html * https://www.suse.com/security/cve/CVE-2026-16361.html * https://www.suse.com/security/cve/CVE-2026-16362.html * https://www.suse.com/security/cve/CVE-2026-16363.html * https://www.suse.com/security/cve/CVE-2026-16368.html * https://www.suse.com/security/cve/CVE-2026-16369.html * https://www.suse.com/security/cve/CVE-2026-16371.html * https://www.suse.com/security/cve/CVE-2026-16374.html * https://www.suse.com/security/cve/CVE-2026-16375.html * https://www.suse.com/security/cve/CVE-2026-16377.html * https://www.suse.com/security/cve/CVE-2026-16379.html * https://www.suse.com/security/cve/CVE-2026-16381.html * https://www.suse.com/security/cve/CVE-2026-16383.html * https://www.suse.com/security/cve/CVE-2026-16387.html * https://www.suse.com/security/cve/CVE-2026-16390.html * https://www.suse.com/security/cve/CVE-2026-16391.html * https://www.suse.com/security/cve/CVE-2026-16396.html * https://www.suse.com/security/cve/CVE-2026-16405.html * https://www.suse.com/security/cve/CVE-2026-16412.html * https://bugzilla.suse.com/show_bug.cgi?id=1271649 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 08:39:08 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 08:39:08 -0000 Subject: SUSE-SU-2026:3199-1: moderate: Security update for multipath-tools Message-ID: <178479594856.359.2282902911155656894@91cb4ee470e0> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:3199-1 Release Date: 2026-07-22T18:46:43Z Rating: moderate References: * bsc#1268144 * bsc#1268145 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that has two security fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues * kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device or disk image(bsc#1268145). * kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256 consecutive format labels (bsc#1268144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3199=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3199=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3199=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3199=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3199=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * kpartx-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-0.9.0+168+suse.54b6b26-150400.4.22.1 * kpartx-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debugsource-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-0.9.0+168+suse.54b6b26-150400.4.22.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * kpartx-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-0.9.0+168+suse.54b6b26-150400.4.22.1 * kpartx-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debugsource-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-0.9.0+168+suse.54b6b26-150400.4.22.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * kpartx-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-0.9.0+168+suse.54b6b26-150400.4.22.1 * kpartx-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debugsource-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-0.9.0+168+suse.54b6b26-150400.4.22.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * kpartx-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-0.9.0+168+suse.54b6b26-150400.4.22.1 * kpartx-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debugsource-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-0.9.0+168+suse.54b6b26-150400.4.22.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libdmmp-devel-0.9.0+168+suse.54b6b26-150400.4.22.1 * kpartx-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * libdmmp0_2_0-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * libdmmp0_2_0-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-0.9.0+168+suse.54b6b26-150400.4.22.1 * kpartx-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-devel-0.9.0+168+suse.54b6b26-150400.4.22.1 * multipath-tools-debugsource-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-debuginfo-0.9.0+168+suse.54b6b26-150400.4.22.1 * libmpath0-0.9.0+168+suse.54b6b26-150400.4.22.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268144 * https://bugzilla.suse.com/show_bug.cgi?id=1268145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:30:24 -0000 Subject: SUSE-SU-2026:3214-1: important: Security update for ntfs-3g_ntfsprogs Message-ID: <178483862432.598.17320214689596915688@54f0d6838c13> # Security update for ntfs-3g_ntfsprogs Announcement ID: SUSE-SU-2026:3214-1 Release Date: 2026-07-23T14:18:49Z Rating: important References: * bsc#1271102 * bsc#1271103 * bsc#1271104 * bsc#1271105 * bsc#1271106 * bsc#1271107 * bsc#1271108 * bsc#1271109 * bsc#1271110 Cross-References: * CVE-2026-42616 * CVE-2026-42617 * CVE-2026-42618 * CVE-2026-46569 * CVE-2026-46570 * CVE-2026-46571 * CVE-2026-46572 * CVE-2026-56135 * CVE-2026-56136 CVSS scores: * CVE-2026-42616 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-42616 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42617 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-42617 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42618 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-42618 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46569 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46569 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46570 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46571 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46571 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46572 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46572 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-56135 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56135 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-56136 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-56136 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for ntfs-3g_ntfsprogs fixes the following issues * CVE-2026-42616: heap buffer overflow in `cat()` of `cat.c` can lead to heap corruption in the ntfscat binary via a specially crafted NTFS image (bsc#1271102). * CVE-2026-42617: heap buffer overflow in `ntfs_ir_to_ib()` of `index.c` can lead to heap corruption in the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271103). * CVE-2026-42618: heap buffer overflow in `ntfs_decompress()` of `compress.c` can lead to heap corruption in the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271104). * CVE-2026-46569: heap buffer overflow in `ntfs_ib_copy_tail()` of `libntfs-3g/index.c`can lead to heap corruption in the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271105). * CVE-2026-46570: heap buffer overflow in `ntfs_index_walk_down()` of `libntfs-3g/index.c` can lead to heap corruption in the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271106). * CVE-2026-46571: out-of-bounds read in `ntfs_fix_file_name()` of `libntfs-3g/reparse.c` can lead to disclosure of confidential information from the ntfs-3g process memory when handling a specially crafted NTFS image (bsc#1271107). * CVE-2026-46572: heap buffer overflow in `ntfs_ib_cut_tail()` of `libntfs-3g/index.c` can lead to heap corruption in the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271108). * CVE-2026-56135: heap-based buffer overflow in `build_inherited_id()` of `libntfs-3g/security.c` can lead to heap corruption in the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271109). * CVE-2026-56136: out-of-bounds read in `ntfs_ir_nill()` of `libntfs-3g/index.c` can lead to disclosure of confidential information from the ntfs-3g process memory when handling a specially crafted NTFS image (bsc#1271110). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3214=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3214=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3214=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3214=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libntfs-3g87-2022.5.17-150000.3.27.1 * libntfs-3g-devel-2022.5.17-150000.3.27.1 * libntfs-3g87-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g_ntfsprogs-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g-2022.5.17-150000.3.27.1 * ntfs-3g-debuginfo-2022.5.17-150000.3.27.1 * ntfsprogs-2022.5.17-150000.3.27.1 * ntfsprogs-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g_ntfsprogs-debugsource-2022.5.17-150000.3.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libntfs-3g87-2022.5.17-150000.3.27.1 * libntfs-3g-devel-2022.5.17-150000.3.27.1 * libntfs-3g87-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g_ntfsprogs-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g-2022.5.17-150000.3.27.1 * ntfs-3g-debuginfo-2022.5.17-150000.3.27.1 * ntfsprogs-2022.5.17-150000.3.27.1 * ntfsprogs-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g_ntfsprogs-debugsource-2022.5.17-150000.3.27.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libntfs-3g87-2022.5.17-150000.3.27.1 * libntfs-3g87-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g_ntfsprogs-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g-2022.5.17-150000.3.27.1 * ntfs-3g-debuginfo-2022.5.17-150000.3.27.1 * ntfsprogs-2022.5.17-150000.3.27.1 * ntfsprogs-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g_ntfsprogs-debugsource-2022.5.17-150000.3.27.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libntfs-3g-devel-2022.5.17-150000.3.27.1 * ntfs-3g_ntfsprogs-debuginfo-2022.5.17-150000.3.27.1 * ntfs-3g_ntfsprogs-debugsource-2022.5.17-150000.3.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42616.html * https://www.suse.com/security/cve/CVE-2026-42617.html * https://www.suse.com/security/cve/CVE-2026-42618.html * https://www.suse.com/security/cve/CVE-2026-46569.html * https://www.suse.com/security/cve/CVE-2026-46570.html * https://www.suse.com/security/cve/CVE-2026-46571.html * https://www.suse.com/security/cve/CVE-2026-46572.html * https://www.suse.com/security/cve/CVE-2026-56135.html * https://www.suse.com/security/cve/CVE-2026-56136.html * https://bugzilla.suse.com/show_bug.cgi?id=1271102 * https://bugzilla.suse.com/show_bug.cgi?id=1271103 * https://bugzilla.suse.com/show_bug.cgi?id=1271104 * https://bugzilla.suse.com/show_bug.cgi?id=1271105 * https://bugzilla.suse.com/show_bug.cgi?id=1271106 * https://bugzilla.suse.com/show_bug.cgi?id=1271107 * https://bugzilla.suse.com/show_bug.cgi?id=1271108 * https://bugzilla.suse.com/show_bug.cgi?id=1271109 * https://bugzilla.suse.com/show_bug.cgi?id=1271110 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:30:40 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:30:40 -0000 Subject: SUSE-SU-2026:3213-1: important: Security update for ntfs-3g_ntfsprogs Message-ID: <178483864022.598.9862964081767026539@54f0d6838c13> # Security update for ntfs-3g_ntfsprogs Announcement ID: SUSE-SU-2026:3213-1 Release Date: 2026-07-23T14:18:15Z Rating: important References: * bsc#1271102 * bsc#1271103 * bsc#1271104 * bsc#1271105 * bsc#1271106 * bsc#1271107 * bsc#1271108 * bsc#1271109 * bsc#1271110 Cross-References: * CVE-2026-42616 * CVE-2026-42617 * CVE-2026-42618 * CVE-2026-46569 * CVE-2026-46570 * CVE-2026-46571 * CVE-2026-46572 * CVE-2026-56135 * CVE-2026-56136 CVSS scores: * CVE-2026-42616 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-42616 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42617 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-42617 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42618 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-42618 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46569 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46569 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46570 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46571 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46571 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46572 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46572 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-56135 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56135 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-56136 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-56136 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for ntfs-3g_ntfsprogs fixes the following issues * CVE-2026-42616: heap buffer overflow in cat() in cat.c (bsc#1271102). * CVE-2026-42617: heap buffer overflow in ntfs_ir_to_ib() in index.c (bsc#1271103). * CVE-2026-42618: heap buffer overflow in ntfs_decompress() in compress.c (bsc#1271104). * CVE-2026-46569: heap buffer overflow in ntfs_ib_copy_tail() in libntfs-3g/index.c (bsc#1271105). * CVE-2026-46570: heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c (bsc#1271106). * CVE-2026-46571: out-of-bounds read in ntfs_fix_file_name() in libntfs-3g/reparse.c (bsc#1271107). * CVE-2026-46572: heap buffer overflow in ntfs_ib_cut_tail() in libntfs-3g/index.c (bsc#1271108). * CVE-2026-56135: heap-based buffer overflow in build_inherited_id() in libntfs-3g/security.c (bsc#1271109). * CVE-2026-56136: out-of-bounds read in ntfs_ir_nill() in libntfs-3g/index.c (bsc#1271110). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3213=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3213=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libntfs-3g-devel-2022.5.17-5.23.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libntfs-3g-devel-2022.5.17-5.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42616.html * https://www.suse.com/security/cve/CVE-2026-42617.html * https://www.suse.com/security/cve/CVE-2026-42618.html * https://www.suse.com/security/cve/CVE-2026-46569.html * https://www.suse.com/security/cve/CVE-2026-46570.html * https://www.suse.com/security/cve/CVE-2026-46571.html * https://www.suse.com/security/cve/CVE-2026-46572.html * https://www.suse.com/security/cve/CVE-2026-56135.html * https://www.suse.com/security/cve/CVE-2026-56136.html * https://bugzilla.suse.com/show_bug.cgi?id=1271102 * https://bugzilla.suse.com/show_bug.cgi?id=1271103 * https://bugzilla.suse.com/show_bug.cgi?id=1271104 * https://bugzilla.suse.com/show_bug.cgi?id=1271105 * https://bugzilla.suse.com/show_bug.cgi?id=1271106 * https://bugzilla.suse.com/show_bug.cgi?id=1271107 * https://bugzilla.suse.com/show_bug.cgi?id=1271108 * https://bugzilla.suse.com/show_bug.cgi?id=1271109 * https://bugzilla.suse.com/show_bug.cgi?id=1271110 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:30:48 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:30:48 -0000 Subject: SUSE-SU-2026:3212-1: moderate: Security update for multipath-tools Message-ID: <178483864813.598.12057255642415403572@54f0d6838c13> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:3212-1 Release Date: 2026-07-23T14:13:53Z Rating: moderate References: * bsc#1268144 * bsc#1268145 Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has two security fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues Update to version 0.7.9+238+suse.1249506. * kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device or disk image (bsc#1268145). * kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256 consecutive format labels (bsc#1268144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3212=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * multipath-tools-0.7.9+238+suse.1249506-3.20.1 * kpartx-0.7.9+238+suse.1249506-3.20.1 * multipath-tools-debuginfo-0.7.9+238+suse.1249506-3.20.1 * multipath-tools-debugsource-0.7.9+238+suse.1249506-3.20.1 * multipath-tools-devel-0.7.9+238+suse.1249506-3.20.1 * kpartx-debuginfo-0.7.9+238+suse.1249506-3.20.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268144 * https://bugzilla.suse.com/show_bug.cgi?id=1268145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:30:53 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:30:53 -0000 Subject: SUSE-SU-2026:3211-1: moderate: Security update for gawk Message-ID: <178483865369.598.7866853144185124224@54f0d6838c13> # Security update for gawk Announcement ID: SUSE-SU-2026:3211-1 Release Date: 2026-07-23T14:13:48Z Rating: moderate References: * bsc#1271352 Cross-References: * CVE-2026-40468 CVSS scores: * CVE-2026-40468 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L * CVE-2026-40468 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40468 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40468 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gawk fixes the following issue: * CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3211=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gawk-4.1.0-5.6.1 * gawk-debugsource-4.1.0-5.6.1 * gawk-debuginfo-4.1.0-5.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40468.html * https://bugzilla.suse.com/show_bug.cgi?id=1271352 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:30:59 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:30:59 -0000 Subject: SUSE-SU-2026:3210-1: important: Security update for google-guest-agent Message-ID: <178483865922.598.17371535199177692286@54f0d6838c13> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:3210-1 Release Date: 2026-07-23T14:12:44Z Rating: important References: * bsc#1266603 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for google-guest-agent fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3210=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3210=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3210=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3210=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3210=1 ## Package List: * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.73.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.73.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.73.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.73.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.73.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:31:04 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:31:04 -0000 Subject: SUSE-SU-2026:3209-1: important: Security update for google-osconfig-agent Message-ID: <178483866471.598.13915571950213004722@54f0d6838c13> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:3209-1 Release Date: 2026-07-23T14:12:01Z Rating: important References: * bsc#1266603 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for google-osconfig-agent fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3209=1 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260615.01-1.50.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:31:19 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:31:19 -0000 Subject: SUSE-SU-2026:3208-1: important: Security update for python-aiohttp Message-ID: <178483867946.598.4889754413884075333@54f0d6838c13> # Security update for python-aiohttp Announcement ID: SUSE-SU-2026:3208-1 Release Date: 2026-07-23T14:11:28Z Rating: important References: * bsc#1268398 * bsc#1268543 * bsc#1268544 * bsc#1268549 * bsc#1268556 * bsc#1268559 * bsc#1268560 * bsc#1268561 Cross-References: * CVE-2026-50269 * CVE-2026-54273 * CVE-2026-54274 * CVE-2026-54275 * CVE-2026-54277 * CVE-2026-54278 * CVE-2026-54279 * CVE-2026-54280 CVSS scores: * CVE-2026-50269 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-50269 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50269 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54273 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54273 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54273 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54274 ( SUSE ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U * CVE-2026-54274 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54274 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54274 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54275 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-54275 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54275 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54277 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54277 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54277 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54278 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54278 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54278 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54278 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54279 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54279 ( NVD ): 1.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54279 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54280 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54280 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-aiohttp fixes the following issues: * CVE-2026-50269: improper validation of user-controlled strings allows for CRLF injection in multipart headers (bsc#1268398). * CVE-2026-54273: no limit in the HTTP/1 pipelined request queue can lead to excessive resource consumption (bsc#1268543). * CVE-2026-54274: incomplete websocket frame payloads can bypass memory use limits and cause a DoS via excessive resource consumption (bsc#1268544). * CVE-2026-54275: `server_hostname` TLS SNI check bypass when an existing connection is reused (bsc#1268549). * CVE-2026-54277: `max_line_size` bypass when using the optimised C HTTP parser can lead to excessive resource consumption (bsc#1268556). * CVE-2026-54278: unread compressed request bodies can bypass `client_max_size` during cleanup and cause a DoS (bsc#1268559). * CVE-2026-54279: host-only cookies become domain cookies after `CookieJar` persistence (bsc#1268560). * CVE-2026-54280: payload resources are not closed correctly when a client disconnects in the middle of a write and can cause resource starvation (bsc#1268561). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3208=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3208=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3208=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3208=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.38.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.38.1 * python3-aiohttp-3.6.0-150100.3.38.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.38.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.38.1 * python3-aiohttp-3.6.0-150100.3.38.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.38.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.38.1 * python3-aiohttp-3.6.0-150100.3.38.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-debuginfo-3.6.0-150100.3.38.1 * python-aiohttp-debugsource-3.6.0-150100.3.38.1 * python3-aiohttp-3.6.0-150100.3.38.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50269.html * https://www.suse.com/security/cve/CVE-2026-54273.html * https://www.suse.com/security/cve/CVE-2026-54274.html * https://www.suse.com/security/cve/CVE-2026-54275.html * https://www.suse.com/security/cve/CVE-2026-54277.html * https://www.suse.com/security/cve/CVE-2026-54278.html * https://www.suse.com/security/cve/CVE-2026-54279.html * https://www.suse.com/security/cve/CVE-2026-54280.html * https://bugzilla.suse.com/show_bug.cgi?id=1268398 * https://bugzilla.suse.com/show_bug.cgi?id=1268543 * https://bugzilla.suse.com/show_bug.cgi?id=1268544 * https://bugzilla.suse.com/show_bug.cgi?id=1268549 * https://bugzilla.suse.com/show_bug.cgi?id=1268556 * https://bugzilla.suse.com/show_bug.cgi?id=1268559 * https://bugzilla.suse.com/show_bug.cgi?id=1268560 * https://bugzilla.suse.com/show_bug.cgi?id=1268561 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:31:47 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:31:47 -0000 Subject: SUSE-SU-2026:3207-1: important: Security update for python-aiohttp Message-ID: <178483870799.598.14989748037705763411@54f0d6838c13> # Security update for python-aiohttp Announcement ID: SUSE-SU-2026:3207-1 Release Date: 2026-07-23T14:10:51Z Rating: important References: * bsc#1261320 * bsc#1261321 * bsc#1261322 * bsc#1261329 * bsc#1261331 * bsc#1261332 * bsc#1261334 * bsc#1261335 * bsc#1261343 * bsc#1267471 * bsc#1267561 * bsc#1268398 * bsc#1268543 * bsc#1268544 * bsc#1268549 * bsc#1268556 * bsc#1268559 * bsc#1268560 * bsc#1268561 Cross-References: * CVE-2026-22815 * CVE-2026-34513 * CVE-2026-34514 * CVE-2026-34516 * CVE-2026-34517 * CVE-2026-34518 * CVE-2026-34519 * CVE-2026-34520 * CVE-2026-34525 * CVE-2026-34993 * CVE-2026-47265 * CVE-2026-50269 * CVE-2026-54273 * CVE-2026-54274 * CVE-2026-54275 * CVE-2026-54277 * CVE-2026-54278 * CVE-2026-54279 * CVE-2026-54280 CVSS scores: * CVE-2026-22815 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22815 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22815 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-22815 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34513 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34513 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34513 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34513 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34514 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-34514 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34514 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34514 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34516 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34516 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34516 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34516 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34517 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34517 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-34517 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34517 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34518 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34518 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34518 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34518 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34519 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34519 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34519 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34519 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34520 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34520 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34520 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34520 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-34525 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-34525 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-34525 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34525 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34993 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-34993 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2026-34993 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L * CVE-2026-34993 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-47265 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-47265 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47265 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50269 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-50269 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50269 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54273 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54273 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54273 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54274 ( SUSE ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U * CVE-2026-54274 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54274 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54274 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54275 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-54275 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54275 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54277 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54277 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54277 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54278 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54278 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54278 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54278 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54279 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54279 ( NVD ): 1.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54279 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54280 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54280 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for python-aiohttp fixes the following issues * CVE-2026-22815: insufficient restrictions in header/trailer handling can cause uncapped memory usage and a denial of service (bsc#1261320). * CVE-2026-34513: unbounded DNS cache can cause a excessive memory usage and lead to a denial of service (bsc#1261321). * CVE-2026-34514: `content_type` parameter manipulation can lead to header injection (bsc#1261322). * CVE-2026-34516: response with excessive multipart headers can use more memory than intended and cause a denial of service (bsc#1261329). * CVE-2026-34517: large multipart form fields read into memory without size check can cause a denial of service (bsc#1261331). * CVE-2026-34518: retained `Cookie` and `Proxy-Authorization` headers when following redirects can lead to information disclosure (bsc#1261332). * CVE-2026-34519: response `reason` parameter can be use to perform header injection (bsc#1261334). * CVE-2026-34520: improper character handling by C parser can lead to header injection (bsc#1261335). * CVE-2026-34525: multiple `Host` headers allow for potential security bypass in proxy servers (bsc#1261343). * CVE-2026-34993: loading untrusted input in `CookieJar.load()` can lead to arbitrary code execution (bsc#1267471). * CVE-2026-47265: cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect and can leak sensitive data (bsc#1267561). * CVE-2026-50269: improper validation of user-controlled strings allows for CRLF injection in multipart headers (bsc#1268398). * CVE-2026-54273: no limit in the HTTP/1 pipelined request queue can lead to excessive resource consumption (bsc#1268543). * CVE-2026-54274: incomplete websocket frame payloads can bypass memory use limits and cause a DoS via excessive resource consumption (bsc#1268544). * CVE-2026-54275: `server_hostname` TLS SNI check bypass when an existing connection is reused (bsc#1268549). * CVE-2026-54277: `max_line_size` bypass when using the optimised C HTTP parser can lead to excessive resource consumption (bsc#1268556). * CVE-2026-54278: unread compressed request bodies can bypass `client_max_size` during cleanup and cause a DoS (bsc#1268559). * CVE-2026-54279: host-only cookies become domain cookies after `CookieJar` persistence (bsc#1268560). * CVE-2026-54280: payload resources are not closed correctly when a client disconnects in the middle of a write and can cause resource starvation (bsc#1268561). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3207=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3207=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3207=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3207=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3207=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3207=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3207=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3207=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3207=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3207=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3207=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3207=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3207=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22815.html * https://www.suse.com/security/cve/CVE-2026-34513.html * https://www.suse.com/security/cve/CVE-2026-34514.html * https://www.suse.com/security/cve/CVE-2026-34516.html * https://www.suse.com/security/cve/CVE-2026-34517.html * https://www.suse.com/security/cve/CVE-2026-34518.html * https://www.suse.com/security/cve/CVE-2026-34519.html * https://www.suse.com/security/cve/CVE-2026-34520.html * https://www.suse.com/security/cve/CVE-2026-34525.html * https://www.suse.com/security/cve/CVE-2026-34993.html * https://www.suse.com/security/cve/CVE-2026-47265.html * https://www.suse.com/security/cve/CVE-2026-50269.html * https://www.suse.com/security/cve/CVE-2026-54273.html * https://www.suse.com/security/cve/CVE-2026-54274.html * https://www.suse.com/security/cve/CVE-2026-54275.html * https://www.suse.com/security/cve/CVE-2026-54277.html * https://www.suse.com/security/cve/CVE-2026-54278.html * https://www.suse.com/security/cve/CVE-2026-54279.html * https://www.suse.com/security/cve/CVE-2026-54280.html * https://bugzilla.suse.com/show_bug.cgi?id=1261320 * https://bugzilla.suse.com/show_bug.cgi?id=1261321 * https://bugzilla.suse.com/show_bug.cgi?id=1261322 * https://bugzilla.suse.com/show_bug.cgi?id=1261329 * https://bugzilla.suse.com/show_bug.cgi?id=1261331 * https://bugzilla.suse.com/show_bug.cgi?id=1261332 * https://bugzilla.suse.com/show_bug.cgi?id=1261334 * https://bugzilla.suse.com/show_bug.cgi?id=1261335 * https://bugzilla.suse.com/show_bug.cgi?id=1261343 * https://bugzilla.suse.com/show_bug.cgi?id=1267471 * https://bugzilla.suse.com/show_bug.cgi?id=1267561 * https://bugzilla.suse.com/show_bug.cgi?id=1268398 * https://bugzilla.suse.com/show_bug.cgi?id=1268543 * https://bugzilla.suse.com/show_bug.cgi?id=1268544 * https://bugzilla.suse.com/show_bug.cgi?id=1268549 * https://bugzilla.suse.com/show_bug.cgi?id=1268556 * https://bugzilla.suse.com/show_bug.cgi?id=1268559 * https://bugzilla.suse.com/show_bug.cgi?id=1268560 * https://bugzilla.suse.com/show_bug.cgi?id=1268561 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:32:00 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:32:00 -0000 Subject: SUSE-SU-2026:3206-1: important: Security update for wget Message-ID: <178483872065.598.14882066704563259541@54f0d6838c13> # Security update for wget Announcement ID: SUSE-SU-2026:3206-1 Release Date: 2026-07-23T14:08:08Z Rating: important References: * bsc#1271033 * bsc#1271034 * bsc#1271035 * bsc#1271036 * bsc#1271320 * bsc#1272219 Cross-References: * CVE-2026-15146 * CVE-2026-58469 * CVE-2026-58470 * CVE-2026-58471 * CVE-2026-58472 CVSS scores: * CVE-2026-15146 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-15146 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-15146 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58469 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58469 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58470 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58470 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58470 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58470 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58471 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-58471 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58471 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58471 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58471 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58472 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-58472 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58472 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58472 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58472 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities and has one security fix can now be installed. ## Description: This update for wget fixes the following issues: * CVE-2026-15146: unvalidated IP address in an FTP PASV response can lead to server-side request forgery (bsc#1271320). * CVE-2026-58469: Metalink document containing a whitespace-only URL can cause a heap buffer underread (bsc#1271033). * CVE-2026-58470: server-controlled `Content-Range` header values can cause an integer overflow in `parse_content_range()` (bsc#1271034). * CVE-2026-58471: server-supplied filenames requiring character set conversion could lead to heap memory corruption (bsc#1271035). * CVE-2026-58472: crafted HTML attribute with a large number of characters requiring entity encoding can lead to a heap buffer overflow (bsc#1271036). * Fix metalink regression from CVE-2026-58469 fix (bsc#1272219). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3206=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3206=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3206=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3206=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3206=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3206=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3206=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3206=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3206=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * wget-debuginfo-1.20.3-150000.3.34.1 * wget-1.20.3-150000.3.34.1 * wget-debugsource-1.20.3-150000.3.34.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * wget-debuginfo-1.20.3-150000.3.34.1 * wget-debugsource-1.20.3-150000.3.34.1 * wget-1.20.3-150000.3.34.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * wget-debuginfo-1.20.3-150000.3.34.1 * wget-1.20.3-150000.3.34.1 * wget-debugsource-1.20.3-150000.3.34.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * wget-debuginfo-1.20.3-150000.3.34.1 * wget-1.20.3-150000.3.34.1 * wget-debugsource-1.20.3-150000.3.34.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * wget-debuginfo-1.20.3-150000.3.34.1 * wget-debugsource-1.20.3-150000.3.34.1 * wget-1.20.3-150000.3.34.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * wget-debuginfo-1.20.3-150000.3.34.1 * wget-1.20.3-150000.3.34.1 * wget-debugsource-1.20.3-150000.3.34.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * wget-debuginfo-1.20.3-150000.3.34.1 * wget-debugsource-1.20.3-150000.3.34.1 * wget-1.20.3-150000.3.34.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * wget-debuginfo-1.20.3-150000.3.34.1 * wget-1.20.3-150000.3.34.1 * wget-debugsource-1.20.3-150000.3.34.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * wget-debuginfo-1.20.3-150000.3.34.1 * wget-1.20.3-150000.3.34.1 * wget-debugsource-1.20.3-150000.3.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15146.html * https://www.suse.com/security/cve/CVE-2026-58469.html * https://www.suse.com/security/cve/CVE-2026-58470.html * https://www.suse.com/security/cve/CVE-2026-58471.html * https://www.suse.com/security/cve/CVE-2026-58472.html * https://bugzilla.suse.com/show_bug.cgi?id=1271033 * https://bugzilla.suse.com/show_bug.cgi?id=1271034 * https://bugzilla.suse.com/show_bug.cgi?id=1271035 * https://bugzilla.suse.com/show_bug.cgi?id=1271036 * https://bugzilla.suse.com/show_bug.cgi?id=1271320 * https://bugzilla.suse.com/show_bug.cgi?id=1272219 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:32:08 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:32:08 -0000 Subject: SUSE-SU-2026:3205-1: moderate: Security update for wget Message-ID: <178483872863.598.17600999062907023644@54f0d6838c13> # Security update for wget Announcement ID: SUSE-SU-2026:3205-1 Release Date: 2026-07-23T14:05:51Z Rating: moderate References: * bsc#1271034 * bsc#1271036 * bsc#1271320 Cross-References: * CVE-2026-15146 * CVE-2026-58470 * CVE-2026-58472 CVSS scores: * CVE-2026-15146 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-15146 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-15146 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58470 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58470 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58470 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58470 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58472 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-58472 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58472 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58472 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-58472 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for wget fixes the following issues * CVE-2026-15146: unvalidated IP address in an FTP PASV response can lead to server-side request forgery (bsc#1271320). * CVE-2026-58470: server-controlled `Content-Range` header values can cause an integer overflow in `parse_content_range()` (bsc#1271034). * CVE-2026-58472: crafted HTML attribute with a large number of characters requiring entity encoding can lead to a heap buffer overflow (bsc#1271036). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3205=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * wget-debuginfo-1.14-21.28.1 * wget-1.14-21.28.1 * wget-debugsource-1.14-21.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15146.html * https://www.suse.com/security/cve/CVE-2026-58470.html * https://www.suse.com/security/cve/CVE-2026-58472.html * https://bugzilla.suse.com/show_bug.cgi?id=1271034 * https://bugzilla.suse.com/show_bug.cgi?id=1271036 * https://bugzilla.suse.com/show_bug.cgi?id=1271320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:32:15 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:32:15 -0000 Subject: SUSE-SU-2026:0367-2: moderate: Security update for python-urllib3 Message-ID: <178483873546.598.17699925612434206262@54f0d6838c13> # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:0367-2 Release Date: 2026-07-23T13:46:58Z Rating: moderate References: * bsc#1254866 * bsc#1254867 Cross-References: * CVE-2025-66418 * CVE-2025-66471 CVSS scores: * CVE-2025-66418 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66418 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66418 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66418 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-66471 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66471 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66471 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66471 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-urllib3 fixes the following issues: * CVE-2025-66471: excessive resource consumption via decompression of highly compressed data in Streaming API (bsc#1254867). * CVE-2025-66418: resource exhaustion via unbounded number of links in the decompression chain (bsc#1254866). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-367=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-367=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-367=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-367=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-367=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-367=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-367=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-367=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-367=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-367=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-urllib3-2.0.7-150400.7.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-urllib3-2.0.7-150400.7.27.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-urllib3-2.0.7-150400.7.27.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-urllib3-2.0.7-150400.7.27.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-urllib3-2.0.7-150400.7.27.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-urllib3-2.0.7-150400.7.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-urllib3-2.0.7-150400.7.27.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python311-urllib3-2.0.7-150400.7.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-urllib3-2.0.7-150400.7.27.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-urllib3-2.0.7-150400.7.27.1 ## References: * https://www.suse.com/security/cve/CVE-2025-66418.html * https://www.suse.com/security/cve/CVE-2025-66471.html * https://bugzilla.suse.com/show_bug.cgi?id=1254866 * https://bugzilla.suse.com/show_bug.cgi?id=1254867 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:32:26 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:32:26 -0000 Subject: SUSE-SU-2026:3203-1: important: Security update for kubevirt Message-ID: <178483874604.598.1981436321564847918@54f0d6838c13> # Security update for kubevirt Announcement ID: SUSE-SU-2026:3203-1 Release Date: 2026-07-23T13:33:52Z Rating: important References: * bsc#1262265 * bsc#1265736 * bsc#1266151 * bsc#1266575 * bsc#1267120 Cross-References: * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33814 * CVE-2026-35469 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-35469 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for kubevirt fixes the following issues: * Security: re-vendor the bundled Go dependencies (no upstream source changes; tarball rebuilt from v1.7.4 with updated go.mod/vendor): * golang.org/x/net v0.48.0 -> v0.55.0: CVE-2026-33814 (bsc#1265736), CVE-2026-39821 (bsc#1266575), CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-42502, CVE-2026-42506 (bsc#1267120) * golang.org/x/crypto v0.46.0 -> v0.52.0: CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598 (bsc#1266151) * github.com/moby/spdystream v0.5.0 -> v0.5.1 folded into the vendor tree; * Build with Go >= 1.25 (required by golang.org/x/net 0.55). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3203=1 ## Package List: * Containers Module 15-SP7 (aarch64 x86_64) * kubevirt-manifests-1.7.4-150700.3.30.1 * kubevirt-virtctl-debuginfo-1.7.4-150700.3.30.1 * kubevirt-virtctl-1.7.4-150700.3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1262265 * https://bugzilla.suse.com/show_bug.cgi?id=1265736 * https://bugzilla.suse.com/show_bug.cgi?id=1266151 * https://bugzilla.suse.com/show_bug.cgi?id=1266575 * https://bugzilla.suse.com/show_bug.cgi?id=1267120 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:32:36 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:32:36 -0000 Subject: SUSE-RU-2026:3202-1: important: Recommended update for pesign Message-ID: <178483875620.598.3541659866218603240@54f0d6838c13> # Recommended update for pesign Announcement ID: SUSE-RU-2026:3202-1 Release Date: 2026-07-23T13:12:55Z Rating: important References: * bsc#1271405 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for pesign fixes the following issues: * Set stricter permissions on /etc/pki/pesign (bsc#1271405) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3202=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3202=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3202=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3202=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3202=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3202=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3202=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3202=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3202=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3202=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3202=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * pesign-systemd-0.112-150000.4.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * pesign-systemd-0.112-150000.4.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * pesign-systemd-0.112-150000.4.29.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * pesign-systemd-0.112-150000.4.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * pesign-systemd-0.112-150000.4.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * pesign-systemd-0.112-150000.4.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * pesign-systemd-0.112-150000.4.29.1 * Basesystem Module 15-SP7 (noarch) * pesign-systemd-0.112-150000.4.29.1 * Basesystem Module 15-SP7 (aarch64 x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * pesign-systemd-0.112-150000.4.29.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * pesign-systemd-0.112-150000.4.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * pesign-debugsource-0.112-150000.4.29.1 * pesign-0.112-150000.4.29.1 * pesign-debuginfo-0.112-150000.4.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * pesign-systemd-0.112-150000.4.29.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271405 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 23 20:32:42 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 23 Jul 2026 20:32:42 -0000 Subject: SUSE-SU-2026:0255-2: moderate: Security update for python-urllib3 Message-ID: <178483876231.598.12935973180267009363@54f0d6838c13> # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:0255-2 Release Date: 2026-07-23T12:16:46Z Rating: moderate References: * bsc#1256331 Cross-References: * CVE-2026-21441 CVSS scores: * CVE-2026-21441 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-21441 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-21441 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-21441 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21441 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for python-urllib3 fixes the following issues: * CVE-2026-21441: Fixed excessive resource consumption during decompression of data in HTTP redirect responses (bsc#1256331) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-255=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-255=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-255=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-255=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-255=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-255=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-255=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-255=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-255=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-255=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-urllib3-2.0.7-150400.7.24.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-urllib3-2.0.7-150400.7.24.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python311-urllib3-2.0.7-150400.7.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-urllib3-2.0.7-150400.7.24.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-urllib3-2.0.7-150400.7.24.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-urllib3-2.0.7-150400.7.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-urllib3-2.0.7-150400.7.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-urllib3-2.0.7-150400.7.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-urllib3-2.0.7-150400.7.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-urllib3-2.0.7-150400.7.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-21441.html * https://bugzilla.suse.com/show_bug.cgi?id=1256331 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:31:42 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:31:42 -0000 Subject: SUSE-SU-2026:3225-1: moderate: Security update for apache-commons-compress, apache-ivy, brotli-java, zstd-jni Message-ID: <178488190241.807.14792918625958136406@cbbac00f79c6> # Security update for apache-commons-compress, apache-ivy, brotli-java, zstd-jni Announcement ID: SUSE-SU-2026:3225-1 Release Date: 2026-07-23T18:36:42Z Rating: moderate References: * bsc#1269480 * bsc#1271727 Cross-References: * CVE-2026-26032 CVSS scores: * CVE-2026-26032 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-26032 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-26032 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for apache-commons-compress, apache-ivy, brotli-java, zstd-jni fixes the following issue Security issues fixed: * CVE-2026-26032: improper pathname limitation in `PackagerResolver` allows for arbitrary files writes outside of the configured `buildRoot` directory (bsc#1271727). Other updates and bugfixes: * Update `apache-commons-compress` to 1.28.0. * Update `apache-ivy` to 2.6.0. * Include `brotli-java` and update to 1.2.0. * Include `zstd-jni` and update to v1.5.7.11. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3225=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3225=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * apache-commons-compress-1.28.0-150200.3.19.1 * Development Tools Module 15-SP7 (noarch) * apache-ivy-2.6.0-150200.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26032.html * https://bugzilla.suse.com/show_bug.cgi?id=1269480 * https://bugzilla.suse.com/show_bug.cgi?id=1271727 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:32:00 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:32:00 -0000 Subject: SUSE-SU-2026:3224-1: important: Security update for SVT-AV1, libyuv0, libaom3 Message-ID: <178488192003.807.5955211648228885848@cbbac00f79c6> # Security update for SVT-AV1, libyuv0, libaom3 Announcement ID: SUSE-SU-2026:3224-1 Release Date: 2026-07-23T18:34:25Z Rating: important References: * bsc#1263678 * bsc#1268242 * bsc#1268650 * bsc#1268651 * bsc#1268653 * bsc#1268655 Cross-References: * CVE-2026-56208 * CVE-2026-56209 * CVE-2026-56210 * CVE-2026-56211 CVSS scores: * CVE-2026-56208 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56208 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56209 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56209 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56210 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56210 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56211 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56211 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities and has two security fixes can now be installed. ## Description: This update for SVT-AV1, libyuv0, libaom3 fixes the following issues: * CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap- based buffer overflow and a process crash (bsc#1268650). * CVE-2026-56209: crafted video frames with specific Y-plane pixel values can lead to an arbitrary memory write (bsc#1268651). * CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out- of-bounds heap read (bsc#1268653). * CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to remote code execution (bsc#1268655). Bug fixes: * Add SVT-AV1, libyuv0, libaom3 to Basesystem, no source changes. (bsc#1263678). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3224=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3224=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3224=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3224=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3224=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * aom-tools-debuginfo-3.7.1-150600.3.9.1 * libaom-debugsource-3.7.1-150600.3.9.1 * libaom-devel-3.7.1-150600.3.9.1 * libyuv-tools-20230517+a377993-150600.3.4.2 * libyuv-devel-20230517+a377993-150600.3.4.2 * libyuv0-20230517+a377993-150600.3.4.2 * libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2 * libaom3-3.7.1-150600.3.9.1 * libyuv0-debuginfo-20230517+a377993-150600.3.4.2 * aom-tools-3.7.1-150600.3.9.1 * libaom3-debuginfo-3.7.1-150600.3.9.1 * libyuv-debugsource-20230517+a377993-150600.3.4.2 * openSUSE Leap 15.6 (aarch64 x86_64) * SVT-AV1-debugsource-1.8.0-150600.3.2.5 * libSvtAv1Enc1-1.8.0-150600.3.2.5 * SVT-AV1-debuginfo-1.8.0-150600.3.2.5 * libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5 * libSvtAv1Dec0-1.8.0-150600.3.2.5 * SVT-AV1-devel-1.8.0-150600.3.2.5 * libSvtAv1Dec0-debuginfo-1.8.0-150600.3.2.5 * SVT-AV1-1.8.0-150600.3.2.5 * openSUSE Leap 15.6 (noarch) * libaom-devel-doc-3.7.1-150600.3.9.3 * openSUSE Leap 15.6 (x86_64) * libyuv0-32bit-20230517+a377993-150600.3.4.2 * libaom3-32bit-debuginfo-3.7.1-150600.3.9.1 * libaom3-32bit-3.7.1-150600.3.9.1 * libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libaom3-64bit-3.7.1-150600.3.9.1 * libaom3-64bit-debuginfo-3.7.1-150600.3.9.1 * libyuv0-64bit-debuginfo-20230517+a377993-150600.3.4.2 * libyuv0-64bit-20230517+a377993-150600.3.4.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libaom3-debuginfo-3.7.1-150600.3.9.1 * aom-tools-debuginfo-3.7.1-150600.3.9.1 * libaom-debugsource-3.7.1-150600.3.9.1 * libaom-devel-3.7.1-150600.3.9.1 * libyuv-tools-20230517+a377993-150600.3.4.2 * libyuv0-20230517+a377993-150600.3.4.2 * libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2 * libyuv0-debuginfo-20230517+a377993-150600.3.4.2 * libaom3-3.7.1-150600.3.9.1 * aom-tools-3.7.1-150600.3.9.1 * libyuv-devel-20230517+a377993-150600.3.4.2 * libyuv-debugsource-20230517+a377993-150600.3.4.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libyuv0-32bit-20230517+a377993-150600.3.4.2 * libaom3-32bit-3.7.1-150600.3.9.1 * libaom3-32bit-debuginfo-3.7.1-150600.3.9.1 * libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * SVT-AV1-debuginfo-1.8.0-150600.3.2.5 * SVT-AV1-debugsource-1.8.0-150600.3.2.5 * libSvtAv1Enc1-1.8.0-150600.3.2.5 * libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * libaom-devel-doc-3.7.1-150600.3.9.3 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libaom-debugsource-3.7.1-150600.3.9.1 * libyuv0-20230517+a377993-150600.3.4.2 * libyuv0-debuginfo-20230517+a377993-150600.3.4.2 * libaom3-3.7.1-150600.3.9.1 * libyuv-debugsource-20230517+a377993-150600.3.4.2 * libaom3-debuginfo-3.7.1-150600.3.9.1 * Basesystem Module 15-SP7 (aarch64 x86_64) * libSvtAv1Enc1-1.8.0-150600.3.2.5 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * aom-tools-debuginfo-3.7.1-150600.3.9.1 * libaom-debugsource-3.7.1-150600.3.9.1 * libaom-devel-3.7.1-150600.3.9.1 * aom-tools-3.7.1-150600.3.9.1 * libyuv-tools-20230517+a377993-150600.3.4.2 * libyuv-devel-20230517+a377993-150600.3.4.2 * libyuv0-20230517+a377993-150600.3.4.2 * libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2 * libyuv0-debuginfo-20230517+a377993-150600.3.4.2 * libaom3-3.7.1-150600.3.9.1 * libyuv-debugsource-20230517+a377993-150600.3.4.2 * libaom3-debuginfo-3.7.1-150600.3.9.1 * Desktop Applications Module 15-SP7 (aarch64 x86_64) * SVT-AV1-debuginfo-1.8.0-150600.3.2.5 * SVT-AV1-debugsource-1.8.0-150600.3.2.5 * libSvtAv1Enc1-1.8.0-150600.3.2.5 * libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5 * Desktop Applications Module 15-SP7 (x86_64) * libaom3-32bit-3.7.1-150600.3.9.1 * libyuv0-32bit-20230517+a377993-150600.3.4.2 * libaom3-32bit-debuginfo-3.7.1-150600.3.9.1 * libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2 * Desktop Applications Module 15-SP7 (noarch) * libaom-devel-doc-3.7.1-150600.3.9.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * SVT-AV1-debugsource-1.8.0-150600.3.2.5 * SVT-AV1-debuginfo-1.8.0-150600.3.2.5 * libSvtAv1Enc1-1.8.0-150600.3.2.5 * libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2 * libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5 * libaom3-32bit-3.7.1-150600.3.9.1 * libyuv0-32bit-20230517+a377993-150600.3.4.2 * libaom3-32bit-debuginfo-3.7.1-150600.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libaom3-debuginfo-3.7.1-150600.3.9.1 * aom-tools-debuginfo-3.7.1-150600.3.9.1 * libaom-debugsource-3.7.1-150600.3.9.1 * libaom-devel-3.7.1-150600.3.9.1 * aom-tools-3.7.1-150600.3.9.1 * libyuv-tools-20230517+a377993-150600.3.4.2 * libyuv0-20230517+a377993-150600.3.4.2 * libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2 * libaom3-3.7.1-150600.3.9.1 * libyuv0-debuginfo-20230517+a377993-150600.3.4.2 * libyuv-debugsource-20230517+a377993-150600.3.4.2 * libyuv-devel-20230517+a377993-150600.3.4.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * libaom-devel-doc-3.7.1-150600.3.9.3 ## References: * https://www.suse.com/security/cve/CVE-2026-56208.html * https://www.suse.com/security/cve/CVE-2026-56209.html * https://www.suse.com/security/cve/CVE-2026-56210.html * https://www.suse.com/security/cve/CVE-2026-56211.html * https://bugzilla.suse.com/show_bug.cgi?id=1263678 * https://bugzilla.suse.com/show_bug.cgi?id=1268242 * https://bugzilla.suse.com/show_bug.cgi?id=1268650 * https://bugzilla.suse.com/show_bug.cgi?id=1268651 * https://bugzilla.suse.com/show_bug.cgi?id=1268653 * https://bugzilla.suse.com/show_bug.cgi?id=1268655 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:32:06 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:32:06 -0000 Subject: SUSE-SU-2026:3223-1: moderate: Security update for net-tools Message-ID: <178488192638.807.9967714035303352327@cbbac00f79c6> # Security update for net-tools Announcement ID: SUSE-SU-2026:3223-1 Release Date: 2026-07-23T18:31:56Z Rating: moderate References: * bsc#1254323 Cross-References: * CVE-2024-58251 CVSS scores: * CVE-2024-58251 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-58251 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-58251 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * Legacy Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for net-tools fixes the following issues: * CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3223=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3223=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3223=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3223=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3223=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3223=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3223=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * net-tools-debugsource-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-debuginfo-2.0+git20170221.479bb4a-150000.5.18.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * net-tools-debugsource-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-debuginfo-2.0+git20170221.479bb4a-150000.5.18.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * net-tools-debugsource-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-debuginfo-2.0+git20170221.479bb4a-150000.5.18.1 * Basesystem Module 15-SP7 (noarch) * net-tools-lang-2.0+git20170221.479bb4a-150000.5.18.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * net-tools-debugsource-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-deprecated-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-debuginfo-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-deprecated-debuginfo-2.0+git20170221.479bb4a-150000.5.18.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * net-tools-debugsource-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-debuginfo-2.0+git20170221.479bb4a-150000.5.18.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * net-tools-debugsource-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-debuginfo-2.0+git20170221.479bb4a-150000.5.18.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * net-tools-debugsource-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-2.0+git20170221.479bb4a-150000.5.18.1 * net-tools-debuginfo-2.0+git20170221.479bb4a-150000.5.18.1 ## References: * https://www.suse.com/security/cve/CVE-2024-58251.html * https://bugzilla.suse.com/show_bug.cgi?id=1254323 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:32:13 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:32:13 -0000 Subject: SUSE-SU-2026:3222-1: moderate: Security update for net-tools Message-ID: <178488193375.807.8101695777936332799@cbbac00f79c6> # Security update for net-tools Announcement ID: SUSE-SU-2026:3222-1 Release Date: 2026-07-23T18:30:38Z Rating: moderate References: * bsc#1254323 Cross-References: * CVE-2024-58251 CVSS scores: * CVE-2024-58251 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-58251 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-58251 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for net-tools fixes the following issues: * CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3222=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * net-tools-1.60-765.20.1 * net-tools-debugsource-1.60-765.20.1 * net-tools-debuginfo-1.60-765.20.1 ## References: * https://www.suse.com/security/cve/CVE-2024-58251.html * https://bugzilla.suse.com/show_bug.cgi?id=1254323 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:32:19 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:32:19 -0000 Subject: SUSE-SU-2026:3221-1: critical: Security update for MozillaFirefox Message-ID: <178488193990.807.10247641026763427848@cbbac00f79c6> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:3221-1 Release Date: 2026-07-23T17:39:41Z Rating: critical References: * bsc#1271649 Cross-References: * CVE-2026-15718 * CVE-2026-15719 * CVE-2026-16349 * CVE-2026-16350 * CVE-2026-16351 * CVE-2026-16352 * CVE-2026-16353 * CVE-2026-16354 * CVE-2026-16355 * CVE-2026-16356 * CVE-2026-16357 * CVE-2026-16358 * CVE-2026-16359 * CVE-2026-16360 * CVE-2026-16361 * CVE-2026-16362 * CVE-2026-16363 * CVE-2026-16368 * CVE-2026-16369 * CVE-2026-16371 * CVE-2026-16374 * CVE-2026-16375 * CVE-2026-16377 * CVE-2026-16379 * CVE-2026-16381 * CVE-2026-16383 * CVE-2026-16387 * CVE-2026-16390 * CVE-2026-16391 * CVE-2026-16396 * CVE-2026-16405 * CVE-2026-16412 CVSS scores: * CVE-2026-15718 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15719 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-16349 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16350 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16351 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16352 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16353 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16354 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16356 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16358 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16359 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16360 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16361 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16362 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16363 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16368 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16369 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16371 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16374 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16375 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16377 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16379 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16381 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16390 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16396 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16412 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 32 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issue: * Firefox Extended Support Release 140.13.0 ESR (MFSA 2026-70, bsc#1271649): * CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component. * CVE-2026-15719: Site isolation issue in the DOM: Navigation component. * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component. * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component. * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component. * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component. * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component. * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component. * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component. * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component. * CVE-2026-16357: Incorrect boundary conditions in the Graphics component. * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component. * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component. * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153. * CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13. * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component. * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component. * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component. * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component. * CVE-2026-16371: Privilege escalation in the DOM: Navigation component. * CVE-2026-16374: Information disclosure in the Framework component in DevTools. * CVE-2026-16375: Site isolation issue in the Networking: HTTP component. * CVE-2026-16377: Mitigation bypass in the PDF Viewer component. * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component. * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component. * CVE-2026-16383: Mitigation bypass in the DOM: Networking component. * CVE-2026-16387: Site isolation issue in the Networking component. * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component. * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component. * CVE-2026-16396: Privilege escalation in WebExtensions. * CVE-2026-16405: Information disclosure in the Networking: WebSockets component. * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3221=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3221=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3221=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3221=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3221=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3221=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3221=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3221=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3221=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3221=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3221=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * Desktop Applications Module 15-SP7 (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * MozillaFirefox-debugsource-140.13.0-150200.152.248.1 * MozillaFirefox-translations-other-140.13.0-150200.152.248.1 * MozillaFirefox-debuginfo-140.13.0-150200.152.248.1 * MozillaFirefox-translations-common-140.13.0-150200.152.248.1 * MozillaFirefox-140.13.0-150200.152.248.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * MozillaFirefox-devel-140.13.0-150200.152.248.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15718.html * https://www.suse.com/security/cve/CVE-2026-15719.html * https://www.suse.com/security/cve/CVE-2026-16349.html * https://www.suse.com/security/cve/CVE-2026-16350.html * https://www.suse.com/security/cve/CVE-2026-16351.html * https://www.suse.com/security/cve/CVE-2026-16352.html * https://www.suse.com/security/cve/CVE-2026-16353.html * https://www.suse.com/security/cve/CVE-2026-16354.html * https://www.suse.com/security/cve/CVE-2026-16355.html * https://www.suse.com/security/cve/CVE-2026-16356.html * https://www.suse.com/security/cve/CVE-2026-16357.html * https://www.suse.com/security/cve/CVE-2026-16358.html * https://www.suse.com/security/cve/CVE-2026-16359.html * https://www.suse.com/security/cve/CVE-2026-16360.html * https://www.suse.com/security/cve/CVE-2026-16361.html * https://www.suse.com/security/cve/CVE-2026-16362.html * https://www.suse.com/security/cve/CVE-2026-16363.html * https://www.suse.com/security/cve/CVE-2026-16368.html * https://www.suse.com/security/cve/CVE-2026-16369.html * https://www.suse.com/security/cve/CVE-2026-16371.html * https://www.suse.com/security/cve/CVE-2026-16374.html * https://www.suse.com/security/cve/CVE-2026-16375.html * https://www.suse.com/security/cve/CVE-2026-16377.html * https://www.suse.com/security/cve/CVE-2026-16379.html * https://www.suse.com/security/cve/CVE-2026-16381.html * https://www.suse.com/security/cve/CVE-2026-16383.html * https://www.suse.com/security/cve/CVE-2026-16387.html * https://www.suse.com/security/cve/CVE-2026-16390.html * https://www.suse.com/security/cve/CVE-2026-16391.html * https://www.suse.com/security/cve/CVE-2026-16396.html * https://www.suse.com/security/cve/CVE-2026-16405.html * https://www.suse.com/security/cve/CVE-2026-16412.html * https://bugzilla.suse.com/show_bug.cgi?id=1271649 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:32:26 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:32:26 -0000 Subject: SUSE-SU-2026:3220-1: moderate: Security update for nmap Message-ID: <178488194612.807.3809164090614863223@cbbac00f79c6> # Security update for nmap Announcement ID: SUSE-SU-2026:3220-1 Release Date: 2026-07-23T17:37:38Z Rating: moderate References: * bsc#1269570 Cross-References: * CVE-2026-58058 CVSS scores: * CVE-2026-58058 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58058 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58058 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for nmap fixes the following issue: * CVE-2026-58058: crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash (bsc#1269570). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3220=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * ncat-debuginfo-7.92-150400.3.3.1 * ncat-7.92-150400.3.3.1 * nmap-debuginfo-7.92-150400.3.3.1 * nping-7.92-150400.3.3.1 * nmap-7.92-150400.3.3.1 * nping-debuginfo-7.92-150400.3.3.1 * nmap-debugsource-7.92-150400.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58058.html * https://bugzilla.suse.com/show_bug.cgi?id=1269570 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:33:18 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:33:18 -0000 Subject: SUSE-SU-2026:3219-1: important: Security update for ImageMagick Message-ID: <178488199848.807.12795530238562968502@cbbac00f79c6> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3219-1 Release Date: 2026-07-23T17:35:28Z Rating: important References: * bsc#1268640 * bsc#1268878 * bsc#1270006 * bsc#1270081 * bsc#1271100 * bsc#1271293 * bsc#1271294 * bsc#1271311 * bsc#1271312 * bsc#1271313 * bsc#1271314 * bsc#1271315 * bsc#1271316 * bsc#1271484 * bsc#1271486 * bsc#1271487 * bsc#1271488 * bsc#1271489 * bsc#1271490 * bsc#1271491 * bsc#1271492 * bsc#1271493 * bsc#1271494 * bsc#1271495 * bsc#1271496 * bsc#1271497 Cross-References: * CVE-2026-55628 * CVE-2026-56362 * CVE-2026-56366 * CVE-2026-56372 * CVE-2026-56373 * CVE-2026-56375 * CVE-2026-56377 * CVE-2026-56379 * CVE-2026-61464 * CVE-2026-61465 * CVE-2026-61857 * CVE-2026-61858 * CVE-2026-61859 * CVE-2026-61860 * CVE-2026-61861 * CVE-2026-61862 * CVE-2026-61863 * CVE-2026-61864 * CVE-2026-61865 * CVE-2026-61866 * CVE-2026-61867 * CVE-2026-61868 * CVE-2026-61869 * CVE-2026-61870 * CVE-2026-61872 CVSS scores: * CVE-2026-55628 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55628 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56362 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56362 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56362 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56366 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56366 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56366 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56366 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56366 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56372 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56372 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56372 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56373 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56373 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56375 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56375 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56375 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56375 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56377 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-56377 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56377 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56377 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-61464 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61464 ( NVD ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61464 ( NVD ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61465 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61465 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-61857 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61857 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61857 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61857 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61857 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61858 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61858 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61858 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61859 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-61859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61859 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61859 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61860 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61860 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61860 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61861 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61861 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61862 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61862 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61862 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61863 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61863 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61863 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61863 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61864 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61864 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61864 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61864 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61865 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61865 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61865 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61865 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61866 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61866 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61867 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61867 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61867 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61867 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61868 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61869 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61870 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61870 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61872 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61872 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61872 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 25 vulnerabilities and has one security fix can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). * CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). * CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). * CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314). * CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640, bsc#1271315). * CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495). * CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006). * CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496). * CVE-2026-61465: policy bypass possible with matrix-backed operations (bsc#1271313). * CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312). * CVE-2026-61858: policy bypass in APNG encoder and delegates due to a missing check (bsc#1271311). * CVE-2026-61859: policy bypass in script operation due to missing checks (bsc#1271497). * CVE-2026-61860: use-after-free when `freetype` initialization fails (bsc#1271494). * CVE-2026-61861: use-after-free in `FormatMagickCaption` when memory allocation fails (bsc#1271294). * CVE-2026-61862: information disclosure when printing profiles with debug enabled (bsc#1271493). * CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not be created (bsc#1271492). * CVE-2026-61864: memory leak in color transformation to log colorspace when operation fails (bsc#1271491). * CVE-2026-61865: memory leak in hough lines operation when an operation fails (bsc#1271490). * CVE-2026-61866: memory leak in JNG encoder when a blob could not be opened (bsc#1271489). * CVE-2026-61867: memory leak in TIFF encoder when an allocation fails (bsc#1271488). * CVE-2026-61868: memory leak in YUV decoder when opening of blob fails (bsc#1271487). * CVE-2026-61869: memory leak in MIFF encoder when allocation fails (bsc#1271486). * CVE-2026-61870: memory leak in VIFF encoder when allocation fails (bsc#1271293). * CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile- geometry` is specified (bsc#1271484). * Extend CVE-2026-56379 patch by f63c78b (bsc#1268878). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3219=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3219=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3219=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libMagick++-devel-7.1.1.21-150600.3.80.2 * perl-PerlMagick-7.1.1.21-150600.3.80.2 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2 * ImageMagick-7.1.1.21-150600.3.80.2 * ImageMagick-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2 * libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2 * ImageMagick-debugsource-7.1.1.21-150600.3.80.2 * ImageMagick-devel-7.1.1.21-150600.3.80.2 * libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2 * perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.1.21-150600.3.80.2 * perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2 * libMagick++-devel-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-7.1.1.21-150600.3.80.2 * libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2 * ImageMagick-debugsource-7.1.1.21-150600.3.80.2 * libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2 * ImageMagick-extra-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2 * perl-PerlMagick-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-extra-7.1.1.21-150600.3.80.2 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2 * ImageMagick-devel-7.1.1.21-150600.3.80.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libMagick++-7_Q16HDRI5-64bit-7.1.1.21-150600.3.80.2 * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-64bit-7.1.1.21-150600.3.80.2 * libMagick++-devel-64bit-7.1.1.21-150600.3.80.2 * libMagickCore-7_Q16HDRI10-64bit-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-devel-64bit-7.1.1.21-150600.3.80.2 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.80.2 * openSUSE Leap 15.6 (x86_64) * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-devel-32bit-7.1.1.21-150600.3.80.2 * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.80.2 * libMagickCore-7_Q16HDRI10-32bit-7.1.1.21-150600.3.80.2 * libMagick++-devel-32bit-7.1.1.21-150600.3.80.2 * libMagick++-7_Q16HDRI5-32bit-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-32bit-7.1.1.21-150600.3.80.2 * openSUSE Leap 15.6 (noarch) * ImageMagick-doc-7.1.1.21-150600.3.80.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2 * perl-PerlMagick-7.1.1.21-150600.3.80.2 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2 * libMagick++-devel-7.1.1.21-150600.3.80.2 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2 * ImageMagick-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2 * ImageMagick-debuginfo-7.1.1.21-150600.3.80.2 * libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2 * ImageMagick-debugsource-7.1.1.21-150600.3.80.2 * ImageMagick-devel-7.1.1.21-150600.3.80.2 * libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2 * perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2 * ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2 ## References: * https://www.suse.com/security/cve/CVE-2026-55628.html * https://www.suse.com/security/cve/CVE-2026-56362.html * https://www.suse.com/security/cve/CVE-2026-56366.html * https://www.suse.com/security/cve/CVE-2026-56372.html * https://www.suse.com/security/cve/CVE-2026-56373.html * https://www.suse.com/security/cve/CVE-2026-56375.html * https://www.suse.com/security/cve/CVE-2026-56377.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://www.suse.com/security/cve/CVE-2026-61464.html * https://www.suse.com/security/cve/CVE-2026-61465.html * https://www.suse.com/security/cve/CVE-2026-61857.html * https://www.suse.com/security/cve/CVE-2026-61858.html * https://www.suse.com/security/cve/CVE-2026-61859.html * https://www.suse.com/security/cve/CVE-2026-61860.html * https://www.suse.com/security/cve/CVE-2026-61861.html * https://www.suse.com/security/cve/CVE-2026-61862.html * https://www.suse.com/security/cve/CVE-2026-61863.html * https://www.suse.com/security/cve/CVE-2026-61864.html * https://www.suse.com/security/cve/CVE-2026-61865.html * https://www.suse.com/security/cve/CVE-2026-61866.html * https://www.suse.com/security/cve/CVE-2026-61867.html * https://www.suse.com/security/cve/CVE-2026-61868.html * https://www.suse.com/security/cve/CVE-2026-61869.html * https://www.suse.com/security/cve/CVE-2026-61870.html * https://www.suse.com/security/cve/CVE-2026-61872.html * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1270006 * https://bugzilla.suse.com/show_bug.cgi?id=1270081 * https://bugzilla.suse.com/show_bug.cgi?id=1271100 * https://bugzilla.suse.com/show_bug.cgi?id=1271293 * https://bugzilla.suse.com/show_bug.cgi?id=1271294 * https://bugzilla.suse.com/show_bug.cgi?id=1271311 * https://bugzilla.suse.com/show_bug.cgi?id=1271312 * https://bugzilla.suse.com/show_bug.cgi?id=1271313 * https://bugzilla.suse.com/show_bug.cgi?id=1271314 * https://bugzilla.suse.com/show_bug.cgi?id=1271315 * https://bugzilla.suse.com/show_bug.cgi?id=1271316 * https://bugzilla.suse.com/show_bug.cgi?id=1271484 * https://bugzilla.suse.com/show_bug.cgi?id=1271486 * https://bugzilla.suse.com/show_bug.cgi?id=1271487 * https://bugzilla.suse.com/show_bug.cgi?id=1271488 * https://bugzilla.suse.com/show_bug.cgi?id=1271489 * https://bugzilla.suse.com/show_bug.cgi?id=1271490 * https://bugzilla.suse.com/show_bug.cgi?id=1271491 * https://bugzilla.suse.com/show_bug.cgi?id=1271492 * https://bugzilla.suse.com/show_bug.cgi?id=1271493 * https://bugzilla.suse.com/show_bug.cgi?id=1271494 * https://bugzilla.suse.com/show_bug.cgi?id=1271495 * https://bugzilla.suse.com/show_bug.cgi?id=1271496 * https://bugzilla.suse.com/show_bug.cgi?id=1271497 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:33:25 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:33:25 -0000 Subject: SUSE-SU-2026:3218-1: moderate: Security update for avahi Message-ID: <178488200529.807.6170340681443745983@cbbac00f79c6> # Security update for avahi Announcement ID: SUSE-SU-2026:3218-1 Release Date: 2026-07-23T17:34:30Z Rating: moderate References: * bsc#1255451 Cross-References: * CVE-2025-59529 CVSS scores: * CVE-2025-59529 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issue: * CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3218=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3218=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3218=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3218=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libavahi-gobject0-debuginfo-0.8-150600.15.21.1 * avahi-debugsource-0.8-150600.15.21.1 * avahi-compat-mDNSResponder-devel-0.8-150600.15.21.1 * libavahi-ui-gtk3-0-0.8-150600.15.21.1 * libavahi-ui-gtk3-0-debuginfo-0.8-150600.15.21.1 * avahi-utils-debuginfo-0.8-150600.15.21.1 * avahi-debuginfo-0.8-150600.15.21.1 * libdns_sd-debuginfo-0.8-150600.15.21.1 * libhowl0-debuginfo-0.8-150600.15.21.1 * typelib-1_0-Avahi-0_6-0.8-150600.15.21.1 * libavahi-client3-0.8-150600.15.21.1 * avahi-utils-0.8-150600.15.21.1 * libavahi-glib1-debuginfo-0.8-150600.15.21.1 * avahi-0.8-150600.15.21.1 * avahi-compat-howl-devel-0.8-150600.15.21.1 * libavahi-glib-devel-0.8-150600.15.21.1 * libhowl0-0.8-150600.15.21.1 * libdns_sd-0.8-150600.15.21.1 * libavahi-glib1-0.8-150600.15.21.1 * avahi-glib2-debugsource-0.8-150600.15.21.1 * libavahi-core7-0.8-150600.15.21.1 * libavahi-common3-debuginfo-0.8-150600.15.21.1 * libavahi-gobject0-0.8-150600.15.21.1 * libavahi-core7-debuginfo-0.8-150600.15.21.1 * libavahi-libevent1-0.8-150600.15.21.1 * libavahi-common3-0.8-150600.15.21.1 * libavahi-devel-0.8-150600.15.21.1 * libavahi-client3-debuginfo-0.8-150600.15.21.1 * libavahi-libevent1-debuginfo-0.8-150600.15.21.1 * Basesystem Module 15-SP7 (x86_64) * libavahi-client3-32bit-0.8-150600.15.21.1 * libavahi-client3-32bit-debuginfo-0.8-150600.15.21.1 * avahi-32bit-debuginfo-0.8-150600.15.21.1 * libavahi-common3-32bit-0.8-150600.15.21.1 * libavahi-common3-32bit-debuginfo-0.8-150600.15.21.1 * Basesystem Module 15-SP7 (noarch) * avahi-lang-0.8-150600.15.21.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * python3-avahi-0.8-150600.15.21.1 * libavahi-gobject0-debuginfo-0.8-150600.15.21.1 * libavahi-qt5-1-debuginfo-0.8-150600.15.21.1 * avahi-debugsource-0.8-150600.15.21.1 * avahi-compat-mDNSResponder-devel-0.8-150600.15.21.1 * libavahi-ui-gtk3-0-0.8-150600.15.21.1 * avahi-utils-gtk-0.8-150600.15.21.1 * python3-avahi-gtk-0.8-150600.15.21.1 * libavahi-ui-gtk3-0-debuginfo-0.8-150600.15.21.1 * avahi-utils-debuginfo-0.8-150600.15.21.1 * avahi-qt5-debugsource-0.8-150600.15.21.1 * avahi-debuginfo-0.8-150600.15.21.1 * libhowl0-debuginfo-0.8-150600.15.21.1 * libdns_sd-debuginfo-0.8-150600.15.21.1 * libavahi-qt5-1-0.8-150600.15.21.1 * libavahi-qt5-devel-0.8-150600.15.21.1 * typelib-1_0-Avahi-0_6-0.8-150600.15.21.1 * libavahi-client3-0.8-150600.15.21.1 * avahi-utils-0.8-150600.15.21.1 * libavahi-glib1-debuginfo-0.8-150600.15.21.1 * libavahi-gobject-devel-0.8-150600.15.21.1 * avahi-0.8-150600.15.21.1 * avahi-compat-howl-devel-0.8-150600.15.21.1 * libavahi-glib-devel-0.8-150600.15.21.1 * avahi-autoipd-debuginfo-0.8-150600.15.21.1 * libhowl0-0.8-150600.15.21.1 * libdns_sd-0.8-150600.15.21.1 * libavahi-glib1-0.8-150600.15.21.1 * avahi-autoipd-0.8-150600.15.21.1 * avahi-glib2-debugsource-0.8-150600.15.21.1 * libavahi-core7-0.8-150600.15.21.1 * libavahi-common3-debuginfo-0.8-150600.15.21.1 * libavahi-gobject0-0.8-150600.15.21.1 * libavahi-core7-debuginfo-0.8-150600.15.21.1 * libavahi-libevent1-0.8-150600.15.21.1 * libavahi-common3-0.8-150600.15.21.1 * libavahi-devel-0.8-150600.15.21.1 * libavahi-client3-debuginfo-0.8-150600.15.21.1 * libavahi-libevent1-debuginfo-0.8-150600.15.21.1 * avahi-utils-gtk-debuginfo-0.8-150600.15.21.1 * openSUSE Leap 15.6 (x86_64) * libavahi-client3-32bit-0.8-150600.15.21.1 * libavahi-glib1-32bit-debuginfo-0.8-150600.15.21.1 * libavahi-common3-32bit-debuginfo-0.8-150600.15.21.1 * libavahi-client3-32bit-debuginfo-0.8-150600.15.21.1 * avahi-32bit-debuginfo-0.8-150600.15.21.1 * libavahi-common3-32bit-0.8-150600.15.21.1 * libdns_sd-32bit-0.8-150600.15.21.1 * libdns_sd-32bit-debuginfo-0.8-150600.15.21.1 * libavahi-glib1-32bit-0.8-150600.15.21.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libdns_sd-64bit-0.8-150600.15.21.1 * libavahi-glib1-64bit-0.8-150600.15.21.1 * libdns_sd-64bit-debuginfo-0.8-150600.15.21.1 * libavahi-client3-64bit-0.8-150600.15.21.1 * avahi-64bit-debuginfo-0.8-150600.15.21.1 * libavahi-client3-64bit-debuginfo-0.8-150600.15.21.1 * libavahi-glib1-64bit-debuginfo-0.8-150600.15.21.1 * libavahi-common3-64bit-0.8-150600.15.21.1 * libavahi-common3-64bit-debuginfo-0.8-150600.15.21.1 * openSUSE Leap 15.6 (noarch) * avahi-lang-0.8-150600.15.21.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * avahi-autoipd-debuginfo-0.8-150600.15.21.1 * avahi-debugsource-0.8-150600.15.21.1 * avahi-utils-gtk-0.8-150600.15.21.1 * avahi-autoipd-0.8-150600.15.21.1 * avahi-debuginfo-0.8-150600.15.21.1 * avahi-glib2-debugsource-0.8-150600.15.21.1 * libavahi-gobject-devel-0.8-150600.15.21.1 * avahi-utils-gtk-debuginfo-0.8-150600.15.21.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-avahi-0.8-150600.15.21.1 * avahi-debugsource-0.8-150600.15.21.1 * avahi-debuginfo-0.8-150600.15.21.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59529.html * https://bugzilla.suse.com/show_bug.cgi?id=1255451 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:33:32 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:33:32 -0000 Subject: SUSE-SU-2026:3217-1: moderate: Security update for avahi Message-ID: <178488201279.807.17467803992056770542@cbbac00f79c6> # Security update for avahi Announcement ID: SUSE-SU-2026:3217-1 Release Date: 2026-07-23T17:33:52Z Rating: moderate References: * bsc#1255451 Cross-References: * CVE-2025-59529 CVSS scores: * CVE-2025-59529 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issue: * CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3217=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3217=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3217=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3217=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3217=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3217=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * avahi-autoipd-debuginfo-0.8-150400.7.34.1 * python3-avahi-0.8-150400.7.34.1 * libhowl0-debuginfo-0.8-150400.7.34.1 * avahi-utils-gtk-debuginfo-0.8-150400.7.34.1 * libavahi-gobject0-debuginfo-0.8-150400.7.34.1 * libavahi-qt5-1-0.8-150400.7.34.1 * avahi-autoipd-0.8-150400.7.34.1 * python3-avahi-gtk-0.8-150400.7.34.1 * libavahi-core7-0.8-150400.7.34.1 * libavahi-qt5-1-debuginfo-0.8-150400.7.34.1 * libavahi-glib-devel-0.8-150400.7.34.1 * libavahi-glib1-0.8-150400.7.34.1 * libdns_sd-0.8-150400.7.34.1 * avahi-compat-mDNSResponder-devel-0.8-150400.7.34.1 * libhowl0-0.8-150400.7.34.1 * libavahi-common3-0.8-150400.7.34.1 * libavahi-ui-gtk3-0-debuginfo-0.8-150400.7.34.1 * avahi-compat-howl-devel-0.8-150400.7.34.1 * avahi-qt5-debugsource-0.8-150400.7.34.1 * libavahi-common3-debuginfo-0.8-150400.7.34.1 * libavahi-glib1-debuginfo-0.8-150400.7.34.1 * libdns_sd-debuginfo-0.8-150400.7.34.1 * avahi-debugsource-0.8-150400.7.34.1 * libavahi-libevent1-0.8-150400.7.34.1 * libavahi-devel-0.8-150400.7.34.1 * libavahi-ui-gtk3-0-0.8-150400.7.34.1 * avahi-utils-debuginfo-0.8-150400.7.34.1 * libavahi-client3-debuginfo-0.8-150400.7.34.1 * avahi-utils-0.8-150400.7.34.1 * libavahi-qt5-devel-0.8-150400.7.34.1 * typelib-1_0-Avahi-0_6-0.8-150400.7.34.1 * libavahi-libevent1-debuginfo-0.8-150400.7.34.1 * avahi-0.8-150400.7.34.1 * libavahi-gobject0-0.8-150400.7.34.1 * avahi-utils-gtk-0.8-150400.7.34.1 * libavahi-gobject-devel-0.8-150400.7.34.1 * avahi-debuginfo-0.8-150400.7.34.1 * libavahi-client3-0.8-150400.7.34.1 * libavahi-core7-debuginfo-0.8-150400.7.34.1 * avahi-glib2-debugsource-0.8-150400.7.34.1 * openSUSE Leap 15.4 (noarch) * avahi-lang-0.8-150400.7.34.1 * openSUSE Leap 15.4 (x86_64) * libavahi-client3-32bit-0.8-150400.7.34.1 * libavahi-client3-32bit-debuginfo-0.8-150400.7.34.1 * libavahi-common3-32bit-debuginfo-0.8-150400.7.34.1 * libdns_sd-32bit-0.8-150400.7.34.1 * libavahi-glib1-32bit-debuginfo-0.8-150400.7.34.1 * libavahi-common3-32bit-0.8-150400.7.34.1 * libdns_sd-32bit-debuginfo-0.8-150400.7.34.1 * libavahi-glib1-32bit-0.8-150400.7.34.1 * avahi-32bit-debuginfo-0.8-150400.7.34.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libavahi-client3-64bit-0.8-150400.7.34.1 * libdns_sd-64bit-0.8-150400.7.34.1 * libavahi-client3-64bit-debuginfo-0.8-150400.7.34.1 * libdns_sd-64bit-debuginfo-0.8-150400.7.34.1 * libavahi-glib1-64bit-debuginfo-0.8-150400.7.34.1 * avahi-64bit-debuginfo-0.8-150400.7.34.1 * libavahi-common3-64bit-debuginfo-0.8-150400.7.34.1 * libavahi-common3-64bit-0.8-150400.7.34.1 * libavahi-glib1-64bit-0.8-150400.7.34.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libavahi-common3-debuginfo-0.8-150400.7.34.1 * libavahi-core7-0.8-150400.7.34.1 * avahi-debugsource-0.8-150400.7.34.1 * avahi-0.8-150400.7.34.1 * avahi-debuginfo-0.8-150400.7.34.1 * libavahi-common3-0.8-150400.7.34.1 * libavahi-core7-debuginfo-0.8-150400.7.34.1 * libavahi-client3-debuginfo-0.8-150400.7.34.1 * libavahi-client3-0.8-150400.7.34.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libavahi-common3-debuginfo-0.8-150400.7.34.1 * libavahi-core7-0.8-150400.7.34.1 * avahi-debugsource-0.8-150400.7.34.1 * avahi-0.8-150400.7.34.1 * avahi-debuginfo-0.8-150400.7.34.1 * libavahi-common3-0.8-150400.7.34.1 * libavahi-core7-debuginfo-0.8-150400.7.34.1 * libavahi-client3-debuginfo-0.8-150400.7.34.1 * libavahi-client3-0.8-150400.7.34.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libavahi-common3-debuginfo-0.8-150400.7.34.1 * libavahi-core7-0.8-150400.7.34.1 * avahi-debugsource-0.8-150400.7.34.1 * avahi-0.8-150400.7.34.1 * avahi-debuginfo-0.8-150400.7.34.1 * libavahi-common3-0.8-150400.7.34.1 * libavahi-core7-debuginfo-0.8-150400.7.34.1 * libavahi-client3-debuginfo-0.8-150400.7.34.1 * libavahi-client3-0.8-150400.7.34.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libavahi-common3-debuginfo-0.8-150400.7.34.1 * libavahi-core7-0.8-150400.7.34.1 * avahi-debugsource-0.8-150400.7.34.1 * avahi-0.8-150400.7.34.1 * avahi-debuginfo-0.8-150400.7.34.1 * libavahi-common3-0.8-150400.7.34.1 * libavahi-core7-debuginfo-0.8-150400.7.34.1 * libavahi-client3-debuginfo-0.8-150400.7.34.1 * libavahi-client3-0.8-150400.7.34.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libavahi-common3-debuginfo-0.8-150400.7.34.1 * libavahi-core7-0.8-150400.7.34.1 * avahi-debugsource-0.8-150400.7.34.1 * avahi-0.8-150400.7.34.1 * avahi-debuginfo-0.8-150400.7.34.1 * libavahi-common3-0.8-150400.7.34.1 * libavahi-core7-debuginfo-0.8-150400.7.34.1 * libavahi-client3-debuginfo-0.8-150400.7.34.1 * libavahi-client3-0.8-150400.7.34.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59529.html * https://bugzilla.suse.com/show_bug.cgi?id=1255451 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 08:33:38 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 08:33:38 -0000 Subject: SUSE-SU-2026:3216-1: moderate: Security update for avahi Message-ID: <178488201896.807.3634709145743466294@cbbac00f79c6> # Security update for avahi Announcement ID: SUSE-SU-2026:3216-1 Release Date: 2026-07-23T17:33:11Z Rating: moderate References: * bsc#1255451 Cross-References: * CVE-2025-59529 CVSS scores: * CVE-2025-59529 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issue: * CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3216=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libdns_sd-0.6.32-32.45.1 * libdns_sd-debuginfo-0.6.32-32.45.1 * libavahi-client3-debuginfo-32bit-0.6.32-32.45.1 * libavahi-common3-debuginfo-32bit-0.6.32-32.45.1 * avahi-debuginfo-32bit-0.6.32-32.45.1 * libavahi-common3-debuginfo-0.6.32-32.45.1 * libavahi-client3-0.6.32-32.45.1 * avahi-utils-debuginfo-0.6.32-32.45.1 * avahi-debuginfo-0.6.32-32.45.1 * libavahi-common3-32bit-0.6.32-32.45.1 * avahi-debugsource-0.6.32-32.45.1 * avahi-compat-mDNSResponder-devel-0.6.32-32.45.1 * libavahi-core7-debuginfo-0.6.32-32.45.1 * avahi-utils-0.6.32-32.45.1 * avahi-0.6.32-32.45.1 * libavahi-client3-32bit-0.6.32-32.45.1 * libavahi-core7-0.6.32-32.45.1 * libdns_sd-32bit-0.6.32-32.45.1 * avahi-compat-howl-devel-0.6.32-32.45.1 * libdns_sd-debuginfo-32bit-0.6.32-32.45.1 * libavahi-common3-0.6.32-32.45.1 * libavahi-devel-0.6.32-32.45.1 * libavahi-client3-debuginfo-0.6.32-32.45.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * avahi-lang-0.6.32-32.45.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59529.html * https://bugzilla.suse.com/show_bug.cgi?id=1255451 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 12:30:07 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 12:30:07 -0000 Subject: SUSE-RU-2026:3233-1: moderate: Recommended update for release-notes-ha Message-ID: <178489620750.969.7978359558179859585@cbbac00f79c6> # Recommended update for release-notes-ha Announcement ID: SUSE-RU-2026:3233-1 Release Date: 2026-07-24T07:09:55Z Rating: moderate References: * bsc#933411 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has one fix can now be installed. ## Description: This update for release-notes-ha fixes the following issues: * Update to version 15.4.20260709 (bsc#933411): * Fixed wording in "Improve the graceful shutdown..." note ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-3233=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3233=1 ## Package List: * openSUSE Leap 15.4 (noarch) * release-notes-ha-15.4.20260709-150400.3.8.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (noarch) * release-notes-ha-15.4.20260709-150400.3.8.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 12:30:17 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 12:30:17 -0000 Subject: SUSE-RU-2026:3232-1: moderate: Recommended update for release-notes-ha Message-ID: <178489621753.969.17036748108769879452@cbbac00f79c6> # Recommended update for release-notes-ha Announcement ID: SUSE-RU-2026:3232-1 Release Date: 2026-07-24T07:09:39Z Rating: moderate References: * bsc#933411 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Availability Extension 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has one fix can now be installed. ## Description: This update for release-notes-ha fixes the following issues: * Update to version 15.5.20260709 (bsc#933411): * Fixed wording in "Improve the graceful shutdown..." note ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2026-3232=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3232=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP5 (noarch) * release-notes-ha-15.5.20260709-150500.3.12.1 * openSUSE Leap 15.5 (noarch) * release-notes-ha-15.5.20260709-150500.3.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 12:30:23 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 12:30:23 -0000 Subject: SUSE-RU-2026:3231-1: moderate: Recommended update for release-notes-ha Message-ID: <178489622342.969.8427463586888142593@cbbac00f79c6> # Recommended update for release-notes-ha Announcement ID: SUSE-RU-2026:3231-1 Release Date: 2026-07-24T07:09:24Z Rating: moderate References: * bsc#933411 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one fix can now be installed. ## Description: This update for release-notes-ha fixes the following issues: * Update to version 15.6.20260709 (bsc#933411): * Fixed wording in "Improve the graceful shutdown..." note ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3231=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3231=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP6 (noarch) * release-notes-ha-15.6.20260709-150600.3.12.1 * openSUSE Leap 15.6 (noarch) * release-notes-ha-15.6.20260709-150600.3.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 12:30:31 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 12:30:31 -0000 Subject: SUSE-RU-2026:3230-1: moderate: Recommended update for release-notes-ha Message-ID: <178489623108.969.12984077626059310371@cbbac00f79c6> # Recommended update for release-notes-ha Announcement ID: SUSE-RU-2026:3230-1 Release Date: 2026-07-24T07:09:07Z Rating: moderate References: * bsc#933411 Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one fix can now be installed. ## Description: This update for release-notes-ha fixes the following issues: * Update to version 15.7.20260709 (bsc#933411): * Fixed wording in "Improve the graceful shutdown..." note ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-3230=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP7 (noarch) * release-notes-ha-15.7.20260709-150700.3.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 12:30:41 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 12:30:41 -0000 Subject: SUSE-RU-2026:3229-1: moderate: Recommended update for release-notes-sles-for-sap Message-ID: <178489624182.969.4290708865978089384@cbbac00f79c6> # Recommended update for release-notes-sles-for-sap Announcement ID: SUSE-RU-2026:3229-1 Release Date: 2026-07-24T07:08:56Z Rating: moderate References: * bsc#1205940 * bsc#933411 Affected Products: * openSUSE Leap 15.4 * SAP Applications Module 15-SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that has two fixes can now be installed. ## Description: This update for release-notes-sles-for-sap fixes the following issues: * Update to version 15.4.20260709 (bsc#933411): * SLES for SAP 15 SP4: Updated Python 3 statement to exclude Python 2 (bsc#1205940) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3229=1 * SAP Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP4-2026-3229=1 ## Package List: * SAP Applications Module 15-SP4 (noarch) * release-notes-sles-for-sap-15.4.20260709-150400.3.21.1 * openSUSE Leap 15.4 (noarch) * release-notes-sles-for-sap-15.4.20260709-150400.3.21.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1205940 * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 12:30:49 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 12:30:49 -0000 Subject: SUSE-RU-2026:3228-1: moderate: Recommended update for release-notes-sles-for-sap Message-ID: <178489624900.969.6684095480205574000@cbbac00f79c6> # Recommended update for release-notes-sles-for-sap Announcement ID: SUSE-RU-2026:3228-1 Release Date: 2026-07-24T07:08:36Z Rating: moderate References: * bsc#1205940 * bsc#933411 Affected Products: * openSUSE Leap 15.5 * SAP Applications Module 15-SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has two fixes can now be installed. ## Description: This update for release-notes-sles-for-sap fixes the following issues: * Update to version 15.5.20260709 (bsc#933411): * SLES for SAP 15 SP5: Updated Python 3 statement to exclude Python 2 (bsc#1205940) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SAP Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP5-2026-3228=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3228=1 ## Package List: * SAP Applications Module 15-SP5 (noarch) * release-notes-sles-for-sap-15.5.20260709-150500.3.9.1 * openSUSE Leap 15.5 (noarch) * release-notes-sles-for-sap-15.5.20260709-150500.3.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1205940 * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 12:30:56 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 12:30:56 -0000 Subject: SUSE-RU-2026:3227-1: moderate: Recommended update for release-notes-sles-for-sap Message-ID: <178489625621.969.4932812545854591119@cbbac00f79c6> # Recommended update for release-notes-sles-for-sap Announcement ID: SUSE-RU-2026:3227-1 Release Date: 2026-07-24T07:08:15Z Rating: moderate References: * bsc#1205940 * bsc#933411 Affected Products: * openSUSE Leap 15.6 * SAP Applications Module 15-SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has two fixes can now be installed. ## Description: This update for release-notes-sles-for-sap fixes the following issues: * Update to version 15.6.20260709 (bsc#933411): * SLES for SAP 15 SP6: Updated Python 3 statement to exclude Python 2 (bsc#1205940) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SAP Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP6-2026-3227=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3227=1 ## Package List: * SAP Applications Module 15-SP6 (noarch) * release-notes-sles-for-sap-15.6.20260709-150600.3.9.1 * openSUSE Leap 15.6 (noarch) * release-notes-sles-for-sap-15.6.20260709-150600.3.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1205940 * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 24 12:31:04 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 24 Jul 2026 12:31:04 -0000 Subject: SUSE-RU-2026:3226-1: moderate: Recommended update for release-notes-sles-for-sap Message-ID: <178489626465.969.16183596486486457027@cbbac00f79c6> # Recommended update for release-notes-sles-for-sap Announcement ID: SUSE-RU-2026:3226-1 Release Date: 2026-07-24T07:07:53Z Rating: moderate References: * bsc#1205940 * bsc#1258177 * bsc#933411 Affected Products: * SAP Applications Module 15-SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has three fixes can now be installed. ## Description: This update for release-notes-sles-for-sap fixes the following issues: * Update to version 15.7.20260709 (bsc#933411): * SLES for SAP 15 SP7: Updated Python 3 statement to exclude Python 2 (bsc#1205940) * Update to version 15.7.20260227 (bsc#933411) * Added note about updated doc links (bsc#1258177) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SAP Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP7-2026-3226=1 ## Package List: * SAP Applications Module 15-SP7 (noarch) * release-notes-sles-for-sap-15.7.20260709-150700.3.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1205940 * https://bugzilla.suse.com/show_bug.cgi?id=1258177 * https://bugzilla.suse.com/show_bug.cgi?id=933411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:30:30 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:30:30 -0000 Subject: SUSE-SU-2026:3256-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Message-ID: <178515543066.2122.14361753175026596388@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3256-1 Release Date: 2026-07-27T07:33:42Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.52 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3260=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-3256=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-3255=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-3258=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-3257=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-3259=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3263=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3256=1 SUSE-2026-3255=1 SUSE-2026-3258=1 SUSE-2026-3257=1 SUSE-2026-3259=1 SUSE-2026-3260=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_95-default-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-5-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_24-debugsource-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_100-default-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_19-debugsource-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_84-default-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_103-default-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-10-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_22-debugsource-7-150600.2.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_95-default-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-7-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-5-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_24-debugsource-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_100-default-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_19-debugsource-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_84-default-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_103-default-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-10-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_22-debugsource-7-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_14-debugsource-4-150700.2.1 * kernel-livepatch-6_4_0-150700_53_52-default-debuginfo-4-150700.2.1 * kernel-livepatch-6_4_0-150700_53_52-default-4-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:31:28 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:31:28 -0000 Subject: SUSE-RU-2026:3262-1: important: Recommended update for cifs-utils Message-ID: <178515548837.2122.13441668715289065679@cbbac00f79c6> # Recommended update for cifs-utils Announcement ID: SUSE-RU-2026:3262-1 Release Date: 2026-07-27T05:52:04Z Rating: important References: * bsc#1271183 * bsc#1271234 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has two fixes can now be installed. ## Description: This update for cifs-utils fixes the following issues: * cifs.upcall: fix regression with krb5 + creduid (bsc#1271183, bsc#1271234) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3262=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3262=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cifs-utils-debugsource-6.9-13.29.1 * cifs-utils-6.9-13.29.1 * cifs-utils-devel-6.9-13.29.1 * cifs-utils-debuginfo-6.9-13.29.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * cifs-utils-debugsource-6.9-13.29.1 * cifs-utils-6.9-13.29.1 * cifs-utils-devel-6.9-13.29.1 * cifs-utils-debuginfo-6.9-13.29.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271183 * https://bugzilla.suse.com/show_bug.cgi?id=1271234 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:31:52 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:31:52 -0000 Subject: SUSE-RU-2026:3261-1: important: Recommended update for cifs-utils Message-ID: <178515551204.2122.17199455399326026566@cbbac00f79c6> # Recommended update for cifs-utils Announcement ID: SUSE-RU-2026:3261-1 Release Date: 2026-07-27T05:51:51Z Rating: important References: * bsc#1271183 * bsc#1271234 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has two fixes can now be installed. ## Description: This update for cifs-utils fixes the following issues: * cifs.upcall: fix regression with krb5 + creduid (bsc#1271183, bsc#1271234) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3261=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3261=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3261=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3261=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3261=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3261=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3261=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3261=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3261=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3261=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3261=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3261=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3261=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3261=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3261=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3261=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3261=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * cifs-utils-6.15-150400.3.24.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * cifs-utils-6.15-150400.3.24.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * cifs-utils-6.15-150400.3.24.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * pam_cifscreds-debuginfo-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * pam_cifscreds-6.15-150400.3.24.1 * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * cifs-utils-6.15-150400.3.24.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * cifs-utils-6.15-150400.3.24.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * cifs-utils-6.15-150400.3.24.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cifs-utils-6.15-150400.3.24.1 * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cifs-utils-debugsource-6.15-150400.3.24.1 * cifs-utils-devel-6.15-150400.3.24.1 * cifs-utils-debuginfo-6.15-150400.3.24.1 * cifs-utils-6.15-150400.3.24.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271183 * https://bugzilla.suse.com/show_bug.cgi?id=1271234 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:32:29 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:32:29 -0000 Subject: SUSE-SU-2026:3254-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP6) Message-ID: <178515554989.2122.11377902308479117283@cbbac00f79c6> # Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:3254-1 Release Date: 2026-07-26T18:33:35Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.109 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3254=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3254=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_109-default-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-4-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_25-debugsource-4-150600.2.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_109-default-4-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_25-debugsource-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-4-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:33:26 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:33:26 -0000 Subject: SUSE-SU-2026:3253-1: important: Security update for the Linux Kernel RT (Live Patch 17 for SUSE Linux Enterprise 15 SP7) Message-ID: <178515560600.2122.16450661494863692529@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 17 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3253-1 Release Date: 2026-07-25T04:04:27Z Rating: important References: * bsc#1271370 Cross-References: * CVE-2026-53366 CVSS scores: * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.62 fixes various security issues: The following security issues were fixed: * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3253=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_62-rt-debuginfo-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_62-rt-2-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_17-debugsource-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:34:06 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:34:06 -0000 Subject: SUSE-SU-2026:3248-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Message-ID: <178515564655.2122.6208984154151121134@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3248-1 Release Date: 2026-07-25T03:33:48Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.54 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3248=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-SLE15-SP7-RT_Update_15-debugsource-3-150700.2.1 * kernel-livepatch-6_4_0-150700_7_54-rt-3-150700.2.1 * kernel-livepatch-6_4_0-150700_7_54-rt-debuginfo-3-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:34:56 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:34:56 -0000 Subject: SUSE-SU-2026:3246-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Message-ID: <178515569667.2122.18205377843080260713@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3246-1 Release Date: 2026-07-25T03:34:00Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.28 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3246=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-3249=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-3247=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3251=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3252=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-3250=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-SLE15-SP7-RT_Update_9-debugsource-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_31-rt-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_31-rt-debuginfo-9-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_11-debugsource-7-150700.2.1 * kernel-livepatch-6_4_0-150700_7_37-rt-7-150700.2.1 * kernel-livepatch-6_4_0-150700_7_34-rt-debuginfo-7-150700.2.1 * kernel-livepatch-6_4_0-150700_7_51-rt-4-150700.2.1 * kernel-livepatch-6_4_0-150700_7_28-rt-10-150700.2.1 * kernel-livepatch-6_4_0-150700_7_37-rt-debuginfo-7-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_10-debugsource-7-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_8-debugsource-10-150700.2.1 * kernel-livepatch-6_4_0-150700_7_44-rt-debuginfo-5-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_14-debugsource-4-150700.2.1 * kernel-livepatch-6_4_0-150700_7_28-rt-debuginfo-10-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_13-debugsource-5-150700.2.1 * kernel-livepatch-6_4_0-150700_7_51-rt-debuginfo-4-150700.2.1 * kernel-livepatch-6_4_0-150700_7_34-rt-7-150700.2.1 * kernel-livepatch-6_4_0-150700_7_44-rt-5-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:35:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:35:49 -0000 Subject: SUSE-SU-2026:22811-1: important: Security update for kernel-livepatch-MICRO-6-0-RT_Update_27 Message-ID: <178515574911.2122.8426925511060438081@cbbac00f79c6> # Security update for kernel-livepatch-MICRO-6-0-RT_Update_27 Announcement ID: SUSE-SU-2026:22811-1 Release Date: 2026-07-22T11:20:16Z Rating: important References: * bsc#1103203 * bsc#1149841 * bsc#1196281 * bsc#1244337 * bsc#1248108 * bsc#904970 * bsc#907150 * bsc#920615 * bsc#920633 * bsc#930408 * jsc#PED-14811 * jsc#PED-7906 Affected Products: * SUSE Linux Micro 6.0 An update that contains two features and has 10 fixes can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_27 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 27 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-539=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_27-debugsource-1-1.1 * kernel-livepatch-6_4_0-50-rt-1-1.1 * kernel-livepatch-6_4_0-50-rt-debuginfo-1-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1103203 * https://bugzilla.suse.com/show_bug.cgi?id=1149841 * https://bugzilla.suse.com/show_bug.cgi?id=1196281 * https://bugzilla.suse.com/show_bug.cgi?id=1244337 * https://bugzilla.suse.com/show_bug.cgi?id=1248108 * https://bugzilla.suse.com/show_bug.cgi?id=904970 * https://bugzilla.suse.com/show_bug.cgi?id=907150 * https://bugzilla.suse.com/show_bug.cgi?id=920615 * https://bugzilla.suse.com/show_bug.cgi?id=920633 * https://bugzilla.suse.com/show_bug.cgi?id=930408 * https://jira.suse.com/browse/PED-14811 * https://jira.suse.com/browse/PED-7906 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:38:33 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:38:33 -0000 Subject: SUSE-SU-2026:22810-1: important: Security update for the Linux Kernel Message-ID: <178515591349.2122.10842795510619747372@cbbac00f79c6> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22810-1 Release Date: 2026-07-22T11:19:22Z Rating: important References: * bsc#1243603 * bsc#1260593 * bsc#1263077 * bsc#1264003 * bsc#1264056 * bsc#1264180 * bsc#1264270 * bsc#1264302 * bsc#1264304 * bsc#1264328 * bsc#1264386 * bsc#1264419 * bsc#1264531 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264556 * bsc#1264580 * bsc#1264624 * bsc#1264731 * bsc#1264744 * bsc#1264790 * bsc#1264794 * bsc#1264853 * bsc#1264978 * bsc#1264987 * bsc#1264993 * bsc#1264997 * bsc#1265023 * bsc#1265041 * bsc#1265079 * bsc#1265142 * bsc#1266458 * bsc#1266686 * bsc#1266722 * bsc#1266726 * bsc#1266740 * bsc#1266773 * bsc#1266838 * bsc#1266883 * bsc#1266893 * bsc#1267213 * bsc#1267360 * bsc#1267493 * bsc#1267494 * bsc#1267495 * bsc#1267618 * bsc#1267992 * bsc#1267994 * bsc#1268989 * bsc#1269036 * bsc#1269129 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269172 * bsc#1269174 * bsc#1269188 * bsc#1269190 * bsc#1269193 * bsc#1269230 * bsc#1269262 * bsc#1269389 * bsc#1269392 * bsc#1269493 * bsc#1269527 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269645 * bsc#1269646 * bsc#1269651 * bsc#1269675 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269814 * bsc#1269886 * bsc#1269986 * bsc#1269989 * bsc#1269992 * bsc#1269993 * bsc#1270022 * bsc#1270059 * bsc#1270226 * bsc#1270257 * bsc#1271040 * bsc#1271050 * bsc#1271366 Cross-References: * CVE-2023-20585 * CVE-2026-31503 * CVE-2026-43019 * CVE-2026-43057 * CVE-2026-43092 * CVE-2026-43124 * CVE-2026-43157 * CVE-2026-43167 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43199 * CVE-2026-43204 * CVE-2026-43205 * CVE-2026-43226 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43253 * CVE-2026-43294 * CVE-2026-43304 * CVE-2026-43320 * CVE-2026-43373 * CVE-2026-43383 * CVE-2026-43445 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43473 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45899 * CVE-2026-45920 * CVE-2026-45987 * CVE-2026-45997 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46052 * CVE-2026-46059 * CVE-2026-46099 * CVE-2026-46161 * CVE-2026-46178 * CVE-2026-46242 * CVE-2026-46314 * CVE-2026-46322 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52961 * CVE-2026-52993 * CVE-2026-53021 * CVE-2026-53035 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53139 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53181 * CVE-2026-53196 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53245 * CVE-2026-53249 * CVE-2026-53256 * CVE-2026-53258 * CVE-2026-53274 * CVE-2026-53285 * CVE-2026-53306 * CVE-2026-53357 * CVE-2026-53359 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2023-20585 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-20585 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2023-20585 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31503 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31503 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31503 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43253 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52961 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53181 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53181 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 87 vulnerabilities and has six fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). * CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). * CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). * CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593). * CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). * CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). * CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53366: kernel: ipv4: account for fraggap on the paged allocation path (bsc#1271366) The following non security issues were fixed: * batman-adv: access unicast_ttvn skb->data only after skb realloc (git- fixes). * batman-adv: bla: reacquire gw address after skb realloc (git-fixes). * batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). * batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). * batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). * bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). * bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). * bnxt_en: Add TX timestamp completion logic (bsc#1264180). * bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). * bnxt_en: fix module unload sequence (bsc#1264180). * bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). * bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). * bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). * bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). * bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). * bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). * bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). * bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). * bnxt_en: silence clang build warning (bsc#1264180). * crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). * crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable- fixes). * drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). * drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git- fixes). * drm/amdgpu: fix aperture mapping leak (git-fixes). * drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). * drm/i915: Return NULL on error in active_instance (git-fixes). * drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). * drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). * drm/virtio: bound EDID block reads to the response buffer (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * gpio-f7188x: Add support for NCT6126D version B (git-fixes). * gpio: htc-egpio: use managed gpiochip registration (git-fixes). * gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). * gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git- fixes). * gpios: palmas: add .get_direction() op (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). * iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git- fixes). * iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). * iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). * iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). * iio: event: Fix event FIFO reset race (git-fixes). * iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). * iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). * iio: light: al3010: fix incorrect scale for the highest gain range (git- fixes). * iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). * iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). * Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). * Input: mms114 - fix multi-touch slot corruption (git-fixes). * iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). * ipv4: account for fraggap on the paged allocation path (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * pinctrl: meson: restore non-sleeping GPIO access (git-fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). * serial: 8250_omap: clear rx_running on zero-length DMA completes (git- fixes). * serial: msm: Disable DMA for kernel console UART (git-fixes). * staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). * staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git- fixes). * staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). * staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). * staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). * staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git- fixes). * tpm: Make the TPM character devices non-seekable (git-fixes). * usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git- fixes). * USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). * usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git- fixes). * usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). * usb: free iso schedules on failed submit (git-fixes). * usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git- fixes). * usb: gadget: f_printer: take kref only for successful open (git-fixes). * USB: idmouse: fix use-after-free on disconnect race (git-fixes). * USB: iowarrior: fix use-after-free on disconnect (git-fixes). * USB: ldusb: fix use-after-free on disconnect race (git-fixes). * USB: legousbtower: fix use-after-free on disconnect race (git-fixes). * USB: misc: uss720: unregister parport on probe failure (git-fixes). * usb: mtu3: unmap request DMA on queue failure (git-fixes). * USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). * USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). * USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). * USB: serial: keyspan_pda: fix information leak (git-fixes). * usb: sl811-hcd: disable controller wakeup on remove (git-fixes). * USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). * usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). * usb: typec: class: drop PD lookup reference (git-fixes). * usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). * usb: typec: ucsi: cancel pending work on system suspend (git-fixes). * usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). * usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). * usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). * USB: ulpi: fix memory leak on registration failure (git-fixes). * USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). * usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). * usbip: tools: support SuperSpeedPlus devices (git-fixes). * usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-536=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 nosrc s390x x86_64) * kernel-default-6.4.0-50.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-kvmsmall-6.4.0-50.1 * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * kernel-default-debugsource-6.4.0-50.1 * kernel-default-debuginfo-6.4.0-50.1 * SUSE Linux Micro 6.0 (noarch) * kernel-macros-6.4.0-50.2 * kernel-devel-6.4.0-50.2 * kernel-source-6.4.0-50.2 * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-default-livepatch-6.4.0-50.1 * SUSE Linux Micro 6.0 (x86_64) * kernel-kvmsmall-debugsource-6.4.0-50.1 * kernel-kvmsmall-debuginfo-6.4.0-50.1 ## References: * https://www.suse.com/security/cve/CVE-2023-20585.html * https://www.suse.com/security/cve/CVE-2026-31503.html * https://www.suse.com/security/cve/CVE-2026-43019.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43204.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43253.html * https://www.suse.com/security/cve/CVE-2026-43294.html * https://www.suse.com/security/cve/CVE-2026-43304.html * https://www.suse.com/security/cve/CVE-2026-43320.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43445.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43473.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45987.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46059.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52961.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53035.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53181.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53245.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1243603 * https://bugzilla.suse.com/show_bug.cgi?id=1260593 * https://bugzilla.suse.com/show_bug.cgi?id=1263077 * https://bugzilla.suse.com/show_bug.cgi?id=1264003 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264180 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264419 * https://bugzilla.suse.com/show_bug.cgi?id=1264531 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264731 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264853 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264987 * https://bugzilla.suse.com/show_bug.cgi?id=1264993 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265041 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1267213 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267495 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269129 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269190 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269675 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269886 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1271040 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:41:14 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:41:14 -0000 Subject: SUSE-SU-2026:22809-1: important: Security update for the Linux Kernel Message-ID: <178515607401.2122.9414189731465013923@cbbac00f79c6> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22809-1 Release Date: 2026-07-22T11:18:12Z Rating: important References: * bsc#1243603 * bsc#1260593 * bsc#1263077 * bsc#1264003 * bsc#1264056 * bsc#1264180 * bsc#1264270 * bsc#1264302 * bsc#1264304 * bsc#1264328 * bsc#1264386 * bsc#1264419 * bsc#1264531 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264556 * bsc#1264580 * bsc#1264624 * bsc#1264731 * bsc#1264744 * bsc#1264790 * bsc#1264794 * bsc#1264853 * bsc#1264978 * bsc#1264987 * bsc#1264993 * bsc#1264997 * bsc#1265023 * bsc#1265041 * bsc#1265079 * bsc#1265142 * bsc#1266458 * bsc#1266686 * bsc#1266722 * bsc#1266726 * bsc#1266740 * bsc#1266773 * bsc#1266838 * bsc#1266883 * bsc#1266893 * bsc#1267213 * bsc#1267360 * bsc#1267493 * bsc#1267494 * bsc#1267495 * bsc#1267618 * bsc#1267992 * bsc#1267994 * bsc#1268989 * bsc#1269036 * bsc#1269129 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269172 * bsc#1269174 * bsc#1269188 * bsc#1269190 * bsc#1269193 * bsc#1269230 * bsc#1269262 * bsc#1269389 * bsc#1269392 * bsc#1269493 * bsc#1269527 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269645 * bsc#1269646 * bsc#1269651 * bsc#1269675 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269814 * bsc#1269886 * bsc#1269986 * bsc#1269989 * bsc#1269992 * bsc#1269993 * bsc#1270022 * bsc#1270059 * bsc#1270226 * bsc#1270257 * bsc#1271040 * bsc#1271050 * bsc#1271366 Cross-References: * CVE-2023-20585 * CVE-2026-31503 * CVE-2026-43019 * CVE-2026-43057 * CVE-2026-43092 * CVE-2026-43124 * CVE-2026-43157 * CVE-2026-43167 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43199 * CVE-2026-43204 * CVE-2026-43205 * CVE-2026-43226 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43253 * CVE-2026-43294 * CVE-2026-43304 * CVE-2026-43320 * CVE-2026-43373 * CVE-2026-43383 * CVE-2026-43445 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43473 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45899 * CVE-2026-45920 * CVE-2026-45987 * CVE-2026-45997 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46052 * CVE-2026-46059 * CVE-2026-46099 * CVE-2026-46161 * CVE-2026-46178 * CVE-2026-46242 * CVE-2026-46314 * CVE-2026-46322 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52961 * CVE-2026-52993 * CVE-2026-53021 * CVE-2026-53035 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53139 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53181 * CVE-2026-53196 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53245 * CVE-2026-53249 * CVE-2026-53256 * CVE-2026-53258 * CVE-2026-53274 * CVE-2026-53285 * CVE-2026-53306 * CVE-2026-53357 * CVE-2026-53359 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2023-20585 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-20585 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2023-20585 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31503 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31503 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31503 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43253 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52961 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53181 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53181 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 87 vulnerabilities and has six fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). * CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). * CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). * CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593). * CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). * CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). * CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53366: kernel: ipv4: account for fraggap on the paged allocation path (bsc#1271366) The following non security issues were fixed: * batman-adv: access unicast_ttvn skb->data only after skb realloc (git- fixes). * batman-adv: bla: reacquire gw address after skb realloc (git-fixes). * batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). * batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). * batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). * bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). * bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). * bnxt_en: Add TX timestamp completion logic (bsc#1264180). * bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). * bnxt_en: fix module unload sequence (bsc#1264180). * bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). * bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). * bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). * bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). * bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). * bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). * bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). * bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). * bnxt_en: silence clang build warning (bsc#1264180). * crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). * crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable- fixes). * drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). * drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git- fixes). * drm/amdgpu: fix aperture mapping leak (git-fixes). * drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). * drm/i915: Return NULL on error in active_instance (git-fixes). * drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). * drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). * drm/virtio: bound EDID block reads to the response buffer (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * gpio-f7188x: Add support for NCT6126D version B (git-fixes). * gpio: htc-egpio: use managed gpiochip registration (git-fixes). * gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). * gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git- fixes). * gpios: palmas: add .get_direction() op (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). * iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git- fixes). * iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). * iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). * iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). * iio: event: Fix event FIFO reset race (git-fixes). * iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). * iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). * iio: light: al3010: fix incorrect scale for the highest gain range (git- fixes). * iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). * iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). * Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). * Input: mms114 - fix multi-touch slot corruption (git-fixes). * iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). * ipv4: account for fraggap on the paged allocation path (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * pinctrl: meson: restore non-sleeping GPIO access (git-fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). * serial: 8250_omap: clear rx_running on zero-length DMA completes (git- fixes). * serial: msm: Disable DMA for kernel console UART (git-fixes). * staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). * staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git- fixes). * staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). * staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). * staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). * staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git- fixes). * tpm: Make the TPM character devices non-seekable (git-fixes). * usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git- fixes). * USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). * usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git- fixes). * usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). * usb: free iso schedules on failed submit (git-fixes). * usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git- fixes). * usb: gadget: f_printer: take kref only for successful open (git-fixes). * USB: idmouse: fix use-after-free on disconnect race (git-fixes). * USB: iowarrior: fix use-after-free on disconnect (git-fixes). * USB: ldusb: fix use-after-free on disconnect race (git-fixes). * USB: legousbtower: fix use-after-free on disconnect race (git-fixes). * USB: misc: uss720: unregister parport on probe failure (git-fixes). * usb: mtu3: unmap request DMA on queue failure (git-fixes). * USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). * USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). * USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). * USB: serial: keyspan_pda: fix information leak (git-fixes). * usb: sl811-hcd: disable controller wakeup on remove (git-fixes). * USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). * usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). * usb: typec: class: drop PD lookup reference (git-fixes). * usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). * usb: typec: ucsi: cancel pending work on system suspend (git-fixes). * usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). * usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). * usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). * USB: ulpi: fix memory leak on registration failure (git-fixes). * USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). * usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). * usbip: tools: support SuperSpeedPlus devices (git-fixes). * usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-538=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-rt-debugsource-6.4.0-50.1 * kernel-rt-livepatch-6.4.0-50.1 * kernel-rt-debuginfo-6.4.0-50.1 * SUSE Linux Micro 6.0 (noarch) * kernel-source-rt-6.4.0-50.2 * kernel-devel-rt-6.4.0-50.2 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-rt-6.4.0-50.1 ## References: * https://www.suse.com/security/cve/CVE-2023-20585.html * https://www.suse.com/security/cve/CVE-2026-31503.html * https://www.suse.com/security/cve/CVE-2026-43019.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43204.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43253.html * https://www.suse.com/security/cve/CVE-2026-43294.html * https://www.suse.com/security/cve/CVE-2026-43304.html * https://www.suse.com/security/cve/CVE-2026-43320.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43445.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43473.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45987.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46059.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52961.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53035.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53181.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53245.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1243603 * https://bugzilla.suse.com/show_bug.cgi?id=1260593 * https://bugzilla.suse.com/show_bug.cgi?id=1263077 * https://bugzilla.suse.com/show_bug.cgi?id=1264003 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264180 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264419 * https://bugzilla.suse.com/show_bug.cgi?id=1264531 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264731 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264853 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264987 * https://bugzilla.suse.com/show_bug.cgi?id=1264993 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265041 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1267213 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267495 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269129 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269190 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269675 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269886 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1271040 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:41:51 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:41:51 -0000 Subject: SUSE-SU-2026:22808-1: moderate: Security update for kernel-livepatch-MICRO-6-0_Update_27 Message-ID: <178515611151.2122.7937970843472852994@cbbac00f79c6> # Security update for kernel-livepatch-MICRO-6-0_Update_27 Announcement ID: SUSE-SU-2026:22808-1 Release Date: 2026-07-22T11:17:22Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_27 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 27 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-537=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_27-debugsource-1-1.1 * kernel-livepatch-6_4_0-50-default-1-1.1 * kernel-livepatch-6_4_0-50-default-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:42:30 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:42:30 -0000 Subject: SUSE-SU-2026:22807-1: moderate: Security update for pam Message-ID: <178515615006.2122.111599719281267860@cbbac00f79c6> # Security update for pam Announcement ID: SUSE-SU-2026:22807-1 Release Date: 2026-07-22T08:39:49Z Rating: moderate References: * bsc#1268290 Cross-References: * CVE-2026-54411 CVSS scores: * CVE-2026-54411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-54411 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X * CVE-2026-54411 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for pam fixes the following issue * CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext- password comparison (bsc#1268290). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-805=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * pam-debugsource-1.6.0-6.1 * pam-1.6.0-6.1 * pam-debuginfo-1.6.0-6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54411.html * https://bugzilla.suse.com/show_bug.cgi?id=1268290 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:43:08 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:43:08 -0000 Subject: SUSE-SU-2026:22806-1: important: Security update for libxml2 Message-ID: <178515618858.2122.4190528812428107719@cbbac00f79c6> # Security update for libxml2 Announcement ID: SUSE-SU-2026:22806-1 Release Date: 2026-07-22T08:36:58Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-806=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libxml2-2-2.11.6-13.1 * python311-libxml2-debuginfo-2.11.6-13.1 * libxml2-tools-debuginfo-2.11.6-13.1 * python311-libxml2-2.11.6-13.1 * libxml2-debugsource-2.11.6-13.1 * libxml2-tools-2.11.6-13.1 * libxml2-2-debuginfo-2.11.6-13.1 * libxml2-python-debugsource-2.11.6-13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:43:47 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:43:47 -0000 Subject: SUSE-RU-2026:22805-1: moderate: Recommended update for nvidia-open-driver-G07-signed Message-ID: <178515622711.2122.4407228933693441029@cbbac00f79c6> # Recommended update for nvidia-open-driver-G07-signed Announcement ID: SUSE-RU-2026:22805-1 Release Date: 2026-07-21T16:00:11Z Rating: moderate References: * bsc#1268792 Affected Products: * SUSE Linux Micro 6.0 An update that has one fix can now be installed. ## Description: This update for nvidia-open-driver-G07-signed fixes the following issues: * update non-CUDA variant to 595.84 (bsc#1268792) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-534=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 x86_64) * nvidia-open-driver-G07-signed-cuda-kmp-default-610.43.02_k6.4.0_49-1.2 * nvidia-open-driver-G07-signed-kmp-default-595.84_k6.4.0_49-1.1 * nvidia-open-driver-G07-signed-cuda-debugsource-610.43.02-1.2 * nvidia-open-driver-G07-signed-cuda-kmp-default-debuginfo-610.43.02_k6.4.0_49-1.2 * nvidia-open-driver-G07-signed-kmp-default-debuginfo-595.84_k6.4.0_49-1.1 * nvidia-open-driver-G07-signed-debugsource-595.84-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268792 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:44:08 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:44:08 -0000 Subject: SUSE-RU-2026:22804-1: moderate: Recommended update for lifecycle-data-sle-module-live-patching Message-ID: <178515624896.2122.11661363311292991085@cbbac00f79c6> # Recommended update for lifecycle-data-sle-module-live-patching Announcement ID: SUSE-RU-2026:22804-1 Release Date: 2026-07-21T15:56:28Z Rating: moderate References: * bsc#1020320 Affected Products: * SUSE Linux Micro 6.0 An update that has one fix can now be installed. ## Description: This update for lifecycle-data-sle-module-live-patching fixes the following issues: * Added data for 6_4_0-42, 6_4_0-43, 6_4_0-44, 6_4_0-45, 6_4_0-48, +kernel- livepatch-6_4_0-41-rt,_,+kernel-livepatch-6_4_0-46-rt,_ ,+kernel- livepatch-6_4_0-47-rt,*. (bsc#1020320) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-535=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * lifecycle-data-sle-module-live-patching-6-8.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1020320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:44:30 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:44:30 -0000 Subject: SUSE-RU-2026:22803-1: important: Recommended update for container-selinux Message-ID: <178515627044.2122.42057724954011996@cbbac00f79c6> # Recommended update for container-selinux Announcement ID: SUSE-RU-2026:22803-1 Release Date: 2026-07-21T09:42:28Z Rating: important References: * bsc#1268490 Affected Products: * SUSE Linux Micro 6.0 An update that has one fix can now be installed. ## Description: This update for container-selinux fixes the following issues: * Introduce container_can_execstack boolean for older Java applications and allow execmem (bsc#1268490) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-804=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * container-selinux-2.236.0-2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268490 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:44:52 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:44:52 -0000 Subject: SUSE-RU-2026:22802-1: moderate: Recommended update for python-gcemetadata Message-ID: <178515629209.2122.6660786344324191234@cbbac00f79c6> # Recommended update for python-gcemetadata Announcement ID: SUSE-RU-2026:22802-1 Release Date: 2026-07-21T09:35:58Z Rating: moderate References: * bsc#1269423 Affected Products: * SUSE Linux Micro 6.0 An update that has one fix can now be installed. ## Description: This update for python-gcemetadata fixes the following issues: * Update to version 1.1.1: * Fix UnboundLocalError when using --xml with --query (bsc#1269423) * Update comments ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-803=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * python-gcemetadata-1.1.1-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269423 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:45:26 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:45:26 -0000 Subject: SUSE-SU-2026:22801-1: important: Security update for python-cryptography Message-ID: <178515632682.2122.12958222804464125452@cbbac00f79c6> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:22801-1 Release Date: 2026-07-20T10:15:33Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270620). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270706). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270801). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-801=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * python311-cryptography-42.0.4-5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:46:05 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:46:05 -0000 Subject: SUSE-SU-2026:22800-1: moderate: Security update for containerd Message-ID: <178515636552.2122.11137189748168992614@cbbac00f79c6> # Security update for containerd Announcement ID: SUSE-SU-2026:22800-1 Release Date: 2026-07-20T10:12:23Z Rating: moderate References: * bsc#1262266 Cross-References: * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-35469 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-35469 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for containerd fixes the following issues * CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262266). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-802=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * containerd-1.7.29-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1262266 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:46:45 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:46:45 -0000 Subject: SUSE-SU-2026:22799-1: important: Security update for sssd Message-ID: <178515640576.2122.14321671234855472331@cbbac00f79c6> # Security update for sssd Announcement ID: SUSE-SU-2026:22799-1 Release Date: 2026-07-17T18:43:58Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-800=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * sssd-debuginfo-2.8.2-8.1 * sssd-ad-debuginfo-2.8.2-8.1 * sssd-dbus-2.8.2-8.1 * libsss_idmap0-2.8.2-8.1 * sssd-2.8.2-8.1 * sssd-ldap-2.8.2-8.1 * libsss_certmap0-2.8.2-8.1 * sssd-tools-debuginfo-2.8.2-8.1 * sssd-krb5-common-debuginfo-2.8.2-8.1 * sssd-krb5-common-2.8.2-8.1 * python3-sssd-config-debuginfo-2.8.2-8.1 * libsss_idmap0-debuginfo-2.8.2-8.1 * libsss_nss_idmap0-debuginfo-2.8.2-8.1 * sssd-ad-2.8.2-8.1 * python3-sssd-config-2.8.2-8.1 * sssd-dbus-debuginfo-2.8.2-8.1 * sssd-tools-2.8.2-8.1 * sssd-krb5-2.8.2-8.1 * libsss_nss_idmap0-2.8.2-8.1 * sssd-debugsource-2.8.2-8.1 * libsss_certmap0-debuginfo-2.8.2-8.1 * sssd-ldap-debuginfo-2.8.2-8.1 * sssd-krb5-debuginfo-2.8.2-8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:47:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:47:25 -0000 Subject: SUSE-SU-2026:22798-1: critical: Security update for pcr-oracle Message-ID: <178515644595.2122.6511535281227334910@cbbac00f79c6> # Security update for pcr-oracle Announcement ID: SUSE-SU-2026:22798-1 Release Date: 2026-07-17T14:47:10Z Rating: critical References: * bsc#1265042 * bsc#1270265 Affected Products: * SUSE Linux Micro 6.0 An update that has two fixes can now be installed. ## Description: This update for pcr-oracle fixes the following issue: * integer underflow vulnerability in `parse_sbatlevel_section()` (bsc#1265042). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-798=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 x86_64) * pcr-oracle-debugsource-0.4.6-9.1 * pcr-oracle-0.4.6-9.1 * pcr-oracle-debuginfo-0.4.6-9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265042 * https://bugzilla.suse.com/show_bug.cgi?id=1270265 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:48:07 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:48:07 -0000 Subject: SUSE-SU-2026:22797-1: important: Security update for vim Message-ID: <178515648759.2122.8283048736757311961@cbbac00f79c6> # Security update for vim Announcement ID: SUSE-SU-2026:22797-1 Release Date: 2026-07-17T12:29:36Z Rating: important References: * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for vim fixes the following issues * Updated to version 9.2.0780 * CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). * CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). * CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-796=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * vim-small-9.2.0780-1.1 * vim-debugsource-9.2.0780-1.1 * vim-small-debuginfo-9.2.0780-1.1 * SUSE Linux Micro 6.0 (noarch) * vim-data-common-9.2.0780-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:48:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:48:49 -0000 Subject: SUSE-SU-2026:22796-1: important: Security update for tiff Message-ID: <178515652922.2122.9240130644933091975@cbbac00f79c6> # Security update for tiff Announcement ID: SUSE-SU-2026:22796-1 Release Date: 2026-07-17T12:21:31Z Rating: important References: * bsc#1257123 * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for tiff fixes the following issues: Update to version 4.7.2. Security issues fixed: * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Other updates and bugfixes: * Enable Lerc support in openSUSE (bsc#1257123). * Version 4.7.2: * Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. * Library changes: * New/improved functionalities:: * Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781) * Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824) * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. * Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-795=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * tiff-debugsource-4.7.2-1.1 * libtiff6-debuginfo-4.7.2-1.1 * libtiff6-4.7.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://bugzilla.suse.com/show_bug.cgi?id=1257123 * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:50:03 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:50:03 -0000 Subject: SUSE-SU-2026:22795-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178515660358.2122.15146846800402616431@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22795-1 Release Date: 2026-07-17T07:44:22Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-532=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-35-rt-14-1.1 * kernel-livepatch-6_4_0-35-rt-debuginfo-14-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:51:19 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:51:19 -0000 Subject: SUSE-SU-2026:22794-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178515667951.2122.16750217310364508326@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22794-1 Release Date: 2026-07-17T07:44:22Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues: The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-531=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-18-1.1 * kernel-livepatch-6_4_0-34-rt-18-1.1 * kernel-livepatch-6_4_0-34-rt-debuginfo-18-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:52:34 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:52:34 -0000 Subject: SUSE-SU-2026:22793-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178515675445.2122.17658464301764810789@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22793-1 Release Date: 2026-07-17T07:44:11Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-533=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-36-rt-13-1.1 * kernel-livepatch-6_4_0-36-rt-debuginfo-13-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:53:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:53:49 -0000 Subject: SUSE-SU-2026:22792-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178515682909.2122.5369758082168359325@cbbac00f79c6> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22792-1 Release Date: 2026-07-17T07:41:16Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-33.1 fixes various security issues: The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-530=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-33-rt-debuginfo-18-1.2 * kernel-livepatch-6_4_0-33-rt-18-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_9-debugsource-18-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:56:35 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:56:35 -0000 Subject: SUSE-SU-2026:22791-1: important: Security update for the Linux Kernel Message-ID: <178515699598.2122.1686287742997063093@cbbac00f79c6> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22791-1 Release Date: 2026-07-22T11:18:12Z Rating: important References: * bsc#1243603 * bsc#1260593 * bsc#1263077 * bsc#1264003 * bsc#1264056 * bsc#1264180 * bsc#1264270 * bsc#1264302 * bsc#1264304 * bsc#1264328 * bsc#1264386 * bsc#1264419 * bsc#1264531 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264556 * bsc#1264580 * bsc#1264624 * bsc#1264731 * bsc#1264744 * bsc#1264790 * bsc#1264794 * bsc#1264853 * bsc#1264978 * bsc#1264987 * bsc#1264993 * bsc#1264997 * bsc#1265023 * bsc#1265041 * bsc#1265079 * bsc#1265142 * bsc#1266458 * bsc#1266686 * bsc#1266722 * bsc#1266726 * bsc#1266740 * bsc#1266773 * bsc#1266838 * bsc#1266883 * bsc#1266893 * bsc#1267213 * bsc#1267360 * bsc#1267493 * bsc#1267494 * bsc#1267495 * bsc#1267618 * bsc#1267992 * bsc#1267994 * bsc#1268989 * bsc#1269036 * bsc#1269129 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269172 * bsc#1269174 * bsc#1269188 * bsc#1269190 * bsc#1269193 * bsc#1269230 * bsc#1269262 * bsc#1269389 * bsc#1269392 * bsc#1269493 * bsc#1269527 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269645 * bsc#1269646 * bsc#1269651 * bsc#1269675 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269814 * bsc#1269886 * bsc#1269986 * bsc#1269989 * bsc#1269992 * bsc#1269993 * bsc#1270022 * bsc#1270059 * bsc#1270226 * bsc#1270257 * bsc#1271040 * bsc#1271050 * bsc#1271366 Cross-References: * CVE-2023-20585 * CVE-2026-31503 * CVE-2026-43019 * CVE-2026-43057 * CVE-2026-43092 * CVE-2026-43124 * CVE-2026-43157 * CVE-2026-43167 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43199 * CVE-2026-43204 * CVE-2026-43205 * CVE-2026-43226 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43253 * CVE-2026-43294 * CVE-2026-43304 * CVE-2026-43320 * CVE-2026-43373 * CVE-2026-43383 * CVE-2026-43445 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43473 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45899 * CVE-2026-45920 * CVE-2026-45987 * CVE-2026-45997 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46052 * CVE-2026-46059 * CVE-2026-46099 * CVE-2026-46161 * CVE-2026-46178 * CVE-2026-46242 * CVE-2026-46314 * CVE-2026-46322 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52961 * CVE-2026-52993 * CVE-2026-53021 * CVE-2026-53035 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53139 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53181 * CVE-2026-53196 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53245 * CVE-2026-53249 * CVE-2026-53256 * CVE-2026-53258 * CVE-2026-53274 * CVE-2026-53285 * CVE-2026-53306 * CVE-2026-53357 * CVE-2026-53359 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2023-20585 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-20585 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2023-20585 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31503 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31503 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31503 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43253 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52961 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53181 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53181 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 87 vulnerabilities and has six fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). * CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). * CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). * CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593). * CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). * CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). * CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53366: kernel: ipv4: account for fraggap on the paged allocation path (bsc#1271366) The following non security issues were fixed: * batman-adv: access unicast_ttvn skb->data only after skb realloc (git- fixes). * batman-adv: bla: reacquire gw address after skb realloc (git-fixes). * batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). * batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). * batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). * bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). * bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). * bnxt_en: Add TX timestamp completion logic (bsc#1264180). * bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). * bnxt_en: fix module unload sequence (bsc#1264180). * bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). * bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). * bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). * bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). * bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). * bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). * bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). * bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). * bnxt_en: silence clang build warning (bsc#1264180). * crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). * crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable- fixes). * drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). * drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git- fixes). * drm/amdgpu: fix aperture mapping leak (git-fixes). * drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). * drm/i915: Return NULL on error in active_instance (git-fixes). * drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). * drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). * drm/virtio: bound EDID block reads to the response buffer (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * gpio-f7188x: Add support for NCT6126D version B (git-fixes). * gpio: htc-egpio: use managed gpiochip registration (git-fixes). * gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). * gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git- fixes). * gpios: palmas: add .get_direction() op (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). * iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git- fixes). * iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). * iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). * iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). * iio: event: Fix event FIFO reset race (git-fixes). * iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). * iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). * iio: light: al3010: fix incorrect scale for the highest gain range (git- fixes). * iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). * iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). * Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). * Input: mms114 - fix multi-touch slot corruption (git-fixes). * iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). * ipv4: account for fraggap on the paged allocation path (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * pinctrl: meson: restore non-sleeping GPIO access (git-fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). * serial: 8250_omap: clear rx_running on zero-length DMA completes (git- fixes). * serial: msm: Disable DMA for kernel console UART (git-fixes). * staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). * staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git- fixes). * staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). * staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). * staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). * staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git- fixes). * tpm: Make the TPM character devices non-seekable (git-fixes). * usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git- fixes). * USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). * usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git- fixes). * usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). * usb: free iso schedules on failed submit (git-fixes). * usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git- fixes). * usb: gadget: f_printer: take kref only for successful open (git-fixes). * USB: idmouse: fix use-after-free on disconnect race (git-fixes). * USB: iowarrior: fix use-after-free on disconnect (git-fixes). * USB: ldusb: fix use-after-free on disconnect race (git-fixes). * USB: legousbtower: fix use-after-free on disconnect race (git-fixes). * USB: misc: uss720: unregister parport on probe failure (git-fixes). * usb: mtu3: unmap request DMA on queue failure (git-fixes). * USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). * USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). * USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). * USB: serial: keyspan_pda: fix information leak (git-fixes). * usb: sl811-hcd: disable controller wakeup on remove (git-fixes). * USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). * usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). * usb: typec: class: drop PD lookup reference (git-fixes). * usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). * usb: typec: ucsi: cancel pending work on system suspend (git-fixes). * usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). * usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). * usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). * USB: ulpi: fix memory leak on registration failure (git-fixes). * USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). * usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). * usbip: tools: support SuperSpeedPlus devices (git-fixes). * usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-538=1 ## Package List: * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-rt-debugsource-6.4.0-50.1 * kernel-rt-devel-6.4.0-50.1 * kernel-rt-devel-debuginfo-6.4.0-50.1 * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-rt-6.4.0-50.1 ## References: * https://www.suse.com/security/cve/CVE-2023-20585.html * https://www.suse.com/security/cve/CVE-2026-31503.html * https://www.suse.com/security/cve/CVE-2026-43019.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43204.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43253.html * https://www.suse.com/security/cve/CVE-2026-43294.html * https://www.suse.com/security/cve/CVE-2026-43304.html * https://www.suse.com/security/cve/CVE-2026-43320.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43445.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43473.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45987.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46059.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52961.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53035.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53181.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53245.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1243603 * https://bugzilla.suse.com/show_bug.cgi?id=1260593 * https://bugzilla.suse.com/show_bug.cgi?id=1263077 * https://bugzilla.suse.com/show_bug.cgi?id=1264003 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264180 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264419 * https://bugzilla.suse.com/show_bug.cgi?id=1264531 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264731 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264853 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264987 * https://bugzilla.suse.com/show_bug.cgi?id=1264993 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265041 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1267213 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267495 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269129 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269190 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269675 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269886 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1271040 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 12:59:23 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 12:59:23 -0000 Subject: SUSE-SU-2026:22790-1: important: Security update for the Linux Kernel Message-ID: <178515716396.2122.14392329598608965100@cbbac00f79c6> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22790-1 Release Date: 2026-07-22T13:52:17Z Rating: important References: * bsc#1243603 * bsc#1260593 * bsc#1263077 * bsc#1264003 * bsc#1264056 * bsc#1264180 * bsc#1264270 * bsc#1264302 * bsc#1264304 * bsc#1264328 * bsc#1264386 * bsc#1264419 * bsc#1264531 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264556 * bsc#1264580 * bsc#1264624 * bsc#1264731 * bsc#1264744 * bsc#1264790 * bsc#1264794 * bsc#1264853 * bsc#1264978 * bsc#1264987 * bsc#1264993 * bsc#1264997 * bsc#1265023 * bsc#1265041 * bsc#1265079 * bsc#1265142 * bsc#1266458 * bsc#1266686 * bsc#1266722 * bsc#1266726 * bsc#1266740 * bsc#1266773 * bsc#1266838 * bsc#1266883 * bsc#1266893 * bsc#1267213 * bsc#1267360 * bsc#1267493 * bsc#1267494 * bsc#1267495 * bsc#1267618 * bsc#1267992 * bsc#1267994 * bsc#1268989 * bsc#1269036 * bsc#1269129 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269172 * bsc#1269174 * bsc#1269188 * bsc#1269190 * bsc#1269193 * bsc#1269230 * bsc#1269262 * bsc#1269389 * bsc#1269392 * bsc#1269493 * bsc#1269527 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269645 * bsc#1269646 * bsc#1269651 * bsc#1269675 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269814 * bsc#1269886 * bsc#1269986 * bsc#1269989 * bsc#1269992 * bsc#1269993 * bsc#1270022 * bsc#1270059 * bsc#1270226 * bsc#1270257 * bsc#1271040 * bsc#1271050 * bsc#1271366 Cross-References: * CVE-2023-20585 * CVE-2026-31503 * CVE-2026-43019 * CVE-2026-43057 * CVE-2026-43092 * CVE-2026-43124 * CVE-2026-43157 * CVE-2026-43167 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43199 * CVE-2026-43204 * CVE-2026-43205 * CVE-2026-43226 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43253 * CVE-2026-43294 * CVE-2026-43304 * CVE-2026-43320 * CVE-2026-43373 * CVE-2026-43383 * CVE-2026-43445 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43473 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45899 * CVE-2026-45920 * CVE-2026-45987 * CVE-2026-45997 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46052 * CVE-2026-46059 * CVE-2026-46099 * CVE-2026-46161 * CVE-2026-46178 * CVE-2026-46242 * CVE-2026-46314 * CVE-2026-46322 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52961 * CVE-2026-52993 * CVE-2026-53021 * CVE-2026-53035 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53139 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53181 * CVE-2026-53196 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53245 * CVE-2026-53249 * CVE-2026-53256 * CVE-2026-53258 * CVE-2026-53274 * CVE-2026-53285 * CVE-2026-53306 * CVE-2026-53357 * CVE-2026-53359 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2023-20585 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-20585 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2023-20585 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31503 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31503 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31503 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43253 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52961 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53181 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53181 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 87 vulnerabilities and has six fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). * CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). * CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). * CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593). * CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). * CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). * CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53366: kernel: ipv4: account for fraggap on the paged allocation path (bsc#1271366) The following non security issues were fixed: * batman-adv: access unicast_ttvn skb->data only after skb realloc (git- fixes). * batman-adv: bla: reacquire gw address after skb realloc (git-fixes). * batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). * batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). * batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). * bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). * bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). * bnxt_en: Add TX timestamp completion logic (bsc#1264180). * bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). * bnxt_en: fix module unload sequence (bsc#1264180). * bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). * bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). * bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). * bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). * bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). * bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). * bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). * bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). * bnxt_en: silence clang build warning (bsc#1264180). * crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). * crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable- fixes). * drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). * drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git- fixes). * drm/amdgpu: fix aperture mapping leak (git-fixes). * drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). * drm/i915: Return NULL on error in active_instance (git-fixes). * drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). * drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). * drm/virtio: bound EDID block reads to the response buffer (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * gpio-f7188x: Add support for NCT6126D version B (git-fixes). * gpio: htc-egpio: use managed gpiochip registration (git-fixes). * gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). * gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git- fixes). * gpios: palmas: add .get_direction() op (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). * iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git- fixes). * iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). * iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). * iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). * iio: event: Fix event FIFO reset race (git-fixes). * iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). * iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). * iio: light: al3010: fix incorrect scale for the highest gain range (git- fixes). * iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). * iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). * Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). * Input: mms114 - fix multi-touch slot corruption (git-fixes). * iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). * ipv4: account for fraggap on the paged allocation path (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * pinctrl: meson: restore non-sleeping GPIO access (git-fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). * serial: 8250_omap: clear rx_running on zero-length DMA completes (git- fixes). * serial: msm: Disable DMA for kernel console UART (git-fixes). * staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). * staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git- fixes). * staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). * staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). * staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). * staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git- fixes). * tpm: Make the TPM character devices non-seekable (git-fixes). * usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git- fixes). * USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). * usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git- fixes). * usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). * usb: free iso schedules on failed submit (git-fixes). * usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git- fixes). * usb: gadget: f_printer: take kref only for successful open (git-fixes). * USB: idmouse: fix use-after-free on disconnect race (git-fixes). * USB: iowarrior: fix use-after-free on disconnect (git-fixes). * USB: ldusb: fix use-after-free on disconnect race (git-fixes). * USB: legousbtower: fix use-after-free on disconnect race (git-fixes). * USB: misc: uss720: unregister parport on probe failure (git-fixes). * usb: mtu3: unmap request DMA on queue failure (git-fixes). * USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). * USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). * USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). * USB: serial: keyspan_pda: fix information leak (git-fixes). * usb: sl811-hcd: disable controller wakeup on remove (git-fixes). * USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). * usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). * usb: typec: class: drop PD lookup reference (git-fixes). * usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). * usb: typec: ucsi: cancel pending work on system suspend (git-fixes). * usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). * usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). * usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). * USB: ulpi: fix memory leak on registration failure (git-fixes). * USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). * usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). * usbip: tools: support SuperSpeedPlus devices (git-fixes). * usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-536=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * kernel-obs-build-debugsource-6.4.0-50.1 * kernel-default-devel-6.4.0-50.1 * kernel-default-debugsource-6.4.0-50.1 * kernel-obs-build-6.4.0-50.1 * kernel-syms-6.4.0-50.1 * SUSE Linux Micro Extras 6.0 (aarch64) * kernel-64kb-debugsource-6.4.0-50.1 * kernel-64kb-devel-6.4.0-50.1 * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-default-6.4.0-50.1 * kernel-64kb-6.4.0-50.1 * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-default-devel-debuginfo-6.4.0-50.1 ## References: * https://www.suse.com/security/cve/CVE-2023-20585.html * https://www.suse.com/security/cve/CVE-2026-31503.html * https://www.suse.com/security/cve/CVE-2026-43019.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43204.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43253.html * https://www.suse.com/security/cve/CVE-2026-43294.html * https://www.suse.com/security/cve/CVE-2026-43304.html * https://www.suse.com/security/cve/CVE-2026-43320.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43445.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43473.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45987.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46059.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52961.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53035.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53181.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53245.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1243603 * https://bugzilla.suse.com/show_bug.cgi?id=1260593 * https://bugzilla.suse.com/show_bug.cgi?id=1263077 * https://bugzilla.suse.com/show_bug.cgi?id=1264003 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264180 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264419 * https://bugzilla.suse.com/show_bug.cgi?id=1264531 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264731 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264853 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264987 * https://bugzilla.suse.com/show_bug.cgi?id=1264993 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265041 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1267213 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267495 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269129 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269190 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269675 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269886 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1271040 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:00:05 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:00:05 -0000 Subject: SUSE-SU-2026:22789-1: important: Security update for vim Message-ID: <178515720592.2122.6700341359283670090@cbbac00f79c6> # Security update for vim Announcement ID: SUSE-SU-2026:22789-1 Release Date: 2026-07-17T12:25:54Z Rating: important References: * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for vim fixes the following issues * Updated to version 9.2.0780 * CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). * CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). * CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-796=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * vim-9.2.0780-1.1 * vim-debugsource-9.2.0780-1.1 * vim-debuginfo-9.2.0780-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:00:48 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:00:48 -0000 Subject: SUSE-SU-2026:3245-1: important: Security update for python3 Message-ID: <178515724858.2122.8575391922301508162@cbbac00f79c6> # Security update for python3 Announcement ID: SUSE-SU-2026:3245-1 Release Date: 2026-07-24T13:43:52Z Rating: important References: * bsc#1264962 * bsc#1265268 * bsc#1268977 Cross-References: * CVE-2026-11940 * CVE-2026-7210 * CVE-2026-8328 CVSS scores: * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2026-7210: insufficient entropy used for Expat hash-flooding protection allows a crafted XML document to trigger hash flooding (bsc#1264962). * CVE-2026-8328: server-supplied PASV host address is trusted by `ftpcp()` and allows for SSRF (bsc#1265268). * CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3245=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3245=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python3-base-debuginfo-3.4.10-25.188.1 * python3-tk-debuginfo-3.4.10-25.188.1 * python3-3.4.10-25.188.1 * python3-base-debugsource-3.4.10-25.188.1 * python3-curses-debuginfo-3.4.10-25.188.1 * python3-tk-3.4.10-25.188.1 * python3-devel-3.4.10-25.188.1 * libpython3_4m1_0-3.4.10-25.188.1 * python3-base-3.4.10-25.188.1 * libpython3_4m1_0-debuginfo-3.4.10-25.188.1 * python3-debugsource-3.4.10-25.188.1 * python3-curses-3.4.10-25.188.1 * python3-debuginfo-3.4.10-25.188.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * python3-base-debuginfo-32bit-3.4.10-25.188.1 * libpython3_4m1_0-32bit-3.4.10-25.188.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.188.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.188.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python3-base-debuginfo-3.4.10-25.188.1 * libpython3_4m1_0-32bit-3.4.10-25.188.1 * python3-tk-debuginfo-3.4.10-25.188.1 * python3-tk-3.4.10-25.188.1 * python3-3.4.10-25.188.1 * python3-curses-debuginfo-3.4.10-25.188.1 * python3-base-debugsource-3.4.10-25.188.1 * python3-devel-3.4.10-25.188.1 * python3-base-debuginfo-32bit-3.4.10-25.188.1 * libpython3_4m1_0-3.4.10-25.188.1 * python3-devel-debuginfo-3.4.10-25.188.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.188.1 * libpython3_4m1_0-debuginfo-3.4.10-25.188.1 * python3-base-3.4.10-25.188.1 * python3-debuginfo-3.4.10-25.188.1 * python3-debugsource-3.4.10-25.188.1 * python3-curses-3.4.10-25.188.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:01:36 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:01:36 -0000 Subject: SUSE-SU-2026:3244-1: moderate: Security update for systemd Message-ID: <178515729677.2122.17955974169850275931@cbbac00f79c6> # Security update for systemd Announcement ID: SUSE-SU-2026:3244-1 Release Date: 2026-07-24T13:11:41Z Rating: moderate References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1262305 * bsc#1267644 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability and has five security fixes can now be installed. ## Description: This update for systemd fixes the following issues: Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Fix soft reboot not restarting user services with default.target (bsc#1262305). * Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). * Import commit 429043ca9a (bsc#1261982 bsc#1261983). * Import commit 58e5d2e21e (bsc#1261982). * Import commit 4bd91117cc (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3244=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3244=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3244=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libudev-mini1-debuginfo-254.27-150600.4.71.1 * systemd-sysvcompat-debuginfo-254.27-150600.4.71.2 * systemd-mini-254.27-150600.4.71.1 * systemd-network-254.27-150600.4.71.2 * systemd-testsuite-254.27-150600.4.71.2 * systemd-254.27-150600.4.71.2 * systemd-resolved-debuginfo-254.27-150600.4.71.2 * libsystemd0-debuginfo-254.27-150600.4.71.2 * systemd-doc-254.27-150600.4.71.2 * udev-254.27-150600.4.71.2 * systemd-journal-remote-debuginfo-254.27-150600.4.71.2 * systemd-networkd-254.27-150600.4.71.2 * udev-mini-debuginfo-254.27-150600.4.71.1 * libudev1-debuginfo-254.27-150600.4.71.2 * systemd-debugsource-254.27-150600.4.71.2 * systemd-homed-debuginfo-254.27-150600.4.71.2 * systemd-networkd-debuginfo-254.27-150600.4.71.2 * systemd-mini-debuginfo-254.27-150600.4.71.1 * systemd-mini-container-debuginfo-254.27-150600.4.71.1 * libsystemd0-254.27-150600.4.71.2 * udev-mini-254.27-150600.4.71.1 * libudev1-254.27-150600.4.71.2 * systemd-experimental-debuginfo-254.27-150600.4.71.2 * systemd-mini-devel-254.27-150600.4.71.1 * libudev-mini1-254.27-150600.4.71.1 * systemd-debuginfo-254.27-150600.4.71.2 * libsystemd0-mini-debuginfo-254.27-150600.4.71.1 * systemd-coredump-debuginfo-254.27-150600.4.71.2 * systemd-testsuite-debuginfo-254.27-150600.4.71.2 * systemd-container-254.27-150600.4.71.2 * systemd-experimental-254.27-150600.4.71.2 * systemd-portable-debuginfo-254.27-150600.4.71.2 * libsystemd0-mini-254.27-150600.4.71.1 * systemd-portable-254.27-150600.4.71.2 * systemd-mini-debugsource-254.27-150600.4.71.1 * systemd-journal-remote-254.27-150600.4.71.2 * systemd-coredump-254.27-150600.4.71.2 * systemd-mini-container-254.27-150600.4.71.1 * systemd-resolved-254.27-150600.4.71.2 * systemd-container-debuginfo-254.27-150600.4.71.2 * systemd-homed-254.27-150600.4.71.2 * udev-debuginfo-254.27-150600.4.71.2 * systemd-devel-254.27-150600.4.71.2 * systemd-sysvcompat-254.27-150600.4.71.2 * openSUSE Leap 15.6 (x86_64) * libudev1-32bit-254.27-150600.4.71.2 * libsystemd0-32bit-debuginfo-254.27-150600.4.71.2 * libudev1-32bit-debuginfo-254.27-150600.4.71.2 * libsystemd0-32bit-254.27-150600.4.71.2 * systemd-32bit-254.27-150600.4.71.2 * systemd-devel-32bit-254.27-150600.4.71.2 * systemd-32bit-debuginfo-254.27-150600.4.71.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libudev1-64bit-254.27-150600.4.71.2 * systemd-64bit-debuginfo-254.27-150600.4.71.2 * libsystemd0-64bit-debuginfo-254.27-150600.4.71.2 * systemd-devel-64bit-254.27-150600.4.71.2 * libsystemd0-64bit-254.27-150600.4.71.2 * libudev1-64bit-debuginfo-254.27-150600.4.71.2 * systemd-64bit-254.27-150600.4.71.2 * openSUSE Leap 15.6 (aarch64 i586 x86_64) * systemd-boot-254.27-150600.4.71.2 * systemd-boot-debuginfo-254.27-150600.4.71.2 * openSUSE Leap 15.6 (noarch) * systemd-lang-254.27-150600.4.71.2 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * systemd-sysvcompat-debuginfo-254.27-150600.4.71.2 * systemd-doc-254.27-150600.4.71.2 * libsystemd0-debuginfo-254.27-150600.4.71.2 * systemd-resolved-debuginfo-254.27-150600.4.71.2 * systemd-254.27-150600.4.71.2 * udev-254.27-150600.4.71.2 * systemd-journal-remote-debuginfo-254.27-150600.4.71.2 * libudev1-debuginfo-254.27-150600.4.71.2 * systemd-debugsource-254.27-150600.4.71.2 * libsystemd0-254.27-150600.4.71.2 * libudev1-254.27-150600.4.71.2 * systemd-debuginfo-254.27-150600.4.71.2 * systemd-coredump-debuginfo-254.27-150600.4.71.2 * systemd-container-254.27-150600.4.71.2 * systemd-journal-remote-254.27-150600.4.71.2 * systemd-coredump-254.27-150600.4.71.2 * systemd-resolved-254.27-150600.4.71.2 * systemd-container-debuginfo-254.27-150600.4.71.2 * udev-debuginfo-254.27-150600.4.71.2 * systemd-devel-254.27-150600.4.71.2 * systemd-sysvcompat-254.27-150600.4.71.2 * Basesystem Module 15-SP7 (noarch) * systemd-lang-254.27-150600.4.71.2 * Basesystem Module 15-SP7 (x86_64) * libudev1-32bit-254.27-150600.4.71.2 * libsystemd0-32bit-debuginfo-254.27-150600.4.71.2 * libudev1-32bit-debuginfo-254.27-150600.4.71.2 * libsystemd0-32bit-254.27-150600.4.71.2 * systemd-32bit-254.27-150600.4.71.2 * systemd-32bit-debuginfo-254.27-150600.4.71.2 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * systemd-debugsource-254.27-150600.4.71.2 * systemd-debuginfo-254.27-150600.4.71.2 * systemd-network-254.27-150600.4.71.2 * systemd-networkd-debuginfo-254.27-150600.4.71.2 * systemd-networkd-254.27-150600.4.71.2 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1262305 * https://bugzilla.suse.com/show_bug.cgi?id=1267644 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:02:32 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:02:32 -0000 Subject: SUSE-SU-2026:3243-1: low: Security update for gpg2 Message-ID: <178515735297.2122.16406138750847356502@cbbac00f79c6> # Security update for gpg2 Announcement ID: SUSE-SU-2026:3243-1 Release Date: 2026-07-24T13:09:39Z Rating: low References: * bsc#1269279 Cross-References: * CVE-2026-57062 CVSS scores: * CVE-2026-57062 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-57062 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-57062 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gpg2 fixes the following issue: * CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3243=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3243=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * gpg2-debugsource-2.4.4-150600.3.18.1 * gpg2-tpm-debuginfo-2.4.4-150600.3.18.1 * gpg2-2.4.4-150600.3.18.1 * dirmngr-debuginfo-2.4.4-150600.3.18.1 * dirmngr-2.4.4-150600.3.18.1 * gpg2-debuginfo-2.4.4-150600.3.18.1 * gpg2-tpm-2.4.4-150600.3.18.1 * openSUSE Leap 15.6 (noarch) * gpg2-lang-2.4.4-150600.3.18.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gpg2-debugsource-2.4.4-150600.3.18.1 * gpg2-2.4.4-150600.3.18.1 * dirmngr-debuginfo-2.4.4-150600.3.18.1 * dirmngr-2.4.4-150600.3.18.1 * gpg2-debuginfo-2.4.4-150600.3.18.1 * Basesystem Module 15-SP7 (noarch) * gpg2-lang-2.4.4-150600.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57062.html * https://bugzilla.suse.com/show_bug.cgi?id=1269279 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:03:28 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:03:28 -0000 Subject: SUSE-SU-2026:3241-1: important: Security update for gzip Message-ID: <178515740842.2122.18190038459113176507@cbbac00f79c6> # Security update for gzip Announcement ID: SUSE-SU-2026:3241-1 Release Date: 2026-07-24T13:06:57Z Rating: important References: * bsc#1269622 Cross-References: * CVE-2026-41991 CVSS scores: * CVE-2026-41991 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41991 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41991 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41991 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gzip fixes the following issue: * CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3241=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3241=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gzip-debugsource-1.10-4.17.1 * gzip-debuginfo-1.10-4.17.1 * gzip-1.10-4.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gzip-1.10-4.17.1 * gzip-debugsource-1.10-4.17.1 * gzip-debuginfo-1.10-4.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41991.html * https://bugzilla.suse.com/show_bug.cgi?id=1269622 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:04:10 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:04:10 -0000 Subject: SUSE-SU-2026:3240-1: important: Security update for python-soupsieve Message-ID: <178515745021.2122.15300512112867899191@cbbac00f79c6> # Security update for python-soupsieve Announcement ID: SUSE-SU-2026:3240-1 Release Date: 2026-07-24T13:05:20Z Rating: important References: * bsc#1256316 * bsc#1271187 * bsc#1271188 Cross-References: * CVE-2026-49476 * CVE-2026-49477 CVSS scores: * CVE-2026-49476 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49476 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for python-soupsieve fixes the following issues * CVE-2026-49476: Memory Exhaustion via Large Comma-Separated Selector Lists (bsc#1271187). * CVE-2026-49477: Regular Expression Denial of Service (ReDoS) via Selector Parser (bsc#1271188). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3240=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3240=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3240=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3240=1 ## Package List: * openSUSE Leap 15.6 (noarch) * python311-soupsieve-2.5-150600.3.3.1 * Python 3 Module 15-SP7 (noarch) * python311-soupsieve-2.5-150600.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-soupsieve-2.5-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-soupsieve-2.5-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49476.html * https://www.suse.com/security/cve/CVE-2026-49477.html * https://bugzilla.suse.com/show_bug.cgi?id=1256316 * https://bugzilla.suse.com/show_bug.cgi?id=1271187 * https://bugzilla.suse.com/show_bug.cgi?id=1271188 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:05:09 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:05:09 -0000 Subject: SUSE-SU-2026:3239-1: important: Security update for python-soupsieve Message-ID: <178515750960.2122.1849692146570618001@cbbac00f79c6> # Security update for python-soupsieve Announcement ID: SUSE-SU-2026:3239-1 Release Date: 2026-07-24T13:04:57Z Rating: important References: * bsc#1256316 * bsc#1271187 * bsc#1271188 Cross-References: * CVE-2026-49476 * CVE-2026-49477 CVSS scores: * CVE-2026-49476 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49476 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for python-soupsieve fixes the following issues * CVE-2026-49476: Memory Exhaustion via Large Comma-Separated Selector Lists (bsc#1271187). * CVE-2026-49477: Regular Expression Denial of Service (ReDoS) via Selector Parser (bsc#1271188). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3239=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3239=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3239=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3239=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3239=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3239=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3239=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3239=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3239=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3239=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3239=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 * Basesystem Module 15-SP7 (noarch) * python3-soupsieve-1.9.5-150200.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49476.html * https://www.suse.com/security/cve/CVE-2026-49477.html * https://bugzilla.suse.com/show_bug.cgi?id=1256316 * https://bugzilla.suse.com/show_bug.cgi?id=1271187 * https://bugzilla.suse.com/show_bug.cgi?id=1271188 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:05:51 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:05:51 -0000 Subject: SUSE-SU-2026:3238-1: important: Security update for python-pyasn1 Message-ID: <178515755126.2122.8450707267773518106@cbbac00f79c6> # Security update for python-pyasn1 Announcement ID: SUSE-SU-2026:3238-1 Release Date: 2026-07-24T12:56:31Z Rating: important References: * bsc#1271464 * bsc#1271465 * bsc#1271466 Cross-References: * CVE-2026-59884 * CVE-2026-59885 * CVE-2026-59886 CVSS scores: * CVE-2026-59884 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59884 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59884 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59885 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59885 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59885 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59886 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59886 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59886 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-pyasn1 fixes the following issues: * CVE-2026-59884: BER/CER/DER decoder denial of service via unbounded long- form tag IDs (bsc#1271464). * CVE-2026-59885: quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service (bsc#1271465). * CVE-2026-59886: uncontrolled resource consumption when converting decoded REAL values (bsc#1271466). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3238=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3238=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3238=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3238=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3238=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3238=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3238=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3238=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3238=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3238=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3238=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3238=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3238=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * openSUSE Leap 15.4 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * Public Cloud Module 15-SP4 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-pyasn1-0.5.0-150400.12.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59884.html * https://www.suse.com/security/cve/CVE-2026-59885.html * https://www.suse.com/security/cve/CVE-2026-59886.html * https://bugzilla.suse.com/show_bug.cgi?id=1271464 * https://bugzilla.suse.com/show_bug.cgi?id=1271465 * https://bugzilla.suse.com/show_bug.cgi?id=1271466 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:06:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:06:49 -0000 Subject: SUSE-SU-2026:3237-1: important: Security update for vim Message-ID: <178515760942.2122.17810024846975969508@cbbac00f79c6> # Security update for vim Announcement ID: SUSE-SU-2026:3237-1 Release Date: 2026-07-24T12:46:19Z Rating: important References: * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for vim fixes the following issues * Updated to version 9.2.0780. * CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). * CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). * CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3237=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3237=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gvim-debuginfo-9.2.0780-17.73.1 * vim-debugsource-9.2.0780-17.73.1 * vim-debuginfo-9.2.0780-17.73.1 * gvim-9.2.0780-17.73.1 * vim-9.2.0780-17.73.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * vim-data-9.2.0780-17.73.1 * vim-data-common-9.2.0780-17.73.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gvim-debuginfo-9.2.0780-17.73.1 * vim-debugsource-9.2.0780-17.73.1 * vim-debuginfo-9.2.0780-17.73.1 * gvim-9.2.0780-17.73.1 * vim-9.2.0780-17.73.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * vim-data-9.2.0780-17.73.1 * vim-data-common-9.2.0780-17.73.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:07:36 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:07:36 -0000 Subject: SUSE-SU-2026:3236-1: important: Security update for glib2 Message-ID: <178515765621.2122.13317825830295815709@cbbac00f79c6> # Security update for glib2 Announcement ID: SUSE-SU-2026:3236-1 Release Date: 2026-07-24T12:42:39Z Rating: important References: * bsc#1270008 * bsc#1270009 * bsc#1270010 * bsc#1270016 * bsc#1270018 * bsc#1270021 Cross-References: * CVE-2026-58010 * CVE-2026-58011 * CVE-2026-58012 * CVE-2026-58013 * CVE-2026-58014 * CVE-2026-58016 CVSS scores: * CVE-2026-58010 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58012 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). * CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). * CVE-2026-58012: raw byte regex matches with UTF-8 functions during case- change replacements could cause an out-of- bounds read (bsc#1270016). * CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). * CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). * CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3236=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3236=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libgio-2_0-0-2.48.2-12.61.1 * glib2-debugsource-2.48.2-12.61.1 * glib2-devel-static-2.48.2-12.61.1 * libgthread-2_0-0-debuginfo-2.48.2-12.61.1 * glib2-devel-2.48.2-12.61.1 * libgthread-2_0-0-2.48.2-12.61.1 * glib2-tools-2.48.2-12.61.1 * libglib-2_0-0-2.48.2-12.61.1 * glib2-devel-debuginfo-2.48.2-12.61.1 * libglib-2_0-0-debuginfo-2.48.2-12.61.1 * libgobject-2_0-0-debuginfo-2.48.2-12.61.1 * libgobject-2_0-0-2.48.2-12.61.1 * libgmodule-2_0-0-debuginfo-2.48.2-12.61.1 * glib2-tools-debuginfo-2.48.2-12.61.1 * libgio-2_0-0-debuginfo-2.48.2-12.61.1 * libgmodule-2_0-0-2.48.2-12.61.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libgthread-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * libgmodule-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * libgobject-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * libgio-2_0-0-32bit-2.48.2-12.61.1 * libgobject-2_0-0-32bit-2.48.2-12.61.1 * libgio-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * libgthread-2_0-0-32bit-2.48.2-12.61.1 * libgmodule-2_0-0-32bit-2.48.2-12.61.1 * libglib-2_0-0-32bit-2.48.2-12.61.1 * libglib-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * glib2-lang-2.48.2-12.61.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * glib2-tools-2.48.2-12.61.1 * libgthread-2_0-0-32bit-2.48.2-12.61.1 * libgmodule-2_0-0-32bit-2.48.2-12.61.1 * libglib-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * libgthread-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * libgmodule-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * glib2-devel-static-2.48.2-12.61.1 * libgio-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * libgthread-2_0-0-2.48.2-12.61.1 * libglib-2_0-0-2.48.2-12.61.1 * libgobject-2_0-0-debuginfo-2.48.2-12.61.1 * libglib-2_0-0-32bit-2.48.2-12.61.1 * libgmodule-2_0-0-debuginfo-2.48.2-12.61.1 * libgio-2_0-0-debuginfo-2.48.2-12.61.1 * libgobject-2_0-0-32bit-2.48.2-12.61.1 * libgthread-2_0-0-debuginfo-2.48.2-12.61.1 * glib2-devel-debuginfo-2.48.2-12.61.1 * libgobject-2_0-0-debuginfo-32bit-2.48.2-12.61.1 * glib2-debugsource-2.48.2-12.61.1 * libgio-2_0-0-2.48.2-12.61.1 * libgio-2_0-0-32bit-2.48.2-12.61.1 * glib2-devel-2.48.2-12.61.1 * libglib-2_0-0-debuginfo-2.48.2-12.61.1 * libgobject-2_0-0-2.48.2-12.61.1 * glib2-tools-debuginfo-2.48.2-12.61.1 * libgmodule-2_0-0-2.48.2-12.61.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * glib2-lang-2.48.2-12.61.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58010.html * https://www.suse.com/security/cve/CVE-2026-58011.html * https://www.suse.com/security/cve/CVE-2026-58012.html * https://www.suse.com/security/cve/CVE-2026-58013.html * https://www.suse.com/security/cve/CVE-2026-58014.html * https://www.suse.com/security/cve/CVE-2026-58016.html * https://bugzilla.suse.com/show_bug.cgi?id=1270008 * https://bugzilla.suse.com/show_bug.cgi?id=1270009 * https://bugzilla.suse.com/show_bug.cgi?id=1270010 * https://bugzilla.suse.com/show_bug.cgi?id=1270016 * https://bugzilla.suse.com/show_bug.cgi?id=1270018 * https://bugzilla.suse.com/show_bug.cgi?id=1270021 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 13:08:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 13:08:25 -0000 Subject: SUSE-SU-2026:3235-1: important: Security update for glib2 Message-ID: <178515770553.2122.18015075986602982044@cbbac00f79c6> # Security update for glib2 Announcement ID: SUSE-SU-2026:3235-1 Release Date: 2026-07-24T12:42:20Z Rating: important References: * bsc#1270008 * bsc#1270009 * bsc#1270010 * bsc#1270016 * bsc#1270018 * bsc#1270021 Cross-References: * CVE-2026-58010 * CVE-2026-58011 * CVE-2026-58012 * CVE-2026-58013 * CVE-2026-58014 * CVE-2026-58016 CVSS scores: * CVE-2026-58010 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58012 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). * CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). * CVE-2026-58012: raw byte regex matches with UTF-8 functions during case- change replacements could cause an out-of- bounds read (bsc#1270016). * CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). * CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). * CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3235=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3235=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3235=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3235=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3235=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3235=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3235=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3235=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3235=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3235=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3235=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3235=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3235=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3235=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * glib2-lang-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * glib2-devel-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * glib2-devel-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * glib2-lang-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * glib2-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * glib2-lang-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * glib2-tests-devel-2.70.5-150400.3.37.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgthread-2_0-0-2.70.5-150400.3.37.1 * glib2-tests-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-doc-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * glib2-devel-static-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgmodule-2_0-0-64bit-2.70.5-150400.3.37.1 * libgthread-2_0-0-64bit-2.70.5-150400.3.37.1 * glib2-devel-64bit-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-64bit-2.70.5-150400.3.37.1 * libgmodule-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-64bit-2.70.5-150400.3.37.1 * libglib-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-64bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-64bit-2.70.5-150400.3.37.1 * libgio-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-64bit-2.70.5-150400.3.37.1 * libgio-2_0-0-64bit-2.70.5-150400.3.37.1 * libgthread-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1 * openSUSE Leap 15.4 (x86_64) * libgthread-2_0-0-32bit-2.70.5-150400.3.37.1 * libgthread-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1 * glib2-devel-32bit-2.70.5-150400.3.37.1 * glib2-tools-32bit-2.70.5-150400.3.37.1 * glib2-tools-32bit-debuginfo-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.37.1 * glib2-devel-32bit-debuginfo-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-2.70.5-150400.3.37.1 * openSUSE Leap 15.4 (noarch) * glib2-lang-2.70.5-150400.3.37.1 * gio-branding-upstream-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * glib2-devel-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * glib2-lang-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * glib2-devel-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * glib2-lang-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * glib2-devel-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * glib2-lang-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * glib2-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * glib2-lang-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * glib2-tools-debuginfo-2.70.5-150400.3.37.1 * glib2-debugsource-2.70.5-150400.3.37.1 * libglib-2_0-0-2.70.5-150400.3.37.1 * libgmodule-2_0-0-2.70.5-150400.3.37.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-2.70.5-150400.3.37.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1 * glib2-tools-2.70.5-150400.3.37.1 * glib2-devel-debuginfo-2.70.5-150400.3.37.1 * glib2-devel-2.70.5-150400.3.37.1 * libgio-2_0-0-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-2.70.5-150400.3.37.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-2.70.5-150400.3.37.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * glib2-lang-2.70.5-150400.3.37.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58010.html * https://www.suse.com/security/cve/CVE-2026-58011.html * https://www.suse.com/security/cve/CVE-2026-58012.html * https://www.suse.com/security/cve/CVE-2026-58013.html * https://www.suse.com/security/cve/CVE-2026-58014.html * https://www.suse.com/security/cve/CVE-2026-58016.html * https://bugzilla.suse.com/show_bug.cgi?id=1270008 * https://bugzilla.suse.com/show_bug.cgi?id=1270009 * https://bugzilla.suse.com/show_bug.cgi?id=1270010 * https://bugzilla.suse.com/show_bug.cgi?id=1270016 * https://bugzilla.suse.com/show_bug.cgi?id=1270018 * https://bugzilla.suse.com/show_bug.cgi?id=1270021 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:30:36 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:30:36 -0000 Subject: SUSE-SU-2026:22916-1: important: Security update for kernel-livepatch-MICRO-6-0-RT_Update_27 Message-ID: <178516983607.2240.5388341510415134365@c3e054a4ce29> # Security update for kernel-livepatch-MICRO-6-0-RT_Update_27 Announcement ID: SUSE-SU-2026:22916-1 Release Date: 2026-07-22T11:20:16Z Rating: important References: * bsc#1103203 * bsc#1149841 * bsc#1196281 * bsc#1244337 * bsc#1248108 * bsc#904970 * bsc#907150 * bsc#920615 * bsc#920633 * bsc#930408 * jsc#PED-14811 * jsc#PED-7906 Affected Products: * SUSE Linux Micro 6.1 An update that contains two features and has 10 fixes can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_27 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 27 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-539=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_27-debugsource-1-1.1 * kernel-livepatch-6_4_0-50-rt-1-1.1 * kernel-livepatch-6_4_0-50-rt-debuginfo-1-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1103203 * https://bugzilla.suse.com/show_bug.cgi?id=1149841 * https://bugzilla.suse.com/show_bug.cgi?id=1196281 * https://bugzilla.suse.com/show_bug.cgi?id=1244337 * https://bugzilla.suse.com/show_bug.cgi?id=1248108 * https://bugzilla.suse.com/show_bug.cgi?id=904970 * https://bugzilla.suse.com/show_bug.cgi?id=907150 * https://bugzilla.suse.com/show_bug.cgi?id=920615 * https://bugzilla.suse.com/show_bug.cgi?id=920633 * https://bugzilla.suse.com/show_bug.cgi?id=930408 * https://jira.suse.com/browse/PED-14811 * https://jira.suse.com/browse/PED-7906 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:31:59 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:31:59 -0000 Subject: SUSE-SU-2026:22915-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178516991999.2240.18041588912107860276@c3e054a4ce29> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22915-1 Release Date: 2026-07-17T07:44:22Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-532=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-35-rt-debuginfo-14-1.1 * kernel-livepatch-6_4_0-35-rt-14-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:33:38 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:33:38 -0000 Subject: SUSE-SU-2026:22914-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178517001800.2240.17977520025105939457@c3e054a4ce29> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22914-1 Release Date: 2026-07-17T07:44:22Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues: The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-531=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-34-rt-debuginfo-18-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-18-1.1 * kernel-livepatch-6_4_0-34-rt-18-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:35:02 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:35:02 -0000 Subject: SUSE-SU-2026:22913-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178517010240.2240.4636945344499648018@c3e054a4ce29> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22913-1 Release Date: 2026-07-17T07:44:11Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-533=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-36-rt-debuginfo-13-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-13-1.1 * kernel-livepatch-6_4_0-36-rt-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:36:24 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:36:24 -0000 Subject: SUSE-SU-2026:22912-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178517018416.2240.18339440247822622854@c3e054a4ce29> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22912-1 Release Date: 2026-07-17T07:41:16Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-33.1 fixes various security issues: The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-530=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_9-debugsource-18-1.2 * kernel-livepatch-6_4_0-33-rt-18-1.2 * kernel-livepatch-6_4_0-33-rt-debuginfo-18-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:37:01 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:37:01 -0000 Subject: SUSE-SU-2026:22911-1: moderate: Security update for kernel-livepatch-MICRO-6-0_Update_27 Message-ID: <178517022169.2240.8341200673563252184@c3e054a4ce29> # Security update for kernel-livepatch-MICRO-6-0_Update_27 Announcement ID: SUSE-SU-2026:22911-1 Release Date: 2026-07-22T11:21:34Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.1 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_27 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 27 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-537=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-50-default-debuginfo-1-1.1 * kernel-livepatch-MICRO-6-0_Update_27-debugsource-1-1.1 * kernel-livepatch-6_4_0-50-default-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:37:42 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:37:42 -0000 Subject: SUSE-SU-2026:22910-1: moderate: Security update for s390-tools Message-ID: <178517026217.2240.11127023469209152322@c3e054a4ce29> # Security update for s390-tools Announcement ID: SUSE-SU-2026:22910-1 Release Date: 2026-07-21T16:53:29Z Rating: moderate References: * bsc#1270185 Cross-References: * CVE-2026-41676 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for s390-tools fixes the following issue * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270185). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-621=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * s390-tools-genprotimg-data-2.31.0-slfo.1.1_4.1 * SUSE Linux Micro 6.1 (s390x) * libkmipclient1-debuginfo-2.31.0-slfo.1.1_4.1 * libekmfweb1-debuginfo-2.31.0-slfo.1.1_4.1 * libkmipclient1-2.31.0-slfo.1.1_4.1 * s390-tools-debugsource-2.31.0-slfo.1.1_4.1 * libekmfweb1-2.31.0-slfo.1.1_4.1 * s390-tools-2.31.0-slfo.1.1_4.1 * s390-tools-debuginfo-2.31.0-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270185 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:38:22 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:38:22 -0000 Subject: SUSE-RU-2026:22909-1: moderate: Recommended update for lifecycle-data-sle-module-live-patching Message-ID: <178517030228.2240.15012340462051975168@c3e054a4ce29> # Recommended update for lifecycle-data-sle-module-live-patching Announcement ID: SUSE-RU-2026:22909-1 Release Date: 2026-07-21T15:56:32Z Rating: moderate References: * bsc#1020320 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for lifecycle-data-sle-module-live-patching fixes the following issues: * Added data for 6_4_0-42, 6_4_0-43, 6_4_0-44, 6_4_0-45, 6_4_0-48, +kernel- livepatch-6_4_0-41-rt,_,+kernel-livepatch-6_4_0-46-rt,_ ,+kernel- livepatch-6_4_0-47-rt,*. (bsc#1020320) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-535=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * lifecycle-data-sle-module-live-patching-6-8.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1020320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:38:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:38:49 -0000 Subject: SUSE-RU-2026:22908-1: important: Recommended update for ServiceReport Message-ID: <178517032970.2240.15360931097730357608@c3e054a4ce29> # Recommended update for ServiceReport Announcement ID: SUSE-RU-2026:22908-1 Release Date: 2026-07-23T11:35:08Z Rating: important References: * bsc#1244547 * bsc#1270052 Affected Products: * SUSE Linux Micro 6.1 An update that has two fixes can now be installed. ## Description: This update for ServiceReport fixes the following issues: * Update to version 2.2.4+git12.bc007b2 (bsc#1270052): * [kdump] Fix TypeError in kdump component check * Update to version 2.2.4+git11.8bf0f05: * Remove PrivateDevices=true * remove type=oneshot * add new plugin Spyre card configuration * Fix packaging to use proper Python related macros (bsc#1244547) * Modernize upstream packaging ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-636=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * ServiceReport-2.2.4+git12.bc007b2-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1244547 * https://bugzilla.suse.com/show_bug.cgi?id=1270052 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:39:13 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:39:13 -0000 Subject: SUSE-SU-2026:22907-1: moderate: Security update for libgcrypt Message-ID: <178517035378.2240.2901814436708904657@c3e054a4ce29> # Security update for libgcrypt Announcement ID: SUSE-SU-2026:22907-1 Release Date: 2026-07-24T07:28:58Z Rating: moderate References: * bsc#1262684 Cross-References: * CVE-2026-41989 CVSS scores: * CVE-2026-41989 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue: * CVE-2026-41989: crafted ECDH ciphertext can lead denial of service (bsc#1262684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-638=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libgcrypt20-1.10.3-slfo.1.1_4.1 * libgcrypt-debugsource-1.10.3-slfo.1.1_4.1 * libgcrypt20-debuginfo-1.10.3-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41989.html * https://bugzilla.suse.com/show_bug.cgi?id=1262684 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:39:52 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:39:52 -0000 Subject: SUSE-SU-2026:22906-1: important: Security update for gzip Message-ID: <178517039291.2240.18191776632019041435@c3e054a4ce29> # Security update for gzip Announcement ID: SUSE-SU-2026:22906-1 Release Date: 2026-07-24T07:24:05Z Rating: important References: * bsc#1269622 Cross-References: * CVE-2026-41991 CVSS scores: * CVE-2026-41991 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41991 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41991 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41991 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for gzip fixes the following issue * CVE-2026-41991: insecure temporary file handling in the `gzexe` utility when the `mktemp` utility is not available in a user's `PATH` (bsc#1269622). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-637=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * gzip-1.13-slfo.1.1_3.1 * gzip-debuginfo-1.13-slfo.1.1_3.1 * gzip-debugsource-1.13-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41991.html * https://bugzilla.suse.com/show_bug.cgi?id=1269622 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:40:35 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:40:35 -0000 Subject: SUSE-SU-2026:22905-1: low: Security update for patch Message-ID: <178517043574.2240.8162637780683914595@c3e054a4ce29> # Security update for patch Announcement ID: SUSE-SU-2026:22905-1 Release Date: 2026-07-23T11:28:15Z Rating: low References: * bsc#1194037 * bsc#1271166 * bsc#1271167 Cross-References: * CVE-2021-45261 * CVE-2026-56288 * CVE-2026-56289 CVSS scores: * CVE-2021-45261 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2021-45261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56288 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56288 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56289 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2026-56289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56289 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56289 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for patch fixes the following issues * CVE-2021-45261: Invalid Pointer via another_hunk function (bsc#1194037). * CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167). * CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-635=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * patch-2.7.6-slfo.1.1_2.1 * patch-debuginfo-2.7.6-slfo.1.1_2.1 * patch-debugsource-2.7.6-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2021-45261.html * https://www.suse.com/security/cve/CVE-2026-56288.html * https://www.suse.com/security/cve/CVE-2026-56289.html * https://bugzilla.suse.com/show_bug.cgi?id=1194037 * https://bugzilla.suse.com/show_bug.cgi?id=1271166 * https://bugzilla.suse.com/show_bug.cgi?id=1271167 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:43:39 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:43:39 -0000 Subject: SUSE-SU-2026:22904-1: important: Security update for the Linux Kernel Message-ID: <178517061944.2240.7833116297122354511@c3e054a4ce29> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22904-1 Release Date: 2026-07-22T13:52:17Z Rating: important References: * bsc#1243603 * bsc#1260593 * bsc#1263077 * bsc#1264003 * bsc#1264056 * bsc#1264180 * bsc#1264270 * bsc#1264302 * bsc#1264304 * bsc#1264328 * bsc#1264386 * bsc#1264419 * bsc#1264531 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264556 * bsc#1264580 * bsc#1264624 * bsc#1264731 * bsc#1264744 * bsc#1264790 * bsc#1264794 * bsc#1264853 * bsc#1264978 * bsc#1264987 * bsc#1264993 * bsc#1264997 * bsc#1265023 * bsc#1265041 * bsc#1265079 * bsc#1265142 * bsc#1266458 * bsc#1266686 * bsc#1266722 * bsc#1266726 * bsc#1266740 * bsc#1266773 * bsc#1266838 * bsc#1266883 * bsc#1266893 * bsc#1267213 * bsc#1267360 * bsc#1267493 * bsc#1267494 * bsc#1267495 * bsc#1267618 * bsc#1267992 * bsc#1267994 * bsc#1268989 * bsc#1269036 * bsc#1269129 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269172 * bsc#1269174 * bsc#1269188 * bsc#1269190 * bsc#1269193 * bsc#1269230 * bsc#1269262 * bsc#1269389 * bsc#1269392 * bsc#1269493 * bsc#1269527 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269645 * bsc#1269646 * bsc#1269651 * bsc#1269675 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269814 * bsc#1269886 * bsc#1269986 * bsc#1269989 * bsc#1269992 * bsc#1269993 * bsc#1270022 * bsc#1270059 * bsc#1270226 * bsc#1270257 * bsc#1271040 * bsc#1271050 * bsc#1271366 Cross-References: * CVE-2023-20585 * CVE-2026-31503 * CVE-2026-43019 * CVE-2026-43057 * CVE-2026-43092 * CVE-2026-43124 * CVE-2026-43157 * CVE-2026-43167 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43199 * CVE-2026-43204 * CVE-2026-43205 * CVE-2026-43226 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43253 * CVE-2026-43294 * CVE-2026-43304 * CVE-2026-43320 * CVE-2026-43373 * CVE-2026-43383 * CVE-2026-43445 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43473 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45899 * CVE-2026-45920 * CVE-2026-45987 * CVE-2026-45997 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46052 * CVE-2026-46059 * CVE-2026-46099 * CVE-2026-46161 * CVE-2026-46178 * CVE-2026-46242 * CVE-2026-46314 * CVE-2026-46322 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52961 * CVE-2026-52993 * CVE-2026-53021 * CVE-2026-53035 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53139 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53181 * CVE-2026-53196 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53245 * CVE-2026-53249 * CVE-2026-53256 * CVE-2026-53258 * CVE-2026-53274 * CVE-2026-53285 * CVE-2026-53306 * CVE-2026-53357 * CVE-2026-53359 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2023-20585 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-20585 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2023-20585 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31503 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31503 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31503 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43253 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52961 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53181 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53181 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 87 vulnerabilities and has six fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). * CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). * CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). * CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593). * CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). * CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). * CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53366: kernel: ipv4: account for fraggap on the paged allocation path (bsc#1271366) The following non security issues were fixed: * batman-adv: access unicast_ttvn skb->data only after skb realloc (git- fixes). * batman-adv: bla: reacquire gw address after skb realloc (git-fixes). * batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). * batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). * batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). * bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). * bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). * bnxt_en: Add TX timestamp completion logic (bsc#1264180). * bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). * bnxt_en: fix module unload sequence (bsc#1264180). * bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). * bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). * bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). * bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). * bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). * bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). * bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). * bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). * bnxt_en: silence clang build warning (bsc#1264180). * crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). * crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable- fixes). * drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). * drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git- fixes). * drm/amdgpu: fix aperture mapping leak (git-fixes). * drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). * drm/i915: Return NULL on error in active_instance (git-fixes). * drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). * drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). * drm/virtio: bound EDID block reads to the response buffer (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * gpio-f7188x: Add support for NCT6126D version B (git-fixes). * gpio: htc-egpio: use managed gpiochip registration (git-fixes). * gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). * gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git- fixes). * gpios: palmas: add .get_direction() op (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). * iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git- fixes). * iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). * iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). * iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). * iio: event: Fix event FIFO reset race (git-fixes). * iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). * iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). * iio: light: al3010: fix incorrect scale for the highest gain range (git- fixes). * iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). * iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). * Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). * Input: mms114 - fix multi-touch slot corruption (git-fixes). * iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). * ipv4: account for fraggap on the paged allocation path (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * pinctrl: meson: restore non-sleeping GPIO access (git-fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). * serial: 8250_omap: clear rx_running on zero-length DMA completes (git- fixes). * serial: msm: Disable DMA for kernel console UART (git-fixes). * staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). * staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git- fixes). * staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). * staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). * staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). * staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git- fixes). * tpm: Make the TPM character devices non-seekable (git-fixes). * usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git- fixes). * USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). * usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git- fixes). * usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). * usb: free iso schedules on failed submit (git-fixes). * usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git- fixes). * usb: gadget: f_printer: take kref only for successful open (git-fixes). * USB: idmouse: fix use-after-free on disconnect race (git-fixes). * USB: iowarrior: fix use-after-free on disconnect (git-fixes). * USB: ldusb: fix use-after-free on disconnect race (git-fixes). * USB: legousbtower: fix use-after-free on disconnect race (git-fixes). * USB: misc: uss720: unregister parport on probe failure (git-fixes). * usb: mtu3: unmap request DMA on queue failure (git-fixes). * USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). * USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). * USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). * USB: serial: keyspan_pda: fix information leak (git-fixes). * usb: sl811-hcd: disable controller wakeup on remove (git-fixes). * USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). * usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). * usb: typec: class: drop PD lookup reference (git-fixes). * usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). * usb: typec: ucsi: cancel pending work on system suspend (git-fixes). * usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). * usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). * usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). * USB: ulpi: fix memory leak on registration failure (git-fixes). * USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). * usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). * usbip: tools: support SuperSpeedPlus devices (git-fixes). * usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-536=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-kvmsmall-debugsource-6.4.0-50.1 * kernel-kvmsmall-debuginfo-6.4.0-50.1 * SUSE Linux Micro 6.1 (noarch) * kernel-source-6.4.0-50.2 * kernel-devel-6.4.0-50.2 * kernel-macros-6.4.0-50.2 * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * kernel-default-devel-6.4.0-50.1 * kernel-default-debugsource-6.4.0-50.1 * kernel-default-debuginfo-6.4.0-50.1 * SUSE Linux Micro 6.1 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-50.1 * SUSE Linux Micro 6.1 (nosrc x86_64) * kernel-kvmsmall-6.4.0-50.1 * SUSE Linux Micro 6.1 (ppc64le x86_64) * kernel-default-devel-debuginfo-6.4.0-50.1 * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-default-livepatch-6.4.0-50.1 ## References: * https://www.suse.com/security/cve/CVE-2023-20585.html * https://www.suse.com/security/cve/CVE-2026-31503.html * https://www.suse.com/security/cve/CVE-2026-43019.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43204.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43253.html * https://www.suse.com/security/cve/CVE-2026-43294.html * https://www.suse.com/security/cve/CVE-2026-43304.html * https://www.suse.com/security/cve/CVE-2026-43320.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43445.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43473.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45987.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46059.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52961.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53035.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53181.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53245.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1243603 * https://bugzilla.suse.com/show_bug.cgi?id=1260593 * https://bugzilla.suse.com/show_bug.cgi?id=1263077 * https://bugzilla.suse.com/show_bug.cgi?id=1264003 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264180 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264419 * https://bugzilla.suse.com/show_bug.cgi?id=1264531 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264731 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264853 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264987 * https://bugzilla.suse.com/show_bug.cgi?id=1264993 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265041 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1267213 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267495 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269129 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269190 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269675 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269886 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1271040 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:46:59 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:46:59 -0000 Subject: SUSE-SU-2026:22903-1: important: Security update for the Linux Kernel Message-ID: <178517081929.2240.2849740077065718658@c3e054a4ce29> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22903-1 Release Date: 2026-07-22T13:38:14Z Rating: important References: * bsc#1243603 * bsc#1260593 * bsc#1263077 * bsc#1264003 * bsc#1264056 * bsc#1264180 * bsc#1264270 * bsc#1264302 * bsc#1264304 * bsc#1264328 * bsc#1264386 * bsc#1264419 * bsc#1264531 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264556 * bsc#1264580 * bsc#1264624 * bsc#1264731 * bsc#1264744 * bsc#1264790 * bsc#1264794 * bsc#1264853 * bsc#1264978 * bsc#1264987 * bsc#1264993 * bsc#1264997 * bsc#1265023 * bsc#1265041 * bsc#1265079 * bsc#1265142 * bsc#1266458 * bsc#1266686 * bsc#1266722 * bsc#1266726 * bsc#1266740 * bsc#1266773 * bsc#1266838 * bsc#1266883 * bsc#1266893 * bsc#1267213 * bsc#1267360 * bsc#1267493 * bsc#1267494 * bsc#1267495 * bsc#1267618 * bsc#1267992 * bsc#1267994 * bsc#1268989 * bsc#1269036 * bsc#1269129 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269172 * bsc#1269174 * bsc#1269188 * bsc#1269190 * bsc#1269193 * bsc#1269230 * bsc#1269262 * bsc#1269389 * bsc#1269392 * bsc#1269493 * bsc#1269527 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269645 * bsc#1269646 * bsc#1269651 * bsc#1269675 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269814 * bsc#1269886 * bsc#1269986 * bsc#1269989 * bsc#1269992 * bsc#1269993 * bsc#1270022 * bsc#1270059 * bsc#1270226 * bsc#1270257 * bsc#1271040 * bsc#1271050 * bsc#1271366 Cross-References: * CVE-2023-20585 * CVE-2026-31503 * CVE-2026-43019 * CVE-2026-43057 * CVE-2026-43092 * CVE-2026-43124 * CVE-2026-43157 * CVE-2026-43167 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43199 * CVE-2026-43204 * CVE-2026-43205 * CVE-2026-43226 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43253 * CVE-2026-43294 * CVE-2026-43304 * CVE-2026-43320 * CVE-2026-43373 * CVE-2026-43383 * CVE-2026-43445 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43473 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45899 * CVE-2026-45920 * CVE-2026-45987 * CVE-2026-45997 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46052 * CVE-2026-46059 * CVE-2026-46099 * CVE-2026-46161 * CVE-2026-46178 * CVE-2026-46242 * CVE-2026-46314 * CVE-2026-46322 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52961 * CVE-2026-52993 * CVE-2026-53021 * CVE-2026-53035 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53139 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53181 * CVE-2026-53196 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53245 * CVE-2026-53249 * CVE-2026-53256 * CVE-2026-53258 * CVE-2026-53274 * CVE-2026-53285 * CVE-2026-53306 * CVE-2026-53357 * CVE-2026-53359 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2023-20585 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-20585 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2023-20585 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31503 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31503 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31503 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43253 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52961 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53181 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53181 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 87 vulnerabilities and has six fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). * CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). * CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). * CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593). * CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). * CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). * CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53366: kernel: ipv4: account for fraggap on the paged allocation path (bsc#1271366) The following non security issues were fixed: * batman-adv: access unicast_ttvn skb->data only after skb realloc (git- fixes). * batman-adv: bla: reacquire gw address after skb realloc (git-fixes). * batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). * batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). * batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). * bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). * bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). * bnxt_en: Add TX timestamp completion logic (bsc#1264180). * bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). * bnxt_en: fix module unload sequence (bsc#1264180). * bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). * bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). * bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). * bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). * bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). * bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). * bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). * bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). * bnxt_en: silence clang build warning (bsc#1264180). * crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). * crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable- fixes). * drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). * drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git- fixes). * drm/amdgpu: fix aperture mapping leak (git-fixes). * drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). * drm/i915: Return NULL on error in active_instance (git-fixes). * drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). * drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). * drm/virtio: bound EDID block reads to the response buffer (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * gpio-f7188x: Add support for NCT6126D version B (git-fixes). * gpio: htc-egpio: use managed gpiochip registration (git-fixes). * gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). * gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git- fixes). * gpios: palmas: add .get_direction() op (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). * iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git- fixes). * iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). * iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). * iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). * iio: event: Fix event FIFO reset race (git-fixes). * iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). * iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). * iio: light: al3010: fix incorrect scale for the highest gain range (git- fixes). * iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). * iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). * Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). * Input: mms114 - fix multi-touch slot corruption (git-fixes). * iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). * ipv4: account for fraggap on the paged allocation path (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * pinctrl: meson: restore non-sleeping GPIO access (git-fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). * serial: 8250_omap: clear rx_running on zero-length DMA completes (git- fixes). * serial: msm: Disable DMA for kernel console UART (git-fixes). * staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). * staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git- fixes). * staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). * staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). * staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). * staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git- fixes). * tpm: Make the TPM character devices non-seekable (git-fixes). * usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git- fixes). * USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). * usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git- fixes). * usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). * usb: free iso schedules on failed submit (git-fixes). * usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git- fixes). * usb: gadget: f_printer: take kref only for successful open (git-fixes). * USB: idmouse: fix use-after-free on disconnect race (git-fixes). * USB: iowarrior: fix use-after-free on disconnect (git-fixes). * USB: ldusb: fix use-after-free on disconnect race (git-fixes). * USB: legousbtower: fix use-after-free on disconnect race (git-fixes). * USB: misc: uss720: unregister parport on probe failure (git-fixes). * usb: mtu3: unmap request DMA on queue failure (git-fixes). * USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). * USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). * USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). * USB: serial: keyspan_pda: fix information leak (git-fixes). * usb: sl811-hcd: disable controller wakeup on remove (git-fixes). * USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). * usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). * usb: typec: class: drop PD lookup reference (git-fixes). * usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). * usb: typec: ucsi: cancel pending work on system suspend (git-fixes). * usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). * usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). * usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). * USB: ulpi: fix memory leak on registration failure (git-fixes). * USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). * usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). * usbip: tools: support SuperSpeedPlus devices (git-fixes). * usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-538=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 x86_64) * kernel-rt-debugsource-6.4.0-50.1 * kernel-rt-debuginfo-6.4.0-50.1 * kernel-rt-devel-6.4.0-50.1 * SUSE Linux Micro 6.1 (noarch) * kernel-devel-rt-6.4.0-50.2 * kernel-source-rt-6.4.0-50.2 * SUSE Linux Micro 6.1 (aarch64 nosrc x86_64) * kernel-rt-6.4.0-50.1 * SUSE Linux Micro 6.1 (x86_64) * kernel-rt-devel-debuginfo-6.4.0-50.1 * kernel-rt-livepatch-6.4.0-50.1 ## References: * https://www.suse.com/security/cve/CVE-2023-20585.html * https://www.suse.com/security/cve/CVE-2026-31503.html * https://www.suse.com/security/cve/CVE-2026-43019.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43204.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43253.html * https://www.suse.com/security/cve/CVE-2026-43294.html * https://www.suse.com/security/cve/CVE-2026-43304.html * https://www.suse.com/security/cve/CVE-2026-43320.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43445.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43473.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45987.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46059.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52961.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53035.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53181.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53245.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1243603 * https://bugzilla.suse.com/show_bug.cgi?id=1260593 * https://bugzilla.suse.com/show_bug.cgi?id=1263077 * https://bugzilla.suse.com/show_bug.cgi?id=1264003 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264180 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264419 * https://bugzilla.suse.com/show_bug.cgi?id=1264531 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264731 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264853 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264987 * https://bugzilla.suse.com/show_bug.cgi?id=1264993 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265041 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1267213 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267495 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269129 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269190 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269675 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269886 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1271040 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:47:39 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:47:39 -0000 Subject: SUSE-RU-2026:22902-1: moderate: Recommended update for python-gcemetadata Message-ID: <178517085975.2240.10533038775876364182@c3e054a4ce29> # Recommended update for python-gcemetadata Announcement ID: SUSE-RU-2026:22902-1 Release Date: 2026-07-22T12:31:46Z Rating: moderate References: * bsc#1269423 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for python-gcemetadata fixes the following issues: * Update to version 1.1.1: * Fix UnboundLocalError when using --xml with --query (bsc#1269423) * Update comments ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-634=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * python-gcemetadata-1.1.1-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269423 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:48:06 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:48:06 -0000 Subject: SUSE-SU-2026:22901-1: important: Security update for vim Message-ID: <178517088634.2240.2804301983854052051@c3e054a4ce29> # Security update for vim Announcement ID: SUSE-SU-2026:22901-1 Release Date: 2026-07-22T11:18:45Z Rating: important References: * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for vim fixes the following issues * Updated to version 9.2.0780 * CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). * CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). * CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-633=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * vim-debugsource-9.2.0780-slfo.1.1_1.1 * vim-small-debuginfo-9.2.0780-slfo.1.1_1.1 * vim-small-9.2.0780-slfo.1.1_1.1 * SUSE Linux Micro 6.1 (noarch) * vim-data-common-9.2.0780-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:48:50 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:48:50 -0000 Subject: SUSE-SU-2026:22900-1: important: Security update for jq Message-ID: <178517093082.2240.2661320336697367912@c3e054a4ce29> # Security update for jq Announcement ID: SUSE-SU-2026:22900-1 Release Date: 2026-07-22T11:05:15Z Rating: important References: * bsc#1265075 * bsc#1265076 * bsc#1269220 * bsc#1269390 Cross-References: * CVE-2026-43896 * CVE-2026-44777 * CVE-2026-49839 * CVE-2026-54679 CVSS scores: * CVE-2026-43896 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43896 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44777 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44777 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44777 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49839 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-49839 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-54679 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-54679 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues * CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075). * CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules include each other can lead to stack exhaustion and process crash (bsc#1265076). * CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized- string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220). * CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-632=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * jq-debugsource-1.7.1-slfo.1.1_4.1 * jq-debuginfo-1.7.1-slfo.1.1_4.1 * libjq1-1.7.1-slfo.1.1_4.1 * libjq1-debuginfo-1.7.1-slfo.1.1_4.1 * jq-1.7.1-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43896.html * https://www.suse.com/security/cve/CVE-2026-44777.html * https://www.suse.com/security/cve/CVE-2026-49839.html * https://www.suse.com/security/cve/CVE-2026-54679.html * https://bugzilla.suse.com/show_bug.cgi?id=1265075 * https://bugzilla.suse.com/show_bug.cgi?id=1265076 * https://bugzilla.suse.com/show_bug.cgi?id=1269220 * https://bugzilla.suse.com/show_bug.cgi?id=1269390 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:49:31 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:49:31 -0000 Subject: SUSE-RU-2026:22899-1: moderate: Recommended update for grub2 Message-ID: <178517097120.2240.13999064459740957981@c3e054a4ce29> # Recommended update for grub2 Announcement ID: SUSE-RU-2026:22899-1 Release Date: 2026-07-22T09:44:23Z Rating: moderate References: * bsc#1270265 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for grub2 fixes the following issues: * Dump PCRs on key unsealing fail (bsc#1270265) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-631=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * grub2-x86_64-xen-2.12-slfo.1.1_6.1 * grub2-i386-pc-2.12-slfo.1.1_6.1 * grub2-x86_64-efi-2.12-slfo.1.1_6.1 * grub2-arm64-efi-2.12-slfo.1.1_6.1 * grub2-powerpc-ieee1275-2.12-slfo.1.1_6.1 * grub2-snapper-plugin-2.12-slfo.1.1_6.1 * SUSE Linux Micro 6.1 (aarch64 s390x x86_64) * grub2-debugsource-2.12-slfo.1.1_6.1 * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * grub2-debuginfo-2.12-slfo.1.1_6.1 * grub2-2.12-slfo.1.1_6.1 * SUSE Linux Micro 6.1 (s390x) * grub2-s390x-emu-2.12-slfo.1.1_6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270265 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:50:08 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:50:08 -0000 Subject: SUSE-SU-2026:22898-1: important: Security update for rust-keylime Message-ID: <178517100886.2240.16978541763034716484@c3e054a4ce29> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:22898-1 Release Date: 2026-07-22T09:03:51Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for rust-keylime fixes the following issues: Update to version 0.2.9+49. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270614). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270699). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270842). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270999). Other updates and bugfixes: * Update openssl to 0.10.81. * Make tss-esai-sys depend on bindgen 72.1 to support llvm > 21. * Build with Clang <= 21 (bsc#1260596). * Version 0.2.9+49: * build(deps): bump uuid from 1.23.3 to 1.23.4 * build(deps): bump syn from 2.0.117 to 2.0.118 * build(deps): bump openssl from 0.10.80 to 0.10.81 * build(deps): bump rand from 0.9.4 to 0.10.1 * Added new regression test into packit-ci.yaml * build(deps): bump actions/checkout from 6 to 7 * build(deps): bump uuid from 1.23.1 to 1.23.3 * build(deps): bump log from 0.4.29 to 0.4.32 * build(deps): bump http from 1.4.0 to 1.4.2 * build(deps): bump codecov/codecov-action from 6 to 7 * build(deps): bump retry-policies from 0.5.1 to 0.5.2 * fix: Remove unused base64::Engine import in context_info tests * build(deps): bump reqwest-middleware from 0.5.1 to 0.5.2 * build(deps): bump serde_json from 1.0.149 to 1.0.150 * build(deps): bump openssl from 0.10.79 to 0.10.80 * agent: Hash agent ID before TPM2_Certify qualifying data * cargo: Bump tss-esapi, picky-asn1-x509, and picky-asn1-der * build(deps): bump openssl from 0.10.78 to 0.10.79 * build(deps): bump once_cell from 1.21.3 to 1.21.4 * build(deps): bump tempfile from 3.23.0 to 3.27.0 * push-model: cache UEFI event log bytes at startup * build(deps): bump quote from 1.0.40 to 1.0.45 * build(deps): bump chrono from 0.4.42 to 0.4.44 * build(deps): bump openssl from 0.10.73 to 0.10.78 * build(deps): bump serde_json from 1.0.143 to 1.0.149 * build(deps): bump syn from 2.0.106 to 2.0.117 * build(deps): bump libc from 0.2.175 to 0.2.184 * build(deps): bump rand from 0.9.2 to 0.9.4 * Version 0.2.9+21: * tests: use Express-style named params in Mockoon endpoints * build(deps): bump pest_derive from 2.8.1 to 2.8.6 * build(deps): bump trybuild from 1.0.110 to 1.0.115 * build(deps): bump log from 0.4.28 to 0.4.29 * build(deps): bump uuid from 1.19.0 to 1.20.0 * build(deps): bump codecov/codecov-action from 5 to 6 * build(deps): bump tracing-subscriber from 0.3.20 to 0.3.23 * build(deps): bump cfg-if from 1.0.3 to 1.0.4 * build(deps): bump tokio from 1.49.0 to 1.50.0 * build(deps): bump actix-web from 4.12.1 to 4.13.0 * build(deps): bump anyhow from 1.0.99 to 1.0.102 * build(deps): bump clap from 4.5.57 to 4.5.60 * build(deps): bump tracing from 0.1.36 to 0.1.44 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-625=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * rust-keylime-0.2.9+49-slfo.1.1_1.1 * rust-keylime-debugsource-0.2.9+49-slfo.1.1_1.1 * rust-keylime-debuginfo-0.2.9+49-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:50:50 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:50:50 -0000 Subject: SUSE-SU-2026:22897-1: important: Security update for sssd Message-ID: <178517105030.2240.17598811098476059025@c3e054a4ce29> # Security update for sssd Announcement ID: SUSE-SU-2026:22897-1 Release Date: 2026-07-22T09:01:06Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-626=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libsss_nss_idmap0-2.9.5-slfo.1.1_5.1 * sssd-ldap-debuginfo-2.9.5-slfo.1.1_5.1 * sssd-tools-debuginfo-2.9.5-slfo.1.1_5.1 * libsss_idmap0-debuginfo-2.9.5-slfo.1.1_5.1 * sssd-krb5-common-2.9.5-slfo.1.1_5.1 * sssd-krb5-2.9.5-slfo.1.1_5.1 * sssd-ldap-2.9.5-slfo.1.1_5.1 * sssd-ad-debuginfo-2.9.5-slfo.1.1_5.1 * sssd-krb5-debuginfo-2.9.5-slfo.1.1_5.1 * sssd-dbus-2.9.5-slfo.1.1_5.1 * sssd-debugsource-2.9.5-slfo.1.1_5.1 * python3-sssd-config-2.9.5-slfo.1.1_5.1 * libsss_idmap0-2.9.5-slfo.1.1_5.1 * sssd-tools-2.9.5-slfo.1.1_5.1 * sssd-2.9.5-slfo.1.1_5.1 * sssd-dbus-debuginfo-2.9.5-slfo.1.1_5.1 * libsss_certmap0-debuginfo-2.9.5-slfo.1.1_5.1 * libsss_certmap0-2.9.5-slfo.1.1_5.1 * sssd-debuginfo-2.9.5-slfo.1.1_5.1 * libsss_nss_idmap0-debuginfo-2.9.5-slfo.1.1_5.1 * python3-sssd-config-debuginfo-2.9.5-slfo.1.1_5.1 * sssd-ad-2.9.5-slfo.1.1_5.1 * sssd-krb5-common-debuginfo-2.9.5-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:51:29 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:51:29 -0000 Subject: SUSE-SU-2026:22896-1: moderate: Security update for pam Message-ID: <178517108944.2240.12210454489889178846@c3e054a4ce29> # Security update for pam Announcement ID: SUSE-SU-2026:22896-1 Release Date: 2026-07-22T08:59:50Z Rating: moderate References: * bsc#1268290 Cross-References: * CVE-2026-54411 CVSS scores: * CVE-2026-54411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-54411 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X * CVE-2026-54411 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for pam fixes the following issue * CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext- password comparison (bsc#1268290). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-629=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * pam-debugsource-1.6.1-slfo.1.1_5.1 * pam-1.6.1-slfo.1.1_5.1 * pam-debuginfo-1.6.1-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54411.html * https://bugzilla.suse.com/show_bug.cgi?id=1268290 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:52:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:52:21 -0000 Subject: SUSE-SU-2026:22895-1: important: Security update for python-cryptography Message-ID: <178517114128.2240.1272059280596334786@c3e054a4ce29> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:22895-1 Release Date: 2026-07-22T08:59:50Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270620). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270706). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270801). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-627=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * python311-cryptography-42.0.4-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:53:00 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:53:00 -0000 Subject: SUSE-SU-2026:22894-1: important: Security update for libxml2 Message-ID: <178517118068.2240.1608199633534358704@c3e054a4ce29> # Security update for libxml2 Announcement ID: SUSE-SU-2026:22894-1 Release Date: 2026-07-22T08:53:15Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-630=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libxml2-debugsource-2.11.6-slfo.1.1_9.1 * libxml2-python-debugsource-2.11.6-slfo.1.1_9.1 * libxml2-2-2.11.6-slfo.1.1_9.1 * libxml2-tools-debuginfo-2.11.6-slfo.1.1_9.1 * python311-libxml2-debuginfo-2.11.6-slfo.1.1_9.1 * python311-libxml2-2.11.6-slfo.1.1_9.1 * libxml2-tools-2.11.6-slfo.1.1_9.1 * libxml2-2-debuginfo-2.11.6-slfo.1.1_9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:53:40 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:53:40 -0000 Subject: SUSE-SU-2026:22893-1: moderate: Security update for nghttp2 Message-ID: <178517122034.2240.11307023912915575305@c3e054a4ce29> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:22893-1 Release Date: 2026-07-22T08:53:15Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-624=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libnghttp2-14-1.52.0-slfo.1.1_3.1 * nghttp2-debugsource-1.52.0-slfo.1.1_3.1 * libnghttp2-14-debuginfo-1.52.0-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:54:19 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:54:19 -0000 Subject: SUSE-SU-2026:22892-1: moderate: Security update for containerd Message-ID: <178517125941.2240.1793009402173968089@c3e054a4ce29> # Security update for containerd Announcement ID: SUSE-SU-2026:22892-1 Release Date: 2026-07-22T08:51:49Z Rating: moderate References: * bsc#1262266 Cross-References: * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-35469 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-35469 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for containerd fixes the following issues * CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262266). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-628=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1262266 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:54:58 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:54:58 -0000 Subject: SUSE-RU-2026:22891-1: important: Recommended update for container-selinux Message-ID: <178517129886.2240.5593270897612827497@c3e054a4ce29> # Recommended update for container-selinux Announcement ID: SUSE-RU-2026:22891-1 Release Date: 2026-07-22T07:45:44Z Rating: important References: * bsc#1268490 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for container-selinux fixes the following issues: * Introduce container_can_execstack boolean for older Java applications and allow execmem (bsc#1268490) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-623=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * container-selinux-2.236.0-slfo.1.1_2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268490 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:55:28 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:55:28 -0000 Subject: SUSE-SU-2026:22890-1: important: Security update for systemd Message-ID: <178517132836.2240.6479944654412452508@c3e054a4ce29> # Security update for systemd Announcement ID: SUSE-SU-2026:22890-1 Release Date: 2026-07-21T18:32:40Z Rating: important References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1262305 * bsc#1267644 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability and has five fixes can now be installed. ## Description: This update for systemd fixes the following issues Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Import commit 260e668bfa (bsc#1267647 bsc#1262305 bsc#1267644). * Import commit 58e5d2e21e (bsc#1261982). * Import commit 4bd91117cc (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-622=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * systemd-experimental-debuginfo-254.27-slfo.1.1_5.1 * systemd-journal-remote-debuginfo-254.27-slfo.1.1_5.1 * systemd-debugsource-254.27-slfo.1.1_5.1 * systemd-experimental-254.27-slfo.1.1_5.1 * libsystemd0-debuginfo-254.27-slfo.1.1_5.1 * udev-254.27-slfo.1.1_5.1 * libudev1-254.27-slfo.1.1_5.1 * libsystemd0-254.27-slfo.1.1_5.1 * systemd-coredump-254.27-slfo.1.1_5.1 * systemd-coredump-debuginfo-254.27-slfo.1.1_5.1 * systemd-254.27-slfo.1.1_5.1 * systemd-portable-debuginfo-254.27-slfo.1.1_5.1 * systemd-container-debuginfo-254.27-slfo.1.1_5.1 * systemd-container-254.27-slfo.1.1_5.1 * systemd-debuginfo-254.27-slfo.1.1_5.1 * systemd-portable-254.27-slfo.1.1_5.1 * udev-debuginfo-254.27-slfo.1.1_5.1 * libudev1-debuginfo-254.27-slfo.1.1_5.1 * systemd-journal-remote-254.27-slfo.1.1_5.1 * SUSE Linux Micro 6.1 (ppc64le) * systemd-sysvcompat-debuginfo-254.27-slfo.1.1_5.1 * systemd-sysvcompat-254.27-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1262305 * https://bugzilla.suse.com/show_bug.cgi?id=1267644 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:56:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:56:20 -0000 Subject: SUSE-SU-2026:22889-1: important: Security update for curl Message-ID: <178517138056.2240.11894003094556883017@c3e054a4ce29> # Security update for curl Announcement ID: SUSE-SU-2026:22889-1 Release Date: 2026-07-21T16:46:43Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-619=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * curl-8.14.1-slfo.1.1_8.1 * curl-debugsource-8.14.1-slfo.1.1_8.1 * libcurl4-debuginfo-8.14.1-slfo.1.1_8.1 * curl-debuginfo-8.14.1-slfo.1.1_8.1 * libcurl4-8.14.1-slfo.1.1_8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:56:59 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:56:59 -0000 Subject: SUSE-SU-2026:22888-1: important: Security update for cifs-utils Message-ID: <178517141951.2240.4481578906863669334@c3e054a4ce29> # Security update for cifs-utils Announcement ID: SUSE-SU-2026:22888-1 Release Date: 2026-07-21T16:43:59Z Rating: important References: * bsc#1267389 Cross-References: * CVE-2026-12505 CVSS scores: * CVE-2026-12505 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for cifs-utils fixes the following issue * CVE-2026-12505: cifs.upcall local privilege escalation via request_key- controlled namespace switch and NSS loading (bsc#1267389). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-620=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * cifs-utils-debuginfo-7.0-slfo.1.1_4.1 * wb-cifs-idmap-plugin-7.0-slfo.1.1_4.1 * cifs-utils-debugsource-7.0-slfo.1.1_4.1 * cifs-utils-7.0-slfo.1.1_4.1 * wb-cifs-idmap-plugin-debuginfo-7.0-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12505.html * https://bugzilla.suse.com/show_bug.cgi?id=1267389 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:57:43 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:57:43 -0000 Subject: SUSE-SU-2026:22887-1: important: Security update for docker-compose Message-ID: <178517146313.2240.1941838104540651237@c3e054a4ce29> # Security update for docker-compose Announcement ID: SUSE-SU-2026:22887-1 Release Date: 2026-07-21T16:40:07Z Rating: important References: * bsc#1239340 * bsc#1239766 * bsc#1265782 * bsc#1266625 Cross-References: * CVE-2025-0495 * CVE-2025-22869 * CVE-2026-33814 * CVE-2026-39821 CVSS scores: * CVE-2025-0495 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-0495 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N * CVE-2025-0495 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker-compose fixes the following issues * CVE-2025-0495: buildx: credential leakage to telemetry endpoints when credentials allowed to be set as attribute values in cache-to/cache-from configuration (bsc#1239766). * CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239340). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-618=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * docker-compose-2.33.1-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0495.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1239340 * https://bugzilla.suse.com/show_bug.cgi?id=1239766 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:58:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:58:25 -0000 Subject: SUSE-SU-2026:22886-1: important: Security update for tiff Message-ID: <178517150588.2240.6535535497730920625@c3e054a4ce29> # Security update for tiff Announcement ID: SUSE-SU-2026:22886-1 Release Date: 2026-07-21T16:29:17Z Rating: important References: * bsc#1257123 * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for tiff fixes the following issues Update to version 4.7.2. Security issues fixed: * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Other updates and bugfixes: * Enable Lerc support in openSUSE (bsc#1257123). * Version 4.7.2: * Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. * Library changes: * New/improved functionalities:: * Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781) * Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824) * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. * Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-617=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * tiff-debugsource-4.7.2-slfo.1.1_1.1 * libtiff6-debuginfo-4.7.2-slfo.1.1_1.1 * libtiff6-4.7.2-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://bugzilla.suse.com/show_bug.cgi?id=1257123 * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:59:05 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:59:05 -0000 Subject: SUSE-SU-2026:22885-1: moderate: Security update for python-tornado6 Message-ID: <178517154520.2240.17457635965270496462@c3e054a4ce29> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:22885-1 Release Date: 2026-07-21T16:28:18Z Rating: moderate References: * bsc#1269012 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for python-tornado6 fixes the following issue * GHSA-pw6j-qg29-8w7f: `CurlAsyncHTTPClient` leaks per-request credentials on handle reuse (bsc#1269012). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-616=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * python-tornado6-debugsource-6.4-slfo.1.1_6.1 * python311-tornado6-6.4-slfo.1.1_6.1 * python311-tornado6-debuginfo-6.4-slfo.1.1_6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269012 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 16:59:44 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 16:59:44 -0000 Subject: SUSE-RU-2026:22884-1: moderate: Recommended update for nvidia-open-driver-G07-signed Message-ID: <178517158462.2240.13053904663753004593@c3e054a4ce29> # Recommended update for nvidia-open-driver-G07-signed Announcement ID: SUSE-RU-2026:22884-1 Release Date: 2026-07-21T16:05:47Z Rating: moderate References: * bsc#1268792 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for nvidia-open-driver-G07-signed fixes the following issues: * update non-CUDA variant to 595.84 (bsc#1268792) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-534=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 x86_64) * nvidia-open-driver-G07-signed-cuda-kmp-default-debuginfo-610.43.02_k6.4.0_49-1.2 * nvidia-open-driver-G07-signed-cuda-kmp-default-610.43.02_k6.4.0_49-1.2 * nvidia-open-driver-G07-signed-kmp-default-debuginfo-595.84_k6.4.0_49-1.1 * nvidia-open-driver-G07-signed-cuda-debugsource-610.43.02-1.2 * nvidia-open-driver-G07-signed-kmp-default-595.84_k6.4.0_49-1.1 * nvidia-open-driver-G07-signed-debugsource-595.84-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268792 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:02:56 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:02:56 -0000 Subject: SUSE-SU-2026:22883-1: important: Security update for the Linux Kernel Message-ID: <178517177664.2240.2407252175846315829@c3e054a4ce29> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22883-1 Release Date: 2026-07-22T13:52:17Z Rating: important References: * bsc#1243603 * bsc#1260593 * bsc#1263077 * bsc#1264003 * bsc#1264056 * bsc#1264180 * bsc#1264270 * bsc#1264302 * bsc#1264304 * bsc#1264328 * bsc#1264386 * bsc#1264419 * bsc#1264531 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264556 * bsc#1264580 * bsc#1264624 * bsc#1264731 * bsc#1264744 * bsc#1264790 * bsc#1264794 * bsc#1264853 * bsc#1264978 * bsc#1264987 * bsc#1264993 * bsc#1264997 * bsc#1265023 * bsc#1265041 * bsc#1265079 * bsc#1265142 * bsc#1266458 * bsc#1266686 * bsc#1266722 * bsc#1266726 * bsc#1266740 * bsc#1266773 * bsc#1266838 * bsc#1266883 * bsc#1266893 * bsc#1267213 * bsc#1267360 * bsc#1267493 * bsc#1267494 * bsc#1267495 * bsc#1267618 * bsc#1267992 * bsc#1267994 * bsc#1268989 * bsc#1269036 * bsc#1269129 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269172 * bsc#1269174 * bsc#1269188 * bsc#1269190 * bsc#1269193 * bsc#1269230 * bsc#1269262 * bsc#1269389 * bsc#1269392 * bsc#1269493 * bsc#1269527 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269645 * bsc#1269646 * bsc#1269651 * bsc#1269675 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269814 * bsc#1269886 * bsc#1269986 * bsc#1269989 * bsc#1269992 * bsc#1269993 * bsc#1270022 * bsc#1270059 * bsc#1270226 * bsc#1270257 * bsc#1271040 * bsc#1271050 * bsc#1271366 Cross-References: * CVE-2023-20585 * CVE-2026-31503 * CVE-2026-43019 * CVE-2026-43057 * CVE-2026-43092 * CVE-2026-43124 * CVE-2026-43157 * CVE-2026-43167 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43199 * CVE-2026-43204 * CVE-2026-43205 * CVE-2026-43226 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43253 * CVE-2026-43294 * CVE-2026-43304 * CVE-2026-43320 * CVE-2026-43373 * CVE-2026-43383 * CVE-2026-43445 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43473 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45899 * CVE-2026-45920 * CVE-2026-45987 * CVE-2026-45997 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46052 * CVE-2026-46059 * CVE-2026-46099 * CVE-2026-46161 * CVE-2026-46178 * CVE-2026-46242 * CVE-2026-46314 * CVE-2026-46322 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52955 * CVE-2026-52956 * CVE-2026-52958 * CVE-2026-52961 * CVE-2026-52993 * CVE-2026-53021 * CVE-2026-53035 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53139 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53181 * CVE-2026-53196 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53245 * CVE-2026-53249 * CVE-2026-53256 * CVE-2026-53258 * CVE-2026-53274 * CVE-2026-53285 * CVE-2026-53306 * CVE-2026-53357 * CVE-2026-53359 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2023-20585 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-20585 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2023-20585 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31503 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31503 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31503 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43019 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43204 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43253 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43253 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43304 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43320 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43445 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45987 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46059 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-52961 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53181 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53181 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53196 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53245 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53256 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53357 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 * SUSE Linux Micro Extras 6.1 An update that solves 87 vulnerabilities and has six fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). * CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). * CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). * CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593). * CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). * CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). * CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). * CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). * CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). * CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). * CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). * CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). * CVE-2026-53366: kernel: ipv4: account for fraggap on the paged allocation path (bsc#1271366) The following non security issues were fixed: * batman-adv: access unicast_ttvn skb->data only after skb realloc (git- fixes). * batman-adv: bla: reacquire gw address after skb realloc (git-fixes). * batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). * batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). * batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). * bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). * bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). * bnxt_en: Add TX timestamp completion logic (bsc#1264180). * bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). * bnxt_en: fix module unload sequence (bsc#1264180). * bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). * bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). * bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). * bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). * bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). * bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). * bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). * bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). * bnxt_en: silence clang build warning (bsc#1264180). * crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). * crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable- fixes). * drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). * drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git- fixes). * drm/amdgpu: fix aperture mapping leak (git-fixes). * drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). * drm/i915: Return NULL on error in active_instance (git-fixes). * drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). * drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). * drm/virtio: bound EDID block reads to the response buffer (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * gpio-f7188x: Add support for NCT6126D version B (git-fixes). * gpio: htc-egpio: use managed gpiochip registration (git-fixes). * gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). * gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git- fixes). * gpios: palmas: add .get_direction() op (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). * iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git- fixes). * iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). * iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). * iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). * iio: event: Fix event FIFO reset race (git-fixes). * iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). * iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). * iio: light: al3010: fix incorrect scale for the highest gain range (git- fixes). * iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). * iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). * Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). * Input: mms114 - fix multi-touch slot corruption (git-fixes). * iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). * ipv4: account for fraggap on the paged allocation path (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). * KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). * KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * pinctrl: meson: restore non-sleeping GPIO access (git-fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). * serial: 8250_omap: clear rx_running on zero-length DMA completes (git- fixes). * serial: msm: Disable DMA for kernel console UART (git-fixes). * staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). * staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git- fixes). * staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). * staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). * staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). * staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git- fixes). * tpm: Make the TPM character devices non-seekable (git-fixes). * usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git- fixes). * USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). * usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git- fixes). * usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). * usb: free iso schedules on failed submit (git-fixes). * usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git- fixes). * usb: gadget: f_printer: take kref only for successful open (git-fixes). * USB: idmouse: fix use-after-free on disconnect race (git-fixes). * USB: iowarrior: fix use-after-free on disconnect (git-fixes). * USB: ldusb: fix use-after-free on disconnect race (git-fixes). * USB: legousbtower: fix use-after-free on disconnect race (git-fixes). * USB: misc: uss720: unregister parport on probe failure (git-fixes). * usb: mtu3: unmap request DMA on queue failure (git-fixes). * USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). * USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). * USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). * USB: serial: keyspan_pda: fix information leak (git-fixes). * usb: sl811-hcd: disable controller wakeup on remove (git-fixes). * USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). * usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). * usb: typec: class: drop PD lookup reference (git-fixes). * usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). * usb: typec: ucsi: cancel pending work on system suspend (git-fixes). * usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). * usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). * usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). * USB: ulpi: fix memory leak on registration failure (git-fixes). * USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). * usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). * usbip: tools: support SuperSpeedPlus devices (git-fixes). * usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-Extras-6.1-kernel-536=1 ## Package List: * SUSE Linux Micro Extras 6.1 (aarch64) * kernel-64kb-debugsource-6.4.0-50.1 * kernel-64kb-devel-6.4.0-50.1 * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-debugsource-6.4.0-50.1 * kernel-obs-build-6.4.0-50.1 * kernel-syms-6.4.0-50.1 * SUSE Linux Micro Extras 6.1 (nosrc) * kernel-64kb-6.4.0-50.1 ## References: * https://www.suse.com/security/cve/CVE-2023-20585.html * https://www.suse.com/security/cve/CVE-2026-31503.html * https://www.suse.com/security/cve/CVE-2026-43019.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43204.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43253.html * https://www.suse.com/security/cve/CVE-2026-43294.html * https://www.suse.com/security/cve/CVE-2026-43304.html * https://www.suse.com/security/cve/CVE-2026-43320.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43445.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43473.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45987.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46052.html * https://www.suse.com/security/cve/CVE-2026-46059.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52958.html * https://www.suse.com/security/cve/CVE-2026-52961.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53035.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53181.html * https://www.suse.com/security/cve/CVE-2026-53196.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53245.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53256.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53357.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1243603 * https://bugzilla.suse.com/show_bug.cgi?id=1260593 * https://bugzilla.suse.com/show_bug.cgi?id=1263077 * https://bugzilla.suse.com/show_bug.cgi?id=1264003 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264180 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264419 * https://bugzilla.suse.com/show_bug.cgi?id=1264531 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264731 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264853 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264987 * https://bugzilla.suse.com/show_bug.cgi?id=1264993 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265041 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1267213 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267494 * https://bugzilla.suse.com/show_bug.cgi?id=1267495 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269129 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269172 * https://bugzilla.suse.com/show_bug.cgi?id=1269174 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269190 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269675 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269886 * https://bugzilla.suse.com/show_bug.cgi?id=1269986 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1269993 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1270257 * https://bugzilla.suse.com/show_bug.cgi?id=1271040 * https://bugzilla.suse.com/show_bug.cgi?id=1271050 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:03:42 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:03:42 -0000 Subject: SUSE-SU-2026:22813-1: important: Security update for systemd Message-ID: <178517182268.2240.14478676510589004162@c3e054a4ce29> # Security update for systemd Announcement ID: SUSE-SU-2026:22813-1 Release Date: 2026-07-21T18:32:40Z Rating: important References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1262305 * bsc#1267644 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 * SUSE Linux Micro Extras 6.1 An update that solves one vulnerability and has five fixes can now be installed. ## Description: This update for systemd fixes the following issues Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Import commit 260e668bfa (bsc#1267647 bsc#1262305 bsc#1267644). * Import commit 58e5d2e21e (bsc#1261982). * Import commit 4bd91117cc (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-Extras-6.1-622=1 ## Package List: * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * systemd-debugsource-254.27-slfo.1.1_5.1 * systemd-devel-254.27-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1262305 * https://bugzilla.suse.com/show_bug.cgi?id=1267644 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:04:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:04:21 -0000 Subject: SUSE-RU-2026:22881-1: moderate: Recommended update for python-tornado6 Message-ID: <178517186126.2240.3427133018448610052@c3e054a4ce29> # Recommended update for python-tornado6 Announcement ID: SUSE-RU-2026:22881-1 Release Date: 2026-07-22T16:54:24Z Rating: moderate References: * bsc#1269012 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for python-tornado6 fixes the following issues: Changes in python-tornado6: * GHSA-pw6j-qg29-8w7f: CurlAsyncHTTPClient leaks per-request credentials on handle reuse (bsc#1269012) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1332=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1332=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-tornado6-debuginfo-6.5-160000.6.1 * python313-tornado6-6.5-160000.6.1 * python-tornado6-debugsource-6.5-160000.6.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * python313-tornado6-debuginfo-6.5-160000.6.1 * python313-tornado6-6.5-160000.6.1 * python-tornado6-debugsource-6.5-160000.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269012 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:04:44 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:04:44 -0000 Subject: SUSE-RU-2026:22880-1: important: Recommended update for s390-tools Message-ID: <178517188490.2240.1065330988229382968@c3e054a4ce29> # Recommended update for s390-tools Announcement ID: SUSE-RU-2026:22880-1 Release Date: 2026-07-21T07:57:10Z Rating: important References: * bsc#1266436 * bsc#1268516 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for s390-tools fixes the following issues: * Upgrade to version 2.43.0: * Fix: [QE][Build 39.11] sel-ebc-paes-enforce.service:23: Failed to parse output specifier, ignoring: console (bsc#1268516) * Fix: SCSI LUN for reboot not set ant the end of installation (bsc#1266436) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1308=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1308=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (s390x) * libkmipclient1-2.43.0-160000.2.1 * s390-tools-hmcdrvfs-2.43.0-160000.2.1 * s390-tools-hmcdrvfs-debuginfo-2.43.0-160000.2.1 * s390-tools-debugsource-2.43.0-160000.2.1 * s390-tools-zdsfs-debuginfo-2.43.0-160000.2.1 * s390-tools-debuginfo-2.43.0-160000.2.1 * s390-tools-zdsfs-2.43.0-160000.2.1 * osasnmpd-2.43.0-160000.2.1 * libekmfweb1-2.43.0-160000.2.1 * osasnmpd-debuginfo-2.43.0-160000.2.1 * libkmipclient1-debuginfo-2.43.0-160000.2.1 * libekmfweb1-debuginfo-2.43.0-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * s390-tools-genprotimg-data-2.43.0-160000.2.1 * s390-tools-chreipl-fcp-mpath-2.43.0-160000.2.1 * SUSE Linux Enterprise Server 16.0 (s390x x86_64) * s390-tools-2.43.0-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * s390-tools-2.43.0-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1266436 * https://bugzilla.suse.com/show_bug.cgi?id=1268516 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:05:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:05:20 -0000 Subject: SUSE-SU-2026:22879-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 16) Message-ID: <178517192085.2240.9623313238746155308@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22879-1 Release Date: 2026-07-20T12:21:49Z Rating: important References: * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.34.1 fixes various security issues The following security issues were fixed: * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1302=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1302=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_34-default-debuginfo-2-160000.1.2 * kernel-livepatch-SLE16_Update_13-debugsource-2-160000.1.2 * kernel-livepatch-6_12_0-160000_34-default-2-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_34-default-debuginfo-2-160000.1.2 * kernel-livepatch-SLE16_Update_13-debugsource-2-160000.1.2 * kernel-livepatch-6_12_0-160000_34-default-2-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:05:58 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:05:58 -0000 Subject: SUSE-RU-2026:22878-1: important: Recommended update for the initial kernel livepatch Message-ID: <178517195808.2240.2408028064733189578@c3e054a4ce29> # Recommended update for the initial kernel livepatch Announcement ID: SUSE-RU-2026:22878-1 Release Date: 2026-07-20T10:36:05Z Rating: important References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update contains initial livepatches for the SUSE Linux Enterprise Server 16.0 and SUSE Linux Micro 6.2 kernel update. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1296=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1296=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_36-default-1-160000.1.1 * kernel-livepatch-6_12_0-160000_36-default-debuginfo-1-160000.1.1 * kernel-livepatch-SLE16_Update_15-debugsource-1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_36-default-1-160000.1.1 * kernel-livepatch-6_12_0-160000_36-default-debuginfo-1-160000.1.1 * kernel-livepatch-SLE16_Update_15-debugsource-1-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:06:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:06:49 -0000 Subject: SUSE-SU-2026:22877-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Message-ID: <178517200946.2240.17962884694211559302@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22877-1 Release Date: 2026-07-20T09:52:10Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1297=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1297=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_32-default-debuginfo-4-160000.1.1 * kernel-livepatch-SLE16_Update_11-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_32-default-4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_32-default-debuginfo-4-160000.1.1 * kernel-livepatch-SLE16_Update_11-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_32-default-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:08:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:08:21 -0000 Subject: SUSE-SU-2026:22876-1: important: Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Message-ID: <178517210176.2240.2271432023971377222@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22876-1 Release Date: 2026-07-20T09:29:50Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.7.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1292=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1292=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_7-default-debuginfo-11-160000.1.1 * kernel-livepatch-SLE16_Update_2-debugsource-11-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-11-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_7-default-debuginfo-11-160000.1.1 * kernel-livepatch-SLE16_Update_2-debugsource-11-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:09:31 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:09:31 -0000 Subject: SUSE-SU-2026:22875-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178517217143.2240.10466576658318579145@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22875-1 Release Date: 2026-07-20T09:29:50Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1291=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1291=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_29-default-debuginfo-5-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_29-default-debuginfo-5-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:10:52 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:10:52 -0000 Subject: SUSE-SU-2026:22874-1: important: Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Message-ID: <178517225223.2240.2606286241303144559@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22874-1 Release Date: 2026-07-20T07:46:30Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.26.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1290=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1290=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_26-default-8-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-8-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-debuginfo-8-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_26-default-8-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-8-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-debuginfo-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:12:07 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:12:07 -0000 Subject: SUSE-SU-2026:22873-1: important: Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Message-ID: <178517232701.2240.1216753205154092478@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22873-1 Release Date: 2026-07-20T07:44:50Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.27.1 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1289=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1289=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_27-default-7-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-debuginfo-7-160000.1.1 * kernel-livepatch-SLE16_Update_6-debugsource-7-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_27-default-7-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-debuginfo-7-160000.1.1 * kernel-livepatch-SLE16_Update_6-debugsource-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:13:23 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:13:23 -0000 Subject: SUSE-SU-2026:22872-1: important: Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Message-ID: <178517240368.2240.191280872980532516@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22872-1 Release Date: 2026-07-18T12:12:36Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1284=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1284=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_5-default-15-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-debuginfo-15-160000.4.3 * kernel-livepatch-SLE16_Update_0-debugsource-15-160000.4.3 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_5-default-15-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-debuginfo-15-160000.4.3 * kernel-livepatch-SLE16_Update_0-debugsource-15-160000.4.3 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:14:13 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:14:13 -0000 Subject: SUSE-SU-2026:22871-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 16) Message-ID: <178517245394.2240.7219944742715013011@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22871-1 Release Date: 2026-07-16T21:48:12Z Rating: important References: * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.33.1 fixes various security issues The following security issues were fixed: * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1277=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1277=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_33-default-2-160000.1.1 * kernel-livepatch-6_12_0-160000_33-default-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16_Update_12-debugsource-2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_33-default-2-160000.1.1 * kernel-livepatch-6_12_0-160000_33-default-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16_Update_12-debugsource-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:15:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:15:21 -0000 Subject: SUSE-SU-2026:22870-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Message-ID: <178517252155.2240.2383874349425254813@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22870-1 Release Date: 2026-07-16T11:54:12Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1274=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1274=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_31-default-4-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-debuginfo-4-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-4-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_31-default-4-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-debuginfo-4-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:16:59 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:16:59 -0000 Subject: SUSE-SU-2026:22869-1: important: Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Message-ID: <178517261918.2240.17480729948144415839@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22869-1 Release Date: 2026-07-16T09:15:01Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1273=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1273=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_3-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-10-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-10-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_3-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-10-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:18:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:18:21 -0000 Subject: SUSE-SU-2026:22868-1: important: Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Message-ID: <178517270161.2240.2545878911134788704@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22868-1 Release Date: 2026-07-16T06:11:51Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.28.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1272=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1272=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_28-default-debuginfo-6-160000.1.1 * kernel-livepatch-SLE16_Update_7-debugsource-6-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-6-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_28-default-debuginfo-6-160000.1.1 * kernel-livepatch-SLE16_Update_7-debugsource-6-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:19:38 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:19:38 -0000 Subject: SUSE-SU-2026:22867-1: important: Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Message-ID: <178517277875.2240.13800523658341983675@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22867-1 Release Date: 2026-07-16T02:55:01Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1271=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1271=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_4-debugsource-9-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-9-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-debuginfo-9-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_4-debugsource-9-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-9-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-debuginfo-9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:20:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:20:25 -0000 Subject: SUSE-SU-2026:22866-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Message-ID: <178517282527.2240.17160101861294214187@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22866-1 Release Date: 2026-07-15T20:41:01Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.35.1 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1270=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1270=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_14-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-2-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-debuginfo-2-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_14-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-2-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-debuginfo-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:21:34 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:21:34 -0000 Subject: SUSE-SU-2026:22865-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Message-ID: <178517289414.2240.14643438532008120022@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22865-1 Release Date: 2026-07-15T19:11:41Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.30.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1269=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1269=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_30-default-debuginfo-4-160000.1.1 * kernel-livepatch-SLE16_Update_9-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-4-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_30-default-debuginfo-4-160000.1.1 * kernel-livepatch-SLE16_Update_9-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:22:59 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:22:59 -0000 Subject: SUSE-SU-2026:22864-1: important: Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Message-ID: <178517297911.2240.9809713425066632360@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22864-1 Release Date: 2026-07-15T10:35:25Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.6.1 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1266=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1266=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_6-default-13-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-debuginfo-13-160000.1.1 * kernel-livepatch-SLE16_Update_1-debugsource-13-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_6-default-13-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-debuginfo-13-160000.1.1 * kernel-livepatch-SLE16_Update_1-debugsource-13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:23:38 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:23:38 -0000 Subject: SUSE-SU-2026:22863-1: moderate: Security update for python-urllib3 Message-ID: <178517301838.2240.15840381041201617380@c3e054a4ce29> # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:22863-1 Release Date: 2026-07-23T09:46:12Z Rating: moderate References: * bsc#1268683 Cross-References: * CVE-2026-9375 CVSS scores: * CVE-2026-9375 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-9375 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-9375 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-urllib3 fixes the following issue * CVE-2026-9375: decompression bomb bypass in the streaming API when using Brotli support can lead to a denial of service (bsc#1268683). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1341=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1341=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-urllib3-2.5.0-160000.7.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-urllib3-2.5.0-160000.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9375.html * https://bugzilla.suse.com/show_bug.cgi?id=1268683 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:24:17 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:24:17 -0000 Subject: SUSE-SU-2026:22862-1: low: Security update for net-tools Message-ID: <178517305754.2240.11108330738707573392@c3e054a4ce29> # Security update for net-tools Announcement ID: SUSE-SU-2026:22862-1 Release Date: 2026-07-23T03:40:54Z Rating: low References: * bsc#1254323 Cross-References: * CVE-2024-58251 CVSS scores: * CVE-2024-58251 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-58251 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-58251 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for net-tools fixes the following issue: * CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1340=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1340=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * net-tools-lang-2.10-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * net-tools-debugsource-2.10-160000.4.1 * net-tools-2.10-160000.4.1 * net-tools-debuginfo-2.10-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * net-tools-debugsource-2.10-160000.4.1 * net-tools-2.10-160000.4.1 * net-tools-debuginfo-2.10-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * net-tools-lang-2.10-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2024-58251.html * https://bugzilla.suse.com/show_bug.cgi?id=1254323 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:25:16 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:25:16 -0000 Subject: SUSE-SU-2026:22861-1: important: Security update for ImageMagick Message-ID: <178517311623.2240.17631189773172098706@c3e054a4ce29> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:22861-1 Release Date: 2026-07-22T19:01:21Z Rating: important References: * bsc#1268878 * bsc#1271484 * bsc#1271485 * bsc#1271486 * bsc#1271487 * bsc#1271488 * bsc#1271489 * bsc#1271490 * bsc#1271491 * bsc#1271492 * bsc#1271493 * bsc#1271494 * bsc#1271495 * bsc#1271496 * bsc#1271497 Cross-References: * CVE-2026-56375 * CVE-2026-56379 * CVE-2026-61464 * CVE-2026-61859 * CVE-2026-61860 * CVE-2026-61862 * CVE-2026-61863 * CVE-2026-61864 * CVE-2026-61865 * CVE-2026-61866 * CVE-2026-61867 * CVE-2026-61868 * CVE-2026-61869 * CVE-2026-61871 * CVE-2026-61872 CVSS scores: * CVE-2026-56375 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56375 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56375 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56375 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-61464 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61464 ( NVD ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61464 ( NVD ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61859 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-61859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61859 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61859 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61860 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61860 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61860 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61862 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61862 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61862 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61863 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61863 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61863 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61863 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61864 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61864 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61864 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61864 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61865 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61865 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61865 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61865 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61866 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61866 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61866 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61866 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61867 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61867 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61867 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61867 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61868 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61868 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61869 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61869 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61871 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61871 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61871 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61871 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61872 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61872 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61872 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-56375: Possible memory leak in ASHLAR coder when action fails (bsc#1271495). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * CVE-2026-61464: Heap Buffer Over-Write in X11 import with crafted window title (bsc#1271496). * CVE-2026-61859: Policy Bypass in script operation due to missing checks (bsc#1271497). * CVE-2026-61860: Use-After-Free when freetype initialization fails (bsc#1271494). * CVE-2026-61862: Information Disclosure when printing profiles with debug enabled (bsc#1271493). * CVE-2026-61863: Memory Leak in TIFF encoder when a temporary file could not be created (bsc#1271492). * CVE-2026-61864: Memory Leak in color transformation to log colorspace when operation fails (bsc#1271491). * CVE-2026-61865: Memory Leak in hough lines operation when an operation fails (bsc#1271490). * CVE-2026-61866: Memory Leak in JNG encoder when a blob could not be opened (bsc#1271489). * CVE-2026-61867: Memory Leak in TIFF encoder when an allocation fails (bsc#1271488). * CVE-2026-61868: Memory Leak in YUV decoder when opening of blob fails (bsc#1271487). * CVE-2026-61869: Memory Leak in MIFF encoder when allocation fails (bsc#1271486). * CVE-2026-61871: Memory Leak in ICON decoder when allocation fails (bsc#1271485). * CVE-2026-61872: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified (bsc#1271484). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1337=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1337=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * ImageMagick-debugsource-7.1.2.0-160000.13.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.13.1 * ImageMagick-debuginfo-7.1.2.0-160000.13.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.13.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.13.1 * libMagick++-7_Q16HDRI5-7.1.2.0-160000.13.1 * ImageMagick-devel-7.1.2.0-160000.13.1 * ImageMagick-extra-7.1.2.0-160000.13.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.13.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.13.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.13.1 * perl-PerlMagick-7.1.2.0-160000.13.1 * ImageMagick-7.1.2.0-160000.13.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.13.1 * libMagick++-devel-7.1.2.0-160000.13.1 * SUSE Linux Enterprise Server 16.0 (noarch) * ImageMagick-doc-7.1.2.0-160000.13.1 * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.13.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.13.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1 * ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * ImageMagick-doc-7.1.2.0-160000.13.1 * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.13.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.13.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1 * ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.13.1 * ImageMagick-debugsource-7.1.2.0-160000.13.1 * ImageMagick-debuginfo-7.1.2.0-160000.13.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.13.1 * ImageMagick-devel-7.1.2.0-160000.13.1 * libMagick++-7_Q16HDRI5-7.1.2.0-160000.13.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.13.1 * ImageMagick-extra-7.1.2.0-160000.13.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.13.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.13.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.13.1 * perl-PerlMagick-7.1.2.0-160000.13.1 * ImageMagick-7.1.2.0-160000.13.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.13.1 * libMagick++-devel-7.1.2.0-160000.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56375.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://www.suse.com/security/cve/CVE-2026-61464.html * https://www.suse.com/security/cve/CVE-2026-61859.html * https://www.suse.com/security/cve/CVE-2026-61860.html * https://www.suse.com/security/cve/CVE-2026-61862.html * https://www.suse.com/security/cve/CVE-2026-61863.html * https://www.suse.com/security/cve/CVE-2026-61864.html * https://www.suse.com/security/cve/CVE-2026-61865.html * https://www.suse.com/security/cve/CVE-2026-61866.html * https://www.suse.com/security/cve/CVE-2026-61867.html * https://www.suse.com/security/cve/CVE-2026-61868.html * https://www.suse.com/security/cve/CVE-2026-61869.html * https://www.suse.com/security/cve/CVE-2026-61871.html * https://www.suse.com/security/cve/CVE-2026-61872.html * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1271484 * https://bugzilla.suse.com/show_bug.cgi?id=1271485 * https://bugzilla.suse.com/show_bug.cgi?id=1271486 * https://bugzilla.suse.com/show_bug.cgi?id=1271487 * https://bugzilla.suse.com/show_bug.cgi?id=1271488 * https://bugzilla.suse.com/show_bug.cgi?id=1271489 * https://bugzilla.suse.com/show_bug.cgi?id=1271490 * https://bugzilla.suse.com/show_bug.cgi?id=1271491 * https://bugzilla.suse.com/show_bug.cgi?id=1271492 * https://bugzilla.suse.com/show_bug.cgi?id=1271493 * https://bugzilla.suse.com/show_bug.cgi?id=1271494 * https://bugzilla.suse.com/show_bug.cgi?id=1271495 * https://bugzilla.suse.com/show_bug.cgi?id=1271496 * https://bugzilla.suse.com/show_bug.cgi?id=1271497 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:25:57 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:25:57 -0000 Subject: SUSE-SU-2026:22860-1: moderate: Security update for PackageKit Message-ID: <178517315709.2240.13792257331299110720@c3e054a4ce29> # Security update for PackageKit Announcement ID: SUSE-SU-2026:22860-1 Release Date: 2026-07-22T19:00:17Z Rating: moderate References: * bsc#1263252 * bsc#1267250 Cross-References: * CVE-2026-10294 CVSS scores: * CVE-2026-10294 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10294 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-10294 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10294 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for PackageKit fixes the following issues: Security issue fixed: * CVE-2026-10294: manipulation of the argument frontend-socket can lead to improper authorization (bsc#1267250). Non security issue fixed: * KDE Discover ignores package locks (bsc#1263252). ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1336=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1336=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * PackageKit-devel-debuginfo-1.2.8-160000.5.1 * PackageKit-debugsource-1.2.8-160000.5.1 * PackageKit-backend-zypp-debuginfo-1.2.8-160000.5.1 * PackageKit-backend-zypp-1.2.8-160000.5.1 * PackageKit-devel-1.2.8-160000.5.1 * libpackagekit-glib2-18-debuginfo-1.2.8-160000.5.1 * libpackagekit-glib2-devel-1.2.8-160000.5.1 * libpackagekit-glib2-18-1.2.8-160000.5.1 * PackageKit-debuginfo-1.2.8-160000.5.1 * typelib-1_0-PackageKitGlib-1_0-1.2.8-160000.5.1 * PackageKit-1.2.8-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * PackageKit-lang-1.2.8-160000.5.1 * PackageKit-branding-upstream-1.2.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * PackageKit-devel-debuginfo-1.2.8-160000.5.1 * PackageKit-debugsource-1.2.8-160000.5.1 * PackageKit-backend-zypp-1.2.8-160000.5.1 * PackageKit-devel-1.2.8-160000.5.1 * PackageKit-backend-zypp-debuginfo-1.2.8-160000.5.1 * libpackagekit-glib2-18-debuginfo-1.2.8-160000.5.1 * libpackagekit-glib2-devel-1.2.8-160000.5.1 * libpackagekit-glib2-18-1.2.8-160000.5.1 * PackageKit-debuginfo-1.2.8-160000.5.1 * typelib-1_0-PackageKitGlib-1_0-1.2.8-160000.5.1 * PackageKit-1.2.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * PackageKit-lang-1.2.8-160000.5.1 * PackageKit-branding-upstream-1.2.8-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10294.html * https://bugzilla.suse.com/show_bug.cgi?id=1263252 * https://bugzilla.suse.com/show_bug.cgi?id=1267250 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:26:36 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:26:36 -0000 Subject: SUSE-SU-2026:22859-1: moderate: Security update for perl-HTTP-Date Message-ID: <178517319606.2240.4026889322286918152@c3e054a4ce29> # Security update for perl-HTTP-Date Announcement ID: SUSE-SU-2026:22859-1 Release Date: 2026-07-22T18:58:14Z Rating: moderate References: * bsc#1271705 Cross-References: * CVE-2026-14741 CVSS scores: * CVE-2026-14741 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-14741 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-14741 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTTP-Date fixes the following issue * CVE-2026-14741: CPU exhaustion via polynomial regex backtracking in parse_date (bsc#1271705). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1338=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1338=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * perl-HTTP-Date-6.06-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * perl-HTTP-Date-6.06-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14741.html * https://bugzilla.suse.com/show_bug.cgi?id=1271705 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:27:15 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:27:15 -0000 Subject: SUSE-SU-2026:22858-1: moderate: Security update for apache-ivy Message-ID: <178517323515.2240.10535591625452214849@c3e054a4ce29> # Security update for apache-ivy Announcement ID: SUSE-SU-2026:22858-1 Release Date: 2026-07-22T17:49:04Z Rating: moderate References: * bsc#1271727 Cross-References: * CVE-2026-26032 CVSS scores: * CVE-2026-26032 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-26032 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-26032 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for apache-ivy fixes the following issue: * CVE-2026-26032: directory traversal sequences in module coordinates can allow overwriting arbitrary files outside the configured "buildRoot" directory (bsc#1271727). Changes for apache-ivy: * Upgrade to 2.6.0: * the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660) * when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency resolution, especially when multiple configurations are used. It also fixes issues where the dynamic revisions were replaced by versions from other configurations. (IVY-1485, IVY-1661) * the ivy:deliver task didn't replace dynamic revision from inherited dependencies. (IVY-1410) * the ivy:install task didn't take the from resolver into account when resolving Maven parent modules or source/javadoc artifacts. * the ivy:checkdepsupdate task could suggest a lesser version as update. (IVY-1665) * the ivy:makepom task no longer adds a dependency to the dependencyManagement section. (IVY-1667) * the ivy:deliver task didn't include XML namespaces from a parent ivy module when merging the descriptors. (IVY-1658) * the ivy:checkdepsupdate task no longer shows evicted versions. (IVY-1662) * Improvements * use Apache Commons Compress for pack200 handling to avoid issues on Java 14 and later. If pack200 is needed, make sure to add Apache Commons Compress to your classpath. (IVY-1652) * ivy:retrieve and the 'post resolve tasks' now support the override child element. (IVY-1664) * ivy:makepom will now add override elements of the ivy.xml to the dependencyManagement section of the generated pom. (IVY-1663) * ivy:deliver and ivy:publish now writes inherited dependencies first to preserve resolve order (IVY-1656) * ModuleRevisionId.encodeToString now returns a deterministic string that doesn't rely on a implmentation of HashMap * New feature * added a new nearest conflict manager, which handles conflicts in the same way that Maven does. (IVY-813) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1335=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1335=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * apache-ivy-2.6.0-160000.1.1 * apache-ivy-javadoc-2.6.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * apache-ivy-2.6.0-160000.1.1 * apache-ivy-javadoc-2.6.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26032.html * https://bugzilla.suse.com/show_bug.cgi?id=1271727 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:27:52 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:27:52 -0000 Subject: SUSE-RU-2026:22857-1: moderate: Recommended update for rust, rust1.97 Message-ID: <178517327250.2240.12686628638318554707@c3e054a4ce29> # Recommended update for rust, rust1.97 Announcement ID: SUSE-RU-2026:22857-1 Release Date: 2026-07-22T17:06:33Z Rating: moderate References: * jsc#PED-11411 * jsc#SLE-18626 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains two features can now be installed. ## Description: This update for rust, rust1.97 fixes the following issues: rust1.97 is shipped as new package. * Release notes can be found externally: https://github.com/rust- lang/rust/releases/tag/1.97.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1330=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1330=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cargo1.97-debuginfo-1.97.0-160000.1.1 * rust-1.97.0-160000.1.1 * cargo-1.97.0-160000.1.1 * rust1.97-debuginfo-1.97.0-160000.1.1 * cargo1.97-1.97.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 nosrc ppc64le s390x x86_64) * rust1.97-1.97.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (nosrc ppc64le x86_64) * rust1.97-1.97.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cargo1.97-debuginfo-1.97.0-160000.1.1 * rust-1.97.0-160000.1.1 * cargo-1.97.0-160000.1.1 * rust1.97-debuginfo-1.97.0-160000.1.1 * cargo1.97-1.97.0-160000.1.1 ## References: * https://jira.suse.com/browse/PED-11411 * https://jira.suse.com/browse/SLE-18626 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:28:16 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:28:16 -0000 Subject: SUSE-SU-2026:22856-1: important: Security update for jline3 Message-ID: <178517329609.2240.10043016012740429063@c3e054a4ce29> # Security update for jline3 Announcement ID: SUSE-SU-2026:22856-1 Release Date: 2026-07-22T16:48:17Z Rating: important References: * bsc#1269021 * bsc#1270083 Cross-References: * CVE-2026-56740 * CVE-2026-56741 CVSS scores: * CVE-2026-56740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56740 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56741 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56741 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for jline3 fixes the following issues: * CVE-2026-56740: unauthenticated remote memory exhaustion via unbounded Telnet `NEW-ENVIRON` variables (bsc#1269021). * CVE-2026-56741: unauthenticated remote DoS via Unbounded Telnet NAWS Terminal Geometry (bsc#1270083). Changes for jline3: * Update to upstream version 3.30.15 * fix: guard regex matching against catastrophic backtracking (ReDoS) (#2018, backport of #2012): * Adds SafeRegex utility with TimeoutCharSequence to enforce wall-clock deadlines during regex matching * Fixes 8 locations across terminal, reader, and builtins where user- controlled input could trigger catastrophic backtracking * Addresses GHSA-r2xf-8xr9-62gw, GHSA-2v9w-34q6-wpqx, GHSA-ph9c-7hw9-vhhw, GHSA-5q95-hrpc-m3w3 * fix: backport security hardening (#1986, #1995): * Create persisted history file with owner-only permissions * Use exclusive create for extracted native library temp files * fix: warn on insecure permissions when history file created concurrently ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1334=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1334=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * jline3-terminal-jansi-3.30.15-160000.1.1 * jline3-reader-3.30.15-160000.1.1 * jline3-console-ui-3.30.15-160000.1.1 * jline3-console-3.30.15-160000.1.1 * jline3-remote-telnet-3.30.15-160000.1.1 * jline3-curses-3.30.15-160000.1.1 * jline3-builtins-3.30.15-160000.1.1 * jline3-terminal-jna-3.30.15-160000.1.1 * jline3-jansi-core-3.30.15-160000.1.1 * jline3-terminal-3.30.15-160000.1.1 * jline3-terminal-jni-3.30.15-160000.1.1 * jline3-javadoc-3.30.15-160000.1.1 * jline3-style-3.30.15-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * jline3-native-debuginfo-3.30.15-160000.1.1 * jline3-native-3.30.15-160000.1.1 * jline3-3.30.15-160000.1.1 * jline3-debugsource-3.30.15-160000.1.1 * jline3-jansi-3.30.15-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jline3-native-debuginfo-3.30.15-160000.1.1 * jline3-native-3.30.15-160000.1.1 * jline3-3.30.15-160000.1.1 * jline3-debugsource-3.30.15-160000.1.1 * jline3-jansi-3.30.15-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * jline3-terminal-jansi-3.30.15-160000.1.1 * jline3-reader-3.30.15-160000.1.1 * jline3-console-ui-3.30.15-160000.1.1 * jline3-console-3.30.15-160000.1.1 * jline3-remote-telnet-3.30.15-160000.1.1 * jline3-curses-3.30.15-160000.1.1 * jline3-builtins-3.30.15-160000.1.1 * jline3-terminal-3.30.15-160000.1.1 * jline3-terminal-jni-3.30.15-160000.1.1 * jline3-jansi-core-3.30.15-160000.1.1 * jline3-terminal-jna-3.30.15-160000.1.1 * jline3-javadoc-3.30.15-160000.1.1 * jline3-style-3.30.15-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56740.html * https://www.suse.com/security/cve/CVE-2026-56741.html * https://bugzilla.suse.com/show_bug.cgi?id=1269021 * https://bugzilla.suse.com/show_bug.cgi?id=1270083 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:28:56 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:28:56 -0000 Subject: SUSE-SU-2026:22855-1: important: Security update for helm Message-ID: <178517333626.2240.2426247808476106625@c3e054a4ce29> # Security update for helm Announcement ID: SUSE-SU-2026:22855-1 Release Date: 2026-07-22T16:35:45Z Rating: important References: * bsc#1266598 * bsc#1271997 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for helm fixes the following issues * Update to version 3.21.3 * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1333=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1333=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * helm-zsh-completion-3.21.3-160000.1.1 * helm-fish-completion-3.21.3-160000.1.1 * helm-bash-completion-3.21.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * helm-debuginfo-3.21.3-160000.1.1 * helm-3.21.3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * helm-zsh-completion-3.21.3-160000.1.1 * helm-fish-completion-3.21.3-160000.1.1 * helm-bash-completion-3.21.3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.3-160000.1.1 * helm-3.21.3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 * https://bugzilla.suse.com/show_bug.cgi?id=1271997 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:29:35 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:29:35 -0000 Subject: SUSE-SU-2026:22854-1: important: Security update for shibboleth-sp Message-ID: <178517337533.2240.8393128970277222315@c3e054a4ce29> # Security update for shibboleth-sp Announcement ID: SUSE-SU-2026:22854-1 Release Date: 2026-07-22T12:54:46Z Rating: important References: * bsc#1249394 Cross-References: * CVE-2025-9943 CVSS scores: * CVE-2025-9943 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-9943 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for shibboleth-sp fixes the following issue * CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1329=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1329=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * shibboleth-sp-debugsource-3.5.0-160000.3.1 * libshibsp-lite12-3.5.0-160000.3.1 * shibboleth-sp-debuginfo-3.5.0-160000.3.1 * shibboleth-sp-3.5.0-160000.3.1 * libshibsp-lite12-debuginfo-3.5.0-160000.3.1 * libshibsp12-3.5.0-160000.3.1 * libshibsp12-debuginfo-3.5.0-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * shibboleth-sp-debugsource-3.5.0-160000.3.1 * libshibsp-lite12-3.5.0-160000.3.1 * shibboleth-sp-debuginfo-3.5.0-160000.3.1 * shibboleth-sp-3.5.0-160000.3.1 * libshibsp-lite12-debuginfo-3.5.0-160000.3.1 * libshibsp12-3.5.0-160000.3.1 * libshibsp12-debuginfo-3.5.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9943.html * https://bugzilla.suse.com/show_bug.cgi?id=1249394 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:30:16 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:30:16 -0000 Subject: SUSE-SU-2026:22853-1: moderate: Security update for avahi Message-ID: <178517341665.2240.6136334042928317891@c3e054a4ce29> # Security update for avahi Announcement ID: SUSE-SU-2026:22853-1 Release Date: 2026-07-22T12:41:51Z Rating: moderate References: * bsc#1255451 * jsc#PED-14835 * jsc#PED-14836 Cross-References: * CVE-2025-59529 CVSS scores: * CVE-2025-59529 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and contains two features can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). Changes for avahi: * Make /var/lib/avahi-autoipd a ghost dir instead of packaging it since avahi- autoipd creates it on start (jsc#PED-14836). * Use libalternative instead of update-alternatives in TW and SLFO (jsc#PED-14835). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1328=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1328=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libavahi-libevent1-debuginfo-0.8-160000.6.1 * libdns_sd-0.8-160000.6.1 * libavahi-core7-debuginfo-0.8-160000.6.1 * avahi-autoipd-0.8-160000.6.1 * typelib-1_0-Avahi-0_6-0.8-160000.6.1 * libhowl0-debuginfo-0.8-160000.6.1 * libavahi-ui-gtk3-0-debuginfo-0.8-160000.6.1 * libavahi-glib-devel-0.8-160000.6.1 * avahi-debugsource-0.8-160000.6.1 * libavahi-gobject0-0.8-160000.6.1 * avahi-glib2-debugsource-0.8-160000.6.1 * libavahi-glib1-0.8-160000.6.1 * libavahi-gobject-devel-0.8-160000.6.1 * libavahi-gobject0-debuginfo-0.8-160000.6.1 * libhowl0-0.8-160000.6.1 * python3-avahi-gtk-0.8-160000.6.1 * avahi-compat-mDNSResponder-devel-0.8-160000.6.1 * avahi-utils-gtk-0.8-160000.6.1 * avahi-utils-gtk-debuginfo-0.8-160000.6.1 * libdns_sd-debuginfo-0.8-160000.6.1 * libavahi-libevent1-0.8-160000.6.1 * libavahi-glib1-debuginfo-0.8-160000.6.1 * python313-avahi-0.8-160000.6.1 * avahi-utils-0.8-160000.6.1 * libavahi-core7-0.8-160000.6.1 * libavahi-common3-0.8-160000.6.1 * libavahi-common3-debuginfo-0.8-160000.6.1 * libavahi-ui-gtk3-0-0.8-160000.6.1 * avahi-autoipd-debuginfo-0.8-160000.6.1 * libavahi-devel-0.8-160000.6.1 * libavahi-client3-0.8-160000.6.1 * avahi-debuginfo-0.8-160000.6.1 * avahi-utils-debuginfo-0.8-160000.6.1 * libavahi-client3-debuginfo-0.8-160000.6.1 * avahi-0.8-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * avahi-lang-0.8-160000.6.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libavahi-libevent1-debuginfo-0.8-160000.6.1 * libdns_sd-0.8-160000.6.1 * avahi-autoipd-0.8-160000.6.1 * libavahi-core7-debuginfo-0.8-160000.6.1 * typelib-1_0-Avahi-0_6-0.8-160000.6.1 * libhowl0-debuginfo-0.8-160000.6.1 * libavahi-ui-gtk3-0-debuginfo-0.8-160000.6.1 * libavahi-glib-devel-0.8-160000.6.1 * avahi-debugsource-0.8-160000.6.1 * libavahi-gobject0-0.8-160000.6.1 * avahi-utils-debuginfo-0.8-160000.6.1 * avahi-glib2-debugsource-0.8-160000.6.1 * libavahi-glib1-0.8-160000.6.1 * libavahi-gobject-devel-0.8-160000.6.1 * libavahi-gobject0-debuginfo-0.8-160000.6.1 * libhowl0-0.8-160000.6.1 * avahi-compat-mDNSResponder-devel-0.8-160000.6.1 * python3-avahi-gtk-0.8-160000.6.1 * avahi-utils-gtk-0.8-160000.6.1 * avahi-utils-gtk-debuginfo-0.8-160000.6.1 * libdns_sd-debuginfo-0.8-160000.6.1 * libavahi-libevent1-0.8-160000.6.1 * libavahi-glib1-debuginfo-0.8-160000.6.1 * python313-avahi-0.8-160000.6.1 * avahi-utils-0.8-160000.6.1 * libavahi-common3-0.8-160000.6.1 * libavahi-common3-debuginfo-0.8-160000.6.1 * libavahi-ui-gtk3-0-0.8-160000.6.1 * avahi-autoipd-debuginfo-0.8-160000.6.1 * libavahi-devel-0.8-160000.6.1 * avahi-debuginfo-0.8-160000.6.1 * libavahi-client3-0.8-160000.6.1 * libavahi-core7-0.8-160000.6.1 * libavahi-client3-debuginfo-0.8-160000.6.1 * avahi-0.8-160000.6.1 * SUSE Linux Enterprise Server 16.0 (noarch) * avahi-lang-0.8-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59529.html * https://bugzilla.suse.com/show_bug.cgi?id=1255451 * https://jira.suse.com/browse/PED-14835 * https://jira.suse.com/browse/PED-14836 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:30:57 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:30:57 -0000 Subject: SUSE-RU-2026:22852-1: moderate: Recommended update for wicked2nm Message-ID: <178517345777.2240.7782938709157820754@c3e054a4ce29> # Recommended update for wicked2nm Announcement ID: SUSE-RU-2026:22852-1 Release Date: 2026-07-22T12:41:51Z Rating: moderate References: * bsc#1271079 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for wicked2nm fixes the following issues: * Update v1.5.1: * Update agama to fix default vlan flags: * Previously the default vlan flags in NM was set to 0, which overrides default kernel behavior and thus differed from wicked. It is now set to 1. (bsc#1271079) * Tests: Sort wicked show-config output by interface name * Add leap16.1 to CI * Require minimum cargo version 1.78 for lockfile version 4 parsing ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1327=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1327=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * wicked2nm-debugsource-1.5.1-160000.1.1 * wicked2nm-1.5.1-160000.1.1 * wicked2nm-debuginfo-1.5.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * wicked2nm-debugsource-1.5.1-160000.1.1 * wicked2nm-1.5.1-160000.1.1 * wicked2nm-debuginfo-1.5.1-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271079 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:31:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:31:21 -0000 Subject: SUSE-SU-2026:22851-1: moderate: Security update for wpa_supplicant Message-ID: <178517348139.2240.4745146708417162048@c3e054a4ce29> # Security update for wpa_supplicant Announcement ID: SUSE-SU-2026:22851-1 Release Date: 2026-07-22T12:39:34Z Rating: moderate References: * bsc#1258365 * bsc#1269892 Cross-References: * CVE-2026-58374 CVSS scores: * CVE-2026-58374 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58374 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58374 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for wpa_supplicant fixes the following issues * CVE-2026-58374: Fixed a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1326=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1326=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * wpa_supplicant-debuginfo-2.11-160000.4.1 * wpa_supplicant-2.11-160000.4.1 * wpa_supplicant-debugsource-2.11-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * wpa_supplicant-debugsource-2.11-160000.4.1 * wpa_supplicant-2.11-160000.4.1 * wpa_supplicant-debuginfo-2.11-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58374.html * https://bugzilla.suse.com/show_bug.cgi?id=1258365 * https://bugzilla.suse.com/show_bug.cgi?id=1269892 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:32:03 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:32:03 -0000 Subject: SUSE-RU-2026:22850-1: important: Recommended update for multipath-tools Message-ID: <178517352345.2240.7677424082571176401@c3e054a4ce29> # Recommended update for multipath-tools Announcement ID: SUSE-RU-2026:22850-1 Release Date: 2026-07-22T09:13:19Z Rating: important References: * bsc#1254094 * bsc#1268144 * bsc#1268145 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has three fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Fix ALUA asymmetric access state descriptions in multipathd logs, so that the same terms are used as by the kernel ("lba-dependent", "transitioning"). * Don't set a hardware handler for bio-based multipath devices. * Fix WWID detection for legacy devices that use the older SCSI-2 VPD page 0x83 format for their device identifier. * kpartx: * Fix an integer overflow in the GPT partition table size calculation. (bsc#1268145) * Fix several issues in the DASD partition table reader that could be triggered by a maliciously crafted disk image. (bsc#1268144) * Fix duplicate "checker timed out" log messages when `log_checker_err` is set to `once`. (bsc#1254094) * Avoid potential buffer overflows in the iet and datacore prioritizers. * iet prioritizer: avoid misleading error message with systemd 256 and newer, and properly use udev to derive path parameters. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1324=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1324=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * multipath-tools-0.12.3~1+272+suse.c377867-160000.1.1 * libdmmp0_2_0-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * multipath-tools-devel-0.12.3~1+272+suse.c377867-160000.1.1 * multipath-tools-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * multipath-tools-debugsource-0.12.3~1+272+suse.c377867-160000.1.1 * libmpath0-0.12.3~1+272+suse.c377867-160000.1.1 * libmpath0-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * libdmmp-devel-0.12.3~1+272+suse.c377867-160000.1.1 * libdmmp0_2_0-0.12.3~1+272+suse.c377867-160000.1.1 * kpartx-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * kpartx-0.12.3~1+272+suse.c377867-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * multipath-tools-devel-0.12.3~1+272+suse.c377867-160000.1.1 * libdmmp0_2_0-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * multipath-tools-0.12.3~1+272+suse.c377867-160000.1.1 * multipath-tools-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * multipath-tools-debugsource-0.12.3~1+272+suse.c377867-160000.1.1 * libmpath0-0.12.3~1+272+suse.c377867-160000.1.1 * libmpath0-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * libdmmp-devel-0.12.3~1+272+suse.c377867-160000.1.1 * kpartx-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * libdmmp0_2_0-0.12.3~1+272+suse.c377867-160000.1.1 * kpartx-0.12.3~1+272+suse.c377867-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1254094 * https://bugzilla.suse.com/show_bug.cgi?id=1268144 * https://bugzilla.suse.com/show_bug.cgi?id=1268145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:32:27 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:32:27 -0000 Subject: SUSE-RU-2026:22849-1: important: Recommended update for libzypp Message-ID: <178517354738.2240.16001615048061010221@c3e054a4ce29> # Recommended update for libzypp Announcement ID: SUSE-RU-2026:22849-1 Release Date: 2026-07-22T08:53:42Z Rating: important References: * bsc#1261038 * bsc#1268321 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for libzypp fixes the following issues: Changes in libzypp: Update to version 17.38.14 (35): * zypp.conf: add solver.NoUpdateProvide (default: false) option. In general, packages that obsolete another package are treated as update candidates for the obsoleted package. However, SUSE-specific update rules prefer candidates that also explicitly 'provide' the obsoleted package. Sometimes it is necessary or helpful to disable this rule. (may help in bsc#1261038) * Use HttpHeader class for defining host specific http headers (bsc#1268321) * Compile and link with -fPIE to build on sparc64 (fixes #742) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1314=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1314=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libzypp-debuginfo-17.38.14-160000.1.1 * libzypp-devel-17.38.14-160000.1.1 * libzypp-devel-doc-17.38.14-160000.1.1 * libzypp-17.38.14-160000.1.1 * libzypp-debugsource-17.38.14-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libzypp-devel-17.38.14-160000.1.1 * libzypp-debuginfo-17.38.14-160000.1.1 * libzypp-devel-doc-17.38.14-160000.1.1 * libzypp-17.38.14-160000.1.1 * libzypp-debugsource-17.38.14-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1261038 * https://bugzilla.suse.com/show_bug.cgi?id=1268321 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:32:49 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:32:49 -0000 Subject: SUSE-SU-2026:22848-1: important: Security update for google-cloud-sap-agent Message-ID: <178517356936.2240.3683981171937607114@c3e054a4ce29> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:22848-1 Release Date: 2026-07-22T08:46:39Z Rating: important References: * bsc#1266604 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issue: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266604). Changes for google-cloud-sap-agent: * Update golang.org/x/net to v0.57.0. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1323=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1323=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * google-cloud-sap-agent-debuginfo-3.15-160000.2.1 * google-cloud-sap-agent-3.15-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * google-cloud-sap-agent-debuginfo-3.15-160000.2.1 * google-cloud-sap-agent-3.15-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266604 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:33:33 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:33:33 -0000 Subject: SUSE-SU-2026:22847-1: important: Security update for perl Message-ID: <178517361359.2240.6433885781682171382@c3e054a4ce29> # Security update for perl Announcement ID: SUSE-SU-2026:22847-1 Release Date: 2026-07-22T08:44:23Z Rating: important References: * bsc#1266304 * bsc#1266361 * bsc#1268349 * bsc#1271372 * bsc#1271386 Cross-References: * CVE-2025-15649 * CVE-2026-12087 * CVE-2026-13221 * CVE-2026-57432 * CVE-2026-8376 CVSS scores: * CVE-2025-15649 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-15649 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12087 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12087 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-13221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13221 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-13221 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-13221 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-57432 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-57432 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-57432 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-57432 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8376 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-8376 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-8376 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8376 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for perl fixes the following issues: * CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date (bsc#1266361). * CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). * CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). * CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out- of-bounds heap read in `pack` and `unpack` (bsc#1271372). * CVE-2026-13221: regex trie branch-count overflow leads to silent false- positive/negative pattern matching (bsc#1271386). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1321=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1321=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-5.42.0-160000.3.1 * perl-base-debuginfo-5.42.0-160000.3.1 * perl-debugsource-5.42.0-160000.3.1 * perl-debuginfo-5.42.0-160000.3.1 * perl-base-5.42.0-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * perl-doc-5.42.0-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-5.42.0-160000.3.1 * perl-base-debuginfo-5.42.0-160000.3.1 * perl-debuginfo-5.42.0-160000.3.1 * perl-debugsource-5.42.0-160000.3.1 * perl-base-5.42.0-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * perl-doc-5.42.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15649.html * https://www.suse.com/security/cve/CVE-2026-12087.html * https://www.suse.com/security/cve/CVE-2026-13221.html * https://www.suse.com/security/cve/CVE-2026-57432.html * https://www.suse.com/security/cve/CVE-2026-8376.html * https://bugzilla.suse.com/show_bug.cgi?id=1266304 * https://bugzilla.suse.com/show_bug.cgi?id=1266361 * https://bugzilla.suse.com/show_bug.cgi?id=1268349 * https://bugzilla.suse.com/show_bug.cgi?id=1271372 * https://bugzilla.suse.com/show_bug.cgi?id=1271386 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:34:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:34:20 -0000 Subject: SUSE-SU-2026:22846-1: important: Security update for glib2 Message-ID: <178517366059.2240.4982241920321273161@c3e054a4ce29> # Security update for glib2 Announcement ID: SUSE-SU-2026:22846-1 Release Date: 2026-07-22T08:35:52Z Rating: important References: * bsc#1270008 * bsc#1270009 * bsc#1270010 * bsc#1270016 * bsc#1270018 * bsc#1270021 Cross-References: * CVE-2026-58010 * CVE-2026-58011 * CVE-2026-58012 * CVE-2026-58013 * CVE-2026-58014 * CVE-2026-58016 CVSS scores: * CVE-2026-58010 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58012 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). * CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). * CVE-2026-58012: raw byte regex matches with UTF-8 functions during case- change replacements could cause an out-of- bounds read (bsc#1270016). * CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). * CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). * CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1320=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1320=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * typelib-1_0-GModule-2_0-2.84.4-160000.4.1 * glib2-tools-2.84.4-160000.4.1 * glib2-doc-2.84.4-160000.4.1 * libgio-2_0-0-2.84.4-160000.4.1 * glib2-devel-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-devel-2.84.4-160000.4.1 * glib2-debugsource-2.84.4-160000.4.1 * libgthread-2_0-0-debuginfo-2.84.4-160000.4.1 * libgmodule-2_0-0-debuginfo-2.84.4-160000.4.1 * typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1 * libgirepository-2_0-0-2.84.4-160000.4.1 * libgthread-2_0-0-2.84.4-160000.4.1 * glib2-devel-static-2.84.4-160000.4.1 * libglib-2_0-0-2.84.4-160000.4.1 * libgmodule-2_0-0-2.84.4-160000.4.1 * typelib-1_0-GObject-2_0-2.84.4-160000.4.1 * typelib-1_0-Gio-2_0-2.84.4-160000.4.1 * libgirepository-2_0-0-debuginfo-2.84.4-160000.4.1 * libgio-2_0-0-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-2.84.4-160000.4.1 * libglib-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-tools-debuginfo-2.84.4-160000.4.1 * typelib-1_0-GLib-2_0-2.84.4-160000.4.1 * typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * glib2-lang-2.84.4-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * typelib-1_0-GModule-2_0-2.84.4-160000.4.1 * glib2-tools-2.84.4-160000.4.1 * glib2-doc-2.84.4-160000.4.1 * libgio-2_0-0-2.84.4-160000.4.1 * libgobject-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-devel-debuginfo-2.84.4-160000.4.1 * glib2-devel-2.84.4-160000.4.1 * glib2-debugsource-2.84.4-160000.4.1 * libgthread-2_0-0-debuginfo-2.84.4-160000.4.1 * libgmodule-2_0-0-debuginfo-2.84.4-160000.4.1 * libgirepository-2_0-0-2.84.4-160000.4.1 * libgthread-2_0-0-2.84.4-160000.4.1 * typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1 * glib2-devel-static-2.84.4-160000.4.1 * libglib-2_0-0-2.84.4-160000.4.1 * libgmodule-2_0-0-2.84.4-160000.4.1 * typelib-1_0-GObject-2_0-2.84.4-160000.4.1 * libgirepository-2_0-0-debuginfo-2.84.4-160000.4.1 * typelib-1_0-Gio-2_0-2.84.4-160000.4.1 * libgio-2_0-0-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-2.84.4-160000.4.1 * libglib-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-tools-debuginfo-2.84.4-160000.4.1 * typelib-1_0-GLib-2_0-2.84.4-160000.4.1 * typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * glib2-lang-2.84.4-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58010.html * https://www.suse.com/security/cve/CVE-2026-58011.html * https://www.suse.com/security/cve/CVE-2026-58012.html * https://www.suse.com/security/cve/CVE-2026-58013.html * https://www.suse.com/security/cve/CVE-2026-58014.html * https://www.suse.com/security/cve/CVE-2026-58016.html * https://bugzilla.suse.com/show_bug.cgi?id=1270008 * https://bugzilla.suse.com/show_bug.cgi?id=1270009 * https://bugzilla.suse.com/show_bug.cgi?id=1270010 * https://bugzilla.suse.com/show_bug.cgi?id=1270016 * https://bugzilla.suse.com/show_bug.cgi?id=1270018 * https://bugzilla.suse.com/show_bug.cgi?id=1270021 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:35:03 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:35:03 -0000 Subject: SUSE-SU-2026:22845-1: important: Security update for perl-DBI Message-ID: <178517370369.2240.14729755893785937116@c3e054a4ce29> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:22845-1 Release Date: 2026-07-22T08:23:18Z Rating: important References: * bsc#1271399 * bsc#1271458 * bsc#1271459 * bsc#1271629 Cross-References: * CVE-2026-15043 * CVE-2026-15392 * CVE-2026-60081 * CVE-2026-60082 CVSS scores: * CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-15043 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-15392 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60081 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60082 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-60082 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues: * CVE-2026-15392: failure to validate symbolic links during table path resolution could allow unauthorized file reads and writes outside the configured data director (bsc#1271629). * CVE-2026-15043: `DBI:SQL:Nano` has incorrect predicate evaluation, which allows for bypass of file-backed filters (bsc#1271399). * CVE-2026-60081: `DBI:ProfileData` does not limit the path index in profile parser, which enables small-file memory-amplification DoS (bsc#1271458). * CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row, which allows for a process crash (bsc#1271459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1322=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1322=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-DBI-1.647.0-160000.5.1 * perl-DBI-debuginfo-1.647.0-160000.5.1 * perl-DBI-debugsource-1.647.0-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-DBI-1.647.0-160000.5.1 * perl-DBI-debuginfo-1.647.0-160000.5.1 * perl-DBI-debugsource-1.647.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15043.html * https://www.suse.com/security/cve/CVE-2026-15392.html * https://www.suse.com/security/cve/CVE-2026-60081.html * https://www.suse.com/security/cve/CVE-2026-60082.html * https://bugzilla.suse.com/show_bug.cgi?id=1271399 * https://bugzilla.suse.com/show_bug.cgi?id=1271458 * https://bugzilla.suse.com/show_bug.cgi?id=1271459 * https://bugzilla.suse.com/show_bug.cgi?id=1271629 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:35:43 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:35:43 -0000 Subject: SUSE-SU-2026:22844-1: important: Security update for mariadb-connector-c Message-ID: <178517374321.2240.15772578988121686187@c3e054a4ce29> # Security update for mariadb-connector-c Announcement ID: SUSE-SU-2026:22844-1 Release Date: 2026-07-22T08:23:18Z Rating: important References: * bsc#1266438 Cross-References: * CVE-2026-44172 CVSS scores: * CVE-2026-44172 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for mariadb-connector-c fixes the following issue: * CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). Changes for mariadb-connector-c: * Update to release 3.4.9. * Update to release 3.4.8: * Fix compilation with GCC 15 * CONC-762: always set is_null and length in the bind structure to avoid msan errors * CONC-763: add MySQL collation ID 309 (utf8mb4_0900_bin) * CONC-764: fix build of ma_context.c on Android (X18 is a platform-reserved register) * CONC-766: disable clang -Wcast-function-type-strict for makecontext ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1319=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1319=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libmariadbprivate-debuginfo-3.4.9-160000.1.1 * mariadb-connector-c-debugsource-3.4.9-160000.1.1 * libmariadb3-3.4.9-160000.1.1 * libmariadb_plugins-debuginfo-3.4.9-160000.1.1 * libmariadbprivate-3.4.9-160000.1.1 * libmariadb-devel-3.4.9-160000.1.1 * libmariadb_plugins-3.4.9-160000.1.1 * libmariadb-devel-debuginfo-3.4.9-160000.1.1 * libmariadb3-debuginfo-3.4.9-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * mariadb-connector-c-debugsource-3.4.9-160000.1.1 * libmariadb_plugins-debuginfo-3.4.9-160000.1.1 * libmariadbprivate-debuginfo-3.4.9-160000.1.1 * libmariadb3-3.4.9-160000.1.1 * libmariadbprivate-3.4.9-160000.1.1 * libmariadb-devel-3.4.9-160000.1.1 * libmariadb_plugins-3.4.9-160000.1.1 * libmariadb-devel-debuginfo-3.4.9-160000.1.1 * libmariadb3-debuginfo-3.4.9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44172.html * https://bugzilla.suse.com/show_bug.cgi?id=1266438 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:36:21 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:36:21 -0000 Subject: SUSE-SU-2026:22843-1: important: Security update for joe Message-ID: <178517378187.2240.9679798005470207286@c3e054a4ce29> # Security update for joe Announcement ID: SUSE-SU-2026:22843-1 Release Date: 2026-07-22T08:23:18Z Rating: important References: * bsc#1269379 Cross-References: * CVE-2026-13412 CVSS scores: * CVE-2026-13412 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-13412 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for joe fixes the following issue * CVE-2026-13412: improper validation in tag-file parser can lead to arbitrary command execution (bsc#1269379). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1318=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1318=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * joe-debugsource-4.6-160000.4.1 * joe-debuginfo-4.6-160000.4.1 * joe-4.6-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * joe-debugsource-4.6-160000.4.1 * joe-debuginfo-4.6-160000.4.1 * joe-4.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13412.html * https://bugzilla.suse.com/show_bug.cgi?id=1269379 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:37:01 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:37:01 -0000 Subject: SUSE-RU-2026:22842-1: important: Recommended update for shim Message-ID: <178517382111.2240.8945195891611153434@c3e054a4ce29> # Recommended update for shim Announcement ID: SUSE-RU-2026:22842-1 Release Date: 2026-07-22T07:42:13Z Rating: important References: * bsc#1269084 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for shim fixes the following issues: * shim-install: Improve the detection of SL Micro * The GRUB_DISTRIBUTOR variable in SL Micro images may contain "SL Micro" or "SL-Micro" prefix. (bsc#1269084) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1317=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1317=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * shim-debugsource-16.1-160000.2.1 * shim-16.1-160000.2.1 * shim-debuginfo-16.1-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * shim-debuginfo-16.1-160000.2.1 * shim-16.1-160000.2.1 * shim-debugsource-16.1-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269084 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:37:31 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:37:31 -0000 Subject: SUSE-SU-2026:22841-1: important: Security update for aws-nitro-enclaves-cli Message-ID: <178517385120.2240.2879301247331277988@c3e054a4ce29> # Security update for aws-nitro-enclaves-cli Announcement ID: SUSE-SU-2026:22841-1 Release Date: 2026-07-22T07:42:13Z Rating: important References: * bsc#1270492 * bsc#1270542 * bsc#1270705 * bsc#1270747 * bsc#1270839 * bsc#1270932 * bsc#1270952 Cross-References: * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for aws-nitro-enclaves-cli fixes the following issues: * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270542). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270705). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270747). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270839). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270492). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270932). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270952). Changes for aws-nitro-enclaves-cli: * Update to version 1.4.5. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1316=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1316=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-160000.1.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-160000.1.1 * aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-160000.1.1 * aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-160000.1.1 * aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-160000.1.1 * system-group-ne-1.4.5~git0.18a5f6f-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-160000.1.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-160000.1.1 * aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-160000.1.1 * aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-160000.1.1 * aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-160000.1.1 * system-group-ne-1.4.5~git0.18a5f6f-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270492 * https://bugzilla.suse.com/show_bug.cgi?id=1270542 * https://bugzilla.suse.com/show_bug.cgi?id=1270705 * https://bugzilla.suse.com/show_bug.cgi?id=1270747 * https://bugzilla.suse.com/show_bug.cgi?id=1270839 * https://bugzilla.suse.com/show_bug.cgi?id=1270932 * https://bugzilla.suse.com/show_bug.cgi?id=1270952 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:38:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:38:11 -0000 Subject: SUSE-RU-2026:22840-1: important: Recommended update for pesign Message-ID: <178517389167.2240.13614074985053506199@c3e054a4ce29> # Recommended update for pesign Announcement ID: SUSE-RU-2026:22840-1 Release Date: 2026-07-22T07:42:13Z Rating: important References: * bsc#1258751 * bsc#1271405 * jsc#PED-14755 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature and has two fixes can now be installed. ## Description: This update for pesign fixes the following issues: * Set stricter permissions on /etc/pki/pesign (bsc#1271405) * Disable the wchar_t warnings on arm32 * Constify the return pointer of strrchr() (bsc#1258751) * Use /var/lib/empty as the the home directory of the pesign system user and remove /var/lib/pesign (jsc#PED-14755) * Move '/run/pesign' to pesign-systemd which creates the directory in the post script ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1315=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1315=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * pesign-116-160000.3.1 * pesign-debuginfo-116-160000.3.1 * pesign-debugsource-116-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * pesign-debugsource-116-160000.3.1 * pesign-debuginfo-116-160000.3.1 * pesign-116-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1258751 * https://bugzilla.suse.com/show_bug.cgi?id=1271405 * https://jira.suse.com/browse/PED-14755 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:38:32 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:38:32 -0000 Subject: SUSE-RU-2026:22839-1: moderate: Recommended update for python-wrapt Message-ID: <178517391219.2240.8074610713631604076@c3e054a4ce29> # Recommended update for python-wrapt Announcement ID: SUSE-RU-2026:22839-1 Release Date: 2026-07-22T07:23:21Z Rating: moderate References: * jsc#PED-16058 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for python-wrapt fixes the following issues: Changes in python-wrapt: Update to 2.1.2: * When a weak function proxy was created for a bound method and the instance it was bound to was garbage collected, calling the proxy would silently call the function as unbound instead of raising a ReferenceError. * When deleting an attribute named **annotations** on an object proxy, the attribute was only being deleted from the proxy and not also from the wrapped object. Update to 2.1.1: ## Features Changed * Drop support for Python 3.8. Python version 3.9 or later is now required. ## Bugs Fixed * Missing tox.ini from source distribution package has been added. * Improved type hints so that mypy and ty work better for methods of classes when using wrapt.decorator and wrapt.function_wrapper. Note that applying these to static methods still does not work correctly due to possibly limitations in those type checkers. The pyrefly tool still does not work correctly with wrapt.decorator and wrapt.function_wrapper applied to any methods of classes Update to 2.0.1: ## New Features * Added **all** attribute to wrapt module to expose the public API. * The wrapt.PartialCallableObjectProxy class can now be accessed via the alias wrapt.partial, which is a convenience for users who are used to using functools.partial and want to use the wrapt version of it. * Type hints have been added to the wrapt module. * Added wrapt.BaseObjectProxy class which is the base class for all object proxy classes. * Added wrapt.AutoObjectProxy class which is a pure Python subclass of BaseObjectProxy which overrides the **new**() method to dynamically generate a custom subclass which includes methods for callable, descriptor and iterator protocols, as well as other select special methods. * Added wrapt.LazyObjectProxy class which is a variant of AutoObjectProxy which takes a callable which returns the object to be wrapped. The callable is only invoked the first time an attribute of the wrapped object is accessed. * Added wrapt.lazy_import() function which takes a module name and returns a LazyObjectProxy which will import the module when it is first needed. ## Features Changed * Code related to Python 2.X and workarounds for older Python 3.X versions has been removed. * Dependency at runtime on setuptools for calculating package entry points has been removed. Instead the importlib.metadata module is now used for this purpose. * For reasons to do with backward/forward compatibility the wrapt module included references to getcallargs() and formatargspec() functions which were part of the inspect module at one time or another. These were provided as convenience for users of the wrapt module, but were not actually part of the public API. They have now been removed from the wrapt module and are no longer available. * The enabled, adapter and proxy arguments to the @decorator decorator had to be keyword parameters, and the initial wrapped argument had to be positional only. Because though Python 2.X was still being supported it was not possible to use appropriate syntax to mark them as such. These arguments are now marked as positional and keyword only parameters in the function signature as appropriate. * The object proxy classes now raise a WrapperNotInitializedError exception rather than Python builtin ValueError exception when an attempt is made to access an attribute of the wrapped object before the wrapper has been initialized. ## Bugs Fixed * The wrapt.lazy_import() function wasn't included in the **all** attribute of the wrapt module. * When using wrapt.lazy_import() to lazily import a function of a module, the resulting proxy object wasn't marked as callable until something triggered the import of the module via the proxy. This meant a callable() check on the proxy would return False until the module was actually imported. * Reference count was not being incremented on type object for C implementation of the partial callable object proxy when module was initialized. If wrapt was being used in Python sub interpreters which were deleted it could lead to the process crashing. * Wasn't chaining **mro_entries**() calls when the wrapped object was not a type (class) and itself had a **mro_entries**() method. This meant that if using the object proxy as a base class for a generic class, the generic parameters were being ignored. * When an object proxy wrapped an immutable type, such as an integer, and the object proxy had been assigned to a second variable, the result of an in- place operation on the second variable was also affecting the first variable, when instead the lifetime of the two variables should have been independent to reflect what occurs for normal immutable types. Update to 1.17.3: * Added universal binary wheels for macOS. That is, contains both x86_64 and arm64 architectures in the same wheel. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1313=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1313=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-wrapt-debuginfo-2.1.2-160000.1.1 * python-wrapt-debugsource-2.1.2-160000.1.1 * python313-wrapt-2.1.2-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-wrapt-debuginfo-2.1.2-160000.1.1 * python-wrapt-debugsource-2.1.2-160000.1.1 * python313-wrapt-2.1.2-160000.1.1 ## References: * https://jira.suse.com/browse/PED-16058 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:38:52 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:38:52 -0000 Subject: SUSE-RU-2026:22838-1: moderate: Recommended update for pgvector Message-ID: <178517393268.2240.15706593313422547641@c3e054a4ce29> # Recommended update for pgvector Announcement ID: SUSE-RU-2026:22838-1 Release Date: 2026-07-22T01:42:02Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for pgvector fixes the following issues: Packages for postgresql13 are readded. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1312=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1312=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postgresql15-pgvector-debugsource-0.8.2-160000.3.1 * postgresql14-pgvector-debugsource-0.8.2-160000.3.1 * postgresql16-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql17-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql18-pgvector-0.8.2-160000.3.1 * postgresql17-pgvector-0.8.2-160000.3.1 * postgresql14-pgvector-debuginfo-0.8.2-160000.3.1 * pgvector-devel-0.8.2-160000.3.1 * postgresql14-pgvector-0.8.2-160000.3.1 * postgresql18-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql13-pgvector-0.8.2-160000.3.1 * postgresql15-pgvector-0.8.2-160000.3.1 * postgresql16-pgvector-0.8.2-160000.3.1 * postgresql13-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql17-pgvector-debugsource-0.8.2-160000.3.1 * postgresql18-pgvector-debugsource-0.8.2-160000.3.1 * postgresql15-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql13-pgvector-debugsource-0.8.2-160000.3.1 * postgresql16-pgvector-debugsource-0.8.2-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postgresql15-pgvector-debugsource-0.8.2-160000.3.1 * postgresql14-pgvector-debugsource-0.8.2-160000.3.1 * postgresql16-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql17-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql18-pgvector-0.8.2-160000.3.1 * postgresql17-pgvector-0.8.2-160000.3.1 * postgresql14-pgvector-debuginfo-0.8.2-160000.3.1 * pgvector-devel-0.8.2-160000.3.1 * postgresql14-pgvector-0.8.2-160000.3.1 * postgresql18-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql13-pgvector-0.8.2-160000.3.1 * postgresql15-pgvector-0.8.2-160000.3.1 * postgresql16-pgvector-0.8.2-160000.3.1 * postgresql13-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql17-pgvector-debugsource-0.8.2-160000.3.1 * postgresql18-pgvector-debugsource-0.8.2-160000.3.1 * postgresql15-pgvector-debuginfo-0.8.2-160000.3.1 * postgresql13-pgvector-debugsource-0.8.2-160000.3.1 * postgresql16-pgvector-debugsource-0.8.2-160000.3.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:39:35 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:39:35 -0000 Subject: SUSE-SU-2026:22837-1: critical: Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions Message-ID: <178517397592.2240.12150260313061751895@c3e054a4ce29> # Security update for cockpit, cockpit-machines, cockpit-packages, cockpit- podman, cockpit-repos, cockpit-subscriptions Announcement ID: SUSE-SU-2026:22837-1 Release Date: 2026-07-21T15:45:48Z Rating: critical References: * bsc#1236149 * bsc#1257033 * bsc#1257325 * bsc#1257698 * bsc#1257836 * bsc#1257838 * bsc#1257840 * bsc#1258040 * bsc#1258637 * bsc#1258640 * bsc#1258641 * bsc#1259010 * bsc#1259013 * bsc#1259015 * bsc#1259210 * bsc#1259774 * bsc#1261829 * jsc#PED-15706 * jsc#PED-15820 Cross-References: * CVE-2025-13465 * CVE-2026-25547 * CVE-2026-26996 * CVE-2026-27904 * CVE-2026-4631 * CVE-2026-4802 CVSS scores: * CVE-2025-13465 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-13465 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-13465 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13465 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13465 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-25547 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25547 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25547 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-26996 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27904 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27904 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27904 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4631 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4631 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4802 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4802 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4802 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4802 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities, contains two features and has 11 fixes can now be installed. ## Description: This update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions fixes the following issues: Security issues fixed: * CVE-2025-13465: lodash: prototype pollution in the _.unset and_.omit functions can lead to deletion of methods from global prototypes (bsc#1257325). * CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829). * CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840). * CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637 bsc#1258640 bsc#1258641). * CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking complexity and a ReDoS (bsc#1259010 bsc#1259013 bsc#1259015). Non security issues fixed: * cockpit webUI - 'Software updates - install all updates' got an unexpected internal error (bsc#1259210). * cockpit-machines does not work out of the box, missing libvirt daemon (bsc#1236149). Changes for cockpit: * Update to 364. * Update to 361 (jsc#PED-15706/jsc#CPT-183): * Remove all "Mount" actions in Anaconda mode * Dependency updates * Update to 360: * ws: be more explicit when handling hostnames on cli bsc#1261829/CVE-2026-4631 * ws: support loading a custom login page * Update to 358: * Networking: Add Wi-Fi support * Cockpit Client updated to GTK 4 * Bugfixes and translation updates * Update to 357: * lib: Use browser context menu on shift * bridge: support Python 3.14 on old kernels (RHEL 8) * Update to 356: * systemd: Allow editing timers created by Cockpit * Convert license headers to SPDX format * Update to 355: * ws: Remove obsolete pam_cockpit_cert module * shell: add StartTransientUnit as a sudo alternative Changes for cockpit-machines: * Update to 354. * Update to 352: * Improvements to the "Add disk" and "Create Volume" dialogs. * Update suse_version requirement to function with the planned bump (jsc#PED-15820). * Drop explict dependency on libvirt (bsc#1258040, bsc#1236149). * Update to 348: * Translation updates * Convert license headers to SPDX format * Now requires cockpit-devel 356 due to the replacement of xterm/addon-canvas with xterm/addon-webgl * Update to 347: * Bug fixes and translation updates * Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-packages: * Update to version 5: * Support transactional systems * Improve error/success messages * Translation updates * Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-podman: * Update to 128. * Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-repos: * Update to 4.8. * Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-subscriptions: * Update to version 16.2 (bsc#1257033). * Patch esbuild to use native runtime on ppc64 (bsc#1257698). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1309=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1309=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cockpit-ws-debuginfo-364-160000.1.1 * cockpit-364-160000.1.1 * cockpit-debugsource-364-160000.1.1 * cockpit-devel-364-160000.1.1 * cockpit-ws-selinux-364-160000.1.1 * cockpit-ws-364-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * cockpit-podman-128-160000.1.1 * cockpit-networkmanager-364-160000.1.1 * cockpit-packages-5-160000.1.1 * cockpit-machines-354-160000.1.1 * cockpit-firewalld-364-160000.1.1 * cockpit-system-364-160000.1.1 * cockpit-packagekit-364-160000.1.1 * cockpit-kdump-364-160000.1.1 * cockpit-repos-4.8-160000.1.1 * cockpit-doc-364-160000.1.1 * cockpit-bridge-364-160000.1.1 * cockpit-subscriptions-16.2-160000.1.1 * cockpit-selinux-364-160000.1.1 * cockpit-storaged-364-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * cockpit-podman-128-160000.1.1 * cockpit-networkmanager-364-160000.1.1 * cockpit-packages-5-160000.1.1 * cockpit-machines-354-160000.1.1 * cockpit-firewalld-364-160000.1.1 * cockpit-system-364-160000.1.1 * cockpit-packagekit-364-160000.1.1 * cockpit-kdump-364-160000.1.1 * cockpit-repos-4.8-160000.1.1 * cockpit-doc-364-160000.1.1 * cockpit-bridge-364-160000.1.1 * cockpit-subscriptions-16.2-160000.1.1 * cockpit-selinux-364-160000.1.1 * cockpit-storaged-364-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cockpit-ws-debuginfo-364-160000.1.1 * cockpit-debugsource-364-160000.1.1 * cockpit-364-160000.1.1 * cockpit-devel-364-160000.1.1 * cockpit-ws-selinux-364-160000.1.1 * cockpit-ws-364-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13465.html * https://www.suse.com/security/cve/CVE-2026-25547.html * https://www.suse.com/security/cve/CVE-2026-26996.html * https://www.suse.com/security/cve/CVE-2026-27904.html * https://www.suse.com/security/cve/CVE-2026-4631.html * https://www.suse.com/security/cve/CVE-2026-4802.html * https://bugzilla.suse.com/show_bug.cgi?id=1236149 * https://bugzilla.suse.com/show_bug.cgi?id=1257033 * https://bugzilla.suse.com/show_bug.cgi?id=1257325 * https://bugzilla.suse.com/show_bug.cgi?id=1257698 * https://bugzilla.suse.com/show_bug.cgi?id=1257836 * https://bugzilla.suse.com/show_bug.cgi?id=1257838 * https://bugzilla.suse.com/show_bug.cgi?id=1257840 * https://bugzilla.suse.com/show_bug.cgi?id=1258040 * https://bugzilla.suse.com/show_bug.cgi?id=1258637 * https://bugzilla.suse.com/show_bug.cgi?id=1258640 * https://bugzilla.suse.com/show_bug.cgi?id=1258641 * https://bugzilla.suse.com/show_bug.cgi?id=1259010 * https://bugzilla.suse.com/show_bug.cgi?id=1259013 * https://bugzilla.suse.com/show_bug.cgi?id=1259015 * https://bugzilla.suse.com/show_bug.cgi?id=1259210 * https://bugzilla.suse.com/show_bug.cgi?id=1259774 * https://bugzilla.suse.com/show_bug.cgi?id=1261829 * https://jira.suse.com/browse/PED-15706 * https://jira.suse.com/browse/PED-15820 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:40:14 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:40:14 -0000 Subject: SUSE-SU-2026:22836-1: important: Security update for radvd Message-ID: <178517401478.2240.3954922240234429094@c3e054a4ce29> # Security update for radvd Announcement ID: SUSE-SU-2026:22836-1 Release Date: 2026-07-21T15:16:48Z Rating: important References: * bsc#1268641 Cross-References: * CVE-2026-48715 CVSS scores: * CVE-2026-48715 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48715 ( NVD ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48715 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for radvd fixes the following issue * CVE-2026-48715: crafted ICMPv6 Router Advertisement can lead to a stack- based buffer overflow (bsc#1268641). Changes for radvd: * Update to version 2.21. * feat: RFC8319 support: Increase max AdvDefaultLifetime and MaxRtrAdvInterval. * feat: Add DHCPv6-PD preferred flag. * fix: improve file checks for procfs knobs. * feat: allow libc strlcpy. * fix: make libcheck fatal if missing with --with-check. * refactor: make drop_root_privileges reusable. * fix: support incoming jumbo packets. * Avoid libbsd header with libc strlcpy. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1310=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1310=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * radvd-debugsource-2.21-160000.1.1 * radvd-debuginfo-2.21-160000.1.1 * radvd-2.21-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * radvd-debugsource-2.21-160000.1.1 * radvd-debuginfo-2.21-160000.1.1 * radvd-2.21-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48715.html * https://bugzilla.suse.com/show_bug.cgi?id=1268641 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:47:30 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:47:30 -0000 Subject: SUSE-SU-2026:22835-1: important: Security update for the Linux Kernel Message-ID: <178517445073.2240.14671698073903376285@c3e054a4ce29> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22835-1 Release Date: 2026-07-21T08:27:32Z Rating: important References: * bsc#1149651 * bsc#1204315 * bsc#1236743 * bsc#1255029 * bsc#1257506 * bsc#1258538 * bsc#1259800 * bsc#1260565 * bsc#1261250 * bsc#1261256 * bsc#1261562 * bsc#1261604 * bsc#1262085 * bsc#1262392 * bsc#1262430 * bsc#1262618 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262765 * bsc#1262798 * bsc#1263057 * bsc#1263072 * bsc#1263133 * bsc#1263137 * bsc#1263143 * bsc#1263169 * bsc#1263178 * bsc#1263319 * bsc#1263563 * bsc#1263568 * bsc#1263573 * bsc#1263578 * bsc#1263581 * bsc#1263796 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1263998 * bsc#1264001 * bsc#1264007 * bsc#1264010 * bsc#1264012 * bsc#1264015 * bsc#1264045 * bsc#1264056 * bsc#1264067 * bsc#1264084 * bsc#1264145 * bsc#1264230 * bsc#1264231 * bsc#1264236 * bsc#1264239 * bsc#1264241 * bsc#1264250 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264263 * bsc#1264266 * bsc#1264270 * bsc#1264286 * bsc#1264294 * bsc#1264295 * bsc#1264302 * bsc#1264304 * bsc#1264320 * bsc#1264328 * bsc#1264333 * bsc#1264337 * bsc#1264372 * bsc#1264386 * bsc#1264429 * bsc#1264449 * bsc#1264532 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264549 * bsc#1264556 * bsc#1264561 * bsc#1264580 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264612 * bsc#1264614 * bsc#1264624 * bsc#1264643 * bsc#1264734 * bsc#1264740 * bsc#1264741 * bsc#1264744 * bsc#1264763 * bsc#1264789 * bsc#1264790 * bsc#1264794 * bsc#1264852 * bsc#1264974 * bsc#1264978 * bsc#1264997 * bsc#1265000 * bsc#1265005 * bsc#1265020 * bsc#1265023 * bsc#1265073 * bsc#1265079 * bsc#1265082 * bsc#1265084 * bsc#1265091 * bsc#1265097 * bsc#1265103 * bsc#1265112 * bsc#1265113 * bsc#1265123 * bsc#1265128 * bsc#1265129 * bsc#1265142 * bsc#1265143 * bsc#1265628 * bsc#1265629 * bsc#1266008 * bsc#1266214 * bsc#1266283 * bsc#1266284 * bsc#1266290 * bsc#1266390 * bsc#1266396 * bsc#1266397 * bsc#1266398 * bsc#1266452 * bsc#1266458 * bsc#1266686 * bsc#1266693 * bsc#1266697 * bsc#1266698 * bsc#1266700 * bsc#1266704 * bsc#1266705 * bsc#1266717 * bsc#1266718 * bsc#1266722 * bsc#1266726 * bsc#1266734 * bsc#1266740 * bsc#1266750 * bsc#1266754 * bsc#1266761 * bsc#1266773 * bsc#1266805 * bsc#1266830 * bsc#1266838 * bsc#1266840 * bsc#1266847 * bsc#1266878 * bsc#1266883 * bsc#1266892 * bsc#1266893 * bsc#1266895 * bsc#1266899 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266925 * bsc#1266929 * bsc#1266933 * bsc#1267208 * bsc#1267218 * bsc#1267228 * bsc#1267238 * bsc#1267251 * bsc#1267360 * bsc#1267361 * bsc#1267365 * bsc#1267369 * bsc#1267387 * bsc#1267419 * bsc#1267427 * bsc#1267431 * bsc#1267437 * bsc#1267458 * bsc#1267493 * bsc#1267505 * bsc#1267548 * bsc#1267582 * bsc#1267591 * bsc#1267600 * bsc#1267618 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267635 * bsc#1267637 * bsc#1267640 * bsc#1267654 * bsc#1267682 * bsc#1267684 * bsc#1267685 * bsc#1267697 * bsc#1267717 * bsc#1267722 * bsc#1267732 * bsc#1267744 * bsc#1267816 * bsc#1267824 * bsc#1267825 * bsc#1267937 * bsc#1267966 * bsc#1267992 * bsc#1267993 * bsc#1267994 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268238 * bsc#1268276 * bsc#1268307 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1268989 * bsc#1269022 * bsc#1269031 * bsc#1269033 * bsc#1269036 * bsc#1269087 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269188 * bsc#1269193 * bsc#1269199 * bsc#1269230 * bsc#1269234 * bsc#1269252 * bsc#1269262 * bsc#1269288 * bsc#1269310 * bsc#1269389 * bsc#1269392 * bsc#1269397 * bsc#1269398 * bsc#1269416 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269527 * bsc#1269531 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269617 * bsc#1269645 * bsc#1269646 * bsc#1269647 * bsc#1269651 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269708 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269798 * bsc#1269809 * bsc#1269814 * bsc#1269821 * bsc#1269904 * bsc#1269982 * bsc#1269989 * bsc#1269992 * bsc#1270000 * bsc#1270022 * bsc#1270042 * bsc#1270059 * bsc#1270226 * bsc#1271366 * jsc#PED-10906 * jsc#PED-15986 * jsc#PED-16390 * jsc#SLE-8615 Cross-References: * CVE-2025-10263 * CVE-2025-39894 * CVE-2025-40341 * CVE-2026-23248 * CVE-2026-23394 * CVE-2026-23451 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31438 * CVE-2026-31450 * CVE-2026-31452 * CVE-2026-31466 * CVE-2026-31469 * CVE-2026-31479 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31502 * CVE-2026-31555 * CVE-2026-31560 * CVE-2026-31580 * CVE-2026-31596 * CVE-2026-31646 * CVE-2026-31647 * CVE-2026-31663 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31670 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31743 * CVE-2026-31752 * CVE-2026-31771 * CVE-2026-43010 * CVE-2026-43014 * CVE-2026-43015 * CVE-2026-43016 * CVE-2026-43022 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43034 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43053 * CVE-2026-43057 * CVE-2026-43074 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43083 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43090 * CVE-2026-43092 * CVE-2026-43093 * CVE-2026-43094 * CVE-2026-43101 * CVE-2026-43107 * CVE-2026-43119 * CVE-2026-43124 * CVE-2026-43128 * CVE-2026-43130 * CVE-2026-43132 * CVE-2026-43139 * CVE-2026-43145 * CVE-2026-43157 * CVE-2026-43158 * CVE-2026-43161 * CVE-2026-43167 * CVE-2026-43171 * CVE-2026-43175 * CVE-2026-43187 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43198 * CVE-2026-43199 * CVE-2026-43205 * CVE-2026-43213 * CVE-2026-43226 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43260 * CVE-2026-43283 * CVE-2026-43284 * CVE-2026-43298 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43337 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43351 * CVE-2026-43373 * CVE-2026-43374 * CVE-2026-43383 * CVE-2026-43384 * CVE-2026-43386 * CVE-2026-43403 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43415 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43456 * CVE-2026-43457 * CVE-2026-43458 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43471 * CVE-2026-43491 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45837 * CVE-2026-45838 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45848 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45861 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45884 * CVE-2026-45888 * CVE-2026-45891 * CVE-2026-45894 * CVE-2026-45899 * CVE-2026-45901 * CVE-2026-45912 * CVE-2026-45920 * CVE-2026-45922 * CVE-2026-45933 * CVE-2026-45940 * CVE-2026-45948 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45985 * CVE-2026-45997 * CVE-2026-45999 * CVE-2026-46005 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46078 * CVE-2026-46079 * CVE-2026-46091 * CVE-2026-46093 * CVE-2026-46099 * CVE-2026-46101 * CVE-2026-46111 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46124 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46161 * CVE-2026-46162 * CVE-2026-46172 * CVE-2026-46173 * CVE-2026-46178 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46227 * CVE-2026-46242 * CVE-2026-46244 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46259 * CVE-2026-46266 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46314 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46322 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52919 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52955 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52975 * CVE-2026-52980 * CVE-2026-52993 * CVE-2026-53015 * CVE-2026-53021 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53053 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53081 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53103 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53139 * CVE-2026-53156 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53194 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53249 * CVE-2026-53258 * CVE-2026-53262 * CVE-2026-53263 * CVE-2026-53266 * CVE-2026-53272 * CVE-2026-53274 * CVE-2026-53281 * CVE-2026-53285 * CVE-2026-53286 * CVE-2026-53287 * CVE-2026-53306 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-39894 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-39894 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23248 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23394 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23394 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31479 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31479 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31560 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31580 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31646 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31646 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31646 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31647 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31743 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31743 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43016 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43090 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43090 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43094 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43130 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43130 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43132 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43145 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43145 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43145 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43175 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43213 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43260 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43283 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43283 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43298 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43298 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43298 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43374 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43384 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43384 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-43384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43403 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43403 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43415 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43415 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43415 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43457 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43457 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43458 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43458 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43471 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45837 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45837 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45837 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45861 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45861 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45884 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45884 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45884 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45888 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45888 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45888 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45901 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45901 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45901 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45922 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45922 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45922 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45999 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45999 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46078 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46078 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46093 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52919 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52962 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52980 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52980 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53015 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53103 ( SUSE ): 5.9 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53103 ( SUSE ): 4.8 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53103 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53122 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53156 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53156 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53194 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53194 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53194 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53262 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53262 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53263 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53272 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53272 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53272 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53286 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 255 vulnerabilities, contains four features and has 30 fixes can now be installed. ## Description: The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-10263: arm64: cputype: Add C1-Premium definitions (bsc#1266290). * CVE-2025-39894: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm (bsc#1262430). * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2026-23248: perf: Make perf_pmu_unregister() useable (bsc#1259800). * CVE-2026-23394: Revert: "af_unix: Remove lock dance in unix_peek_fds()." (bsc#1260565). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31438: netfs: Fix kernel BUG in netfs_limit_iter() for ITER_KVEC iterators (bsc#1267824). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). * CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31646: net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() (bsc#1263796). * CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578). * CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31743: nvmem: zynqmp_nvmem: Fix buffer size in DMA and memcpy (bsc#1264067). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43014,CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal (bsc#1264010 bsc#1264012). * CVE-2026-43016: bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready() (bsc#1264007). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084). * CVE-2026-43057: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback (bsc#1264056). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43090: xfrm: fix refcount leak in xfrm_migrate_policy_find (bsc#1264250). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43130: iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode (bsc#1264532). * CVE-2026-43132: dm-verity: correctly handle dm_bufio_client_create() failure (bsc#1264614). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43145: remoteproc: imx_rproc: Fix invalid loaded resource table detection (bsc#1265091). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43161: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode (bsc#1264333). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549). * CVE-2026-43175: clk: rs9: Reserve 8 struct clk_hw slots for for 9FGV0841 (bsc#1264372). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43213: wifi: rtw89: pci: validate sequence number of TX release report (bsc#1264643). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429). * CVE-2026-43283: net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle (bsc#1264295). * CVE-2026-43298: drm/amdgpu: Skip vcn poison irq release on VF (bsc#1264852). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43351: KVM: arm64: gic: Set vgic_model before initing private IRQs (bsc#1265082). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43374: net: nexthop: fix percpu use-after-free in remove_nh_grp_entry (bsc#1265084). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43384: net/tcp-ao: Fix MAC comparison to be constant-time (bsc#1265097). * CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (bsc#1264740). * CVE-2026-43403: nsfs: tighten permission checks for ns iteration ioctls (bsc#1265129). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43415: scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend (bsc#1265123). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43457: mctp: i2c: fix skb memory leak in receive path (bsc#1265000). * CVE-2026-43458: serial: caif: hold tty->link reference in ldisc_open and ser_release (bsc#1265005). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43471: scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_trace() (bsc#1264789). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45837: Require (reasonably) normal mappings for MADV_DOFORK (bsc#1266398). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 (bsc#1266773). * CVE-2026-45861: gfs2: Fix slab-use-after-free in qd_put (bsc#1266754). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45884: apparmor: avoid per-cpu hold underflow in aa_get_buffer (bsc#1266718). * CVE-2026-45888: md/raid1: fix memory leak in raid1_run() (bsc#1266761). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45901: netfilter: nf_tables: revert commit_mutex usage in reset path (bsc#1266892). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805). * CVE-2026-45933: bpf: Preserve id of register in sync_linked_regs() (bsc#1266693). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-45999: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (bsc#1266750). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents (bsc#1267505). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46093: mm/vmalloc: take vmap_purge_lock in shrinker (bsc#1267548). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: printk: add print_hex_dump_devel() (bsc#1267937). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52919: batman-adv: fix tp_meter counter underflow during shutdown (bsc#1269031). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52975: bonding: 3ad: implement proper RCU rules for port->aggregator (bsc#1269234). * CVE-2026-52980: sched/fair: Clear rel_deadline when initializing forked entities (bsc#1269252). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53015: erofs: unify lcn as u64 for 32-bit platforms (bsc#1269087). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53081: bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars (bsc#1269708). * CVE-2026-53086: net: bcmgenet: move DESC_INDEX flow to ring 0 (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53103: wifi: mt76: mt7925: fix potential deadlock in mt7925_roc_abort_sync (bsc#1269416). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53156: nvmem: core: fix use-after-free bugs in error paths (bsc#1269288). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000). * CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression (bsc#1269647). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress (bsc#1269809). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53286: idpf: fix double free and use-after-free in aux device error paths (bsc#1269531). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). The following non security issues were fixed: * accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: scarlett2: Allow flash writes ending at segment boundary (git-fixes). * ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes (stable- fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: timer: Forcibly close timer instances at closing (git-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: virtio: Validate control metadata from the device (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64 (bsc#1267600). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: amd: acp-sdw-sof: Bound DAI link iteration (git-fixes). * ASoC: codecs: aw88261: fix incorrect masks for boost regs (git-fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git- fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). * ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_core: Fix UAF in hci_unregister_dev() (git-fixes). * Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non- serdev device (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls (git- fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: ISO: Fix not using bc_sid as advertisement SID (stable-fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * Bluetooth: sco: Fix a race condition in sco_sock_timeout() (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * bpf: Free reuseport cBPF prog after RCU grace period (git-fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * crypto/hmac: reject keys shorter than 128 bits in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow ffdhe2048 in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow plain ecb() usage in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow sha224 + sha3-224 in fips mode (bsc#1266284 jsc#PED-15986). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) (git-fixes). * crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) (git-fixes). * crypto: ccp - Do not initialize SNP for SEV ioctls (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * crypto: tegra - Fix dma_free_coherent size error (git-fixes). * crypto: tegra - fix refcount leak in tegra_se_host1x_submit() (git-fixes). * crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm (git-fixes). * dm init: ensure device probing has finished in dm-mod.waitfor= (git-fixes). * dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc (git-fixes). * dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). * drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). * drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git- fixes). * drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: always resume_all after suspend_all (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/gpuvm: Do not prepare NULL objects (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). * drm/imagination: Count paired job fence as dependency in prepare_job() (git- fixes). * drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/rockchip: Test for imported buffers with drm_gem_is_imported() (git- fixes). * drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). * drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * ftrace: Check against is_kernel_text() instead of kaslr_offset() (bsc#1267600). * ftrace: Do not over-allocate ftrace memory (bsc#1267600). * ftrace: Have ftrace pages output reflect freed pages (bsc#1267600). * ftrace: Test mcount_loc addr before calling ftrace_call_addr() (bsc#1267600). * ftrace: Update the mcount_loc check of skipped entries (bsc#1267600). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpio: mxc: fix irq_high handling (git-fixes). * gpio: rockchip: convert bank->clk to devm_clk_get_enabled() (git-fixes). * gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write() (git-fixes). * gpio: zynq: fix runtime PM leak on remove (git-fixes). * gpiolib: Extract gpiochip_choose_fwnode() for wider use (stable-fixes). * gpiolib: Remove redundant assignment of return variable (stable-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * HID: core: Add printk_ratelimited variants to hid_warn() etc (stable-fixes). * HID: hid-goodix-spi: validate report size to prevent stack buffer overflow (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: rate-limit hid_warn to prevent log flooding (stable-fixes). * HID: remove duplicate hid_warn_ratelimited definition (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hv: utils: replace deprecated strcpy with strscpy in kvp_register (git- fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (git-fixes). * hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (max1619) add missing 'select REGMAP' to Kconfig (git-fixes). * hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: disable runtime PM on adapter registration failure (git-fixes). * i2c: core: fix adapter debugfs creation (git-fixes). * i2c: core: fix adapter deregistration race (git-fixes). * i2c: core: fix adapter probe deferral loop (git-fixes). * i2c: core: fix adapter registration race (git-fixes). * i2c: core: fix hang on adapter registration failure (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: core: fix NULL-deref on adapter registration failure (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: imx-lpi2c: mark I2C adapter when hardware is powered down (git-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: riic: fix refcount leak in riic_i2c_resume_noirq() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock (git- fixes). * ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: ti-ads1298: add bounds check to pga_settings index (stable-fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: backend: fix uninitialized data in debugfs (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: light: veml6075: add bounds check to veml6075_it_ms index (stable- fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: resolver: ad2s1210: notify trigger and clear state on fault read error (git-fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * io_uring/cancel: de-unionize file and user_data in struct io_cancel_data (git-fixes bsc#1261250). * io_uring/filetable: clamp alloc_hint to the configured alloc range (git- fixes bsc#1261250). * io_uring/io-wq: fix incorrect io_wq_for_each_worker() termination logic (git-fixes bsc#1261250). * io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git- fixes bsc#1261250). * io_uring/wait: fix min_timeout behavior (git-fixes bsc#1261250). * io_uring/waitid: clear waitid info before copying it to userspace (git- fixes). * io_uring: fix min_wait wakeups for SQPOLL (git-fixes bsc#1261250). * ipv4: account for fraggap on the paged allocation path (git-fixes). * ipv6: account for fraggap on the paged allocation path (git-fixes). * KEYS: fix overflow in keyctl_pkey_params_get_2() (git-fixes). * KEYS: Use acquire when reading state in keyring search (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: vgic: Free private_irqs when init fails after allocation (git- fixes). * KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (git-fixes). * KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (git- fixes). * KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2 (git-fixes). * KVM: nVMX: Immediately refresh APICv controls as needed on nested VM-Exit (git-fixes). * KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (git-fixes). * KVM: SEV: Add an anonymous "psc" struct to track current PSC metadata (git- fixes). * KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA (git-fixes). * KVM: SEV: Don't terminate SNP VMs on #VMGEXIT without a registered GHCB (git-fixes). * KVM: SEV: Make it more obvious when KVM is writing back the current PSC index (git-fixes). * KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() (git-fixes). * KVM: SEV: Read start/end indices of PSC requests exactly once per #VMGEXIT (git-fixes). * KVM: SEV: Return INVALID_EVENT for SNP-only #VMGEXIT from non-SNP guest (git-fixes). * KVM: SEV: Return INVALID_INPUT, not MISSING_INPUT, for bad GUEST_REQUEST input(s) (git-fixes). * KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: Use vCPU specific memslots in __kvm_vcpu_map() (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: VMX: Read 32-bit GPR values for ENCLS instructions outside of 64-bit mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86/xen: Bug the VM if 32-bit KVM observes a 64-bit mode hypercall (git-fixes). * KVM: x86/xen: Don't truncate RAX when handling hypercall from protected guest (git-fixes). * KVM: x86: Consolidate CPUID fault handling for emulator and interception logic (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Prioritize CPUID faulting over CPUID VM-exits in nested VMX (git- fixes). * KVM: x86: Trace hypercall register _after_ truncating values for 32-bit (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() (git-fixes). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: Pause continuous reads at block boundaries (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program (stable-fixes). * mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g (stable-fixes). * mtd: spi-nor: spansion: use die erase for multi-die devices only (git- fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Cache MANA_QUERY_LINK_CONFIG result to avoid repeated HWC queries (bsc#1268238). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Sync page pool RX frags for CPU (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * packaging: Add nvidia kernel description. * packaging: compute-PATCHVERSION.sh -> compute-PATCHVERSION. * page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562). * page_pool: Move pp_magic check into helper functions (bsc#1261562). * page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). * PCI: Update saved_config_space upon resource assignment (git-fixes). * perf/x86/intel/uncore: Fix die ID init and look up bugs (bsc#1267419). * perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1267419). * platform/x86: dell-laptop: fix missing cleanups in init error path (git- fixes). * platform/x86: intel-hid: Protect ACPI notify handler against recursion (git- fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git- fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * pwm: imx27: Fix variable truncation in .apply() (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (git- fixes). * Revert "fs: don't block i_writecount during exec" (bsc#1269982). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scripts/sorttable: Add helper functions for Elf_Ehdr (bsc#1267600). * scripts/sorttable: Add helper functions for Elf_Shdr (bsc#1267600). * scripts/sorttable: Add helper functions for Elf_Sym (bsc#1267600). * scripts/sorttable: Allow matches to functions before function entry (bsc#1267600). * scripts/sorttable: Always use an array for the mcount_loc sorting (bsc#1267600). * scripts/sorttable: Convert Elf_Ehdr to union (bsc#1267600). * scripts/sorttable: Convert Elf_Sym MACRO over to a union (bsc#1267600). * scripts/sorttable: Fix endianness handling in build-time mcount sort (bsc#1267600). * scripts/sorttable: Get start/stop_mcount_loc from ELF file directly (bsc#1267600). * scripts/sorttable: Have mcount rela sort use direct values (bsc#1267600). * scripts/sorttable: Have the ORC code use the _r() functions to read (bsc#1267600). * scripts/sorttable: Make compare_extable() into two functions (bsc#1267600). * scripts/sorttable: Move code from sorttable.h into sorttable.c (bsc#1267600). * scripts/sorttable: Remove unneeded Elf_Rel (bsc#1267600). * scripts/sorttable: Remove unused macro defines (bsc#1267600). * scripts/sorttable: Remove unused write functions (bsc#1267600). * scripts/sorttable: Replace Elf_Shdr Macro with a union (bsc#1267600). * scripts/sorttable: Use a structure of function pointers for elf helpers (bsc#1267600). * scripts/sorttable: Use normal sort if theres no relocs in the mcount section (bsc#1267600). * scripts/sorttable: Use uint64_t for mcount sorting (bsc#1267600). * scripts/sorttable: Zero out weak functions in mcount_loc table (bsc#1267600). * scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (bsc#1257506). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * selftests/bpf: Add BPF_STRICT_BUILD toggle (poo#202224). * selftests/bpf: Allow test_progs to link with a partial object set (poo#202224). * selftests/bpf: Avoid rebuilds when running emit_tests (poo#202224). * selftests/bpf: Consolidate kernel modules into common directory (poo#202224). * selftests/bpf: Copy test_kmods when installing selftest (poo#202224). * selftests/bpf: Fix runqslower cross-endian build (poo#202224). * selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (poo#202224). * selftests/bpf: make BPF_TARGET_ENDIAN non-recursive to speed up *.bpf.o build (poo#202224). * selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (poo#202224). * selftests/bpf: Provide weak definitions for cross-test functions (poo#202224). * selftests/bpf: Skip tests whose objects were not built (poo#202224). * selftests/bpf: Support cross-endian building (poo#202224). * selftests/bpf: Tolerate benchmark build failures (poo#202224). * selftests/bpf: Tolerate BPF and skeleton generation failures (poo#202224). * selftests/bpf: Tolerate missing files during install (poo#202224). * selftests/bpf: Tolerate test file compilation failures (poo#202224). * serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git- fixes). * serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git- fixes). * serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero (git- fixes). * slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (git-fixes). * slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (git-fixes). * slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * slimbus: qcom-ngd-ctrl: Fix probe error path ordering (git-fixes). * slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (git-fixes). * slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (git- fixes). * slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (git- fixes). * soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() (git-fixes). * soc: qcom: ice: Return -ENODEV if the ICE platform device is not found (git- fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: hisi-kunpeng: Use dev_err_probe() for host registration failure (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * thermal: testing: reject missing command arguments (git-fixes). * thermal: testing: zone: Flush work items during cleanup (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: debugfs: Don't stop reading SB registers if just one fails (git-fixes). * thunderbolt: debugfs: Fix margining error counter buffer leak (git-fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * tools/power/x86/intel-speed-select: Harden daemon pidfile open (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt (git-fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (git-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (stable-fixes). * usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 (git- fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). * wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes). * wifi: mt76: mt7921: fix a potential scan no APs (stable-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer (git- fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links (git- fixes). * wifi: mt76: mt7925: keep TX BA state in the primary WCID (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * x86/cpu/amd: Correct the microcode table for Zenbleed (git-fixes). * x86/cpu: Disable FRED when PTI is forced on (git-fixes). * x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63 (git-fixes). * x86/cpu: Validate CPUID leaf 0x2 EDX output (git-fixes). * x86/irq: Ensure initial PIR loads are performed exactly once (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16390). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16390). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1295=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1295=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (x86_64) * kernel-azure-vdso-debuginfo-6.12.0-160000.36.1 * kernel-kvmsmall-vdso-6.12.0-160000.36.1 * kernel-kvmsmall-devel-debuginfo-6.12.0-160000.36.1 * kernel-default-devel-debuginfo-6.12.0-160000.36.1 * kernel-default-vdso-debuginfo-6.12.0-160000.36.1 * kernel-kvmsmall-vdso-debuginfo-6.12.0-160000.36.1 * kernel-azure-devel-debuginfo-6.12.0-160000.36.1 * kernel-azure-vdso-6.12.0-160000.36.1 * kernel-default-vdso-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * kernel-default-debuginfo-6.12.0-160000.36.1 * kernel-obs-qa-6.12.0-160000.36.1 * kernel-default-debugsource-6.12.0-160000.36.1 * kernel-default-devel-6.12.0-160000.36.1 * kernel-default-extra-6.12.0-160000.36.1 * kernel-syms-6.12.0-160000.36.1 * kernel-default-extra-debuginfo-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (noarch) * kernel-devel-6.12.0-160000.36.1 * kernel-docs-html-6.12.0-160000.36.1 * kernel-macros-6.12.0-160000.36.1 * kernel-source-6.12.0-160000.36.1 * kernel-source-vanilla-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (aarch64 nosrc ppc64le x86_64) * kernel-kvmsmall-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (ppc64le x86_64) * kernel-default-base-6.12.0-160000.36.1.160000.2.17 * SUSE Linux Enterprise Server 16.0 (aarch64) * kernel-default-base-6.12.0-160000.36.1.160000.2.18 * kernel-64kb-debugsource-6.12.0-160000.36.1 * kernel-64kb-extra-debuginfo-6.12.0-160000.36.1 * kernel-64kb-debuginfo-6.12.0-160000.36.1 * kernel-64kb-devel-6.12.0-160000.36.1 * kernel-64kb-extra-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (noarch nosrc) * kernel-docs-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * kernel-kvmsmall-devel-6.12.0-160000.36.1 * kernel-kvmsmall-debuginfo-6.12.0-160000.36.1 * kernel-kvmsmall-debugsource-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * kernel-azure-extra-6.12.0-160000.36.1 * kernel-azure-debuginfo-6.12.0-160000.36.1 * kernel-azure-devel-6.12.0-160000.36.1 * kernel-azure-extra-debuginfo-6.12.0-160000.36.1 * kernel-azure-debugsource-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (nosrc s390x) * kernel-zfcpdump-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (aarch64 nosrc x86_64) * kernel-azure-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-default-livepatch-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (s390x) * kernel-zfcpdump-debuginfo-6.12.0-160000.36.1 * kernel-zfcpdump-debugsource-6.12.0-160000.36.1 * SUSE Linux Enterprise Server 16.0 (aarch64 nosrc) * kernel-64kb-6.12.0-160000.36.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (nosrc ppc64le x86_64) * kernel-default-6.12.0-160000.36.1 * kernel-kvmsmall-6.12.0-160000.36.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-kvmsmall-debuginfo-6.12.0-160000.36.1 * kernel-default-debuginfo-6.12.0-160000.36.1 * dlm-kmp-default-debuginfo-6.12.0-160000.36.1 * kernel-obs-qa-6.12.0-160000.36.1 * kernel-default-debugsource-6.12.0-160000.36.1 * kernel-kvmsmall-debugsource-6.12.0-160000.36.1 * gfs2-kmp-default-debuginfo-6.12.0-160000.36.1 * kernel-default-extra-6.12.0-160000.36.1 * kernel-syms-6.12.0-160000.36.1 * kernel-kvmsmall-devel-6.12.0-160000.36.1 * dlm-kmp-default-6.12.0-160000.36.1 * cluster-md-kmp-default-6.12.0-160000.36.1 * kernel-default-livepatch-6.12.0-160000.36.1 * kernel-default-extra-debuginfo-6.12.0-160000.36.1 * gfs2-kmp-default-6.12.0-160000.36.1 * kernel-default-devel-6.12.0-160000.36.1 * kernel-default-base-6.12.0-160000.36.1.160000.2.17 * cluster-md-kmp-default-debuginfo-6.12.0-160000.36.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * kernel-devel-6.12.0-160000.36.1 * kernel-docs-html-6.12.0-160000.36.1 * kernel-macros-6.12.0-160000.36.1 * kernel-source-6.12.0-160000.36.1 * kernel-source-vanilla-6.12.0-160000.36.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch nosrc) * kernel-docs-6.12.0-160000.36.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * kernel-azure-extra-6.12.0-160000.36.1 * kernel-azure-vdso-debuginfo-6.12.0-160000.36.1 * kernel-azure-debuginfo-6.12.0-160000.36.1 * kernel-kvmsmall-vdso-6.12.0-160000.36.1 * kernel-azure-devel-6.12.0-160000.36.1 * kernel-default-vdso-6.12.0-160000.36.1 * kernel-kvmsmall-devel-debuginfo-6.12.0-160000.36.1 * kernel-default-devel-debuginfo-6.12.0-160000.36.1 * kernel-default-vdso-debuginfo-6.12.0-160000.36.1 * kernel-kvmsmall-vdso-debuginfo-6.12.0-160000.36.1 * kernel-azure-extra-debuginfo-6.12.0-160000.36.1 * kernel-azure-debugsource-6.12.0-160000.36.1 * kernel-azure-vdso-6.12.0-160000.36.1 * kernel-azure-devel-debuginfo-6.12.0-160000.36.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (nosrc x86_64) * kernel-azure-6.12.0-160000.36.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-39894.html * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2026-23248.html * https://www.suse.com/security/cve/CVE-2026-23394.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31438.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31479.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31560.html * https://www.suse.com/security/cve/CVE-2026-31580.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31646.html * https://www.suse.com/security/cve/CVE-2026-31647.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31743.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43014.html * https://www.suse.com/security/cve/CVE-2026-43015.html * https://www.suse.com/security/cve/CVE-2026-43016.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43090.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43094.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43130.html * https://www.suse.com/security/cve/CVE-2026-43132.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43145.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43161.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43175.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43213.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43260.html * https://www.suse.com/security/cve/CVE-2026-43283.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43298.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43337.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43351.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43374.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43384.html * https://www.suse.com/security/cve/CVE-2026-43386.html * https://www.suse.com/security/cve/CVE-2026-43403.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43415.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43457.html * https://www.suse.com/security/cve/CVE-2026-43458.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43471.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45837.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45861.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45884.html * https://www.suse.com/security/cve/CVE-2026-45888.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45901.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45922.html * https://www.suse.com/security/cve/CVE-2026-45933.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-45999.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46078.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46093.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46162.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52919.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52980.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53015.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53081.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53103.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53156.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53194.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53262.html * https://www.suse.com/security/cve/CVE-2026-53263.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53272.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53286.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1149651 * https://bugzilla.suse.com/show_bug.cgi?id=1204315 * https://bugzilla.suse.com/show_bug.cgi?id=1236743 * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1257506 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1259800 * https://bugzilla.suse.com/show_bug.cgi?id=1260565 * https://bugzilla.suse.com/show_bug.cgi?id=1261250 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262430 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262765 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1263057 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263169 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263581 * https://bugzilla.suse.com/show_bug.cgi?id=1263796 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264007 * https://bugzilla.suse.com/show_bug.cgi?id=1264010 * https://bugzilla.suse.com/show_bug.cgi?id=1264012 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264067 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264231 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264250 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264295 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264333 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264372 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264429 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264532 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264614 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264643 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264740 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264789 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264852 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265000 * https://bugzilla.suse.com/show_bug.cgi?id=1265005 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265082 * https://bugzilla.suse.com/show_bug.cgi?id=1265084 * https://bugzilla.suse.com/show_bug.cgi?id=1265091 * https://bugzilla.suse.com/show_bug.cgi?id=1265097 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265112 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265123 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265129 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266283 * https://bugzilla.suse.com/show_bug.cgi?id=1266284 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266398 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266693 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266718 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266750 * https://bugzilla.suse.com/show_bug.cgi?id=1266754 * https://bugzilla.suse.com/show_bug.cgi?id=1266761 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266805 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266840 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266892 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266925 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267419 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267505 * https://bugzilla.suse.com/show_bug.cgi?id=1267548 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267600 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1267816 * https://bugzilla.suse.com/show_bug.cgi?id=1267824 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268238 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269031 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269087 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269199 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269252 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269288 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269416 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269531 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269617 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269647 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269708 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269809 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269904 * https://bugzilla.suse.com/show_bug.cgi?id=1269982 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1270000 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270042 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://jira.suse.com/browse/PED-10906 * https://jira.suse.com/browse/PED-15986 * https://jira.suse.com/browse/PED-16390 * https://jira.suse.com/browse/SLE-8615 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:48:33 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:48:33 -0000 Subject: SUSE-RU-2026:22833-1: important: Recommended update for pcr-oracle Message-ID: <178517451389.2240.18410698543567617161@c3e054a4ce29> # Recommended update for pcr-oracle Announcement ID: SUSE-RU-2026:22833-1 Release Date: 2026-07-20T17:29:17Z Rating: important References: * bsc#1270265 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for pcr-oracle fixes the following issues: * Update to 0.6.4: * Support TPM PCR snapshot on PowerPC 64 platform * Fix SBAT string length calculations (bsc#1270265) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1306=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1306=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * pcr-oracle-debugsource-0.6.4-160000.1.1 * pcr-oracle-debuginfo-0.6.4-160000.1.1 * pcr-oracle-0.6.4-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * pcr-oracle-debugsource-0.6.4-160000.1.1 * pcr-oracle-debuginfo-0.6.4-160000.1.1 * pcr-oracle-0.6.4-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270265 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:48:55 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:48:55 -0000 Subject: SUSE-RU-2026:22832-1: important: Recommended update for container-selinux Message-ID: <178517453580.2240.1491088713970952604@c3e054a4ce29> # Recommended update for container-selinux Announcement ID: SUSE-RU-2026:22832-1 Release Date: 2026-07-20T14:06:08Z Rating: important References: * bsc#1268490 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for container-selinux fixes the following issues: * Introduce container_can_execstack boolean for older Java applications and allow execmem (bsc#1268490) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1304=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1304=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * container-selinux-2.239.0-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * container-selinux-2.239.0-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268490 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:49:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:49:20 -0000 Subject: SUSE-SU-2026:22831-1: moderate: Security update for gawk Message-ID: <178517456030.2240.926014904153554191@c3e054a4ce29> # Security update for gawk Announcement ID: SUSE-SU-2026:22831-1 Release Date: 2026-07-20T13:44:04Z Rating: moderate References: * bsc#1271351 * bsc#1271352 * bsc#1271354 Cross-References: * CVE-2026-40467 * CVE-2026-40468 * CVE-2026-40553 CVSS scores: * CVE-2026-40467 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40467 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40467 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40467 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40468 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L * CVE-2026-40468 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40468 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40468 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-40553 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-40553 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-40553 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40553 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for gawk fixes the following issues: * CVE-2026-40467: use-after-free vulnerability within the do_getline_redir() routine could lead to a program crash (bsc#1271351). * CVE-2026-40468: use-after-free vulnerability in gawk's "io.c" file could permit heap metadata manipulation and host memory exhaustion (bsc#1271352). * CVE-2026-40553: buffer overflow in the ftype() routine of the readdir extension could trigger a program crash (bsc#1271354). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1303=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1303=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gawk-5.3.2-160000.3.1 * gawk-debuginfo-5.3.2-160000.3.1 * gawk-debugsource-5.3.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gawk-5.3.2-160000.3.1 * gawk-debuginfo-5.3.2-160000.3.1 * gawk-debugsource-5.3.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40467.html * https://www.suse.com/security/cve/CVE-2026-40468.html * https://www.suse.com/security/cve/CVE-2026-40553.html * https://bugzilla.suse.com/show_bug.cgi?id=1271351 * https://bugzilla.suse.com/show_bug.cgi?id=1271352 * https://bugzilla.suse.com/show_bug.cgi?id=1271354 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:48:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:48:11 -0000 Subject: SUSE-RU-2026:22834-1: important: Recommended update for openCryptoki Message-ID: <178517449117.2240.10951426055288904675@c3e054a4ce29> # Recommended update for openCryptoki Announcement ID: SUSE-RU-2026:22834-1 Release Date: 2026-07-20T17:30:33Z Rating: important References: * bsc#1268745 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for openCryptoki fixes the following issues: * Fix pkcsslotd directory creation failures on immutable/transactional systems (bsc#1268745): * Added systemd service drop-in to allow dynamic token slot path creation via ReadWritePaths ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1307=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1307=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openCryptoki-debuginfo-3.27.0-160000.2.1 * openCryptoki-3.27.0-160000.2.1 * openCryptoki-devel-3.27.0-160000.2.1 * openCryptoki-64bit-3.27.0-160000.2.1 * openCryptoki-debugsource-3.27.0-160000.2.1 * openCryptoki-64bit-debuginfo-3.27.0-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * openCryptoki-debuginfo-3.27.0-160000.2.1 * openCryptoki-3.27.0-160000.2.1 * openCryptoki-devel-3.27.0-160000.2.1 * openCryptoki-64bit-3.27.0-160000.2.1 * openCryptoki-debugsource-3.27.0-160000.2.1 * openCryptoki-64bit-debuginfo-3.27.0-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268745 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:50:39 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:50:39 -0000 Subject: SUSE-SU-2026:22830-1: important: Security update for python-pyasn1 Message-ID: <178517463975.2240.15030012850626003125@c3e054a4ce29> # Security update for python-pyasn1 Announcement ID: SUSE-SU-2026:22830-1 Release Date: 2026-07-20T12:17:20Z Rating: important References: * bsc#1271464 * bsc#1271465 * bsc#1271466 Cross-References: * CVE-2026-59884 * CVE-2026-59885 * CVE-2026-59886 CVSS scores: * CVE-2026-59884 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59884 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59884 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59885 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59885 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59885 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59886 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59886 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59886 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-pyasn1 fixes the following issues: * CVE-2026-59884: BER/CER/DER decoder denial of service via unbounded long- form tag IDs (bsc#1271464). * CVE-2026-59885: quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service (bsc#1271465). * CVE-2026-59886: uncontrolled resource consumption when converting decoded REAL values (bsc#1271466). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1301=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1301=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-pyasn1-0.6.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-pyasn1-0.6.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59884.html * https://www.suse.com/security/cve/CVE-2026-59885.html * https://www.suse.com/security/cve/CVE-2026-59886.html * https://bugzilla.suse.com/show_bug.cgi?id=1271464 * https://bugzilla.suse.com/show_bug.cgi?id=1271465 * https://bugzilla.suse.com/show_bug.cgi?id=1271466 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:51:32 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:51:32 -0000 Subject: SUSE-SU-2026:22829-1: moderate: Security update for ImageMagick Message-ID: <178517469249.2240.14012696943260177217@c3e054a4ce29> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:22829-1 Release Date: 2026-07-20T10:18:43Z Rating: moderate References: * bsc#1268640 * bsc#1270006 * bsc#1270081 * bsc#1271100 * bsc#1271293 * bsc#1271294 * bsc#1271311 * bsc#1271312 * bsc#1271313 * bsc#1271314 * bsc#1271315 * bsc#1271316 Cross-References: * CVE-2026-55628 * CVE-2026-56362 * CVE-2026-56366 * CVE-2026-56372 * CVE-2026-56373 * CVE-2026-56377 * CVE-2026-61465 * CVE-2026-61857 * CVE-2026-61858 * CVE-2026-61861 * CVE-2026-61870 CVSS scores: * CVE-2026-55628 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55628 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56362 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56362 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56362 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56366 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56366 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56366 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56366 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56366 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56372 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56372 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56372 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56373 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56373 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56377 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-56377 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56377 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56377 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61465 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61465 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61465 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-61857 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61857 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61857 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61857 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61857 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61858 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61858 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61858 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61861 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61861 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61861 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-61861 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61870 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 11 vulnerabilities and has one fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-55628: Policy Bypass in concatenate operation due to missing checks (bsc#1270081). * CVE-2026-56362: Heap-buffer-overflow read in GetPixelIndex due to metadata- cache desynchronization in OpenPixelCache (bsc#1271100). * CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). * CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized magnify:method value (bsc#1271314). * CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315). * CVE-2026-56377: Policy Bypass can create or truncate files (bsc#1270006). * CVE-2026-61465: Policy Bypass possible with matrix-backed operations (bsc#1271313). * CVE-2026-61857: Heap-use-after-free via XMP profile could result in a crash (bsc#1271312). * CVE-2026-61858: Policy Bypass in APNG encoder and delegates due to a missing check (bsc#1271311). * CVE-2026-61861: Use-After-Free in FormatMagickCaption when memory allocation fails (bsc#1271294). * CVE-2026-61870: Memory leak in VIFF encoder when allocation fails (bsc#1271293). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1300=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1300=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * ImageMagick-devel-7.1.2.0-160000.12.1 * perl-PerlMagick-7.1.2.0-160000.12.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.12.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.12.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.12.1 * ImageMagick-debuginfo-7.1.2.0-160000.12.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.12.1 * libMagick++-7_Q16HDRI5-7.1.2.0-160000.12.1 * ImageMagick-extra-7.1.2.0-160000.12.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.12.1 * ImageMagick-7.1.2.0-160000.12.1 * ImageMagick-debugsource-7.1.2.0-160000.12.1 * libMagick++-devel-7.1.2.0-160000.12.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.12.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.12.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * ImageMagick-doc-7.1.2.0-160000.12.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.12.1 * ImageMagick-config-7-SUSE-7.1.2.0-160000.12.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.12.1 * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.12.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.12.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-PerlMagick-7.1.2.0-160000.12.1 * ImageMagick-devel-7.1.2.0-160000.12.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.12.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.12.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.12.1 * ImageMagick-debuginfo-7.1.2.0-160000.12.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.12.1 * libMagick++-devel-7.1.2.0-160000.12.1 * ImageMagick-extra-7.1.2.0-160000.12.1 * ImageMagick-debugsource-7.1.2.0-160000.12.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.12.1 * ImageMagick-7.1.2.0-160000.12.1 * libMagick++-7_Q16HDRI5-7.1.2.0-160000.12.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.12.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.12.1 * SUSE Linux Enterprise Server 16.0 (noarch) * ImageMagick-doc-7.1.2.0-160000.12.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.12.1 * ImageMagick-config-7-SUSE-7.1.2.0-160000.12.1 * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.12.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.12.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55628.html * https://www.suse.com/security/cve/CVE-2026-56362.html * https://www.suse.com/security/cve/CVE-2026-56366.html * https://www.suse.com/security/cve/CVE-2026-56372.html * https://www.suse.com/security/cve/CVE-2026-56373.html * https://www.suse.com/security/cve/CVE-2026-56377.html * https://www.suse.com/security/cve/CVE-2026-61465.html * https://www.suse.com/security/cve/CVE-2026-61857.html * https://www.suse.com/security/cve/CVE-2026-61858.html * https://www.suse.com/security/cve/CVE-2026-61861.html * https://www.suse.com/security/cve/CVE-2026-61870.html * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1270006 * https://bugzilla.suse.com/show_bug.cgi?id=1270081 * https://bugzilla.suse.com/show_bug.cgi?id=1271100 * https://bugzilla.suse.com/show_bug.cgi?id=1271293 * https://bugzilla.suse.com/show_bug.cgi?id=1271294 * https://bugzilla.suse.com/show_bug.cgi?id=1271311 * https://bugzilla.suse.com/show_bug.cgi?id=1271312 * https://bugzilla.suse.com/show_bug.cgi?id=1271313 * https://bugzilla.suse.com/show_bug.cgi?id=1271314 * https://bugzilla.suse.com/show_bug.cgi?id=1271315 * https://bugzilla.suse.com/show_bug.cgi?id=1271316 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:52:09 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:52:09 -0000 Subject: SUSE-RU-2026:22828-1: moderate: Recommended update for maven-doxia-sitetools, maven-dependency-plugin Message-ID: <178517472995.2240.6762689805321590550@c3e054a4ce29> # Recommended update for maven-doxia-sitetools, maven-dependency-plugin Announcement ID: SUSE-RU-2026:22828-1 Release Date: 2026-07-20T09:58:12Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for maven-doxia-sitetools, maven-dependency-plugin fixes the following issues: Changes in maven-doxia-sitetools: Upgrade to upstream version 2.1.0: * New features and improvements * Expose SCM last modification date and author from Doxia source in Velocity * Allow to set an alternative source directory (for editing) * Support conditional resources from skins * Support for rendering Mermaid diagrams client-side. * Bug Fixes * Interpolate using user and system properties in Site Descriptor * Documentation updates * Convert Sites from APT to MD * Clarify menu inheritance and default behavior of "inherit" attribute * Upgrade to Site Descriptor 2.x * Clarify image attributes in site descriptor * Document value "none" for attribute "position" * Maintenance * JUnit Jupiter best practices * PlexusStringUtils Refaster recipes * PlexusFileUtils Refaster recipes * JUnit Jupiter migration from JUnit 4.x * feat: enable prevent branch protection rules * Enable Github issues * DOXIASITETOOLS-359: Support site directories where duplicates are skipped * DOXIASITETOOLS-356: Provide more context in error message * DOXIASITETOOLS-313: Refresh download page * Dependency updates * Update to Doxia 2.1.0 * Bump org.junit:junit-bom from 5.11.2 to 5.14.3 * Bump org.apache.maven.plugin-testing :maven-plugin-testing-harness from 3.3.0 to 3.5.1 * DOXIASITETOOLS-360: Bump org.codehaus.mojo:l10n-maven-plugin from 1.0.0 to 1.1.0 * Bump org.codehaus.mojo:l10n-maven-plugin from 1.1.0 to 1.2.0 * Bump org.apache.maven:maven-parent from 43 to 47 * Bump org.codehaus.plexus:plexus-testing from 1.4.0 to 2.1.0 * DOXIASITETOOLS-361: Bump org.htmlunit:htmlunit from 4.4.0 to 4.9.0 * Bump org.htmlunit:htmlunit from 4.9.0 to 4.21.0 * Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0 * Bump org.codehaus.plexus:plexus-interpolation from 1.27 to 1.29 * Bump org.codehaus.plexus:plexus-i18n from 1.0-beta-10 to 1.1.0 * Bump commons-io:commons-io from 2.17.0 to 2.21.0 * Bump org.codehaus.plexus:plexus-velocity from 2.2.0 to 2.3.0 * Bump org.codehaus.plexus:plexus-classworlds from 2.8.0 to 2.9.0 * Bump org.apache.velocity:velocity-engine-core from 2.4 to 2.4.1 Changes in maven-dependency-plugin: Upgrade to version 3.11.0: * New features and improvements * Add dependency:add and dependency:remove goals * Added ability to provide arbitrary dependencies to properties mojo * Bug Fixes * Fix artifact relocation support * fix: fix addParentPoms=true causes repositories to be ignored. * Fix false positive in analyze-exclusions with transitive dependency exclusion * Make AbstractAnalyzeMojo.filterArtifactsByScope() null-safe * Prevent NPE in BuildClasspathMojo.appendArtifactPath() when an artifact has no resolved file * Log unpacking at debug level * Resolve plugins declared in pluginManagement for resolve-plugins and go-offline * Fix analyze-exclusions crashes if there is no dependencyManagement element * Maintenance * Enable ITs for dependency:remove and use mock dependencies * More meaningful assertions * Cure various typos IntelliJ complains about * Remove unused jansi dependency * Enable ITs for dependecy:add and use mock dependencies * Cleaner exception handling * Dependency updates * Manage ASM version 9.10 to support JDK 27 * Bump eu.maveniverse.maven.domtrip:domtrip-core from 1.5.0 to 1.5.1 * Bump eu.maveniverse.maven.domtrip:domtrip-maven from 1.5.0 to 1.5.1 * Bump mavenVersion from 3.9.12 to 3.9.16 * Bump org.apache.maven.shared:maven-dependency-analyzer from 1.17.0 to 1.17.1 * Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0 in /src/it/projects/remove-dependency/basic * Bump org.apache.maven.plugins:maven-plugins from 47 to 48 * Bump org.jsoup:jsoup from 1.22.1 to 1.22.2 * Bump org.apache.maven.doxia:doxia-sink-api from 2.0.0 to 2.1.0 * Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 * Bump org.apache.maven.plugin-testing :maven-plugin-testing-harness from 3.5.0 to 3.5.1 Upgrade to version 3.10.0: * New features and improvements * Introduce graphRoots for dependencyFilter based mojos * Bug Fixes * Apply excludeReactor to plugin dependencies in go-offline and resolve-plugins * Only log dependency classpath when no property/file output is specified * MDEP-974: strip ansi codes when writing to a file * Documentation updates * Add analyze-only to usage page * Move doc comment to correct location * Focus on most recent version * Maintenance * Fix Jenkin bages in README * Improve dependencies filtering in AbstractAnalyzeMojo * Migration to JUnit 5 * JUnit Jupiter best practices * Migrate JUnit3 based Tests to JUnit 5 * Dependency updates * Bump org.apache.maven.shared:maven-dependency-analyzer from 1.16.0 to 1.17.0 * Bump org.assertj:assertj-core from 2.9.1 to 3.27.7 in /src/it/projects/analyze-testDependencyWithNonTestScope * Bump org.assertj:assertj-core from 3.27.6 to 3.27.7 * Bump org.codehaus.mojo:mrm-maven-plugin from 1.7.0 to 1.7.1 * Bump org.apache.maven.plugins:maven-plugins from 46 to 47 * Bump org.codehaus.plexus:plexus-archiver from 4.10.1 to 4.11.0 * Bump org.apache.maven.plugins:maven-plugins from 45 to 46 * Bump org.jsoup:jsoup from 1.21.2 to 1.22.1 * Bump mavenVersion from 3.9.11 to 3.9.12 * Bump org.apache.commons:commons-lang3 from 3.19.0 to 3.20.0 * Bump commons-io:commons-io from 2.20.0 to 2.21.0 * Bump org.codehaus.plexus:plexus-io from 3.5.1 to 3.6.0 * Bump org.codehaus.plexus:plexus-i18n from 1.0.0 to 1.1.0 * Bump org.apache.maven.plugin-testing :maven-plugin-testing-harness from 3.3.0 to 3.4.0 Upgrade to version 3.9.0: * New features and improvements * Use Resolver API in go-offline for dependencies resolving * Use Resolver API in go-offline for plugins resolving * Fixes #1522, add render-dependencies mojo * Use Resolver API in resolve-plugin * MDEP-964: unconditionally ignore dependencies known to be loaded by reflection * Update maven-dependency-analyzer to support Java24 * MDEP-972: copy-dependencies: copy signatures alongside artifacts * MDEP-776: Warn when multiple dependencies have the same file name * MDEP-966: Migrate AnalyzeDepMgt to Sisu * MDEP-957: By default, don't report slf4j-simple as unused * Bug Fixes * ProjectBuildingRequest should not be modified * Fix: markersDirectory is not working when unpack goal is executed from command line * Fix broken link for analyze-exclusions-mojo on usage-page * MDEP-839: Avoid extra blank lines in file * Update collect URL * MDEP-689: Fixes ignored dependency filtering in go-offline goal * MDEP-960: Repair silent logging * Documentation updates * MDEP-933: Document dependency tree output formats * Add additional comment to clarify the minimal supported version of outputing dependency tree in JSON fromat. * MNGSITE-529: Rename "Goals" to "Plugin Documentation" * Unix file separators * Maintenance * Simplify usage of RepositoryManager and DependencyResolver * Use Resolver API in copy and unpack * Update site descriptor to 2.0.0 * Enable prevent branch protection rules * Fix [MDEP-931: Replace PrintWriter with Writer in AbstractSerializing Visitor and subclasses * Cleanups dependencies * Copy edit parameter descriptions * Small Javadoc clarifications * MDEP-967: Change info to debug logging in AbstractFromConfigurationMojo * fix: remove duplicate maven-resolver-api and maven-resolver-util dependencies in pom.xml * Enable GH issues * Remove redundant/unneeded code * Add PR Automation and Stale actions * Keep files in temporary directory to be deleted after test * Drop unnecessary call * Avoid deprecated ArtifactFactory * MDEP-966: Convert remaining Mojos to Guice injection * MDEP-966: Convert Analyze Mojos to Guice constructor injection * MDEP-966: Prefer Guice injection * MDEP-966: Migrate TreeMojo/CopyMojo/AnalyzeExclusionsMojo/ /UnpackMojo/CopyDependenciesMojo from Plexus to Sisu Guice * MDEP-966: @component --> @Inject for DisplayAncestorsMojo * Fixing flaky test in TestCopyDependenciesMojo * MNG-2961: Remove workaround for fixed bug * Build * Build by Maven 4 * Dependency updates * Bump Maven in dependencies to 3.9.11 * Bump commons-io:commons-io from 2.16.1 to 2.20.0 * Bump jettyVersion from 9.4.56.v20240826 to 9.4.58.v20250814 * Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.19.0 * Bump org.apache.maven.plugins:maven-plugins from 43 to 45 * Bump org.codehaus.mojo:mrm-maven-plugin from 1.6.0 to 1.7.0 * Bump org.codehaus.plexus:plexus-archiver from 4.10.0 to 4.10.1 * Bump org.codehaus.plexus:plexus-i18n from 1.0-beta-10 to 1.0.0 * Bump org.jsoup:jsoup from 1.18.1 to 1.21.2 * MDEP-963: Bump org.apache.maven.shared:maven-dependency-analyzer from 1.15.0 to 1.15.1 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1299=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1299=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * maven-doxia-sitetools-2.1.0-160000.1.1 * maven-doxia-sitetools-javadoc-2.1.0-160000.1.1 * maven-dependency-plugin-javadoc-3.11.0-160000.1.1 * maven-dependency-plugin-3.11.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * maven-doxia-sitetools-2.1.0-160000.1.1 * maven-dependency-plugin-javadoc-3.11.0-160000.1.1 * maven-dependency-plugin-3.11.0-160000.1.1 * maven-doxia-sitetools-javadoc-2.1.0-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:52:42 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:52:42 -0000 Subject: SUSE-SU-2026:22827-1: important: Security update for afterburn Message-ID: <178517476292.2240.12474032222757725799@c3e054a4ce29> # Security update for afterburn Announcement ID: SUSE-SU-2026:22827-1 Release Date: 2026-07-20T09:31:31Z Rating: important References: * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for afterburn fixes the following issues: Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ? * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1293=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1293=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-160000.1.1 * afterburn-debugsource-5.10.0.git73.b97f772-160000.1.1 * afterburn-5.10.0.git73.b97f772-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-160000.1.1 * afterburn-debugsource-5.10.0.git73.b97f772-160000.1.1 * afterburn-5.10.0.git73.b97f772-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:53:22 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:53:22 -0000 Subject: SUSE-SU-2026:22826-1: moderate: Security update for libgcrypt Message-ID: <178517480268.2240.3617482509782908004@c3e054a4ce29> # Security update for libgcrypt Announcement ID: SUSE-SU-2026:22826-1 Release Date: 2026-07-20T09:26:51Z Rating: moderate References: * bsc#1262684 Cross-References: * CVE-2026-41989 CVSS scores: * CVE-2026-41989 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue * CVE-2026-41989: crafted ECDH ciphertext can lead denial of service (bsc#1262684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1294=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1294=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libgcrypt20-1.12.1-160000.3.1 * libgcrypt20-debuginfo-1.12.1-160000.3.1 * libgcrypt-devel-debuginfo-1.12.1-160000.3.1 * libgcrypt-debugsource-1.12.1-160000.3.1 * libgcrypt-devel-1.12.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libgcrypt20-x86-64-v3-debuginfo-1.12.1-160000.3.1 * libgcrypt-devel-x86-64-v3-1.12.1-160000.3.1 * libgcrypt20-x86-64-v3-1.12.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libgcrypt20-1.12.1-160000.3.1 * libgcrypt20-debuginfo-1.12.1-160000.3.1 * libgcrypt-debugsource-1.12.1-160000.3.1 * libgcrypt-devel-debuginfo-1.12.1-160000.3.1 * libgcrypt-devel-1.12.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libgcrypt20-x86-64-v3-debuginfo-1.12.1-160000.3.1 * libgcrypt-devel-x86-64-v3-1.12.1-160000.3.1 * libgcrypt20-x86-64-v3-1.12.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41989.html * https://bugzilla.suse.com/show_bug.cgi?id=1262684 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:54:01 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:54:01 -0000 Subject: SUSE-SU-2026:22825-1: low: Security update for gpg2 Message-ID: <178517484134.2240.9537579755271099855@c3e054a4ce29> # Security update for gpg2 Announcement ID: SUSE-SU-2026:22825-1 Release Date: 2026-07-20T03:14:32Z Rating: low References: * bsc#1269279 Cross-References: * CVE-2026-57062 CVSS scores: * CVE-2026-57062 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-57062 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-57062 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for gpg2 fixes the following issue: * CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1288=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1288=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gpg2-tpm-debuginfo-2.5.5-160000.6.1 * dirmngr-2.5.5-160000.6.1 * gpg2-debuginfo-2.5.5-160000.6.1 * dirmngr-debuginfo-2.5.5-160000.6.1 * gpg2-debugsource-2.5.5-160000.6.1 * gpg2-2.5.5-160000.6.1 * gpg2-tpm-2.5.5-160000.6.1 * SUSE Linux Enterprise Server 16.0 (noarch) * gpg2-lang-2.5.5-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gpg2-tpm-debuginfo-2.5.5-160000.6.1 * dirmngr-2.5.5-160000.6.1 * gpg2-debuginfo-2.5.5-160000.6.1 * dirmngr-debuginfo-2.5.5-160000.6.1 * gpg2-debugsource-2.5.5-160000.6.1 * gpg2-2.5.5-160000.6.1 * gpg2-tpm-2.5.5-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * gpg2-lang-2.5.5-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57062.html * https://bugzilla.suse.com/show_bug.cgi?id=1269279 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:54:38 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:54:38 -0000 Subject: SUSE-RU-2026:22824-1: moderate: Recommended update for pgvector Message-ID: <178517487853.2240.8758852980984409916@c3e054a4ce29> # Recommended update for pgvector Announcement ID: SUSE-RU-2026:22824-1 Release Date: 2026-07-18T13:40:01Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for pgvector fixes the following issue: Changes in pgvector: * Disable postgresql13 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1287=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1287=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postgresql17-pgvector-debugsource-0.8.2-160000.2.1 * postgresql16-pgvector-debugsource-0.8.2-160000.2.1 * postgresql16-pgvector-0.8.2-160000.2.1 * pgvector-devel-0.8.2-160000.2.1 * postgresql15-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql14-pgvector-debugsource-0.8.2-160000.2.1 * postgresql18-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql14-pgvector-0.8.2-160000.2.1 * postgresql17-pgvector-0.8.2-160000.2.1 * postgresql15-pgvector-0.8.2-160000.2.1 * postgresql14-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql16-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql15-pgvector-debugsource-0.8.2-160000.2.1 * postgresql18-pgvector-0.8.2-160000.2.1 * postgresql17-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql18-pgvector-debugsource-0.8.2-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postgresql17-pgvector-debugsource-0.8.2-160000.2.1 * postgresql16-pgvector-debugsource-0.8.2-160000.2.1 * postgresql16-pgvector-0.8.2-160000.2.1 * pgvector-devel-0.8.2-160000.2.1 * postgresql15-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql14-pgvector-debugsource-0.8.2-160000.2.1 * postgresql18-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql14-pgvector-0.8.2-160000.2.1 * postgresql17-pgvector-0.8.2-160000.2.1 * postgresql15-pgvector-0.8.2-160000.2.1 * postgresql14-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql16-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql15-pgvector-debugsource-0.8.2-160000.2.1 * postgresql18-pgvector-0.8.2-160000.2.1 * postgresql17-pgvector-debuginfo-0.8.2-160000.2.1 * postgresql18-pgvector-debugsource-0.8.2-160000.2.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:55:00 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:55:00 -0000 Subject: SUSE-RU-2026:22823-1: moderate: Recommended update for python-kiwi Message-ID: <178517490076.2240.5941960147615554315@c3e054a4ce29> # Recommended update for python-kiwi Announcement ID: SUSE-RU-2026:22823-1 Release Date: 2026-07-18T13:40:01Z Rating: moderate References: * bsc#1263564 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for python-kiwi fixes the following issues: * Fix reading of runtime config files: * Make sure the reading of the runtime config files in the different locations is not an exclusive procedure. * Add support for sha512sum: * Allow to select between the default shasum size 256 and 512 via a new runtime config section named: shasum. * Fix system resize: * The filesystem check is not applied for btrfs prior resize. * Fix qemu-xxx requirement: * Do not require qemu variant packages for 32bit architectures. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1286=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1286=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * kiwi-systemdeps-iso-media-10.2.33-160000.4.1 * kiwi-systemdeps-filesystems-10.2.33-160000.4.1 * kiwi-systemdeps-core-10.2.33-160000.4.1 * kiwi-systemdeps-disk-images-10.2.33-160000.4.1 * dracut-kiwi-lib-10.2.33-160000.4.1 * kiwi-systemdeps-containers-wsl-10.2.33-160000.4.1 * dracut-kiwi-verity-debuginfo-10.2.33-160000.4.1 * kiwi-man-pages-10.2.33-160000.4.1 * dracut-kiwi-overlay-10.2.33-160000.4.1 * python3-kiwi-10.2.33-160000.4.1 * kiwi-systemdeps-bootloaders-10.2.33-160000.4.1 * dracut-kiwi-oem-dump-10.2.33-160000.4.1 * kiwi-systemdeps-image-validation-10.2.33-160000.4.1 * dracut-kiwi-live-10.2.33-160000.4.1 * dracut-kiwi-verity-10.2.33-160000.4.1 * kiwi-systemdeps-10.2.33-160000.4.1 * dracut-kiwi-oem-repart-10.2.33-160000.4.1 * kiwi-systemdeps-containers-10.2.33-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * kiwi-bash-completion-10.2.33-160000.4.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * kiwi-pxeboot-10.2.33-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kiwi-systemdeps-iso-media-10.2.33-160000.4.1 * kiwi-systemdeps-filesystems-10.2.33-160000.4.1 * kiwi-systemdeps-10.2.33-160000.4.1 * kiwi-systemdeps-containers-wsl-10.2.33-160000.4.1 * dracut-kiwi-lib-10.2.33-160000.4.1 * kiwi-systemdeps-disk-images-10.2.33-160000.4.1 * dracut-kiwi-verity-debuginfo-10.2.33-160000.4.1 * kiwi-man-pages-10.2.33-160000.4.1 * dracut-kiwi-overlay-10.2.33-160000.4.1 * python3-kiwi-10.2.33-160000.4.1 * kiwi-systemdeps-bootloaders-10.2.33-160000.4.1 * dracut-kiwi-oem-dump-10.2.33-160000.4.1 * kiwi-systemdeps-image-validation-10.2.33-160000.4.1 * dracut-kiwi-live-10.2.33-160000.4.1 * dracut-kiwi-verity-10.2.33-160000.4.1 * kiwi-systemdeps-core-10.2.33-160000.4.1 * dracut-kiwi-oem-repart-10.2.33-160000.4.1 * kiwi-systemdeps-containers-10.2.33-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * kiwi-bash-completion-10.2.33-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * kiwi-pxeboot-10.2.33-160000.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1263564 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:55:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:55:25 -0000 Subject: SUSE-SU-2026:22822-1: moderate: Security update for jackson-annotations, jackson-core, jackson-databind Message-ID: <178517492534.2240.8541142653994664975@c3e054a4ce29> # Security update for jackson-annotations, jackson-core, jackson-databind Announcement ID: SUSE-SU-2026:22822-1 Release Date: 2026-07-18T12:46:29Z Rating: moderate References: * bsc#1268902 * bsc#1271440 * bsc#1271442 Cross-References: * CVE-2026-54515 * CVE-2026-59888 * CVE-2026-59889 CVSS scores: * CVE-2026-54515 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54515 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-59888 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-59888 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-59888 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-59889 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-59889 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59889 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for jackson-annotations, jackson-core, jackson-databind fixes the following issues: * CVE-2026-54515: rebuilding the property map from unfiltered bean properties could permit a bypass of @JsonIgnoreProperties exclusions (bsc#1268902). * CVE-2026-59889: missing view guard when deserializing @JsonUnwrapped properties could allow unauthorized writes to @JsonView restricted fields (bsc#1271440). * CVE-2026-59888: mismatch between property renaming and ignore-filtering on Java Records could allow a bypass of @JsonIgnore restrictions (bsc#1271442). Changes for jackson-annotations: * Update to 2.18.9. Changes for jackson-core: * Update to 2.18.9. Changes for jackson-databind: * Update to 2.18.9: * honor @JsonView for external-type-id (EXTERNAL_PROPERTY) properties (GHSA- mhm7-754m-9p8w). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1285=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1285=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * jackson-core-javadoc-2.18.9-160000.1.1 * jackson-databind-javadoc-2.18.9-160000.1.1 * jackson-annotations-2.18.9-160000.1.1 * jackson-databind-2.18.9-160000.1.1 * jackson-annotations-javadoc-2.18.9-160000.1.1 * jackson-core-2.18.9-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * jackson-core-javadoc-2.18.9-160000.1.1 * jackson-databind-javadoc-2.18.9-160000.1.1 * jackson-annotations-2.18.9-160000.1.1 * jackson-databind-2.18.9-160000.1.1 * jackson-annotations-javadoc-2.18.9-160000.1.1 * jackson-core-2.18.9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54515.html * https://www.suse.com/security/cve/CVE-2026-59888.html * https://www.suse.com/security/cve/CVE-2026-59889.html * https://bugzilla.suse.com/show_bug.cgi?id=1268902 * https://bugzilla.suse.com/show_bug.cgi?id=1271440 * https://bugzilla.suse.com/show_bug.cgi?id=1271442 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:56:14 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:56:14 -0000 Subject: SUSE-SU-2026:22821-1: important: Security update for vim Message-ID: <178517497452.2240.11645366625686174469@c3e054a4ce29> # Security update for vim Announcement ID: SUSE-SU-2026:22821-1 Release Date: 2026-07-18T11:51:36Z Rating: important References: * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for vim fixes the following issues: Update to version 9.2.0780. Security issues fixed: * CVE-2026-59856: arbitrary code execution via PHP omni-completion due to improper escaping (bsc#1271194). * CVE-2026-59857: out-of-bounds write in SAL soundfolding due to improper bounds check (bsc#1271195). * CVE-2026-59858: arbitrary code execution via C omni-completion due to improper escaping (bsc#1271193). Other updates and bugfixes: * Version 9.2.0780 changelog: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * tests: test_popupwin fails with zsh because of the prompt (9.2.0757). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * tests: style issue in test_plugin_netrw (9.2.0763). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1283=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1283=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * xxd-debuginfo-9.2.0780-160000.1.1 * vim-small-9.2.0780-160000.1.1 * vim-small-debuginfo-9.2.0780-160000.1.1 * vim-9.2.0780-160000.1.1 * vim-debuginfo-9.2.0780-160000.1.1 * gvim-9.2.0780-160000.1.1 * xxd-9.2.0780-160000.1.1 * gvim-debuginfo-9.2.0780-160000.1.1 * vim-debugsource-9.2.0780-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * vim-data-common-9.2.0780-160000.1.1 * vim-data-9.2.0780-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * vim-data-common-9.2.0780-160000.1.1 * vim-data-9.2.0780-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * xxd-debuginfo-9.2.0780-160000.1.1 * vim-small-9.2.0780-160000.1.1 * vim-small-debuginfo-9.2.0780-160000.1.1 * vim-9.2.0780-160000.1.1 * vim-debuginfo-9.2.0780-160000.1.1 * gvim-9.2.0780-160000.1.1 * xxd-9.2.0780-160000.1.1 * gvim-debuginfo-9.2.0780-160000.1.1 * vim-debugsource-9.2.0780-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:56:56 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:56:56 -0000 Subject: SUSE-RU-2026:22820-1: important: Recommended update for suse-migration-services Message-ID: <178517501628.2240.14680657904082861503@c3e054a4ce29> # Recommended update for suse-migration-services Announcement ID: SUSE-RU-2026:22820-1 Release Date: 2026-07-18T10:13:46Z Rating: important References: * bsc#1258112 * bsc#1260340 * bsc#1263889 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has three fixes can now be installed. ## Description: This update for suse-migration-services fixes the following issues: Changes in suse-migration-services: * yq is only recommended not required * Bump version: 2.1.34 ? 2.1.35 * Update suse-migration-rpm * Handle multipath root (#493) Add handling of multipath_wnn kernel parameter for multipath root. This allows to detect multipath mapped systems and mount them properly in the DMS live migration system and Fixes #491 * Explicitly request python3-base * Make sure to add multipath to the initrd for SAP (bsc#1260340) * Fix install of NetworkManager * Fix missing tests for latest apparmor code change * Bind mount resolv.conf to /system-root/run/.../resolv.conf * Mount /system-root/run as tmpfs Use tmpfs for /run, so we do not write temporal files during migration to disk. * Make sure to add multipath to the initrd (bsc#1260340) * Fix loading SELinux policy of Salt Bundle with workaround * preserve resolv.conf (bsc#1263889) * Avoid temporary test/unit/.coverage in dist archive This temporary file, generated by pytest-cov, is created within each `make test` call containing different content, also if no source files has changed. * Integrate ResolvConf class and reorder network setup services Refactor SetupNameResolver and WickedToNetworkManager to use the new ResolvConf class for unified resolver handling. Swap systemd service dependencies to ensure name resolver setup runs before host network setup. * Add ResolvConf class for unified name resolver mgmt Implement a new ResolvConf class to provide a consistent approach for handling /etc/resolv.conf during migrations. The class introduces logic to: * Detect if /etc/resolv.conf is managed by netconfig or NetworkManager. * Verify user customizations using MD5 checksums (compatible with netconfig) and header analysis. * Preserve custom configurations by moving them to a static file and creating a symlink to prevent future overwrites by network tools. * Support resolver setup for both the target root and live systems. * wicked2nm: explicitly remove sysconfig-netconfig (bsc#1258112) If sysconfig-netconfig is not removed, when dropping wicked, NetworkManager still use `netconfig`. But `netconfig` doesn't find its `/etc/sysconfig/network/scripts/netconfig.function` file, which lead to an error like: `NetworkManager[926]: /usr/sbin/netconfig: line 574: log: command not found` * Fixed log message for already mounted system * Use download-in-advance mode for zypper migration This reduces the risk of download problems while inside of the upgrade process. This Fixes jira#PCT-1170 * Add explicit SLES15 migration target check Instead of falling back to the default with a misleading warning message, make sure to check for this target explicitly beforehand * Bump version: 2.1.33 ? 2.1.34 * Init tools/migrate with debug set to false * Fix Zypper class command output handling The way zypper is called always redirects all output, stdout and stderr into the main log file. Because of that the variables self.output and self.error are always empty. This commit fixes the command call in a way that stdout and stderr are multiplexed such that the caller data can be captured by the python call and the data gets appended to the log file too. This commit also drops the unused and due to the redirection always empty self.error variable. For multiplexing the tee command gets used which impacts the returncode of the actual call. In order to get the correct exit code we use set -o pipefail. * Fix validation of zypper migration result Up to now the assumption was that any situation in which zypper migration cannot migrate the system returns with an error, meaning exit code != 0. However, this assumption is wrong. There are condition in which zypper migration only indicates a problem with a message saying 'No migration available' and the call return with a successful error code = 0. This causes big trouble for the DMS in a way that it continues running its services which all assumes the migration to the next major release was performed. It misleads readers of the log file into the wrong direction and the worst it causes modifications to the host system when it was not migrated. This commit makes sure that the migration stops and treats the above message as an error condition. * Fix quoting * Add time info to backup directory So far only the date information was part of the backup directory. However, if multiple migration attempts happens on the same day, this would overwrite the data. * fix: ensure `logger.handlers` is empty in tests Loggers will only be initialized once; thus if the logger test is scheduled after other tests, loggers might already be initialized and the logger creation code path might not be taken, causing the logger test to fail. * XFSv4 precheck * Fix migrate tool for container based migration The tool overwrites an eventually existing /etc/sle-migration-service.yml config file. This commit fixes it by using yq and inplace updates * update SLES16 DMS image to 16.1 * Fix md device detection Fix detection of device mapper layered rootfs. Software raid disks are not found by findmnt if the actual rootfs is one or more layers down. This commit fixes the detection if we need to pass along the rd.auto cmdline option to let the boot process activate them. * update SLES16 DMS image to 16.1 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1282=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1282=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * suse-migration-services-common-2.1.35-160000.1.1 * suse-migration-pre-checks-2.1.35-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * suse-migration-services-common-2.1.35-160000.1.1 * suse-migration-pre-checks-2.1.35-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1258112 * https://bugzilla.suse.com/show_bug.cgi?id=1260340 * https://bugzilla.suse.com/show_bug.cgi?id=1263889 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:57:28 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:57:28 -0000 Subject: SUSE-SU-2026:22819-1: important: Security update for python-aiohttp Message-ID: <178517504803.2240.3547356444107815667@c3e054a4ce29> # Security update for python-aiohttp Announcement ID: SUSE-SU-2026:22819-1 Release Date: 2026-07-18T09:46:55Z Rating: important References: * bsc#1268398 * bsc#1268543 * bsc#1268544 * bsc#1268549 * bsc#1268556 * bsc#1268559 * bsc#1268560 * bsc#1268561 Cross-References: * CVE-2026-50269 * CVE-2026-54273 * CVE-2026-54274 * CVE-2026-54275 * CVE-2026-54277 * CVE-2026-54278 * CVE-2026-54279 * CVE-2026-54280 CVSS scores: * CVE-2026-50269 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-50269 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50269 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54273 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54273 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54273 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54274 ( SUSE ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U * CVE-2026-54274 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54274 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54274 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54275 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-54275 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54275 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54277 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54277 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54277 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54278 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54278 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54278 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54278 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54279 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54279 ( NVD ): 1.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54279 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54280 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54280 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-aiohttp fixes the following issues * CVE-2026-50269: improper validation of user-controlled strings allows for CRLF injection in multipart headers (bsc#1268398). * CVE-2026-54273: no limit in the HTTP/1 pipelined request queue can lead to excessive resource consumption (bsc#1268543). * CVE-2026-54274: incomplete websocket frame payloads can bypass memory use limits and cause a DoS via excessive resource consumption (bsc#1268544). * CVE-2026-54275: `server_hostname` TLS SNI check bypass when an existing connection is reused (bsc#1268549). * CVE-2026-54277: `max_line_size` bypass when using the optimised C HTTP parser can lead to excessive resource consumption (bsc#1268556). * CVE-2026-54278: unread compressed request bodies can bypass `client_max_size` during cleanup and cause a DoS (bsc#1268559). * CVE-2026-54279: host-only cookies become domain cookies after `CookieJar` persistence (bsc#1268560). * CVE-2026-54280: payload resources are not closed correctly when a client disconnects in the middle of a write and can cause resource starvation (bsc#1268561). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1281=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1281=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-aiohttp-3.11.16-160000.6.1 * python-aiohttp-debugsource-3.11.16-160000.6.1 * python313-aiohttp-debuginfo-3.11.16-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-aiohttp-3.11.16-160000.6.1 * python-aiohttp-debugsource-3.11.16-160000.6.1 * python313-aiohttp-debuginfo-3.11.16-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50269.html * https://www.suse.com/security/cve/CVE-2026-54273.html * https://www.suse.com/security/cve/CVE-2026-54274.html * https://www.suse.com/security/cve/CVE-2026-54275.html * https://www.suse.com/security/cve/CVE-2026-54277.html * https://www.suse.com/security/cve/CVE-2026-54278.html * https://www.suse.com/security/cve/CVE-2026-54279.html * https://www.suse.com/security/cve/CVE-2026-54280.html * https://bugzilla.suse.com/show_bug.cgi?id=1268398 * https://bugzilla.suse.com/show_bug.cgi?id=1268543 * https://bugzilla.suse.com/show_bug.cgi?id=1268544 * https://bugzilla.suse.com/show_bug.cgi?id=1268549 * https://bugzilla.suse.com/show_bug.cgi?id=1268556 * https://bugzilla.suse.com/show_bug.cgi?id=1268559 * https://bugzilla.suse.com/show_bug.cgi?id=1268560 * https://bugzilla.suse.com/show_bug.cgi?id=1268561 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:58:07 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:58:07 -0000 Subject: SUSE-SU-2026:22818-1: important: Security update for gzip Message-ID: <178517508728.2240.1584577073299269230@c3e054a4ce29> # Security update for gzip Announcement ID: SUSE-SU-2026:22818-1 Release Date: 2026-07-18T08:12:44Z Rating: important References: * bsc#1269622 Cross-References: * CVE-2026-41991 CVSS scores: * CVE-2026-41991 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41991 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41991 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41991 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for gzip fixes the following issue * CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1280=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1280=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gzip-debuginfo-1.13-160000.3.1 * gzip-debugsource-1.13-160000.3.1 * gzip-1.13-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gzip-debuginfo-1.13-160000.3.1 * gzip-debugsource-1.13-160000.3.1 * gzip-1.13-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41991.html * https://bugzilla.suse.com/show_bug.cgi?id=1269622 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:58:57 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:58:57 -0000 Subject: SUSE-SU-2026:22817-1: important: Security update for gstreamer-plugins-bad Message-ID: <178517513763.2240.2422588410386101997@c3e054a4ce29> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:22817-1 Release Date: 2026-07-18T06:18:17Z Rating: important References: * bsc#1268168 * bsc#1268172 * bsc#1268406 * bsc#1268408 * bsc#1268410 * bsc#1268872 * bsc#1268971 * bsc#1271051 * bsc#1271168 Cross-References: * CVE-2026-12891 * CVE-2026-12892 * CVE-2026-14935 * CVE-2026-52720 * CVE-2026-52721 * CVE-2026-52722 * CVE-2026-53701 * CVE-2026-53702 * CVE-2026-59692 CVSS scores: * CVE-2026-12891 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-12891 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-12892 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12892 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12892 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-14935 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-14935 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-14935 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-52720 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52721 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-52721 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53701 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53701 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53702 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53702 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59692 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issues * CVE-2026-12891: unchecked aspect_ratio_idc value used as an array index in the H.266 parser could cause a global out- of-bounds read (bsc#1268872). * CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser (bsc#1268971). * CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check (bsc#1271051). * CVE-2026-52720: invalid check of total area instead of individual dimensions could trigger a heap out-of-bounds write (bsc#1268406). * CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could cause an out-of-bounds read (bsc#1268408). * CVE-2026-52722: crafted VMnc stream with large cursor dimensions can overflow signed integer (bsc#1268410). * CVE-2026-53701: multi-slice-in-tile partitions without slice index bounds checks could trigger an out-of-bounds write (bsc#1268172). * CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could result in a stack buffer overflow (bsc#1268168). * CVE-2026-59692: unvalidated peer certificate Subject DN printed during a DTLS handshake could cause a stack buffer overflow (bsc#1271168). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1279=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1279=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libgstadaptivedemux-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstPlayer-1_0-1.26.7-160000.3.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstvulkan-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstinsertbin-1_0-0-1.26.7-160000.3.1 * libgstinsertbin-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstTranscoder-1_0-1.26.7-160000.3.1 * libgstmse-1_0-0-debuginfo-1.26.7-160000.3.1 * libgsttranscoder-1_0-0-1.26.7-160000.3.1 * libgstsctp-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstVa-1_0-1.26.7-160000.3.1 * libgstwayland-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstVulkanXCB-1_0-1.26.7-160000.3.1 * libgstcodecs-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstwebrtcnice-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstphotography-1_0-0-1.26.7-160000.3.1 * gstreamer-transcoder-1.26.7-160000.3.1 * libgstcodecparsers-1_0-0-debuginfo-1.26.7-160000.3.1 * gstreamer-plugins-bad-debugsource-1.26.7-160000.3.1 * typelib-1_0-GstCodecs-1_0-1.26.7-160000.3.1 * libgstsctp-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstmpegts-1_0-0-1.26.7-160000.3.1 * libgstcodecparsers-1_0-0-1.26.7-160000.3.1 * libgstvulkan-1_0-0-1.26.7-160000.3.1 * libgstisoff-1_0-0-1.26.7-160000.3.1 * gstreamer-plugins-bad-debuginfo-1.26.7-160000.3.1 * gstreamer-transcoder-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstPlay-1_0-1.26.7-160000.3.1 * libgstcodecs-1_0-0-1.26.7-160000.3.1 * libgstva-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstanalytics-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstwebrtc-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstphotography-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstva-1_0-0-1.26.7-160000.3.1 * libgstmpegts-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstmse-1_0-0-1.26.7-160000.3.1 * libgstbadaudio-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstbadaudio-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstMse-1_0-1.26.7-160000.3.1 * typelib-1_0-GstVulkan-1_0-1.26.7-160000.3.1 * libgstwebrtc-1_0-0-1.26.7-160000.3.1 * libgstanalytics-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstInsertBin-1_0-1.26.7-160000.3.1 * libgstplay-1_0-0-1.26.7-160000.3.1 * libgsturidownloader-1_0-0-1.26.7-160000.3.1 * libgsturidownloader-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstCuda-1_0-1.26.7-160000.3.1 * libgstisoff-1_0-0-debuginfo-1.26.7-160000.3.1 * libgsttranscoder-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstplayer-1_0-0-1.26.7-160000.3.1 * libgstadaptivedemux-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-CudaGst-1_0-1.26.7-160000.3.1 * libgstcuda-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstAnalytics-1_0-1.26.7-160000.3.1 * libgstcuda-1_0-0-1.26.7-160000.3.1 * libgstbasecamerabinsrc-1_0-0-1.26.7-160000.3.1 * gstreamer-plugins-bad-1.26.7-160000.3.1 * libgstplayer-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstVulkanWayland-1_0-1.26.7-160000.3.1 * typelib-1_0-GstWebRTC-1_0-1.26.7-160000.3.1 * typelib-1_0-GstMpegts-1_0-1.26.7-160000.3.1 * libgstwebrtcnice-1_0-0-1.26.7-160000.3.1 * libgstwayland-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstplay-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstBadAudio-1_0-1.26.7-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * gstreamer-plugins-bad-lang-1.26.7-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libgstadaptivedemux-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstPlayer-1_0-1.26.7-160000.3.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstvulkan-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstinsertbin-1_0-0-1.26.7-160000.3.1 * libgstinsertbin-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstTranscoder-1_0-1.26.7-160000.3.1 * libgstmse-1_0-0-debuginfo-1.26.7-160000.3.1 * libgsttranscoder-1_0-0-1.26.7-160000.3.1 * libgstsctp-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstVulkanXCB-1_0-1.26.7-160000.3.1 * libgstwayland-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstVa-1_0-1.26.7-160000.3.1 * libgstcodecs-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstwebrtcnice-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstphotography-1_0-0-1.26.7-160000.3.1 * gstreamer-transcoder-1.26.7-160000.3.1 * gstreamer-plugins-bad-debugsource-1.26.7-160000.3.1 * libgstcodecparsers-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstCodecs-1_0-1.26.7-160000.3.1 * libgstsctp-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstmpegts-1_0-0-1.26.7-160000.3.1 * libgstvulkan-1_0-0-1.26.7-160000.3.1 * libgstisoff-1_0-0-1.26.7-160000.3.1 * gstreamer-plugins-bad-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstPlay-1_0-1.26.7-160000.3.1 * gstreamer-transcoder-debuginfo-1.26.7-160000.3.1 * libgstcodecs-1_0-0-1.26.7-160000.3.1 * libgstva-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstanalytics-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstwebrtc-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstphotography-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstmpegts-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstbadaudio-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstva-1_0-0-1.26.7-160000.3.1 * libgstmse-1_0-0-1.26.7-160000.3.1 * libgsturidownloader-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstMse-1_0-1.26.7-160000.3.1 * typelib-1_0-GstVulkan-1_0-1.26.7-160000.3.1 * libgstwebrtc-1_0-0-1.26.7-160000.3.1 * libgstbadaudio-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstInsertBin-1_0-1.26.7-160000.3.1 * libgstplay-1_0-0-1.26.7-160000.3.1 * libgsturidownloader-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstanalytics-1_0-0-1.26.7-160000.3.1 * typelib-1_0-GstCuda-1_0-1.26.7-160000.3.1 * libgstisoff-1_0-0-debuginfo-1.26.7-160000.3.1 * libgsttranscoder-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstplayer-1_0-0-1.26.7-160000.3.1 * libgstadaptivedemux-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-CudaGst-1_0-1.26.7-160000.3.1 * libgstcodecparsers-1_0-0-1.26.7-160000.3.1 * libgstcuda-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstcuda-1_0-0-1.26.7-160000.3.1 * libgstbasecamerabinsrc-1_0-0-1.26.7-160000.3.1 * gstreamer-plugins-bad-1.26.7-160000.3.1 * libgstplayer-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstVulkanWayland-1_0-1.26.7-160000.3.1 * typelib-1_0-GstWebRTC-1_0-1.26.7-160000.3.1 * typelib-1_0-GstMpegts-1_0-1.26.7-160000.3.1 * typelib-1_0-GstAnalytics-1_0-1.26.7-160000.3.1 * libgstwayland-1_0-0-debuginfo-1.26.7-160000.3.1 * libgstwebrtcnice-1_0-0-1.26.7-160000.3.1 * libgstplay-1_0-0-debuginfo-1.26.7-160000.3.1 * typelib-1_0-GstBadAudio-1_0-1.26.7-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * gstreamer-plugins-bad-lang-1.26.7-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12891.html * https://www.suse.com/security/cve/CVE-2026-12892.html * https://www.suse.com/security/cve/CVE-2026-14935.html * https://www.suse.com/security/cve/CVE-2026-52720.html * https://www.suse.com/security/cve/CVE-2026-52721.html * https://www.suse.com/security/cve/CVE-2026-52722.html * https://www.suse.com/security/cve/CVE-2026-53701.html * https://www.suse.com/security/cve/CVE-2026-53702.html * https://www.suse.com/security/cve/CVE-2026-59692.html * https://bugzilla.suse.com/show_bug.cgi?id=1268168 * https://bugzilla.suse.com/show_bug.cgi?id=1268172 * https://bugzilla.suse.com/show_bug.cgi?id=1268406 * https://bugzilla.suse.com/show_bug.cgi?id=1268408 * https://bugzilla.suse.com/show_bug.cgi?id=1268410 * https://bugzilla.suse.com/show_bug.cgi?id=1268872 * https://bugzilla.suse.com/show_bug.cgi?id=1268971 * https://bugzilla.suse.com/show_bug.cgi?id=1271051 * https://bugzilla.suse.com/show_bug.cgi?id=1271168 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 17:59:35 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 17:59:35 -0000 Subject: SUSE-RU-2026:22816-1: moderate: Recommended update for gstreamer-plugins-libav Message-ID: <178517517501.2240.4138103332041214521@c3e054a4ce29> # Recommended update for gstreamer-plugins-libav Announcement ID: SUSE-RU-2026:22816-1 Release Date: 2026-07-17T08:38:39Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for gstreamer-plugins-libav fixes the following issues: Rebuilt against current libavfilter. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1278=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1278=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-libav-debuginfo-1.26.7-160000.1.2 * gstreamer-plugins-libav-1.26.7-160000.1.2 * gstreamer-plugins-libav-debugsource-1.26.7-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gstreamer-plugins-libav-debuginfo-1.26.7-160000.1.2 * gstreamer-plugins-libav-1.26.7-160000.1.2 * gstreamer-plugins-libav-debugsource-1.26.7-160000.1.2 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:00:00 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:00:00 -0000 Subject: SUSE-SU-2026:22815-1: moderate: Security update for freetype2 Message-ID: <178517520082.2240.11800980629790050061@c3e054a4ce29> # Security update for freetype2 Announcement ID: SUSE-SU-2026:22815-1 Release Date: 2026-07-16T18:48:33Z Rating: moderate References: * bsc#1252148 * bsc#1259118 * bsc#1271045 Cross-References: * CVE-2026-23865 * CVE-2026-50811 CVSS scores: * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-50811 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-50811 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-50811 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for freetype2 fixes the following issues * Update to version 2.14.3 * CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118). * CVE-2026-50811: out-of-bounds read vulnerabilityin src/truetype/ttgxvar.c in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates (bsc#1271045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1276=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1276=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * freetype2-profile-tti35-2.14.3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * freetype2-devel-2.14.3-160000.1.1 * libfreetype6-debuginfo-2.14.3-160000.1.1 * ftdump-debuginfo-2.14.3-160000.1.1 * libfreetype6-2.14.3-160000.1.1 * freetype2-debugsource-2.14.3-160000.1.1 * ftdump-2.14.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * freetype2-devel-2.14.3-160000.1.1 * libfreetype6-debuginfo-2.14.3-160000.1.1 * ftdump-debuginfo-2.14.3-160000.1.1 * libfreetype6-2.14.3-160000.1.1 * freetype2-debugsource-2.14.3-160000.1.1 * ftdump-2.14.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * freetype2-profile-tti35-2.14.3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-50811.html * https://bugzilla.suse.com/show_bug.cgi?id=1252148 * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1271045 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:00:46 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:00:46 -0000 Subject: SUSE-SU-2026:22814-1: important: Security update for vim Message-ID: <178517524618.2240.13380069014070660911@c3e054a4ce29> # Security update for vim Announcement ID: SUSE-SU-2026:22814-1 Release Date: 2026-07-22T11:18:45Z Rating: important References: * bsc#1269570 * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-58058 * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-58058 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58058 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58058 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 * SUSE Linux Micro 6.1 * SUSE Linux Micro Extras 6.1 An update that solves four vulnerabilities can now be installed. ## Security update for vim ### Description: This update for vim fixes the following issues * Updated to version 9.2.0780 * CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). * CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). * CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). ## Security update for nmap ### Description: This update for nmap fixes the following issue * CVE-2026-58058: crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash (bsc#1269570). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1267=1 * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-Extras-6.1-633=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1267=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * nmap-debuginfo-7.92-160000.3.1 * nmap-7.92-160000.3.1 * ncat-debuginfo-7.92-160000.3.1 * nmap-debugsource-7.92-160000.3.1 * ncat-7.92-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * nmap-debuginfo-7.92-160000.3.1 * nmap-7.92-160000.3.1 * ncat-debuginfo-7.92-160000.3.1 * nmap-debugsource-7.92-160000.3.1 * ncat-7.92-160000.3.1 * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * vim-debuginfo-9.2.0780-slfo.1.1_1.1 * vim-9.2.0780-slfo.1.1_1.1 * vim-debugsource-9.2.0780-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58058.html * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1269570 * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:01:28 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:01:28 -0000 Subject: SUSE-RU-2026:22813-1: moderate: Recommended update for polkit-default-privs Message-ID: <178517528828.2240.2870636719074648235@c3e054a4ce29> # Recommended update for polkit-default-privs Announcement ID: SUSE-RU-2026:22813-1 Release Date: 2026-07-15T08:59:38Z Rating: moderate References: * bsc#1235659 * bsc#1253111 * bsc#1267014 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has three fixes can now be installed. ## Description: This update for polkit-default-privs fixes the following issues: Changes in polkit-default-privs: Update to version 1550+20260709.b1b58aa: * profiles: fwupd new actions in 2.1.4 (bsc#1267014) * profiles: fwupd (bsc#1253111) * profiles: add left out emulation-load action for fwupd (bsc#1235659) * profiles: whitelist fwupd 2.0 major update actions (bsc#1235659) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1265=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1265=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * polkit-default-privs-1550+20260709.b1b58aa-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * polkit-default-privs-1550+20260709.b1b58aa-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1235659 * https://bugzilla.suse.com/show_bug.cgi?id=1253111 * https://bugzilla.suse.com/show_bug.cgi?id=1267014 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:08:22 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:08:22 -0000 Subject: SUSE-SU-2026:22812-1: important: Security update for the Linux Kernel Message-ID: <178517570213.2240.196540783802061092@c3e054a4ce29> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22812-1 Release Date: 2026-07-21T08:27:33Z Rating: important References: * bsc#1149651 * bsc#1204315 * bsc#1236743 * bsc#1255029 * bsc#1257506 * bsc#1258538 * bsc#1259800 * bsc#1260565 * bsc#1261250 * bsc#1261256 * bsc#1261562 * bsc#1261604 * bsc#1262085 * bsc#1262392 * bsc#1262430 * bsc#1262618 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262765 * bsc#1262798 * bsc#1263057 * bsc#1263072 * bsc#1263133 * bsc#1263137 * bsc#1263143 * bsc#1263169 * bsc#1263178 * bsc#1263319 * bsc#1263563 * bsc#1263568 * bsc#1263573 * bsc#1263578 * bsc#1263581 * bsc#1263796 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1263998 * bsc#1264001 * bsc#1264007 * bsc#1264010 * bsc#1264012 * bsc#1264015 * bsc#1264045 * bsc#1264056 * bsc#1264067 * bsc#1264084 * bsc#1264145 * bsc#1264230 * bsc#1264231 * bsc#1264236 * bsc#1264239 * bsc#1264241 * bsc#1264250 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264263 * bsc#1264266 * bsc#1264270 * bsc#1264286 * bsc#1264294 * bsc#1264295 * bsc#1264302 * bsc#1264304 * bsc#1264320 * bsc#1264328 * bsc#1264333 * bsc#1264337 * bsc#1264372 * bsc#1264386 * bsc#1264429 * bsc#1264449 * bsc#1264532 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264549 * bsc#1264556 * bsc#1264561 * bsc#1264580 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264612 * bsc#1264614 * bsc#1264624 * bsc#1264643 * bsc#1264734 * bsc#1264740 * bsc#1264741 * bsc#1264744 * bsc#1264763 * bsc#1264789 * bsc#1264790 * bsc#1264794 * bsc#1264852 * bsc#1264974 * bsc#1264978 * bsc#1264997 * bsc#1265000 * bsc#1265005 * bsc#1265020 * bsc#1265023 * bsc#1265073 * bsc#1265079 * bsc#1265082 * bsc#1265084 * bsc#1265091 * bsc#1265097 * bsc#1265103 * bsc#1265112 * bsc#1265113 * bsc#1265123 * bsc#1265128 * bsc#1265129 * bsc#1265142 * bsc#1265143 * bsc#1265628 * bsc#1265629 * bsc#1266008 * bsc#1266214 * bsc#1266283 * bsc#1266284 * bsc#1266290 * bsc#1266390 * bsc#1266396 * bsc#1266397 * bsc#1266398 * bsc#1266452 * bsc#1266458 * bsc#1266686 * bsc#1266693 * bsc#1266697 * bsc#1266698 * bsc#1266700 * bsc#1266704 * bsc#1266705 * bsc#1266717 * bsc#1266718 * bsc#1266722 * bsc#1266726 * bsc#1266734 * bsc#1266740 * bsc#1266750 * bsc#1266754 * bsc#1266761 * bsc#1266773 * bsc#1266805 * bsc#1266830 * bsc#1266838 * bsc#1266840 * bsc#1266847 * bsc#1266878 * bsc#1266883 * bsc#1266892 * bsc#1266893 * bsc#1266895 * bsc#1266899 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266925 * bsc#1266929 * bsc#1266933 * bsc#1267208 * bsc#1267218 * bsc#1267228 * bsc#1267238 * bsc#1267251 * bsc#1267360 * bsc#1267361 * bsc#1267365 * bsc#1267369 * bsc#1267387 * bsc#1267419 * bsc#1267427 * bsc#1267431 * bsc#1267437 * bsc#1267458 * bsc#1267493 * bsc#1267505 * bsc#1267548 * bsc#1267582 * bsc#1267591 * bsc#1267600 * bsc#1267618 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267635 * bsc#1267637 * bsc#1267640 * bsc#1267654 * bsc#1267682 * bsc#1267684 * bsc#1267685 * bsc#1267697 * bsc#1267717 * bsc#1267722 * bsc#1267732 * bsc#1267744 * bsc#1267816 * bsc#1267824 * bsc#1267825 * bsc#1267937 * bsc#1267966 * bsc#1267992 * bsc#1267993 * bsc#1267994 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268238 * bsc#1268276 * bsc#1268307 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1268989 * bsc#1269022 * bsc#1269031 * bsc#1269033 * bsc#1269036 * bsc#1269087 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269188 * bsc#1269193 * bsc#1269199 * bsc#1269230 * bsc#1269234 * bsc#1269252 * bsc#1269262 * bsc#1269288 * bsc#1269310 * bsc#1269389 * bsc#1269392 * bsc#1269397 * bsc#1269398 * bsc#1269416 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269527 * bsc#1269531 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269617 * bsc#1269645 * bsc#1269646 * bsc#1269647 * bsc#1269651 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269708 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269798 * bsc#1269809 * bsc#1269814 * bsc#1269821 * bsc#1269904 * bsc#1269982 * bsc#1269989 * bsc#1269992 * bsc#1270000 * bsc#1270022 * bsc#1270042 * bsc#1270059 * bsc#1270226 * bsc#1271366 * jsc#PED-10906 * jsc#PED-15986 * jsc#PED-16390 * jsc#SLE-8615 Cross-References: * CVE-2025-10263 * CVE-2025-39894 * CVE-2025-40341 * CVE-2026-23248 * CVE-2026-23394 * CVE-2026-23451 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31438 * CVE-2026-31450 * CVE-2026-31452 * CVE-2026-31466 * CVE-2026-31469 * CVE-2026-31479 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31502 * CVE-2026-31555 * CVE-2026-31560 * CVE-2026-31580 * CVE-2026-31596 * CVE-2026-31646 * CVE-2026-31647 * CVE-2026-31663 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31670 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31743 * CVE-2026-31752 * CVE-2026-31771 * CVE-2026-43010 * CVE-2026-43014 * CVE-2026-43015 * CVE-2026-43016 * CVE-2026-43022 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43034 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43053 * CVE-2026-43057 * CVE-2026-43074 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43083 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43090 * CVE-2026-43092 * CVE-2026-43093 * CVE-2026-43094 * CVE-2026-43101 * CVE-2026-43107 * CVE-2026-43119 * CVE-2026-43124 * CVE-2026-43128 * CVE-2026-43130 * CVE-2026-43132 * CVE-2026-43139 * CVE-2026-43145 * CVE-2026-43157 * CVE-2026-43158 * CVE-2026-43161 * CVE-2026-43167 * CVE-2026-43171 * CVE-2026-43175 * CVE-2026-43187 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43198 * CVE-2026-43199 * CVE-2026-43205 * CVE-2026-43213 * CVE-2026-43226 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43260 * CVE-2026-43283 * CVE-2026-43284 * CVE-2026-43298 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43337 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43351 * CVE-2026-43373 * CVE-2026-43374 * CVE-2026-43383 * CVE-2026-43384 * CVE-2026-43386 * CVE-2026-43403 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43415 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43456 * CVE-2026-43457 * CVE-2026-43458 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43471 * CVE-2026-43491 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45837 * CVE-2026-45838 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45848 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45861 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45884 * CVE-2026-45888 * CVE-2026-45891 * CVE-2026-45894 * CVE-2026-45899 * CVE-2026-45901 * CVE-2026-45912 * CVE-2026-45920 * CVE-2026-45922 * CVE-2026-45933 * CVE-2026-45940 * CVE-2026-45948 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45985 * CVE-2026-45997 * CVE-2026-45999 * CVE-2026-46005 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46078 * CVE-2026-46079 * CVE-2026-46091 * CVE-2026-46093 * CVE-2026-46099 * CVE-2026-46101 * CVE-2026-46111 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46124 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46161 * CVE-2026-46162 * CVE-2026-46172 * CVE-2026-46173 * CVE-2026-46178 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46227 * CVE-2026-46242 * CVE-2026-46244 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46259 * CVE-2026-46266 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46314 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46322 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52919 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52955 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52975 * CVE-2026-52980 * CVE-2026-52993 * CVE-2026-53015 * CVE-2026-53021 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53053 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53081 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53103 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53139 * CVE-2026-53156 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53194 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53249 * CVE-2026-53258 * CVE-2026-53262 * CVE-2026-53263 * CVE-2026-53266 * CVE-2026-53272 * CVE-2026-53274 * CVE-2026-53281 * CVE-2026-53285 * CVE-2026-53286 * CVE-2026-53287 * CVE-2026-53306 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-39894 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-39894 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23248 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23394 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23394 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31479 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31479 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31560 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31580 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31646 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31646 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31646 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31647 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31743 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31743 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43016 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43090 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43090 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43094 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43124 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43130 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43130 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43132 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43145 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43145 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43145 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43175 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43213 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43260 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43283 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43283 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43298 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43298 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43298 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43374 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43383 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-43384 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43384 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-43384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43403 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43403 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43415 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43415 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43415 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43449 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43457 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43457 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43458 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43458 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43471 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45837 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45837 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45837 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45861 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45861 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45884 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45884 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45884 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45888 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45888 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45888 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45901 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45901 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45901 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45922 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45922 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45922 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45999 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45999 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46078 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46078 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46093 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46099 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46099 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52919 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52962 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52980 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52980 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53015 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53049 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53103 ( SUSE ): 5.9 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53103 ( SUSE ): 4.8 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53103 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53122 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53139 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53156 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53156 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53176 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53194 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53194 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53194 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53215 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53258 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53262 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53262 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53263 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53272 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53272 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53272 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53274 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53286 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server High Availability Extension 16.0 An update that solves 255 vulnerabilities, contains four features and has 30 fixes can now be installed. ## Description: The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-10263: arm64: cputype: Add C1-Premium definitions (bsc#1266290). * CVE-2025-39894: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm (bsc#1262430). * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2026-23248: perf: Make perf_pmu_unregister() useable (bsc#1259800). * CVE-2026-23394: Revert: "af_unix: Remove lock dance in unix_peek_fds()." (bsc#1260565). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31438: netfs: Fix kernel BUG in netfs_limit_iter() for ITER_KVEC iterators (bsc#1267824). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). * CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31646: net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() (bsc#1263796). * CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578). * CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31743: nvmem: zynqmp_nvmem: Fix buffer size in DMA and memcpy (bsc#1264067). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43014,CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal (bsc#1264010 bsc#1264012). * CVE-2026-43016: bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready() (bsc#1264007). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084). * CVE-2026-43057: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback (bsc#1264056). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43090: xfrm: fix refcount leak in xfrm_migrate_policy_find (bsc#1264250). * CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43130: iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode (bsc#1264532). * CVE-2026-43132: dm-verity: correctly handle dm_bufio_client_create() failure (bsc#1264614). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43145: remoteproc: imx_rproc: Fix invalid loaded resource table detection (bsc#1265091). * CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43161: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode (bsc#1264333). * CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). * CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549). * CVE-2026-43175: clk: rs9: Reserve 8 struct clk_hw slots for for 9FGV0841 (bsc#1264372). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to- PLL_ON for TMDS on DCN35 (bsc#1264548). * CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). * CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). * CVE-2026-43213: wifi: rtw89: pci: validate sequence number of TX release report (bsc#1264643). * CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). * CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). * CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429). * CVE-2026-43283: net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle (bsc#1264295). * CVE-2026-43298: drm/amdgpu: Skip vcn poison irq release on VF (bsc#1264852). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43351: KVM: arm64: gic: Set vgic_model before initing private IRQs (bsc#1265082). * CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). * CVE-2026-43374: net: nexthop: fix percpu use-after-free in remove_nh_grp_entry (bsc#1265084). * CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). * CVE-2026-43384: net/tcp-ao: Fix MAC comparison to be constant-time (bsc#1265097). * CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (bsc#1264740). * CVE-2026-43403: nsfs: tighten permission checks for ns iteration ioctls (bsc#1265129). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43415: scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend (bsc#1265123). * CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). * CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). * CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43457: mctp: i2c: fix skb memory leak in receive path (bsc#1265000). * CVE-2026-43458: serial: caif: hold tty->link reference in ldisc_open and ser_release (bsc#1265005). * CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). * CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). * CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43471: scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_trace() (bsc#1264789). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45837: Require (reasonably) normal mappings for MADV_DOFORK (bsc#1266398). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). * CVE-2026-45858: ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 (bsc#1266773). * CVE-2026-45861: gfs2: Fix slab-use-after-free in qd_put (bsc#1266754). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45884: apparmor: avoid per-cpu hold underflow in aa_get_buffer (bsc#1266718). * CVE-2026-45888: md/raid1: fix memory leak in raid1_run() (bsc#1266761). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). * CVE-2026-45901: netfilter: nf_tables: revert commit_mutex usage in reset path (bsc#1266892). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). * CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805). * CVE-2026-45933: bpf: Preserve id of register in sync_linked_regs() (bsc#1266693). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). * CVE-2026-45999: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (bsc#1266750). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). * CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). * CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents (bsc#1267505). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46093: mm/vmalloc: take vmap_purge_lock in shrinker (bsc#1267548). * CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). * CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: printk: add print_hex_dump_devel() (bsc#1267937). * CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52919: batman-adv: fix tp_meter counter underflow during shutdown (bsc#1269031). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52975: bonding: 3ad: implement proper RCU rules for port->aggregator (bsc#1269234). * CVE-2026-52980: sched/fair: Clear rel_deadline when initializing forked entities (bsc#1269252). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53015: erofs: unify lcn as u64 for 32-bit platforms (bsc#1269087). * CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). * CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). * CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). * CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). * CVE-2026-53081: bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars (bsc#1269708). * CVE-2026-53086: net: bcmgenet: move DESC_INDEX flow to ring 0 (bsc#1269537). * CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). * CVE-2026-53103: wifi: mt76: mt7925: fix potential deadlock in mt7925_roc_abort_sync (bsc#1269416). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). * CVE-2026-53156: nvmem: core: fix use-after-free bugs in error paths (bsc#1269288). * CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). * CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). * CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). * CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). * CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). * CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). * CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). * CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). * CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). * CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). * CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000). * CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression (bsc#1269647). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress (bsc#1269809). * CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). * CVE-2026-53286: idpf: fix double free and use-after-free in aux device error paths (bsc#1269531). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). The following non security issues were fixed: * accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: scarlett2: Allow flash writes ending at segment boundary (git-fixes). * ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes (stable- fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: timer: Forcibly close timer instances at closing (git-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: virtio: Validate control metadata from the device (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64 (bsc#1267600). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: amd: acp-sdw-sof: Bound DAI link iteration (git-fixes). * ASoC: codecs: aw88261: fix incorrect masks for boost regs (git-fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git- fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). * ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). * Bluetooth: bnep: pin L2CAP connection during netdev registration (git- fixes). * Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git- fixes). * Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_core: Fix UAF in hci_unregister_dev() (git-fixes). * Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non- serdev device (git-fixes). * Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). * Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() (git-fixes). * Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). * Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls (git- fixes). * Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). * Bluetooth: ISO: Fix not using bc_sid as advertisement SID (stable-fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * Bluetooth: L2CAP: validate option length before reading conf opt value (git- fixes). * Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). * Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git- fixes). * Bluetooth: sco: Fix a race condition in sco_sock_timeout() (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * bpf: Free reuseport cBPF prog after RCU grace period (git-fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * crypto/hmac: reject keys shorter than 128 bits in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow ffdhe2048 in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow plain ecb() usage in fips mode (bsc#1266284 jsc#PED-15986). * crypto/testmgr: disallow sha224 + sha3-224 in fips mode (bsc#1266284 jsc#PED-15986). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) (git-fixes). * crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) (git-fixes). * crypto: ccp - Do not initialize SNP for SEV ioctls (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * crypto: tegra - Fix dma_free_coherent size error (git-fixes). * crypto: tegra - fix refcount leak in tegra_se_host1x_submit() (git-fixes). * crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm (git-fixes). * dm init: ensure device probing has finished in dm-mod.waitfor= (git-fixes). * dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc (git-fixes). * dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). * drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). * drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git- fixes). * drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: always resume_all after suspend_all (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/gpuvm: Do not prepare NULL objects (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). * drm/imagination: Count paired job fence as dependency in prepare_job() (git- fixes). * drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/rockchip: Test for imported buffers with drm_gem_is_imported() (git- fixes). * drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). * drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). * fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). * fbdev: fix use-after-free in store_modes() (stable-fixes). * fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * ftrace: Check against is_kernel_text() instead of kaslr_offset() (bsc#1267600). * ftrace: Do not over-allocate ftrace memory (bsc#1267600). * ftrace: Have ftrace pages output reflect freed pages (bsc#1267600). * ftrace: Test mcount_loc addr before calling ftrace_call_addr() (bsc#1267600). * ftrace: Update the mcount_loc check of skipped entries (bsc#1267600). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpio: mxc: fix irq_high handling (git-fixes). * gpio: rockchip: convert bank->clk to devm_clk_get_enabled() (git-fixes). * gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write() (git-fixes). * gpio: zynq: fix runtime PM leak on remove (git-fixes). * gpiolib: Extract gpiochip_choose_fwnode() for wider use (stable-fixes). * gpiolib: Remove redundant assignment of return variable (stable-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * HID: core: Add printk_ratelimited variants to hid_warn() etc (stable-fixes). * HID: hid-goodix-spi: validate report size to prevent stack buffer overflow (git-fixes). * HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). * HID: lg-g15: cancel pending work on remove to fix a use-after-free (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: rate-limit hid_warn to prevent log flooding (stable-fixes). * HID: remove duplicate hid_warn_ratelimited definition (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hv: utils: replace deprecated strcpy with strscpy in kvp_register (git- fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (git-fixes). * hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero (git-fixes). * hwmon: (asus_atk0110) Check package count before accessing element (git- fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (max1619) add missing 'select REGMAP' to Kconfig (git-fixes). * hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). * hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). * hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: disable runtime PM on adapter registration failure (git-fixes). * i2c: core: fix adapter debugfs creation (git-fixes). * i2c: core: fix adapter deregistration race (git-fixes). * i2c: core: fix adapter probe deferral loop (git-fixes). * i2c: core: fix adapter registration race (git-fixes). * i2c: core: fix hang on adapter registration failure (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: core: fix NULL-deref on adapter registration failure (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: imx-lpi2c: mark I2C adapter when hardware is powered down (git-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: riic: fix refcount leak in riic_i2c_resume_noirq() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock (git- fixes). * ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: ti-ads1298: add bounds check to pga_settings index (stable-fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: backend: fix uninitialized data in debugfs (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: light: veml6075: add bounds check to veml6075_it_ms index (stable- fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: resolver: ad2s1210: notify trigger and clear state on fault read error (git-fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * io_uring/cancel: de-unionize file and user_data in struct io_cancel_data (git-fixes bsc#1261250). * io_uring/filetable: clamp alloc_hint to the configured alloc range (git- fixes bsc#1261250). * io_uring/io-wq: fix incorrect io_wq_for_each_worker() termination logic (git-fixes bsc#1261250). * io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git- fixes bsc#1261250). * io_uring/wait: fix min_timeout behavior (git-fixes bsc#1261250). * io_uring/waitid: clear waitid info before copying it to userspace (git- fixes). * io_uring: fix min_wait wakeups for SQPOLL (git-fixes bsc#1261250). * ipv4: account for fraggap on the paged allocation path (git-fixes). * ipv6: account for fraggap on the paged allocation path (git-fixes). * KEYS: fix overflow in keyctl_pkey_params_get_2() (git-fixes). * KEYS: Use acquire when reading state in keyring search (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: vgic: Free private_irqs when init fails after allocation (git- fixes). * KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (git-fixes). * KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (git- fixes). * KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2 (git-fixes). * KVM: nVMX: Immediately refresh APICv controls as needed on nested VM-Exit (git-fixes). * KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (git-fixes). * KVM: SEV: Add an anonymous "psc" struct to track current PSC metadata (git- fixes). * KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA (git-fixes). * KVM: SEV: Don't terminate SNP VMs on #VMGEXIT without a registered GHCB (git-fixes). * KVM: SEV: Make it more obvious when KVM is writing back the current PSC index (git-fixes). * KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() (git-fixes). * KVM: SEV: Read start/end indices of PSC requests exactly once per #VMGEXIT (git-fixes). * KVM: SEV: Return INVALID_EVENT for SNP-only #VMGEXIT from non-SNP guest (git-fixes). * KVM: SEV: Return INVALID_INPUT, not MISSING_INPUT, for bad GUEST_REQUEST input(s) (git-fixes). * KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: Use vCPU specific memslots in __kvm_vcpu_map() (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: VMX: Read 32-bit GPR values for ENCLS instructions outside of 64-bit mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86/xen: Bug the VM if 32-bit KVM observes a 64-bit mode hypercall (git-fixes). * KVM: x86/xen: Don't truncate RAX when handling hypercall from protected guest (git-fixes). * KVM: x86: Consolidate CPUID fault handling for emulator and interception logic (git-fixes). * KVM: x86: Fix shadow paging use-after-free due to unexpected role (git- fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Prioritize CPUID faulting over CPUID VM-exits in nested VMX (git- fixes). * KVM: x86: Trace hypercall register _after_ truncating values for 32-bit (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() (git-fixes). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: Pause continuous reads at block boundaries (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program (stable-fixes). * mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g (stable-fixes). * mtd: spi-nor: spansion: use die erase for multi-die devices only (git- fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Cache MANA_QUERY_LINK_CONFIG result to avoid repeated HWC queries (bsc#1268238). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Sync page pool RX frags for CPU (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * net: mana: Validate the packet length reported by the NIC (git-fixes). * net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). * net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). * net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). * net: wwan: iosm: bound device offsets in the MUX downlink decoder (git- fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * packaging: Add nvidia kernel description. * packaging: compute-PATCHVERSION.sh -> compute-PATCHVERSION. * page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562). * page_pool: Move pp_magic check into helper functions (bsc#1261562). * page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). * PCI: Update saved_config_space upon resource assignment (git-fixes). * perf/x86/intel/uncore: Fix die ID init and look up bugs (bsc#1267419). * perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1267419). * platform/x86: dell-laptop: fix missing cleanups in init error path (git- fixes). * platform/x86: intel-hid: Protect ACPI notify handler against recursion (git- fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git- fixes). * ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). * pwm: imx27: Fix variable truncation in .apply() (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (git- fixes). * Revert "fs: don't block i_writecount during exec" (bsc#1269982). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scripts/sorttable: Add helper functions for Elf_Ehdr (bsc#1267600). * scripts/sorttable: Add helper functions for Elf_Shdr (bsc#1267600). * scripts/sorttable: Add helper functions for Elf_Sym (bsc#1267600). * scripts/sorttable: Allow matches to functions before function entry (bsc#1267600). * scripts/sorttable: Always use an array for the mcount_loc sorting (bsc#1267600). * scripts/sorttable: Convert Elf_Ehdr to union (bsc#1267600). * scripts/sorttable: Convert Elf_Sym MACRO over to a union (bsc#1267600). * scripts/sorttable: Fix endianness handling in build-time mcount sort (bsc#1267600). * scripts/sorttable: Get start/stop_mcount_loc from ELF file directly (bsc#1267600). * scripts/sorttable: Have mcount rela sort use direct values (bsc#1267600). * scripts/sorttable: Have the ORC code use the _r() functions to read (bsc#1267600). * scripts/sorttable: Make compare_extable() into two functions (bsc#1267600). * scripts/sorttable: Move code from sorttable.h into sorttable.c (bsc#1267600). * scripts/sorttable: Remove unneeded Elf_Rel (bsc#1267600). * scripts/sorttable: Remove unused macro defines (bsc#1267600). * scripts/sorttable: Remove unused write functions (bsc#1267600). * scripts/sorttable: Replace Elf_Shdr Macro with a union (bsc#1267600). * scripts/sorttable: Use a structure of function pointers for elf helpers (bsc#1267600). * scripts/sorttable: Use normal sort if theres no relocs in the mcount section (bsc#1267600). * scripts/sorttable: Use uint64_t for mcount sorting (bsc#1267600). * scripts/sorttable: Zero out weak functions in mcount_loc table (bsc#1267600). * scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (bsc#1257506). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * selftests/bpf: Add BPF_STRICT_BUILD toggle (poo#202224). * selftests/bpf: Allow test_progs to link with a partial object set (poo#202224). * selftests/bpf: Avoid rebuilds when running emit_tests (poo#202224). * selftests/bpf: Consolidate kernel modules into common directory (poo#202224). * selftests/bpf: Copy test_kmods when installing selftest (poo#202224). * selftests/bpf: Fix runqslower cross-endian build (poo#202224). * selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (poo#202224). * selftests/bpf: make BPF_TARGET_ENDIAN non-recursive to speed up *.bpf.o build (poo#202224). * selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (poo#202224). * selftests/bpf: Provide weak definitions for cross-test functions (poo#202224). * selftests/bpf: Skip tests whose objects were not built (poo#202224). * selftests/bpf: Support cross-endian building (poo#202224). * selftests/bpf: Tolerate benchmark build failures (poo#202224). * selftests/bpf: Tolerate BPF and skeleton generation failures (poo#202224). * selftests/bpf: Tolerate missing files during install (poo#202224). * selftests/bpf: Tolerate test file compilation failures (poo#202224). * serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git- fixes). * serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git- fixes). * serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero (git- fixes). * slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (git-fixes). * slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (git-fixes). * slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * slimbus: qcom-ngd-ctrl: Fix probe error path ordering (git-fixes). * slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (git-fixes). * slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (git- fixes). * slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (git- fixes). * soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() (git-fixes). * soc: qcom: ice: Return -ENODEV if the ICE platform device is not found (git- fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: hisi-kunpeng: Use dev_err_probe() for host registration failure (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * thermal: testing: reject missing command arguments (git-fixes). * thermal: testing: zone: Flush work items during cleanup (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: debugfs: Don't stop reading SB registers if just one fails (git-fixes). * thunderbolt: debugfs: Fix margining error counter buffer leak (git-fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * tools/power/x86/intel-speed-select: Harden daemon pidfile open (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt (git-fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (git-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (stable-fixes). * usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 (git- fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). * wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes). * wifi: mt76: mt7921: fix a potential scan no APs (stable-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer (git- fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links (git- fixes). * wifi: mt76: mt7925: keep TX BA state in the primary WCID (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * x86/cpu/amd: Correct the microcode table for Zenbleed (git-fixes). * x86/cpu: Disable FRED when PTI is forced on (git-fixes). * x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63 (git-fixes). * x86/cpu: Validate CPUID leaf 0x2 EDX output (git-fixes). * x86/irq: Ensure initial PIR loads are performed exactly once (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16390). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16390). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server High Availability Extension 16.0 zypper in -t patch SUSE-SLES-HA-16.0-1295=1 ## Package List: * SUSE Linux Enterprise Server High Availability Extension 16.0 (ppc64le s390x x86_64) * kernel-default-debuginfo-6.12.0-160000.36.1 * dlm-kmp-default-debuginfo-6.12.0-160000.36.1 * kernel-default-debugsource-6.12.0-160000.36.1 * gfs2-kmp-default-debuginfo-6.12.0-160000.36.1 * dlm-kmp-default-6.12.0-160000.36.1 * cluster-md-kmp-default-6.12.0-160000.36.1 * gfs2-kmp-default-6.12.0-160000.36.1 * cluster-md-kmp-default-debuginfo-6.12.0-160000.36.1 * SUSE Linux Enterprise Server High Availability Extension 16.0 (nosrc) * kernel-default-6.12.0-160000.36.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-39894.html * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2026-23248.html * https://www.suse.com/security/cve/CVE-2026-23394.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31438.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31479.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31560.html * https://www.suse.com/security/cve/CVE-2026-31580.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31646.html * https://www.suse.com/security/cve/CVE-2026-31647.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31743.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43014.html * https://www.suse.com/security/cve/CVE-2026-43015.html * https://www.suse.com/security/cve/CVE-2026-43016.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43090.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43094.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43130.html * https://www.suse.com/security/cve/CVE-2026-43132.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43145.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43161.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43175.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43205.html * https://www.suse.com/security/cve/CVE-2026-43213.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43260.html * https://www.suse.com/security/cve/CVE-2026-43283.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43298.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43337.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43351.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43374.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43384.html * https://www.suse.com/security/cve/CVE-2026-43386.html * https://www.suse.com/security/cve/CVE-2026-43403.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43415.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43457.html * https://www.suse.com/security/cve/CVE-2026-43458.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43471.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45837.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45861.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45884.html * https://www.suse.com/security/cve/CVE-2026-45888.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45901.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45922.html * https://www.suse.com/security/cve/CVE-2026-45933.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-45997.html * https://www.suse.com/security/cve/CVE-2026-45999.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46078.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46093.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46162.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52919.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52980.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53015.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53049.html * https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53081.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53103.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53156.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53194.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53262.html * https://www.suse.com/security/cve/CVE-2026-53263.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53272.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53286.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1149651 * https://bugzilla.suse.com/show_bug.cgi?id=1204315 * https://bugzilla.suse.com/show_bug.cgi?id=1236743 * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1257506 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1259800 * https://bugzilla.suse.com/show_bug.cgi?id=1260565 * https://bugzilla.suse.com/show_bug.cgi?id=1261250 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262430 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262765 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1263057 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263169 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263581 * https://bugzilla.suse.com/show_bug.cgi?id=1263796 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264007 * https://bugzilla.suse.com/show_bug.cgi?id=1264010 * https://bugzilla.suse.com/show_bug.cgi?id=1264012 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264056 * https://bugzilla.suse.com/show_bug.cgi?id=1264067 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264231 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264250 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264270 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264295 * https://bugzilla.suse.com/show_bug.cgi?id=1264302 * https://bugzilla.suse.com/show_bug.cgi?id=1264304 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264328 * https://bugzilla.suse.com/show_bug.cgi?id=1264333 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264372 * https://bugzilla.suse.com/show_bug.cgi?id=1264386 * https://bugzilla.suse.com/show_bug.cgi?id=1264429 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264532 * https://bugzilla.suse.com/show_bug.cgi?id=1264544 * https://bugzilla.suse.com/show_bug.cgi?id=1264545 * https://bugzilla.suse.com/show_bug.cgi?id=1264548 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264556 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264580 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264614 * https://bugzilla.suse.com/show_bug.cgi?id=1264624 * https://bugzilla.suse.com/show_bug.cgi?id=1264643 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264740 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264744 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264789 * https://bugzilla.suse.com/show_bug.cgi?id=1264790 * https://bugzilla.suse.com/show_bug.cgi?id=1264794 * https://bugzilla.suse.com/show_bug.cgi?id=1264852 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1264978 * https://bugzilla.suse.com/show_bug.cgi?id=1264997 * https://bugzilla.suse.com/show_bug.cgi?id=1265000 * https://bugzilla.suse.com/show_bug.cgi?id=1265005 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265023 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265079 * https://bugzilla.suse.com/show_bug.cgi?id=1265082 * https://bugzilla.suse.com/show_bug.cgi?id=1265084 * https://bugzilla.suse.com/show_bug.cgi?id=1265091 * https://bugzilla.suse.com/show_bug.cgi?id=1265097 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265112 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265123 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265129 * https://bugzilla.suse.com/show_bug.cgi?id=1265142 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266283 * https://bugzilla.suse.com/show_bug.cgi?id=1266284 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266398 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266458 * https://bugzilla.suse.com/show_bug.cgi?id=1266686 * https://bugzilla.suse.com/show_bug.cgi?id=1266693 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266718 * https://bugzilla.suse.com/show_bug.cgi?id=1266722 * https://bugzilla.suse.com/show_bug.cgi?id=1266726 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266740 * https://bugzilla.suse.com/show_bug.cgi?id=1266750 * https://bugzilla.suse.com/show_bug.cgi?id=1266754 * https://bugzilla.suse.com/show_bug.cgi?id=1266761 * https://bugzilla.suse.com/show_bug.cgi?id=1266773 * https://bugzilla.suse.com/show_bug.cgi?id=1266805 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266838 * https://bugzilla.suse.com/show_bug.cgi?id=1266840 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266883 * https://bugzilla.suse.com/show_bug.cgi?id=1266892 * https://bugzilla.suse.com/show_bug.cgi?id=1266893 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266925 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267360 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267419 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267493 * https://bugzilla.suse.com/show_bug.cgi?id=1267505 * https://bugzilla.suse.com/show_bug.cgi?id=1267548 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267600 * https://bugzilla.suse.com/show_bug.cgi?id=1267618 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1267816 * https://bugzilla.suse.com/show_bug.cgi?id=1267824 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267992 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1267994 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268238 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1268989 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269031 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269087 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269151 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269164 * https://bugzilla.suse.com/show_bug.cgi?id=1269188 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269199 * https://bugzilla.suse.com/show_bug.cgi?id=1269230 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269252 * https://bugzilla.suse.com/show_bug.cgi?id=1269262 * https://bugzilla.suse.com/show_bug.cgi?id=1269288 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269389 * https://bugzilla.suse.com/show_bug.cgi?id=1269392 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269416 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269527 * https://bugzilla.suse.com/show_bug.cgi?id=1269531 * https://bugzilla.suse.com/show_bug.cgi?id=1269532 * https://bugzilla.suse.com/show_bug.cgi?id=1269537 * https://bugzilla.suse.com/show_bug.cgi?id=1269587 * https://bugzilla.suse.com/show_bug.cgi?id=1269617 * https://bugzilla.suse.com/show_bug.cgi?id=1269645 * https://bugzilla.suse.com/show_bug.cgi?id=1269646 * https://bugzilla.suse.com/show_bug.cgi?id=1269647 * https://bugzilla.suse.com/show_bug.cgi?id=1269651 * https://bugzilla.suse.com/show_bug.cgi?id=1269680 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269691 * https://bugzilla.suse.com/show_bug.cgi?id=1269700 * https://bugzilla.suse.com/show_bug.cgi?id=1269708 * https://bugzilla.suse.com/show_bug.cgi?id=1269710 * https://bugzilla.suse.com/show_bug.cgi?id=1269768 * https://bugzilla.suse.com/show_bug.cgi?id=1269795 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269809 * https://bugzilla.suse.com/show_bug.cgi?id=1269814 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269904 * https://bugzilla.suse.com/show_bug.cgi?id=1269982 * https://bugzilla.suse.com/show_bug.cgi?id=1269989 * https://bugzilla.suse.com/show_bug.cgi?id=1269992 * https://bugzilla.suse.com/show_bug.cgi?id=1270000 * https://bugzilla.suse.com/show_bug.cgi?id=1270022 * https://bugzilla.suse.com/show_bug.cgi?id=1270042 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://bugzilla.suse.com/show_bug.cgi?id=1270226 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://jira.suse.com/browse/PED-10906 * https://jira.suse.com/browse/PED-15986 * https://jira.suse.com/browse/PED-16390 * https://jira.suse.com/browse/SLE-8615 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:09:11 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:09:11 -0000 Subject: SUSE-SU-2026:3264-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Message-ID: <178517575163.2240.12024107260341698903@c3e054a4ce29> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3264-1 Release Date: 2026-07-27T11:35:16Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.34 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3264=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-3274=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-3275=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_11-debugsource-7-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_10-debugsource-7-150700.2.1 * kernel-livepatch-6_4_0-150700_53_37-default-debuginfo-7-150700.2.1 * kernel-livepatch-6_4_0-150700_53_37-default-7-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_12-debugsource-6-150700.2.1 * kernel-livepatch-6_4_0-150700_53_40-default-debuginfo-6-150700.2.1 * kernel-livepatch-6_4_0-150700_53_34-default-debuginfo-7-150700.2.1 * kernel-livepatch-6_4_0-150700_53_34-default-7-150700.2.1 * kernel-livepatch-6_4_0-150700_53_40-default-6-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:09:53 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:09:53 -0000 Subject: SUSE-SU-2026:3273-1: moderate: Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base Message-ID: <178517579308.2240.2156229892562207859@c3e054a4ce29> # Security update for jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base Announcement ID: SUSE-SU-2026:3273-1 Release Date: 2026-07-27T11:32:30Z Rating: moderate References: * bsc#1268902 * bsc#1271440 * bsc#1271442 Cross-References: * CVE-2026-54515 * CVE-2026-59888 * CVE-2026-59889 CVSS scores: * CVE-2026-54515 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54515 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-59888 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-59888 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-59888 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-59889 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-59889 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59889 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base fixes the following issues: * CVE-2026-54515: rebuilding the property map from unfiltered bean properties could permit a bypass of @JsonIgnoreProperties exclusions (bsc#1268902). * CVE-2026-59889: missing view guard when deserializing @JsonUnwrapped properties could allow unauthorized writes to @JsonView restricted fields (bsc#1271440). * CVE-2026-59888: mismatch between property renaming and ignore-filtering on Java Records could allow a bypass of @JsonIgnore restrictions (bsc#1271442). Changes for jackson-annotations: * Update to 2.18.9. Changes for jackson-bom: * Update to 2.18.9. Changes for jackson-core: * Update to 2.18.9. Changes for jackson-databind: * Update to 2.18.9: * honor @JsonView for external-type-id (EXTERNAL_PROPERTY) properties (GHSA- mhm7-754m-9p8w). Changes for jackson-dataformats-binary: * Update to 2.18.9. Changes for jackson-modules-base: * Update to 2.18.9. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3273=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3273=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * jackson-annotations-2.18.9-150200.3.25.1 * jackson-databind-2.18.9-150200.3.33.1 * jackson-core-2.18.9-150200.3.25.1 * Development Tools Module 15-SP7 (noarch) * jackson-dataformat-cbor-2.18.9-150200.3.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54515.html * https://www.suse.com/security/cve/CVE-2026-59888.html * https://www.suse.com/security/cve/CVE-2026-59889.html * https://bugzilla.suse.com/show_bug.cgi?id=1268902 * https://bugzilla.suse.com/show_bug.cgi?id=1271440 * https://bugzilla.suse.com/show_bug.cgi?id=1271442 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:10:33 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:10:33 -0000 Subject: SUSE-SU-2026:3272-1: moderate: Security update for openssl-1_0_0 Message-ID: <178517583392.2240.1996285832910728316@c3e054a4ce29> # Security update for openssl-1_0_0 Announcement ID: SUSE-SU-2026:3272-1 Release Date: 2026-07-27T11:31:37Z Rating: moderate References: * bsc#1260446 * bsc#1261678 Cross-References: * CVE-2026-28390 CVSS scores: * CVE-2026-28390 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28390 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28390 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28390 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for openssl-1_0_0 fixes the following issues: * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678). Changes for openssl-1_0_0: * Security fix: * Fix NULL pointer dereference when processing an OCSP response (bsc#1260446). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3272=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3272=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl1_0_0-debuginfo-1.0.2p-3.112.1 * libopenssl1_0_0-hmac-1.0.2p-3.112.1 * openssl-1_0_0-debugsource-1.0.2p-3.112.1 * openssl-1_0_0-1.0.2p-3.112.1 * openssl-1_0_0-debuginfo-1.0.2p-3.112.1 * libopenssl-1_0_0-devel-1.0.2p-3.112.1 * libopenssl1_0_0-1.0.2p-3.112.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libopenssl1_0_0-hmac-32bit-1.0.2p-3.112.1 * libopenssl1_0_0-32bit-1.0.2p-3.112.1 * libopenssl-1_0_0-devel-32bit-1.0.2p-3.112.1 * libopenssl1_0_0-debuginfo-32bit-1.0.2p-3.112.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * openssl-1_0_0-doc-1.0.2p-3.112.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libopenssl1_0_0-debuginfo-1.0.2p-3.112.1 * libopenssl1_0_0-32bit-1.0.2p-3.112.1 * libopenssl1_0_0-debuginfo-32bit-1.0.2p-3.112.1 * libopenssl1_0_0-hmac-1.0.2p-3.112.1 * libopenssl-1_0_0-devel-32bit-1.0.2p-3.112.1 * libopenssl1_0_0-hmac-32bit-1.0.2p-3.112.1 * openssl-1_0_0-debugsource-1.0.2p-3.112.1 * openssl-1_0_0-1.0.2p-3.112.1 * openssl-1_0_0-debuginfo-1.0.2p-3.112.1 * libopenssl-1_0_0-devel-1.0.2p-3.112.1 * libopenssl1_0_0-1.0.2p-3.112.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * openssl-1_0_0-doc-1.0.2p-3.112.1 ## References: * https://www.suse.com/security/cve/CVE-2026-28390.html * https://bugzilla.suse.com/show_bug.cgi?id=1260446 * https://bugzilla.suse.com/show_bug.cgi?id=1261678 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:11:15 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:11:15 -0000 Subject: SUSE-SU-2026:3271-1: important: Security update for vim Message-ID: <178517587561.2240.8409208839824379641@c3e054a4ce29> # Security update for vim Announcement ID: SUSE-SU-2026:3271-1 Release Date: 2026-07-27T11:02:34Z Rating: important References: * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves three vulnerabilities can now be installed. ## Description: This update for vim fixes the following issues * Updated to version 9.2.0780. * CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). * CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). * CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3271=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3271=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3271=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3271=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3271=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3271=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3271=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3271=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * vim-small-debuginfo-9.2.0780-150000.5.99.1 * vim-debuginfo-9.2.0780-150000.5.99.1 * vim-debugsource-9.2.0780-150000.5.99.1 * vim-small-9.2.0780-150000.5.99.1 * gvim-debuginfo-9.2.0780-150000.5.99.1 * gvim-9.2.0780-150000.5.99.1 * vim-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * vim-data-9.2.0780-150000.5.99.1 * vim-data-common-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * vim-small-debuginfo-9.2.0780-150000.5.99.1 * vim-debuginfo-9.2.0780-150000.5.99.1 * vim-debugsource-9.2.0780-150000.5.99.1 * vim-small-9.2.0780-150000.5.99.1 * gvim-debuginfo-9.2.0780-150000.5.99.1 * gvim-9.2.0780-150000.5.99.1 * vim-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * vim-data-9.2.0780-150000.5.99.1 * vim-data-common-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * vim-debugsource-9.2.0780-150000.5.99.1 * vim-small-debuginfo-9.2.0780-150000.5.99.1 * vim-small-9.2.0780-150000.5.99.1 * vim-debuginfo-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * vim-data-common-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * vim-debugsource-9.2.0780-150000.5.99.1 * vim-small-debuginfo-9.2.0780-150000.5.99.1 * vim-small-9.2.0780-150000.5.99.1 * vim-debuginfo-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * vim-data-common-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * vim-small-debuginfo-9.2.0780-150000.5.99.1 * vim-debugsource-9.2.0780-150000.5.99.1 * vim-small-9.2.0780-150000.5.99.1 * vim-debuginfo-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * vim-data-common-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * vim-small-debuginfo-9.2.0780-150000.5.99.1 * vim-debugsource-9.2.0780-150000.5.99.1 * vim-small-9.2.0780-150000.5.99.1 * vim-debuginfo-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * vim-data-common-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * vim-small-debuginfo-9.2.0780-150000.5.99.1 * vim-debuginfo-9.2.0780-150000.5.99.1 * vim-debugsource-9.2.0780-150000.5.99.1 * gvim-debuginfo-9.2.0780-150000.5.99.1 * vim-small-9.2.0780-150000.5.99.1 * gvim-9.2.0780-150000.5.99.1 * vim-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * vim-data-9.2.0780-150000.5.99.1 * vim-data-common-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * vim-data-9.2.0780-150000.5.99.1 * vim-data-common-9.2.0780-150000.5.99.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * vim-small-debuginfo-9.2.0780-150000.5.99.1 * vim-debuginfo-9.2.0780-150000.5.99.1 * vim-debugsource-9.2.0780-150000.5.99.1 * vim-small-9.2.0780-150000.5.99.1 * gvim-debuginfo-9.2.0780-150000.5.99.1 * gvim-9.2.0780-150000.5.99.1 * vim-9.2.0780-150000.5.99.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:11:54 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:11:54 -0000 Subject: SUSE-SU-2026:3270-1: moderate: Security update for alsa Message-ID: <178517591462.2240.14345717591327090500@c3e054a4ce29> # Security update for alsa Announcement ID: SUSE-SU-2026:3270-1 Release Date: 2026-07-27T11:01:30Z Rating: moderate References: * bsc#1268853 Cross-References: * CVE-2026-56109 CVSS scores: * CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56109 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for alsa fixes the following issue * CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that can allow attackers to corrupt memory (bsc#1268853). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3270=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3270=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le x86_64) * libatopology2-debuginfo-1.2.10-150600.4.3.1 * alsa-topology-devel-1.2.10-150600.4.3.1 * libatopology2-1.2.10-150600.4.3.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * alsa-debugsource-1.2.10-150600.4.3.1 * libasound2-debuginfo-1.2.10-150600.4.3.1 * alsa-1.2.10-150600.4.3.1 * libasound2-1.2.10-150600.4.3.1 * alsa-devel-1.2.10-150600.4.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libatopology2-64bit-1.2.10-150600.4.3.1 * alsa-topology-devel-64bit-1.2.10-150600.4.3.1 * libasound2-64bit-1.2.10-150600.4.3.1 * libatopology2-64bit-debuginfo-1.2.10-150600.4.3.1 * alsa-devel-64bit-1.2.10-150600.4.3.1 * libasound2-64bit-debuginfo-1.2.10-150600.4.3.1 * openSUSE Leap 15.6 (noarch) * alsa-docs-1.2.10-150600.4.3.1 * openSUSE Leap 15.6 (x86_64) * libatopology2-32bit-1.2.10-150600.4.3.1 * libasound2-32bit-debuginfo-1.2.10-150600.4.3.1 * libatopology2-32bit-debuginfo-1.2.10-150600.4.3.1 * alsa-topology-devel-32bit-1.2.10-150600.4.3.1 * libasound2-32bit-1.2.10-150600.4.3.1 * alsa-devel-32bit-1.2.10-150600.4.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * alsa-debugsource-1.2.10-150600.4.3.1 * libasound2-debuginfo-1.2.10-150600.4.3.1 * alsa-1.2.10-150600.4.3.1 * libasound2-1.2.10-150600.4.3.1 * alsa-devel-1.2.10-150600.4.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * libatopology2-debuginfo-1.2.10-150600.4.3.1 * libatopology2-1.2.10-150600.4.3.1 * Basesystem Module 15-SP7 (x86_64) * libasound2-32bit-1.2.10-150600.4.3.1 * libasound2-32bit-debuginfo-1.2.10-150600.4.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56109.html * https://bugzilla.suse.com/show_bug.cgi?id=1268853 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:12:51 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:12:51 -0000 Subject: SUSE-SU-2026:3269-1: important: Security update for gzip Message-ID: <178517597151.2240.3235328984210466458@c3e054a4ce29> # Security update for gzip Announcement ID: SUSE-SU-2026:3269-1 Release Date: 2026-07-27T11:01:03Z Rating: important References: * bsc#1269622 Cross-References: * CVE-2026-41991 CVSS scores: * CVE-2026-41991 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41991 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41991 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41991 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gzip fixes the following issue: * CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3269=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3269=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3269=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3269=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3269=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3269=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3269=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3269=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3269=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3269=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3269=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3269=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3269=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3269=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3269=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3269=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * gzip-1.10-150200.13.1 * gzip-debuginfo-1.10-150200.13.1 * gzip-debugsource-1.10-150200.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41991.html * https://bugzilla.suse.com/show_bug.cgi?id=1269622 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:13:43 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:13:43 -0000 Subject: SUSE-SU-2026:3268-1: important: Security update for python-Pillow Message-ID: <178517602341.2240.13099572127035826420@c3e054a4ce29> # Security update for python-Pillow Announcement ID: SUSE-SU-2026:3268-1 Release Date: 2026-07-27T10:59:26Z Rating: important References: * bsc#1270409 * bsc#1270410 * bsc#1270411 * bsc#1270412 * bsc#1271418 * bsc#1271419 * bsc#1271420 * bsc#1271421 * bsc#1271422 * bsc#1271424 * bsc#1271425 Cross-References: * CVE-2026-54058 * CVE-2026-54059 * CVE-2026-54060 * CVE-2026-55379 * CVE-2026-55380 * CVE-2026-59197 * CVE-2026-59198 * CVE-2026-59199 * CVE-2026-59200 * CVE-2026-59204 * CVE-2026-59205 CVSS scores: * CVE-2026-54058 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54058 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-54058 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59197 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-59197 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-59197 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-59198 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59198 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59198 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-59199 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59199 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59200 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59200 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59200 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59204 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59204 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59205 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59205 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59205 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues: * CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). * CVE-2026-54059: bomb protection bypass via PCF font loading due to `Image.frombytes()` being called without `_decompression_bomb_check()` (bsc#1270409). * CVE-2026-54060: excessive allocation due to `FontFile.compile()`: `Image.new()` being called without `_decompression_bomb_check()` (bsc#1270410). * CVE-2026-55379: bomb protection bypass via font loading due to `Image.new()` being called without `_decompression_bomb_check()` (bsc#1270411). * CVE-2026-55380: unchecked 4.3 GB C-heap allocation due to image dimensions being accepted without `_decompression_bomb_check()` in `GdImageFile._open()` (bsc#1270412). * CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). * CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). * CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). * CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). * CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). * CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch (bsc#1271425). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3268=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3268=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3268=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3268=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3268=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3268=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3268=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3268=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3268=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3268=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3268=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3268=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-Pillow-9.5.0-150400.5.25.1 * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-Pillow-9.5.0-150400.5.25.1 * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-Pillow-9.5.0-150400.5.25.1 * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-Pillow-9.5.0-150400.5.25.1 * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-Pillow-9.5.0-150400.5.25.1 * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-Pillow-9.5.0-150400.5.25.1 * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-Pillow-9.5.0-150400.5.25.1 * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-9.5.0-150400.5.25.1 * python-Pillow-debuginfo-9.5.0-150400.5.25.1 * python311-Pillow-debuginfo-9.5.0-150400.5.25.1 * python-Pillow-debugsource-9.5.0-150400.5.25.1 * python311-Pillow-tk-9.5.0-150400.5.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54058.html * https://www.suse.com/security/cve/CVE-2026-54059.html * https://www.suse.com/security/cve/CVE-2026-54060.html * https://www.suse.com/security/cve/CVE-2026-55379.html * https://www.suse.com/security/cve/CVE-2026-55380.html * https://www.suse.com/security/cve/CVE-2026-59197.html * https://www.suse.com/security/cve/CVE-2026-59198.html * https://www.suse.com/security/cve/CVE-2026-59199.html * https://www.suse.com/security/cve/CVE-2026-59200.html * https://www.suse.com/security/cve/CVE-2026-59204.html * https://www.suse.com/security/cve/CVE-2026-59205.html * https://bugzilla.suse.com/show_bug.cgi?id=1270409 * https://bugzilla.suse.com/show_bug.cgi?id=1270410 * https://bugzilla.suse.com/show_bug.cgi?id=1270411 * https://bugzilla.suse.com/show_bug.cgi?id=1270412 * https://bugzilla.suse.com/show_bug.cgi?id=1271418 * https://bugzilla.suse.com/show_bug.cgi?id=1271419 * https://bugzilla.suse.com/show_bug.cgi?id=1271420 * https://bugzilla.suse.com/show_bug.cgi?id=1271421 * https://bugzilla.suse.com/show_bug.cgi?id=1271422 * https://bugzilla.suse.com/show_bug.cgi?id=1271424 * https://bugzilla.suse.com/show_bug.cgi?id=1271425 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:14:40 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:14:40 -0000 Subject: SUSE-SU-2026:3267-1: important: Security update for ignition Message-ID: <178517608035.2240.9530980623251218514@c3e054a4ce29> # Security update for ignition Announcement ID: SUSE-SU-2026:3267-1 Release Date: 2026-07-27T10:53:03Z Rating: important References: * bsc#1266606 * bsc#1272059 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for ignition fixes the following issues * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266606). * CVE-2026-56852: golang.org/x/text/unicode/norm: handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1272059). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3267=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3267=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * ignition-2.14.0-150400.4.21.1 * ignition-dracut-grub2-2.14.0-150400.4.21.1 * ignition-debuginfo-2.14.0-150400.4.21.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * ignition-2.14.0-150400.4.21.1 * ignition-dracut-grub2-2.14.0-150400.4.21.1 * ignition-debuginfo-2.14.0-150400.4.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266606 * https://bugzilla.suse.com/show_bug.cgi?id=1272059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:15:20 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:15:20 -0000 Subject: SUSE-SU-2026:3266-1: important: Security update for ignition Message-ID: <178517612058.2240.15764390732836048653@c3e054a4ce29> # Security update for ignition Announcement ID: SUSE-SU-2026:3266-1 Release Date: 2026-07-27T10:52:50Z Rating: important References: * bsc#1266606 * bsc#1272059 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves two vulnerabilities can now be installed. ## Description: This update for ignition fixes the following issues * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266606). * CVE-2026-56852: golang.org/x/text/unicode/norm: handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1272059). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3266=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3266=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * ignition-2.15.0-150400.4.20.1 * ignition-dracut-grub2-2.15.0-150400.4.20.1 * ignition-debuginfo-2.15.0-150400.4.20.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * ignition-2.15.0-150400.4.20.1 * ignition-dracut-grub2-2.15.0-150400.4.20.1 * ignition-debuginfo-2.15.0-150400.4.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266606 * https://bugzilla.suse.com/show_bug.cgi?id=1272059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 18:16:00 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 18:16:00 -0000 Subject: SUSE-SU-2026:3265-1: important: Security update for ignition Message-ID: <178517616066.2240.13705925358905976998@c3e054a4ce29> # Security update for ignition Announcement ID: SUSE-SU-2026:3265-1 Release Date: 2026-07-27T10:52:43Z Rating: important References: * bsc#1266606 * bsc#1272059 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves two vulnerabilities can now be installed. ## Description: This update for ignition fixes the following issues * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266606). * CVE-2026-56852: golang.org/x/text/unicode/norm: handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1272059). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3265=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * ignition-2.17.0-150500.3.21.1 * ignition-dracut-grub2-2.17.0-150500.3.21.1 * ignition-debuginfo-2.17.0-150500.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266606 * https://bugzilla.suse.com/show_bug.cgi?id=1272059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:30:17 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:30:17 -0000 Subject: SUSE-SU-2026:22923-1: low: Security update for gpg2 Message-ID: <178518421721.57.5406188645905137928@7908fdd063b2> # Security update for gpg2 Announcement ID: SUSE-SU-2026:22923-1 Release Date: 2026-07-24T12:34:57Z Rating: low References: * bsc#1269279 Cross-References: * CVE-2026-57062 CVSS scores: * CVE-2026-57062 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-57062 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-57062 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for gpg2 fixes the following issue * CVE-2026-57062: CMS parsing in `gpgsm` mishandles the CMS format for AES-GCM (bsc#1269279). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-639=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * gpg2-debuginfo-2.4.4-slfo.1.1_9.1 * gpg2-debugsource-2.4.4-slfo.1.1_9.1 * gpg2-2.4.4-slfo.1.1_9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57062.html * https://bugzilla.suse.com/show_bug.cgi?id=1269279 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:30:55 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:30:55 -0000 Subject: SUSE-SU-2026:22922-1: moderate: Security update for freetype2 Message-ID: <178518425592.57.2783124738256783981@7908fdd063b2> # Security update for freetype2 Announcement ID: SUSE-SU-2026:22922-1 Release Date: 2026-07-24T08:16:08Z Rating: moderate References: * bsc#1271045 Cross-References: * CVE-2026-50811 CVSS scores: * CVE-2026-50811 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-50811 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-50811 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for freetype2 fixes the following issue * Update to version 2.14.3 * CVE-2026-50811: out-of-bounds read vulnerabilityin src/truetype/ttgxvar.c in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates (bsc#1271045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-810=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libfreetype6-debuginfo-2.14.3-1.1 * freetype2-debugsource-2.14.3-1.1 * libfreetype6-2.14.3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50811.html * https://bugzilla.suse.com/show_bug.cgi?id=1271045 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:31:46 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:31:46 -0000 Subject: SUSE-SU-2026:22921-1: important: Security update for rust-keylime Message-ID: <178518430654.57.5101984236721610398@7908fdd063b2> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:22921-1 Release Date: 2026-07-24T08:16:08Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for rust-keylime fixes the following issues Update to version 0.2.9+49. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270614). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270699). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270842). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270999). Other updates and bugfixes: * Update openssl to 0.10.81. * Make tss-esai-sys depend on bindgen 72.1 to support llvm > 21. * Build with Clang <= 21 (bsc#1260596). * Version 0.2.9+49: * build(deps): bump uuid from 1.23.3 to 1.23.4 * build(deps): bump syn from 2.0.117 to 2.0.118 * build(deps): bump openssl from 0.10.80 to 0.10.81 * build(deps): bump rand from 0.9.4 to 0.10.1 * Added new regression test into packit-ci.yaml * build(deps): bump actions/checkout from 6 to 7 * build(deps): bump uuid from 1.23.1 to 1.23.3 * build(deps): bump log from 0.4.29 to 0.4.32 * build(deps): bump http from 1.4.0 to 1.4.2 * build(deps): bump codecov/codecov-action from 6 to 7 * build(deps): bump retry-policies from 0.5.1 to 0.5.2 * fix: Remove unused base64::Engine import in context_info tests * build(deps): bump reqwest-middleware from 0.5.1 to 0.5.2 * build(deps): bump serde_json from 1.0.149 to 1.0.150 * build(deps): bump openssl from 0.10.79 to 0.10.80 * agent: Hash agent ID before TPM2_Certify qualifying data * cargo: Bump tss-esapi, picky-asn1-x509, and picky-asn1-der * build(deps): bump openssl from 0.10.78 to 0.10.79 * build(deps): bump once_cell from 1.21.3 to 1.21.4 * build(deps): bump tempfile from 3.23.0 to 3.27.0 * push-model: cache UEFI event log bytes at startup * build(deps): bump quote from 1.0.40 to 1.0.45 * build(deps): bump chrono from 0.4.42 to 0.4.44 * build(deps): bump openssl from 0.10.73 to 0.10.78 * build(deps): bump serde_json from 1.0.143 to 1.0.149 * build(deps): bump syn from 2.0.106 to 2.0.117 * build(deps): bump libc from 0.2.175 to 0.2.184 * build(deps): bump rand from 0.9.2 to 0.9.4 * Version 0.2.9+21: * tests: use Express-style named params in Mockoon endpoints * build(deps): bump pest_derive from 2.8.1 to 2.8.6 * build(deps): bump trybuild from 1.0.110 to 1.0.115 * build(deps): bump log from 0.4.28 to 0.4.29 * build(deps): bump uuid from 1.19.0 to 1.20.0 * build(deps): bump codecov/codecov-action from 5 to 6 * build(deps): bump tracing-subscriber from 0.3.20 to 0.3.23 * build(deps): bump cfg-if from 1.0.3 to 1.0.4 * build(deps): bump tokio from 1.49.0 to 1.50.0 * build(deps): bump actix-web from 4.12.1 to 4.13.0 * build(deps): bump anyhow from 1.0.99 to 1.0.102 * build(deps): bump clap from 4.5.57 to 4.5.60 * build(deps): bump tracing from 0.1.36 to 0.1.44 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-809=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * rust-keylime-0.2.9+49-1.1 * rust-keylime-debuginfo-0.2.9+49-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:32:25 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:32:25 -0000 Subject: SUSE-SU-2026:22920-1: moderate: Security update for libsoup Message-ID: <178518434516.57.2660178089092304807@7908fdd063b2> # Security update for libsoup Announcement ID: SUSE-SU-2026:22920-1 Release Date: 2026-07-24T08:15:09Z Rating: moderate References: * bsc#1271401 Cross-References: * CVE-2026-0716 * CVE-2026-12478 CVSS scores: * CVE-2026-0716 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0716 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-0716 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12478 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12478 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12478 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libsoup fixes the following issues: * Incomplete fix for CVE-2026-12478: out-of-bounds read in the `process_frame()` function of `SoupWebSocketConnection` (bsc#1271401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-812=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libsoup-3_0-0-debuginfo-3.4.2-17.1 * libsoup-debugsource-3.4.2-17.1 * libsoup-3_0-0-3.4.2-17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0716.html * https://www.suse.com/security/cve/CVE-2026-12478.html * https://bugzilla.suse.com/show_bug.cgi?id=1271401 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:33:04 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:33:04 -0000 Subject: SUSE-SU-2026:22919-1: moderate: Security update for libgcrypt Message-ID: <178518438486.57.7302537365478623823@7908fdd063b2> # Security update for libgcrypt Announcement ID: SUSE-SU-2026:22919-1 Release Date: 2026-07-24T08:12:11Z Rating: moderate References: * bsc#1262684 Cross-References: * CVE-2026-41989 CVSS scores: * CVE-2026-41989 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue * CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-811=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libgcrypt-debugsource-1.10.3-4.1 * libgcrypt20-debuginfo-1.10.3-4.1 * libgcrypt20-1.10.3-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41989.html * https://bugzilla.suse.com/show_bug.cgi?id=1262684 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:33:45 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:33:45 -0000 Subject: SUSE-SU-2026:22918-1: important: Security update for gzip Message-ID: <178518442535.57.12098063697376040562@7908fdd063b2> # Security update for gzip Announcement ID: SUSE-SU-2026:22918-1 Release Date: 2026-07-23T11:09:05Z Rating: important References: * bsc#1269622 Cross-References: * CVE-2026-41991 CVSS scores: * CVE-2026-41991 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41991 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41991 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41991 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for gzip fixes the following issue * CVE-2026-41991: insecure temporary file handling in the `gzexe` utility when the `mktemp` utility is not available in a user's `PATH` (bsc#1269622). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-808=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * gzip-debuginfo-1.13-2.1 * gzip-debugsource-1.13-2.1 * gzip-1.13-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41991.html * https://bugzilla.suse.com/show_bug.cgi?id=1269622 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:34:40 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:34:40 -0000 Subject: SUSE-SU-2026:22917-1: important: Security update for afterburn Message-ID: <178518448061.57.18274983865196779764@7908fdd063b2> # Security update for afterburn Announcement ID: SUSE-SU-2026:22917-1 Release Date: 2026-07-23T11:05:19Z Rating: important References: * bsc#1196972 * bsc#1242665 * bsc#1243850 * bsc#1244199 * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2022-24713 * CVE-2024-12224 * CVE-2025-3416 * CVE-2025-5791 * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2022-24713 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2022-24713 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-5791 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-5791 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2025-5791 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for afterburn fixes the following issues Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2022-24713: regex: high complexity when parsing regexes with large repetitions on empty sub-expressions can lead to DoS (bsc#1196972). * CVE-2024-12224: idna: privilege escalation due acceptance Punycode labels that do not produce any non-ASCII when decoded (bsc#1243850). * CVE-2025-3416: openssl: use-after-free in `Md::fetch` and `Cipher::fetch` (bsc#1242665). * CVE-2025-5791: users: `root` appended to group listings unless the correct listing has exactly 1024 groups (bsc#1244199). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ? * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-807=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-1.1 * afterburn-5.10.0.git73.b97f772-1.1 * afterburn-debugsource-5.10.0.git73.b97f772-1.1 * SUSE Linux Micro 6.0 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-1.1 ## References: * https://www.suse.com/security/cve/CVE-2022-24713.html * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-3416.html * https://www.suse.com/security/cve/CVE-2025-5791.html * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1196972 * https://bugzilla.suse.com/show_bug.cgi?id=1242665 * https://bugzilla.suse.com/show_bug.cgi?id=1243850 * https://bugzilla.suse.com/show_bug.cgi?id=1244199 * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:35:26 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:35:26 -0000 Subject: SUSE-SU-2026:3289-1: important: Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5) Message-ID: <178518452618.57.5081555441909899321@7908fdd063b2> # Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3289-1 Release Date: 2026-07-27T15:36:28Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.116 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3289=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-3295=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-3293=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3287=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3292=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-3296=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3294=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3280=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-3279=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3288=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3290=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3289=1 SUSE-2026-3295=1 SUSE-2026-3293=1 SUSE-2026-3287=1 SUSE-2026-3292=1 SUSE-2026-3296=1 SUSE-2026-3294=1 SUSE-2026-3280=1 SUSE-2026-3279=1 SUSE-2026-3288=1 SUSE-2026-3290=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x) * kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:36:28 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:36:28 -0000 Subject: SUSE-SU-2026:3286-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise 15 SP7) Message-ID: <178518458897.57.8076719895561993513@7908fdd063b2> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3286-1 Release Date: 2026-07-27T14:33:45Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.40 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3276=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-3277=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-3278=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3286=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_9-debugsource-9-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_13-debugsource-5-150700.2.1 * kernel-livepatch-6_4_0-150700_53_28-default-10-150700.2.1 * kernel-livepatch-6_4_0-150700_53_28-default-debuginfo-10-150700.2.1 * kernel-livepatch-6_4_0-150700_53_31-default-9-150700.2.1 * kernel-livepatch-6_4_0-150700_53_31-default-debuginfo-9-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_8-debugsource-10-150700.2.1 * kernel-livepatch-6_4_0-150700_53_45-default-5-150700.2.1 * kernel-livepatch-6_4_0-150700_53_45-default-debuginfo-5-150700.2.1 * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_40-rt-debuginfo-6-150700.2.1 * kernel-livepatch-6_4_0-150700_7_40-rt-6-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_12-debugsource-6-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:37:10 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:37:10 -0000 Subject: SUSE-SU-2026:3291-1: important: Security update for python-tornado Message-ID: <178518463058.57.13408045310244058614@7908fdd063b2> # Security update for python-tornado Announcement ID: SUSE-SU-2026:3291-1 Release Date: 2026-07-27T15:15:54Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 12 * SUSE Linux Enterprise Desktop 12 SP1 * SUSE Linux Enterprise Desktop 12 SP2 * SUSE Linux Enterprise Desktop 12 SP3 * SUSE Linux Enterprise Desktop 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Server for the Raspberry Pi 12-SP2 * SUSE Manager Client Tools for SLE 12 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for SLE 12 zypper in -t patch SUSE-SLE-Manager-Tools-12-2026-3291=1 ## Package List: * SUSE Manager Client Tools for SLE 12 (aarch64 ppc64le s390x x86_64) * python-tornado-debugsource-4.2.1-17.21.1 * python-tornado-debuginfo-4.2.1-17.21.1 * python-tornado-4.2.1-17.21.1 * python3-tornado-4.2.1-17.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:38:13 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:38:13 -0000 Subject: SUSE-SU-2026:3284-1: important: Security update for java-11-openjdk Message-ID: <178518469331.57.11767930024757608823@7908fdd063b2> # Security update for java-11-openjdk Announcement ID: SUSE-SU-2026:3284-1 Release Date: 2026-07-27T13:50:29Z Rating: important References: * bsc#1264994 * bsc#1267355 * bsc#1272223 * bsc#1272224 * bsc#1272225 * bsc#1272227 * bsc#1272228 * bsc#1272233 * bsc#1272234 * bsc#1272235 * bsc#1272236 * bsc#1272237 Cross-References: * CVE-2026-41254 * CVE-2026-46917 * CVE-2026-46968 * CVE-2026-47010 * CVE-2026-47021 * CVE-2026-47027 * CVE-2026-47057 * CVE-2026-47058 * CVE-2026-47059 * CVE-2026-47063 * CVE-2026-60147 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47057 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47057 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47058 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47058 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-47058 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 11 vulnerabilities and has one security fix can now be installed. ## Description: This update for java-11-openjdk fixes the following issues Upgrade to upstream tag jdk-11.0.32+9 (July 2026 CPU). Security issues fixed: * CVE-2026-41254: lcms: information disclosure and denial of service via integer overflow in `CubeSize` (bsc#1264994). * CVE-2026-46917: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1272223). * CVE-2026-46968: unauthenticated attacker with network access via TLS can gain unauthorized creation, deletion or modification access to critical data (bsc#1272224). * CVE-2026-47010: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert or delete access to some data (bsc#1272225). * CVE-2026-47021: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272227). * CVE-2026-47027: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272228). * CVE-2026-47057: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1272233). * CVE-2026-47058: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation, deletion or modification access to critical data (bsc#1272234). * CVE-2026-47059: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272235). * CVE-2026-47063: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation, deletion or modification access to critical data (bsc#1272236). * CVE-2026-60147: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert, delete and read access to some data (bsc#1272237). Other updates and bugfixes: * Upgrade to upstream tag jdk-11.0.32+9 (July 2026 CPU): * JDK-8200566: DistributionPointFetcher fails to fetch CRLs if the DistributionPoints field contains more than one DistributionPoint and the first one fails * JDK-8242314: use reproducible random in vmTestbase shared code * JDK-8252412: [macos11] system dynamic libraries removed from filesystem * JDK-8275405: Linking error for classes with lambda template parameters and virtual functions * JDK-8275843: Random crashes while the UI code is executed * JDK-8286562: GCC 12 reports some compiler warnings * JDK-8287491: compiler/jvmci/errors/TestInvalidDebugInfo.java fails new assert: assert((uint)t < T_CONFLICT + 1) failed: invalid type # * JDK-8292177: InitialSecurityProperty JFR event * JDK-8293691: converting a defined BasicType value to a string should not crash the VM * JDK-8298730: Refactor subsystem_file_line_contents and add docs and tests * JDK-8314555: Build with mawk fails on Windows * JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX * JDK-8324243: Compilation failures in java.desktop module with gcc 14 * JDK-8325766: Extend CertificateBuilder to create trust and end entity certificates programmatically * JDK-8327071: [Testbug] g-tests for cgroup leave files in /tmp on linux * JDK-8336498: [macos] [build]: install-file macro may run into permission denied error * JDK-8342858: Make target mac-jdk-bundle fails on chmod command * JDK-8347740: java/io/File/createTempFile/SpecialTempFile.java failing * JDK-8347811: Container detection code for cgroups v2 should use cgroup.controllers * JDK-8349988: Change cgroup version detection logic to not depend on /proc/cgroups * JDK-8350749: Upgrade JLine to 3.29.0 * JDK-8351359: OperatingSystemMXBean: values from getCpuLoad and getProcessCpuLoad are stale after 24.8 days (Windows) * JDK-8353714: [17u] Backport of 8347740 incomplete * JDK-8354878: File Leak in CgroupSubsystemFactory::determine_type of cgroupSubsystem_linux.cpp:300 * JDK-8355077: Compiler error at splashscreen_gif.c due to unterminated string initialization * JDK-8363966: GHA: Switch cross-compiling sysroots to Debian trixie * JDK-8365098: make/RunTests.gmk generates a wrong path to test artifacts on Alpine * JDK-8365660: test/jdk/sun/security/pkcs11/KeyAgreement/ tests skipped without SkipExceprion * JDK-8366159: SkippedException is treated as a pass for pkcs11/KeyStore, pkcs11/SecretKeyFactory and pkcs11/SecureRandom * JDK-8367766: [11u] src/jdk.crypto.ec/share/native/libsunec/ /impl/mpi.c:321:3: error: 'tmp.dp' may be used uninitialized * JDK-8368041: Enhance TLS certificate handling * JDK-8368670: Deadlock in JFR on event register + class load * JDK-8369032: Add test to ensure serialized ICC_Profile stores only necessary optional data * JDK-8369506: Bytecode rewriting causes Java heap corruption on AArch64 * JDK-8371559: Intermittent timeouts in test javax/net/ssl/Stapling/HttpsUrlConnClient.java * JDK-8372351: Add 2 WISeKey roots * JDK-8373275: Improve DTLS handshaking * JDK-8374058: Enhance JPEG handling * JDK-8374888: Implement internal test cache to help UserIterCount test performance * JDK-8375065: Update LCMS to 2.18 * JDK-8377158: Enhance XBM image support * JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable * JDK-8377498: Improve HttpServer handling * JDK-8377833: Enhance Jar file processing * JDK-8378218: MSYS2 reports cygwin triplet causing bash configure failure * JDK-8378631: Update Zlib Data Compression Library to Version 1.3.2 * JDK-8378687: Improve delegation of HttpURLConnection * JDK-8378823: AIX build fails after zlib updated by JDK-8378631 * JDK-8379685: Bump update version of OpenJDK: 11.0.32 * JDK-8380672: Improve certification checking * JDK-8380947: Add pull request template * JDK-8381039: Enhance AWT ImagingLib * JDK-8381049: Enhance Jar handling * JDK-8381185: Improve Nashorn index handling * JDK-8381195: Enhance Dataview Implementation * JDK-8381519: Enhance Der Value Handling * JDK-8381551: DisabledCurve test fails on Windows after disabling SHA1 * JDK-8381796: Enhance Certificate parsing * JDK-8383175: (tz) Update Timezone Data to 2026b * JDK-8383354: Update LCMS to 2.19.1 * JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change * JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily * JDK-8384495: Update Libpng to 1.6.58 * JDK-8384902: Update GIFlib to 6.1.3 * JDK-8386551: Windows build broken because of MSys2/Make update * JDK-8387976: [11u] Remove designator DEFAULT_PROMOTED_VERSION_PRE=ea for release 11.0.32 * Make post scripts less noisy (bsc#1267355). * Use `libalternatives` instead of `update-alternatives` for distributions where `libalternatives` is available. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3284=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3284=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-11-openjdk-debugsource-11.0.32.0-3.102.1 * java-11-openjdk-headless-11.0.32.0-3.102.1 * java-11-openjdk-demo-11.0.32.0-3.102.1 * java-11-openjdk-debuginfo-11.0.32.0-3.102.1 * java-11-openjdk-11.0.32.0-3.102.1 * java-11-openjdk-devel-11.0.32.0-3.102.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debugsource-11.0.32.0-3.102.1 * java-11-openjdk-headless-11.0.32.0-3.102.1 * java-11-openjdk-demo-11.0.32.0-3.102.1 * java-11-openjdk-debuginfo-11.0.32.0-3.102.1 * java-11-openjdk-11.0.32.0-3.102.1 * java-11-openjdk-devel-11.0.32.0-3.102.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-46917.html * https://www.suse.com/security/cve/CVE-2026-46968.html * https://www.suse.com/security/cve/CVE-2026-47010.html * https://www.suse.com/security/cve/CVE-2026-47021.html * https://www.suse.com/security/cve/CVE-2026-47027.html * https://www.suse.com/security/cve/CVE-2026-47057.html * https://www.suse.com/security/cve/CVE-2026-47058.html * https://www.suse.com/security/cve/CVE-2026-47059.html * https://www.suse.com/security/cve/CVE-2026-47063.html * https://www.suse.com/security/cve/CVE-2026-60147.html * https://bugzilla.suse.com/show_bug.cgi?id=1264994 * https://bugzilla.suse.com/show_bug.cgi?id=1267355 * https://bugzilla.suse.com/show_bug.cgi?id=1272223 * https://bugzilla.suse.com/show_bug.cgi?id=1272224 * https://bugzilla.suse.com/show_bug.cgi?id=1272225 * https://bugzilla.suse.com/show_bug.cgi?id=1272227 * https://bugzilla.suse.com/show_bug.cgi?id=1272228 * https://bugzilla.suse.com/show_bug.cgi?id=1272233 * https://bugzilla.suse.com/show_bug.cgi?id=1272234 * https://bugzilla.suse.com/show_bug.cgi?id=1272235 * https://bugzilla.suse.com/show_bug.cgi?id=1272236 * https://bugzilla.suse.com/show_bug.cgi?id=1272237 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:39:01 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:39:01 -0000 Subject: SUSE-SU-2026:3283-1: important: Security update for perl-DBI Message-ID: <178518474161.57.686999234672219975@7908fdd063b2> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:3283-1 Release Date: 2026-07-27T13:45:37Z Rating: important References: * bsc#1271017 * bsc#1271018 * bsc#1271399 * bsc#1271458 * bsc#1271459 * bsc#1271629 Cross-References: * CVE-2026-14380 * CVE-2026-14740 * CVE-2026-15043 * CVE-2026-15392 * CVE-2026-60081 * CVE-2026-60082 CVSS scores: * CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-15043 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-15392 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60081 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60082 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-60082 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). * CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). * CVE-2026-15043: incorrect predicate evaluation in `DBI:SQL:Nano` can lead to bypass of file-backed filters (bsc#1271399). * CVE-2026-15392: missing checks to ensure the table file is not a symlink to an untrusted location in `DBD::File` allows for arbitrary file reads and writes (bsc#1271629). * CVE-2026-60081: no limiting of the path index in profile parser of `DBI:ProfileData` can enable small-file memory-amplification DoS (bsc#1271458). * CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row can lead to a process crash (bsc#1271459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3283=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3283=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3283=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3283=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3283=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3283=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3283=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3283=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14380.html * https://www.suse.com/security/cve/CVE-2026-14740.html * https://www.suse.com/security/cve/CVE-2026-15043.html * https://www.suse.com/security/cve/CVE-2026-15392.html * https://www.suse.com/security/cve/CVE-2026-60081.html * https://www.suse.com/security/cve/CVE-2026-60082.html * https://bugzilla.suse.com/show_bug.cgi?id=1271017 * https://bugzilla.suse.com/show_bug.cgi?id=1271018 * https://bugzilla.suse.com/show_bug.cgi?id=1271399 * https://bugzilla.suse.com/show_bug.cgi?id=1271458 * https://bugzilla.suse.com/show_bug.cgi?id=1271459 * https://bugzilla.suse.com/show_bug.cgi?id=1271629 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 27 20:39:40 2026 From: null at suse.de (SLE-UPDATES) Date: Mon, 27 Jul 2026 20:39:40 -0000 Subject: SUSE-SU-2026:3281-1: low: Security update for wpa_supplicant Message-ID: <178518478077.57.4284744728079485316@7908fdd063b2> # Security update for wpa_supplicant Announcement ID: SUSE-SU-2026:3281-1 Release Date: 2026-07-27T13:40:46Z Rating: low References: * bsc#1239461 Cross-References: * CVE-2025-24912 CVSS scores: * CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for wpa_supplicant fixes the following issues * CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). * Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3281=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3281=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3281=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3281=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24912.html * https://bugzilla.suse.com/show_bug.cgi?id=1239461 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 08:30:32 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 08:30:32 -0000 Subject: SUSE-SU-2026:3316-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 15 SP7) Message-ID: <178522743237.326.7176940741192644735@7908fdd063b2> # Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3316-1 Release Date: 2026-07-27T19:36:28Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.8 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3316=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-3315=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-3308=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-3307=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-3314=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-3311=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3303=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-3304=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-3309=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3312=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3306=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-3310=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3305=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3313=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3316=1 SUSE-2026-3315=1 SUSE-2026-3308=1 SUSE-2026-3307=1 SUSE-2026-3314=1 SUSE-2026-3311=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_14-debugsource-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-10-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_73-default-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_16-debugsource-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_15-debugsource-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_70-default-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-19-150600.2.1 * kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-19-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_78-default-10-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_13-debugsource-19-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_17-debugsource-10-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_5-debugsource-12-150700.2.1 * kernel-livepatch-6_4_0-150700_53_16-default-15-150700.2.1 * kernel-livepatch-6_4_0-150700_53_19-default-debuginfo-12-150700.2.1 * kernel-livepatch-6_4_0-150700_53_16-default-debuginfo-15-150700.2.1 * kernel-livepatch-6_4_0-150700_53_19-default-12-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_4-debugsource-15-150700.2.1 * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_22-rt-11-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_2-debugsource-19-150700.2.1 * kernel-livepatch-6_4_0-150700_7_8-rt-debuginfo-19-150700.2.1 * kernel-livepatch-6_4_0-150700_7_13-rt-debuginfo-15-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_6-debugsource-11-150700.2.1 * kernel-livepatch-6_4_0-150700_7_8-rt-19-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_4-debugsource-15-150700.2.1 * kernel-livepatch-6_4_0-150700_7_13-rt-15-150700.2.1 * kernel-livepatch-6_4_0-150700_7_25-rt-10-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_7-debugsource-10-150700.2.1 * kernel-livepatch-6_4_0-150700_7_22-rt-debuginfo-11-150700.2.1 * kernel-livepatch-6_4_0-150700_7_16-rt-15-150700.2.1 * kernel-livepatch-6_4_0-150700_7_19-rt-debuginfo-12-150700.2.1 * kernel-livepatch-6_4_0-150700_7_19-rt-12-150700.2.1 * kernel-livepatch-6_4_0-150700_7_25-rt-debuginfo-10-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_3-debugsource-15-150700.2.1 * kernel-livepatch-6_4_0-150700_7_16-rt-debuginfo-15-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_5-debugsource-12-150700.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_14-debugsource-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_78-default-10-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-10-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_13-debugsource-19-150600.2.1 * kernel-livepatch-6_4_0-150600_23_73-default-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_16-debugsource-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_15-debugsource-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_70-default-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-19-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-19-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-15-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-10-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-15-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_17-debugsource-10-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 08:31:30 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 08:31:30 -0000 Subject: SUSE-SU-2026:3301-1: important: Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Message-ID: <178522749010.326.10006343832574822935@7908fdd063b2> # Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3301-1 Release Date: 2026-07-27T17:04:53Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.59 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3301=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_59-rt-3-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_16-debugsource-3-150700.2.1 * kernel-livepatch-6_4_0-150700_7_59-rt-debuginfo-3-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 08:32:19 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 08:32:19 -0000 Subject: SUSE-SU-2026:3302-1: moderate: Security update for libssh Message-ID: <178522753933.326.13531818639130463738@7908fdd063b2> # Security update for libssh Announcement ID: SUSE-SU-2026:3302-1 Release Date: 2026-07-27T17:09:32Z Rating: moderate References: * bsc#1259377 * bsc#1272164 * bsc#1272165 * bsc#1272166 * bsc#1272167 * bsc#1272168 * bsc#1272169 * bsc#1272171 Cross-References: * CVE-2026-3731 * CVE-2026-59843 * CVE-2026-59844 * CVE-2026-59845 * CVE-2026-59846 * CVE-2026-59847 * CVE-2026-59848 * CVE-2026-59850 CVSS scores: * CVE-2026-3731 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-3731 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-3731 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3731 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3731 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59843 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59843 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59845 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-59845 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2026-59846 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59846 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59847 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-59847 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59848 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59848 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for libssh fixes the following issues: * CVE-2026-3731: denial of service via out-of-bounds read in SFTP extension name handler (bsc#1259377). * CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). * CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). * CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). * CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). * CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). * CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). * CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3302=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3302=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libssh4-debuginfo-0.9.8-3.24.1 * libssh-config-0.9.8-3.24.1 * libssh-devel-0.9.8-3.24.1 * libssh-debugsource-0.9.8-3.24.1 * libssh4-0.9.8-3.24.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libssh4-32bit-0.9.8-3.24.1 * libssh4-debuginfo-32bit-0.9.8-3.24.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libssh4-debuginfo-0.9.8-3.24.1 * libssh4-32bit-0.9.8-3.24.1 * libssh-config-0.9.8-3.24.1 * libssh-devel-0.9.8-3.24.1 * libssh4-debuginfo-32bit-0.9.8-3.24.1 * libssh-debugsource-0.9.8-3.24.1 * libssh4-0.9.8-3.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3731.html * https://www.suse.com/security/cve/CVE-2026-59843.html * https://www.suse.com/security/cve/CVE-2026-59844.html * https://www.suse.com/security/cve/CVE-2026-59845.html * https://www.suse.com/security/cve/CVE-2026-59846.html * https://www.suse.com/security/cve/CVE-2026-59847.html * https://www.suse.com/security/cve/CVE-2026-59848.html * https://www.suse.com/security/cve/CVE-2026-59850.html * https://bugzilla.suse.com/show_bug.cgi?id=1259377 * https://bugzilla.suse.com/show_bug.cgi?id=1272164 * https://bugzilla.suse.com/show_bug.cgi?id=1272165 * https://bugzilla.suse.com/show_bug.cgi?id=1272166 * https://bugzilla.suse.com/show_bug.cgi?id=1272167 * https://bugzilla.suse.com/show_bug.cgi?id=1272168 * https://bugzilla.suse.com/show_bug.cgi?id=1272169 * https://bugzilla.suse.com/show_bug.cgi?id=1272171 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 08:33:00 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 08:33:00 -0000 Subject: SUSE-SU-2026:3300-1: important: Security update for ignition Message-ID: <178522758013.326.17336434975181944024@7908fdd063b2> # Security update for ignition Announcement ID: SUSE-SU-2026:3300-1 Release Date: 2026-07-27T17:00:29Z Rating: important References: * bsc#1266606 * bsc#1272059 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for ignition fixes the following issues * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266606). * CVE-2026-56852: golang.org/x/text/unicode/norm: handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1272059). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3300=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3300=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-3300=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * ignition-debuginfo-2.14.0-150400.9.21.1 * ignition-dracut-grub2-2.14.0-150400.9.21.1 * ignition-2.14.0-150400.9.21.1 * HPC Module 15-SP7 (aarch64 x86_64) * ignition-debuginfo-2.14.0-150400.9.21.1 * ignition-dracut-grub2-2.14.0-150400.9.21.1 * ignition-2.14.0-150400.9.21.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * ignition-debuginfo-2.14.0-150400.9.21.1 * ignition-dracut-grub2-2.14.0-150400.9.21.1 * ignition-2.14.0-150400.9.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266606 * https://bugzilla.suse.com/show_bug.cgi?id=1272059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 08:34:03 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 08:34:03 -0000 Subject: SUSE-SU-2026:3299-1: important: Security update for gstreamer-plugins-bad Message-ID: <178522764335.326.4637425260160423151@7908fdd063b2> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:3299-1 Release Date: 2026-07-27T16:58:34Z Rating: important References: * bsc#1268168 * bsc#1268406 * bsc#1268408 * bsc#1268410 * bsc#1268971 * bsc#1271168 Cross-References: * CVE-2026-12892 * CVE-2026-52720 * CVE-2026-52721 * CVE-2026-52722 * CVE-2026-53702 * CVE-2026-59692 CVSS scores: * CVE-2026-12892 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12892 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12892 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-52720 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52721 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-52721 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53702 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53702 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59692 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issues: * CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser (bsc#1268971). * CVE-2026-52720: invalid check of total area instead of individual dimensions could trigger a heap out-of-bounds write (bsc#1268406). * CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could cause an out-of-bounds read (bsc#1268408). * CVE-2026-52722: crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic (bsc#1268410). * CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could result in a stack buffer overflow (bsc#1268168). * CVE-2026-59692: unvalidated peer certificate Subject DN printed during a DTLS handshake could cause a stack buffer overflow (bsc#1271168). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3299=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3299=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libgstgl-1_0-0-debuginfo-1.8.3-18.21.1 * libgstcodecparsers-1_0-0-1.8.3-18.21.1 * libgstgl-1_0-0-1.8.3-18.21.1 * libgstbadaudio-1_0-0-1.8.3-18.21.1 * gstreamer-plugins-bad-1.8.3-18.21.1 * libgstbasecamerabinsrc-1_0-0-1.8.3-18.21.1 * libgstbadvideo-1_0-0-1.8.3-18.21.1 * libgstphotography-1_0-0-1.8.3-18.21.1 * libgstbadbase-1_0-0-1.8.3-18.21.1 * libgstbadaudio-1_0-0-debuginfo-1.8.3-18.21.1 * libgstadaptivedemux-1_0-0-debuginfo-1.8.3-18.21.1 * libgstphotography-1_0-0-debuginfo-1.8.3-18.21.1 * libgstbadvideo-1_0-0-debuginfo-1.8.3-18.21.1 * libgstbadbase-1_0-0-debuginfo-1.8.3-18.21.1 * libgstmpegts-1_0-0-debuginfo-1.8.3-18.21.1 * gstreamer-plugins-bad-debuginfo-1.8.3-18.21.1 * gstreamer-plugins-bad-debugsource-1.8.3-18.21.1 * libgstmpegts-1_0-0-1.8.3-18.21.1 * libgstcodecparsers-1_0-0-debuginfo-1.8.3-18.21.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.8.3-18.21.1 * gstreamer-plugins-bad-devel-1.8.3-18.21.1 * libgsturidownloader-1_0-0-debuginfo-1.8.3-18.21.1 * libgstadaptivedemux-1_0-0-1.8.3-18.21.1 * libgsturidownloader-1_0-0-1.8.3-18.21.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * gstreamer-plugins-bad-lang-1.8.3-18.21.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libgstgl-1_0-0-debuginfo-1.8.3-18.21.1 * libgstcodecparsers-1_0-0-1.8.3-18.21.1 * libgstgl-1_0-0-1.8.3-18.21.1 * libgstbadaudio-1_0-0-1.8.3-18.21.1 * gstreamer-plugins-bad-1.8.3-18.21.1 * libgstbasecamerabinsrc-1_0-0-1.8.3-18.21.1 * libgstbadvideo-1_0-0-1.8.3-18.21.1 * libgstphotography-1_0-0-1.8.3-18.21.1 * libgstbadbase-1_0-0-1.8.3-18.21.1 * libgstbadaudio-1_0-0-debuginfo-1.8.3-18.21.1 * libgstadaptivedemux-1_0-0-debuginfo-1.8.3-18.21.1 * libgstphotography-1_0-0-debuginfo-1.8.3-18.21.1 * libgstbadvideo-1_0-0-debuginfo-1.8.3-18.21.1 * libgstbadbase-1_0-0-debuginfo-1.8.3-18.21.1 * libgstmpegts-1_0-0-debuginfo-1.8.3-18.21.1 * gstreamer-plugins-bad-debuginfo-1.8.3-18.21.1 * gstreamer-plugins-bad-debugsource-1.8.3-18.21.1 * libgstmpegts-1_0-0-1.8.3-18.21.1 * libgstcodecparsers-1_0-0-debuginfo-1.8.3-18.21.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.8.3-18.21.1 * gstreamer-plugins-bad-devel-1.8.3-18.21.1 * libgsturidownloader-1_0-0-debuginfo-1.8.3-18.21.1 * libgstadaptivedemux-1_0-0-1.8.3-18.21.1 * libgsturidownloader-1_0-0-1.8.3-18.21.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * gstreamer-plugins-bad-lang-1.8.3-18.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12892.html * https://www.suse.com/security/cve/CVE-2026-52720.html * https://www.suse.com/security/cve/CVE-2026-52721.html * https://www.suse.com/security/cve/CVE-2026-52722.html * https://www.suse.com/security/cve/CVE-2026-53702.html * https://www.suse.com/security/cve/CVE-2026-59692.html * https://bugzilla.suse.com/show_bug.cgi?id=1268168 * https://bugzilla.suse.com/show_bug.cgi?id=1268406 * https://bugzilla.suse.com/show_bug.cgi?id=1268408 * https://bugzilla.suse.com/show_bug.cgi?id=1268410 * https://bugzilla.suse.com/show_bug.cgi?id=1268971 * https://bugzilla.suse.com/show_bug.cgi?id=1271168 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 08:34:42 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 08:34:42 -0000 Subject: SUSE-SU-2026:3298-1: important: Security update for ImageMagick Message-ID: <178522768252.326.9886791748850349725@7908fdd063b2> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3298-1 Release Date: 2026-07-27T16:49:01Z Rating: important References: * bsc#1268878 Cross-References: * CVE-2026-56379 CVSS scores: * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for ImageMagick fixes the following issue: * Extend CVE-2026-56379 patch by f63c78b (bsc#1268878). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3298=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3298=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * ImageMagick-config-6-SUSE-6.8.8.1-71.267.1 * ImageMagick-debuginfo-6.8.8.1-71.267.1 * ImageMagick-devel-6.8.8.1-71.267.1 * libMagickCore-6_Q16-1-6.8.8.1-71.267.1 * libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.267.1 * ImageMagick-config-6-upstream-6.8.8.1-71.267.1 * libMagick++-devel-6.8.8.1-71.267.1 * ImageMagick-debugsource-6.8.8.1-71.267.1 * libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.267.1 * libMagickWand-6_Q16-1-6.8.8.1-71.267.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * ImageMagick-config-6-SUSE-6.8.8.1-71.267.1 * ImageMagick-debuginfo-6.8.8.1-71.267.1 * ImageMagick-devel-6.8.8.1-71.267.1 * libMagickCore-6_Q16-1-6.8.8.1-71.267.1 * libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.267.1 * ImageMagick-config-6-upstream-6.8.8.1-71.267.1 * libMagick++-devel-6.8.8.1-71.267.1 * ImageMagick-debugsource-6.8.8.1-71.267.1 * libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.267.1 * libMagickWand-6_Q16-1-6.8.8.1-71.267.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1268878 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 08:35:21 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 08:35:21 -0000 Subject: SUSE-SU-2026:3297-1: important: Security update for python-msgpack-python Message-ID: <178522772130.326.8400528248050440082@7908fdd063b2> # Security update for python-msgpack-python Announcement ID: SUSE-SU-2026:3297-1 Release Date: 2026-07-27T16:47:55Z Rating: important References: * bsc#1269947 Cross-References: * CVE-2026-57585 CVSS scores: * CVE-2026-57585 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57585 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 12 * SUSE Linux Enterprise Desktop 12 SP1 * SUSE Linux Enterprise Desktop 12 SP2 * SUSE Linux Enterprise Desktop 12 SP3 * SUSE Linux Enterprise Desktop 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Server for the Raspberry Pi 12-SP2 * SUSE Manager Client Tools for SLE 12 An update that solves one vulnerability can now be installed. ## Description: This update for python-msgpack-python fixes the following issue: * CVE-2026-57585: `Unpacker` reuse after a caught error can lead to an out-of- bounds read and a crash (bsc#1269947). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for SLE 12 zypper in -t patch SUSE-SLE-Manager-Tools-12-2026-3297=1 ## Package List: * SUSE Manager Client Tools for SLE 12 (aarch64 ppc64le s390x x86_64) * python-msgpack-python-0.4.6-8.8.1 * python-msgpack-python-debugsource-0.4.6-8.8.1 * python3-msgpack-python-0.4.6-8.8.1 * python-msgpack-python-debuginfo-0.4.6-8.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57585.html * https://bugzilla.suse.com/show_bug.cgi?id=1269947 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:30:18 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:30:18 -0000 Subject: SUSE-RU-2026:22941-1: moderate: Recommended update for policycoreutils Message-ID: <178524181830.392.11371460257051477688@f1bb1996abf5> # Recommended update for policycoreutils Announcement ID: SUSE-RU-2026:22941-1 Release Date: 2026-07-27T09:31:01Z Rating: moderate References: * bsc#1271645 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for policycoreutils fixes the following issues: Changes in policycoreutils: * Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645) * can be dropped once "policycoreutils/scripts/fixfiles: drop /tmp cleanup" is in the upstream release ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1350=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * policycoreutils-python-utils-3.8.1-160000.5.1 * python313-policycoreutils-3.8.1-160000.5.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * policycoreutils-3.8.1-160000.5.1 * policycoreutils-debugsource-3.8.1-160000.5.1 * policycoreutils-devel-debuginfo-3.8.1-160000.5.1 * policycoreutils-debuginfo-3.8.1-160000.5.1 * policycoreutils-devel-3.8.1-160000.5.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271645 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:30:58 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:30:58 -0000 Subject: SUSE-SU-2026:22940-1: moderate: Security update for libssh Message-ID: <178524185863.392.11209316499722015812@f1bb1996abf5> # Security update for libssh Announcement ID: SUSE-SU-2026:22940-1 Release Date: 2026-07-25T17:13:20Z Rating: moderate References: * bsc#1272162 * bsc#1272164 * bsc#1272165 * bsc#1272166 * bsc#1272167 * bsc#1272168 * bsc#1272169 * bsc#1272170 * bsc#1272171 * jsc#PED-15815 Cross-References: * CVE-2026-15370 * CVE-2026-59843 * CVE-2026-59844 * CVE-2026-59845 * CVE-2026-59846 * CVE-2026-59847 * CVE-2026-59848 * CVE-2026-59849 * CVE-2026-59850 CVSS scores: * CVE-2026-15370 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-15370 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15370 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59843 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59843 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59845 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-59845 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2026-59846 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59846 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59847 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-59847 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59848 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59848 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59849 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59849 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59849 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves nine vulnerabilities and contains one feature can now be installed. ## Description: This update for libssh fixes the following issues: * CVE-2026-15370: stack buffer overflow in SFTP server longname construction (bsc#1272162). * CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). * CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). * CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). * CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). * CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). * CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). * CVE-2026-59849: denial of service via automatic certificate authentication loop (bsc#1272170). * CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). Changes for libssh: * Update to 0.11.5: * Zero-initialize every ssh_string * Fix compatibility with C23 / gcc16 * Fix multiple memory leaks, null checks, and error checks * Validate peer public key in DH key exchange * Avoid remote window overflow * Avoid off-by-one overflow during kbdint authentication * Avoid logging uninitialized sequence numbers * Avoid double conversion of SFTP version number * Send correct SFTP server version number * Avoid handling repeated SFTP INIT messages * Harmonize return values from SFTP server callbacks * Update %suse_version checks for SLES 16.x (jsc#PED-15815) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1349=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libssh4-debuginfo-0.11.5-160000.1.1 * libssh4-0.11.5-160000.1.1 * libssh-debugsource-0.11.5-160000.1.1 * SUSE Linux Micro 6.2 (noarch) * libssh-config-0.11.5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15370.html * https://www.suse.com/security/cve/CVE-2026-59843.html * https://www.suse.com/security/cve/CVE-2026-59844.html * https://www.suse.com/security/cve/CVE-2026-59845.html * https://www.suse.com/security/cve/CVE-2026-59846.html * https://www.suse.com/security/cve/CVE-2026-59847.html * https://www.suse.com/security/cve/CVE-2026-59848.html * https://www.suse.com/security/cve/CVE-2026-59849.html * https://www.suse.com/security/cve/CVE-2026-59850.html * https://bugzilla.suse.com/show_bug.cgi?id=1272162 * https://bugzilla.suse.com/show_bug.cgi?id=1272164 * https://bugzilla.suse.com/show_bug.cgi?id=1272165 * https://bugzilla.suse.com/show_bug.cgi?id=1272166 * https://bugzilla.suse.com/show_bug.cgi?id=1272167 * https://bugzilla.suse.com/show_bug.cgi?id=1272168 * https://bugzilla.suse.com/show_bug.cgi?id=1272169 * https://bugzilla.suse.com/show_bug.cgi?id=1272170 * https://bugzilla.suse.com/show_bug.cgi?id=1272171 * https://jira.suse.com/browse/PED-15815 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:31:37 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:31:37 -0000 Subject: SUSE-SU-2026:22939-1: important: Security update for openssl-3 Message-ID: <178524189791.392.12204398197866030370@f1bb1996abf5> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22939-1 Release Date: 2026-07-25T16:46:55Z Rating: important References: * bsc#1271712 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for openssl-3 fixes the following issue: * "HollowByte" DoS via attacker-controlled memory allocation (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1348=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * openssl-3-3.5.0-160000.9.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.9.1 * libopenssl3-debuginfo-3.5.0-160000.9.1 * libopenssl-3-fips-provider-3.5.0-160000.9.1 * openssl-3-debuginfo-3.5.0-160000.9.1 * openssl-3-debugsource-3.5.0-160000.9.1 * libopenssl-3-devel-3.5.0-160000.9.1 * libopenssl3-3.5.0-160000.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:32:17 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:32:17 -0000 Subject: SUSE-SU-2026:22938-1: low: Security update for runc Message-ID: <178524193715.392.18236454189481230024@f1bb1996abf5> # Security update for runc Announcement ID: SUSE-SU-2026:22938-1 Release Date: 2026-07-23T13:37:43Z Rating: low References: * bsc#1268275 Cross-References: * CVE-2025-31133 * CVE-2025-52565 * CVE-2026-41579 CVSS scores: * CVE-2025-31133 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-31133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-31133 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-52565 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-52565 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-52565 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-52565 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2026-41579 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-41579 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for runc fixes the following issues: Update to 1.3.6. * CVE-2026-41579: malicious image with a `/dev` symlink can trigger limited host filesystem integrity violations (bsc#1268275). Other updates and bugfixes: * Version 1.3.6: * Various integration test improvements. * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). * Version 1.3.5: * Recursive atime-related mount flags (rrelatime et al.) are now applied properly. * PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted. * Updated builds to Go 1.25, libseccomp v2.6.0. * Minor signing keyring updates. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1342=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.3.6-160000.1.1 * runc-1.3.6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31133.html * https://www.suse.com/security/cve/CVE-2025-52565.html * https://www.suse.com/security/cve/CVE-2026-41579.html * https://bugzilla.suse.com/show_bug.cgi?id=1268275 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:32:56 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:32:56 -0000 Subject: SUSE-SU-2026:22937-1: moderate: Security update for python-urllib3 Message-ID: <178524197617.392.9108507836818405496@f1bb1996abf5> # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:22937-1 Release Date: 2026-07-23T09:46:34Z Rating: moderate References: * bsc#1268683 Cross-References: * CVE-2026-9375 CVSS scores: * CVE-2026-9375 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-9375 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-9375 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for python-urllib3 fixes the following issue * CVE-2026-9375: decompression bomb bypass in the streaming API when using Brotli support can lead to a denial of service (bsc#1268683). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1341=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * python313-urllib3-2.5.0-160000.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9375.html * https://bugzilla.suse.com/show_bug.cgi?id=1268683 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:33:35 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:33:35 -0000 Subject: SUSE-SU-2026:22936-1: low: Security update for net-tools Message-ID: <178524201521.392.3593396062639285261@f1bb1996abf5> # Security update for net-tools Announcement ID: SUSE-SU-2026:22936-1 Release Date: 2026-07-23T03:41:25Z Rating: low References: * bsc#1254323 Cross-References: * CVE-2024-58251 CVSS scores: * CVE-2024-58251 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-58251 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-58251 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for net-tools fixes the following issue: * CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1340=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * net-tools-2.10-160000.4.1 * net-tools-debugsource-2.10-160000.4.1 * net-tools-debuginfo-2.10-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2024-58251.html * https://bugzilla.suse.com/show_bug.cgi?id=1254323 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:34:14 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:34:14 -0000 Subject: SUSE-SU-2026:22935-1: important: Security update for nm-configurator Message-ID: <178524205410.392.17793833502902766270@f1bb1996abf5> # Security update for nm-configurator Announcement ID: SUSE-SU-2026:22935-1 Release Date: 2026-07-22T19:23:31Z Rating: important References: * bsc#1271392 Cross-References: * CVE-2026-25541 CVSS scores: * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for nm-configurator fixes the following issue Update to version 0.3.5. Security issue fixed: * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271392). Other updates and bugfixes: * Version 0.3.5: * Bump `version` to v0.3.5 (#206) * Bump `clap` 4.5.53 (#205) * Bump `actions/checkout` to 6 (#204) * Bump `nmstate` to 2.2.55 (#203) * Fix for issue #198 VLAN interface renaming (#201) * Bump `serde` to 1.0.228 (#196) * Bump `anyhow` to 1.0.100 (#194) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1339=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * nm-configurator-0.3.5-160000.1.1 * nm-configurator-debuginfo-0.3.5-160000.1.1 * nm-configurator-debugsource-0.3.5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://bugzilla.suse.com/show_bug.cgi?id=1271392 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:34:54 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:34:54 -0000 Subject: SUSE-SU-2026:22934-1: important: Security update for helm Message-ID: <178524209463.392.9524970273574068936@f1bb1996abf5> # Security update for helm Announcement ID: SUSE-SU-2026:22934-1 Release Date: 2026-07-22T17:26:53Z Rating: important References: * bsc#1266598 * bsc#1271997 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for helm fixes the following issues * Update to version 3.21.3 * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1333=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * helm-bash-completion-3.21.3-160000.1.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * helm-3.21.3-160000.1.1 * helm-debuginfo-3.21.3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 * https://bugzilla.suse.com/show_bug.cgi?id=1271997 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:35:34 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:35:34 -0000 Subject: SUSE-RU-2026:22933-1: moderate: Recommended update for python-tornado6 Message-ID: <178524213444.392.13288779421982309981@f1bb1996abf5> # Recommended update for python-tornado6 Announcement ID: SUSE-RU-2026:22933-1 Release Date: 2026-07-22T16:54:24Z Rating: moderate References: * bsc#1269012 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for python-tornado6 fixes the following issues: Changes in python-tornado6: * GHSA-pw6j-qg29-8w7f: CurlAsyncHTTPClient leaks per-request credentials on handle reuse (bsc#1269012) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1332=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * python313-tornado6-debuginfo-6.5-160000.6.1 * python313-tornado6-6.5-160000.6.1 * python-tornado6-debugsource-6.5-160000.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269012 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:35:56 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:35:56 -0000 Subject: SUSE-SU-2026:22932-1: moderate: Security update for avahi Message-ID: <178524215684.392.14944832090625717241@f1bb1996abf5> # Security update for avahi Announcement ID: SUSE-SU-2026:22932-1 Release Date: 2026-07-22T12:40:21Z Rating: moderate References: * bsc#1255451 * jsc#PED-14835 * jsc#PED-14836 Cross-References: * CVE-2025-59529 CVSS scores: * CVE-2025-59529 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability and contains two features can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). Changes for avahi: * Make /var/lib/avahi-autoipd a ghost dir instead of packaging it since avahi- autoipd creates it on start (jsc#PED-14836). * Use libalternative instead of update-alternatives in TW and SLFO (jsc#PED-14835). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1328=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libavahi-client3-debuginfo-0.8-160000.6.1 * avahi-debugsource-0.8-160000.6.1 * avahi-0.8-160000.6.1 * libavahi-common3-debuginfo-0.8-160000.6.1 * libavahi-core7-0.8-160000.6.1 * libavahi-common3-0.8-160000.6.1 * avahi-debuginfo-0.8-160000.6.1 * libavahi-core7-debuginfo-0.8-160000.6.1 * libavahi-client3-0.8-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59529.html * https://bugzilla.suse.com/show_bug.cgi?id=1255451 * https://jira.suse.com/browse/PED-14835 * https://jira.suse.com/browse/PED-14836 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:36:37 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:36:37 -0000 Subject: SUSE-SU-2026:22931-1: moderate: Security update for wpa_supplicant Message-ID: <178524219794.392.2107079625292469778@f1bb1996abf5> # Security update for wpa_supplicant Announcement ID: SUSE-SU-2026:22931-1 Release Date: 2026-07-22T12:37:24Z Rating: moderate References: * bsc#1258365 * bsc#1269892 Cross-References: * CVE-2026-58374 CVSS scores: * CVE-2026-58374 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58374 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58374 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for wpa_supplicant fixes the following issues * CVE-2026-58374: Fixed a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1326=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * wpa_supplicant-debuginfo-2.11-160000.4.1 * wpa_supplicant-2.11-160000.4.1 * wpa_supplicant-debugsource-2.11-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58374.html * https://bugzilla.suse.com/show_bug.cgi?id=1258365 * https://bugzilla.suse.com/show_bug.cgi?id=1269892 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:37:19 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:37:19 -0000 Subject: SUSE-RU-2026:22930-1: important: Recommended update for multipath-tools Message-ID: <178524223980.392.12185971350960337677@f1bb1996abf5> # Recommended update for multipath-tools Announcement ID: SUSE-RU-2026:22930-1 Release Date: 2026-07-22T09:12:21Z Rating: important References: * bsc#1254094 * bsc#1268144 * bsc#1268145 Affected Products: * SUSE Linux Micro 6.2 An update that has three fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Fix ALUA asymmetric access state descriptions in multipathd logs, so that the same terms are used as by the kernel ("lba-dependent", "transitioning"). * Don't set a hardware handler for bio-based multipath devices. * Fix WWID detection for legacy devices that use the older SCSI-2 VPD page 0x83 format for their device identifier. * kpartx: * Fix an integer overflow in the GPT partition table size calculation. (bsc#1268145) * Fix several issues in the DASD partition table reader that could be triggered by a maliciously crafted disk image. (bsc#1268144) * Fix duplicate "checker timed out" log messages when `log_checker_err` is set to `once`. (bsc#1254094) * Avoid potential buffer overflows in the iet and datacore prioritizers. * iet prioritizer: avoid misleading error message with systemd 256 and newer, and properly use udev to derive path parameters. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1324=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * multipath-tools-0.12.3~1+272+suse.c377867-160000.1.1 * libmpath0-0.12.3~1+272+suse.c377867-160000.1.1 * multipath-tools-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * multipath-tools-debugsource-0.12.3~1+272+suse.c377867-160000.1.1 * libmpath0-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * kpartx-debuginfo-0.12.3~1+272+suse.c377867-160000.1.1 * kpartx-0.12.3~1+272+suse.c377867-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1254094 * https://bugzilla.suse.com/show_bug.cgi?id=1268144 * https://bugzilla.suse.com/show_bug.cgi?id=1268145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:37:51 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:37:51 -0000 Subject: SUSE-SU-2026:22929-1: important: Security update for perl Message-ID: <178524227195.392.10407138717108215539@f1bb1996abf5> # Security update for perl Announcement ID: SUSE-SU-2026:22929-1 Release Date: 2026-07-22T08:30:46Z Rating: important References: * bsc#1266304 * bsc#1266361 * bsc#1268349 * bsc#1271372 * bsc#1271386 Cross-References: * CVE-2025-15649 * CVE-2026-12087 * CVE-2026-13221 * CVE-2026-57432 * CVE-2026-8376 CVSS scores: * CVE-2025-15649 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-15649 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12087 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12087 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-13221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13221 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-13221 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-13221 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-57432 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-57432 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-57432 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-57432 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8376 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-8376 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-8376 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8376 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for perl fixes the following issues: * CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date (bsc#1266361). * CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). * CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). * CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out- of-bounds heap read in `pack` and `unpack` (bsc#1271372). * CVE-2026-13221: regex trie branch-count overflow leads to silent false- positive/negative pattern matching (bsc#1271386). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1321=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * perl-base-debuginfo-5.42.0-160000.3.1 * perl-5.42.0-160000.3.1 * perl-debugsource-5.42.0-160000.3.1 * perl-debuginfo-5.42.0-160000.3.1 * perl-base-5.42.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15649.html * https://www.suse.com/security/cve/CVE-2026-12087.html * https://www.suse.com/security/cve/CVE-2026-13221.html * https://www.suse.com/security/cve/CVE-2026-57432.html * https://www.suse.com/security/cve/CVE-2026-8376.html * https://bugzilla.suse.com/show_bug.cgi?id=1266304 * https://bugzilla.suse.com/show_bug.cgi?id=1266361 * https://bugzilla.suse.com/show_bug.cgi?id=1268349 * https://bugzilla.suse.com/show_bug.cgi?id=1271372 * https://bugzilla.suse.com/show_bug.cgi?id=1271386 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:38:39 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:38:39 -0000 Subject: SUSE-SU-2026:22928-1: important: Security update for glib2 Message-ID: <178524231991.392.16683634910503156422@f1bb1996abf5> # Security update for glib2 Announcement ID: SUSE-SU-2026:22928-1 Release Date: 2026-07-22T08:30:46Z Rating: important References: * bsc#1270008 * bsc#1270009 * bsc#1270010 * bsc#1270016 * bsc#1270018 * bsc#1270021 Cross-References: * CVE-2026-58010 * CVE-2026-58011 * CVE-2026-58012 * CVE-2026-58013 * CVE-2026-58014 * CVE-2026-58016 CVSS scores: * CVE-2026-58010 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58012 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). * CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). * CVE-2026-58012: raw byte regex matches with UTF-8 functions during case- change replacements could cause an out-of- bounds read (bsc#1270016). * CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). * CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). * CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1320=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * typelib-1_0-GLib-2_0-2.84.4-160000.4.1 * libgmodule-2_0-0-2.84.4-160000.4.1 * libgmodule-2_0-0-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-2.84.4-160000.4.1 * libgobject-2_0-0-debuginfo-2.84.4-160000.4.1 * typelib-1_0-GModule-2_0-2.84.4-160000.4.1 * libgirepository-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-debugsource-2.84.4-160000.4.1 * typelib-1_0-GObject-2_0-2.84.4-160000.4.1 * libgio-2_0-0-debuginfo-2.84.4-160000.4.1 * libglib-2_0-0-debuginfo-2.84.4-160000.4.1 * libglib-2_0-0-2.84.4-160000.4.1 * glib2-tools-2.84.4-160000.4.1 * glib2-tools-debuginfo-2.84.4-160000.4.1 * libgio-2_0-0-2.84.4-160000.4.1 * typelib-1_0-Gio-2_0-2.84.4-160000.4.1 * libgirepository-2_0-0-2.84.4-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58010.html * https://www.suse.com/security/cve/CVE-2026-58011.html * https://www.suse.com/security/cve/CVE-2026-58012.html * https://www.suse.com/security/cve/CVE-2026-58013.html * https://www.suse.com/security/cve/CVE-2026-58014.html * https://www.suse.com/security/cve/CVE-2026-58016.html * https://bugzilla.suse.com/show_bug.cgi?id=1270008 * https://bugzilla.suse.com/show_bug.cgi?id=1270009 * https://bugzilla.suse.com/show_bug.cgi?id=1270010 * https://bugzilla.suse.com/show_bug.cgi?id=1270016 * https://bugzilla.suse.com/show_bug.cgi?id=1270018 * https://bugzilla.suse.com/show_bug.cgi?id=1270021 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:39:21 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:39:21 -0000 Subject: SUSE-RU-2026:22927-1: important: Recommended update for libzypp Message-ID: <178524236114.392.1253088061725359952@f1bb1996abf5> # Recommended update for libzypp Announcement ID: SUSE-RU-2026:22927-1 Release Date: 2026-07-22T08:30:46Z Rating: important References: * bsc#1261038 * bsc#1268321 Affected Products: * SUSE Linux Micro 6.2 An update that has two fixes can now be installed. ## Description: This update for libzypp fixes the following issues: Changes in libzypp: Update to version 17.38.14 (35): * zypp.conf: add solver.NoUpdateProvide (default: false) option. In general, packages that obsolete another package are treated as update candidates for the obsoleted package. However, SUSE-specific update rules prefer candidates that also explicitly 'provide' the obsoleted package. Sometimes it is necessary or helpful to disable this rule. (may help in bsc#1261038) * Use HttpHeader class for defining host specific http headers (bsc#1268321) * Compile and link with -fPIE to build on sparc64 (fixes #742) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1314=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libzypp-debugsource-17.38.14-160000.1.1 * libzypp-17.38.14-160000.1.1 * libzypp-debuginfo-17.38.14-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1261038 * https://bugzilla.suse.com/show_bug.cgi?id=1268321 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:39:48 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:39:48 -0000 Subject: SUSE-SU-2026:22926-1: important: Security update for perl-DBI Message-ID: <178524238821.392.10080775005475777296@f1bb1996abf5> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:22926-1 Release Date: 2026-07-22T08:18:32Z Rating: important References: * bsc#1271399 * bsc#1271458 * bsc#1271459 * bsc#1271629 Cross-References: * CVE-2026-15043 * CVE-2026-15392 * CVE-2026-60081 * CVE-2026-60082 CVSS scores: * CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-15043 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-15392 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60081 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60082 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-60082 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves four vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues: * CVE-2026-15392: failure to validate symbolic links during table path resolution could allow unauthorized file reads and writes outside the configured data director (bsc#1271629). * CVE-2026-15043: `DBI:SQL:Nano` has incorrect predicate evaluation, which allows for bypass of file-backed filters (bsc#1271399). * CVE-2026-60081: `DBI:ProfileData` does not limit the path index in profile parser, which enables small-file memory-amplification DoS (bsc#1271458). * CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row, which allows for a process crash (bsc#1271459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1322=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * perl-DBI-debuginfo-1.647.0-160000.5.1 * perl-DBI-debugsource-1.647.0-160000.5.1 * perl-DBI-1.647.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15043.html * https://www.suse.com/security/cve/CVE-2026-15392.html * https://www.suse.com/security/cve/CVE-2026-60081.html * https://www.suse.com/security/cve/CVE-2026-60082.html * https://bugzilla.suse.com/show_bug.cgi?id=1271399 * https://bugzilla.suse.com/show_bug.cgi?id=1271458 * https://bugzilla.suse.com/show_bug.cgi?id=1271459 * https://bugzilla.suse.com/show_bug.cgi?id=1271629 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:40:51 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:40:51 -0000 Subject: SUSE-RU-2026:22924-1: important: Recommended update for pesign Message-ID: <178524245145.392.15378727641538947762@f1bb1996abf5> # Recommended update for pesign Announcement ID: SUSE-RU-2026:22924-1 Release Date: 2026-07-22T07:59:30Z Rating: important References: * bsc#1258751 * bsc#1271405 * jsc#PED-14755 Affected Products: * SUSE Linux Micro 6.2 An update that contains one feature and has two fixes can now be installed. ## Description: This update for pesign fixes the following issues: * Set stricter permissions on /etc/pki/pesign (bsc#1271405) * Disable the wchar_t warnings on arm32 * Constify the return pointer of strrchr() (bsc#1258751) * Use /var/lib/empty as the the home directory of the pesign system user and remove /var/lib/pesign (jsc#PED-14755) * Move '/run/pesign' to pesign-systemd which creates the directory in the post script ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1315=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 x86_64) * pesign-116-160000.3.1 * pesign-debugsource-116-160000.3.1 * pesign-debuginfo-116-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1258751 * https://bugzilla.suse.com/show_bug.cgi?id=1271405 * https://jira.suse.com/browse/PED-14755 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:40:27 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:40:27 -0000 Subject: SUSE-RU-2026:22925-1: important: Recommended update for shim Message-ID: <178524242762.392.18445051754524450246@f1bb1996abf5> # Recommended update for shim Announcement ID: SUSE-RU-2026:22925-1 Release Date: 2026-07-22T07:59:30Z Rating: important References: * bsc#1269084 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for shim fixes the following issues: * shim-install: Improve the detection of SL Micro * The GRUB_DISTRIBUTOR variable in SL Micro images may contain "SL Micro" or "SL-Micro" prefix. (bsc#1269084) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1317=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 x86_64) * shim-debuginfo-16.1-160000.2.1 * shim-debugsource-16.1-160000.2.1 * shim-16.1-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269084 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:41:20 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:41:20 -0000 Subject: SUSE-SU-2026:3319-1: important: Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise 15 SP5) Message-ID: <178524248058.392.2452414495992839730@f1bb1996abf5> # Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3319-1 Release Date: 2026-07-28T03:33:52Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.136 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3319=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-3320=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3319=1 SUSE-2026-3320=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-6-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_35-debugsource-10-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-10-150500.2.1 * kernel-livepatch-5_14_21-150500_55_149-default-6-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_38-debugsource-6-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-10-150500.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-6-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_35-debugsource-10-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-10-150500.2.1 * kernel-livepatch-5_14_21-150500_55_149-default-6-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_38-debugsource-6-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-10-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:43:06 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:43:06 -0000 Subject: SUSE-RU-2026:3323-1: important: Recommended update for multipath-tools Message-ID: <178524258691.392.5138624634242723474@f1bb1996abf5> # Recommended update for multipath-tools Announcement ID: SUSE-RU-2026:3323-1 Release Date: 2026-07-28T06:11:58Z Rating: important References: * bsc#1254094 * bsc#1268144 * bsc#1268145 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has three fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Fix ALUA asymmetric access state descriptions in multipathd logs, so that the same terms are used as by the kernel ("lba-dependent", "transitioning"). * Don't set a hardware handler for bio-based multipath devices. * Fix WWID detection for legacy devices that use the older SCSI-2 VPD page 0x83 format for their device identifier. * kpartx: * Fix an integer overflow in the GPT partition table size calculation. (bsc#1268145) * Fix several issues in the DASD partition table reader that could be triggered by a maliciously crafted disk image. (bsc#1268144) * Fix duplicate "checker timed out" log messages when `log_checker_err` is set to `once`. (bsc#1254094) * Avoid potential buffer overflows in the iet and datacore prioritizers. * iet prioritizer: avoid misleading error message with systemd 256 and newer, and properly use udev to derive path parameters. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3323=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libmpath0-debuginfo-0.10.7~1+211+suse.18f1559-150700.3.14.1 * multipath-tools-debugsource-0.10.7~1+211+suse.18f1559-150700.3.14.1 * multipath-tools-0.10.7~1+211+suse.18f1559-150700.3.14.1 * multipath-tools-devel-0.10.7~1+211+suse.18f1559-150700.3.14.1 * libmpath0-0.10.7~1+211+suse.18f1559-150700.3.14.1 * libdmmp-devel-0.10.7~1+211+suse.18f1559-150700.3.14.1 * multipath-tools-debuginfo-0.10.7~1+211+suse.18f1559-150700.3.14.1 * kpartx-debuginfo-0.10.7~1+211+suse.18f1559-150700.3.14.1 * libdmmp0_2_0-debuginfo-0.10.7~1+211+suse.18f1559-150700.3.14.1 * libdmmp0_2_0-0.10.7~1+211+suse.18f1559-150700.3.14.1 * kpartx-0.10.7~1+211+suse.18f1559-150700.3.14.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1254094 * https://bugzilla.suse.com/show_bug.cgi?id=1268144 * https://bugzilla.suse.com/show_bug.cgi?id=1268145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:42:24 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:42:24 -0000 Subject: SUSE-SU-2026:3321-1: important: Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 15 SP7) Message-ID: <178524254449.392.7716132684351432892@f1bb1996abf5> # Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3321-1 Release Date: 2026-07-28T04:35:42Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.6 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3317=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-3318=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-3321=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_25-default-debuginfo-10-150700.2.1 * kernel-livepatch-6_4_0-150700_53_6-default-19-150700.2.1 * kernel-livepatch-6_4_0-150700_53_6-default-debuginfo-19-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_7-debugsource-10-150700.2.1 * kernel-livepatch-6_4_0-150700_53_11-default-15-150700.2.1 * kernel-livepatch-6_4_0-150700_53_11-default-debuginfo-15-150700.2.1 * kernel-livepatch-6_4_0-150700_53_25-default-10-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_3-debugsource-15-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_2-debugsource-19-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 12:43:27 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 12:43:27 -0000 Subject: SUSE-RU-2026:3322-1: moderate: Recommended update for cosign Message-ID: <178524260789.392.16657862315801123130@f1bb1996abf5> # Recommended update for cosign Announcement ID: SUSE-RU-2026:3322-1 Release Date: 2026-07-28T06:11:46Z Rating: moderate References: Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for cosign fixes the following issues: * updated to version 3.1.2: * Deprecate --payload for sign and verify commands * docs: add OVHcloud KMS in available external plugins * Add insecure registry flag to ko publish in kind-verify-attestation workflow * Deprecate --output-attestation * Add bundle inspect command * Guard against empty certificate PEM in mutate.Signature * fix(download): Validate predicate type for new bundle format * Skip nil subject entries in IntotoSubjectClaimVerifier * Fix Makefile: fall back to "unknown" version info when built outside a git repo * fix(verify): skip identity validation for security keys * fix: include artifactType in OCI 1.1 signature referrer manifest * Allow attestation download to handle both bundle types * Fix panic in dockerfile verify on malformed FROM lines * fix(release): restore signing-step auth and fail on image signing errors * feat(signing-config): add --base-config flag to override services from base config * fix: pass NewBundleFormat to KeyOpts in sign command * fix: ignore build stage references in dockerfile verify * fix: allow '=' in annotation values * Remove unused policy evaluation code * Remove unused signing code * Remove unused OCI code * Remove unused ephemeral signer * feat: improve verify flag shell completions * docs: fix Short style and add Example fields to piv-tool subcommands * docs: add Example fields to env and bundle create commands * docs: fix Short style and add Example fields to pkcs11-tool subcommands ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3322=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3322=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3322=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3322=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3322=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3322=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3322=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3322=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3322=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3322=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3322=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3322=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.2-150400.3.50.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cosign-3.1.2-150400.3.50.1 * Basesystem Module 15-SP7 (noarch) * cosign-bash-completion-3.1.2-150400.3.50.1 * cosign-zsh-completion-3.1.2-150400.3.50.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cosign-3.1.2-150400.3.50.1 * cosign-debuginfo-3.1.2-150400.3.50.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * cosign-3.1.2-150400.3.50.1 * cosign-debuginfo-3.1.2-150400.3.50.1 * openSUSE Leap 15.4 (noarch) * cosign-bash-completion-3.1.2-150400.3.50.1 * cosign-zsh-completion-3.1.2-150400.3.50.1 * cosign-fish-completion-3.1.2-150400.3.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * cosign-3.1.2-150400.3.50.1 * cosign-debuginfo-3.1.2-150400.3.50.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.2-150400.3.50.1 * cosign-debuginfo-3.1.2-150400.3.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cosign-3.1.2-150400.3.50.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cosign-3.1.2-150400.3.50.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * cosign-3.1.2-150400.3.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cosign-3.1.2-150400.3.50.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * cosign-3.1.2-150400.3.50.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.2-150400.3.50.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:30:28 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:30:28 -0000 Subject: SUSE-SU-2026:3345-1: important: Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4) Message-ID: <178525622852.499.423873904286617570@cdce4c525ac1> # Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:3345-1 Release Date: 2026-07-28T12:12:16Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.184 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3347=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-3348=1 SUSE-SLE-Module-Live- Patching-15-SP4-2026-3353=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3345=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3352=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3347=1 SUSE-2026-3348=1 SUSE-2026-3353=1 SUSE-2026-3345=1 SUSE-2026-3352=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_53-debugsource-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_50-debugsource-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_52-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-11-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_53-debugsource-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_50-debugsource-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_52-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-11-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:31:28 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:31:28 -0000 Subject: SUSE-SU-2026:3344-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6) Message-ID: <178525628860.499.12105923343432171836@cdce4c525ac1> # Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:3344-1 Release Date: 2026-07-28T12:06:44Z Rating: important References: * bsc#1266970 * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.112 fixes various security issues: The following security issues were fixed: * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3344=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3344=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-4-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_26-debugsource-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_112-default-4-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-4-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_26-debugsource-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_112-default-4-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:32:32 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:32:32 -0000 Subject: SUSE-SU-2026:3343-1: important: Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 15 SP7) Message-ID: <178525635294.499.3935768248566653203@cdce4c525ac1> # Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3343-1 Release Date: 2026-07-28T12:06:26Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.22 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3343=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_6-debugsource-10-150700.2.1 * kernel-livepatch-6_4_0-150700_53_22-default-10-150700.2.1 * kernel-livepatch-6_4_0-150700_53_22-default-debuginfo-10-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:33:15 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:33:15 -0000 Subject: SUSE-SU-2026:3351-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5) Message-ID: <178525639561.499.17472215945514959793@cdce4c525ac1> # Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3351-1 Release Date: 2026-07-28T12:10:24Z Rating: important References: * bsc#1266970 * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 CVSS scores: * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.166 fixes various security issues: The following security issues were fixed: * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3351=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3351=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3328=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-3349=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3349=1 SUSE-2026-3328=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_219-default-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_54-debugsource-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-3-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_219-default-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_54-debugsource-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-3-150400.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_41-debugsource-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_166-default-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-3-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_40-debugsource-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_169-default-3-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_41-debugsource-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_166-default-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-3-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_40-debugsource-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_169-default-3-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:35:12 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:35:12 -0000 Subject: SUSE-SU-2026:3342-1: important: Security update for helm Message-ID: <178525651244.499.13341857411350866349@cdce4c525ac1> # Security update for helm Announcement ID: SUSE-SU-2026:3342-1 Release Date: 2026-07-28T10:11:24Z Rating: important References: * bsc#1266598 * bsc#1271997 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for helm fixes the following issues: Update to version 3.21.3. * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). * CVE-2026-56852: golang.org/x/text/unicode/norm: handling input containing truncated or invalid UTF-8 bytes can lead to an infinite loop (bsc#1271997). Other updates and bugfixes: * Update x/text to 0.40.0. * Update x/net to 0.57.0. * Version 3.21.3: * Apply suggestions from code review 1ad6e68 (Benoit Tigeot). * fix: drop containerd v1 dep to resolve govulncheck CVEs 037733e (Benoit Tigeot). * chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33 d3e178b. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3342=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3342=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3342=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3342=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3342=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3342=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3342=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3342=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3342=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3342=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3342=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3342=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3342=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * Containers Module 15-SP7 (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * helm-debuginfo-3.21.3-150000.1.85.1 * helm-3.21.3-150000.1.85.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * helm-bash-completion-3.21.3-150000.1.85.1 * helm-zsh-completion-3.21.3-150000.1.85.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 * https://bugzilla.suse.com/show_bug.cgi?id=1271997 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:34:14 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:34:14 -0000 Subject: SUSE-SU-2026:3350-1: important: Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5) Message-ID: <178525645410.499.13311010505797848759@cdce4c525ac1> # Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3350-1 Release Date: 2026-07-28T12:09:45Z Rating: important References: * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-43038 * CVE-2026-53359 CVSS scores: * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.172 fixes various security issues: The following security issues were fixed: * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3350=1 SUSE-2026-3346=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3346=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-3350=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3324=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3324=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_172-default-3-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_42-debugsource-3-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_172-default-3-150500.2.1 * kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-3-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_42-debugsource-3-150500.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_55-debugsource-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_56-debugsource-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-3-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_55-debugsource-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_56-debugsource-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-3-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:36:00 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:36:00 -0000 Subject: SUSE-SU-2026:3341-1: important: Security update for glib2 Message-ID: <178525656056.499.16706021594926917773@cdce4c525ac1> # Security update for glib2 Announcement ID: SUSE-SU-2026:3341-1 Release Date: 2026-07-28T10:09:32Z Rating: important References: * bsc#1270008 * bsc#1270009 * bsc#1270010 * bsc#1270016 * bsc#1270018 * bsc#1270021 Cross-References: * CVE-2026-58010 * CVE-2026-58011 * CVE-2026-58012 * CVE-2026-58013 * CVE-2026-58014 * CVE-2026-58016 CVSS scores: * CVE-2026-58010 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58012 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). * CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). * CVE-2026-58012: raw byte regex matches with UTF-8 functions during case- change replacements could cause an out-of- bounds read (bsc#1270016). * CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). * CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). * CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3341=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3341=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3341=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3341=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libgio-2_0-0-2.78.6-150600.4.38.1 * libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1 * glib2-tests-devel-2.78.6-150600.4.38.1 * libgthread-2_0-0-2.78.6-150600.4.38.1 * glib2-tools-debuginfo-2.78.6-150600.4.38.1 * libgobject-2_0-0-2.78.6-150600.4.38.1 * glib2-tools-2.78.6-150600.4.38.1 * libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1 * glib2-tests-devel-debuginfo-2.78.6-150600.4.38.1 * libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1 * libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1 * glib2-debugsource-2.78.6-150600.4.38.1 * glib2-devel-2.78.6-150600.4.38.1 * glib2-doc-2.78.6-150600.4.38.1 * glib2-devel-static-2.78.6-150600.4.38.1 * libgmodule-2_0-0-2.78.6-150600.4.38.1 * glib2-devel-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-2.78.6-150600.4.38.1 * libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libgmodule-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1 * glib2-devel-64bit-debuginfo-2.78.6-150600.4.38.1 * libgthread-2_0-0-64bit-2.78.6-150600.4.38.1 * libgio-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1 * libgmodule-2_0-0-64bit-2.78.6-150600.4.38.1 * libgobject-2_0-0-64bit-2.78.6-150600.4.38.1 * glib2-tools-64bit-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-64bit-2.78.6-150600.4.38.1 * libgthread-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1 * libgobject-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1 * glib2-devel-64bit-2.78.6-150600.4.38.1 * glib2-tools-64bit-2.78.6-150600.4.38.1 * libgio-2_0-0-64bit-2.78.6-150600.4.38.1 * openSUSE Leap 15.6 (x86_64) * libgio-2_0-0-32bit-2.78.6-150600.4.38.1 * libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * glib2-tools-32bit-2.78.6-150600.4.38.1 * libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1 * libglib-2_0-0-32bit-2.78.6-150600.4.38.1 * libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgthread-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * glib2-devel-32bit-2.78.6-150600.4.38.1 * glib2-devel-32bit-debuginfo-2.78.6-150600.4.38.1 * libgthread-2_0-0-32bit-2.78.6-150600.4.38.1 * libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * glib2-tools-32bit-debuginfo-2.78.6-150600.4.38.1 * libgobject-2_0-0-32bit-2.78.6-150600.4.38.1 * openSUSE Leap 15.6 (noarch) * glib2-lang-2.78.6-150600.4.38.1 * gio-branding-upstream-2.78.6-150600.4.38.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * glib2-devel-2.78.6-150600.4.38.1 * libgthread-2_0-0-2.78.6-150600.4.38.1 * libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1 * libgmodule-2_0-0-2.78.6-150600.4.38.1 * libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1 * glib2-devel-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-2.78.6-150600.4.38.1 * glib2-tools-debuginfo-2.78.6-150600.4.38.1 * glib2-debugsource-2.78.6-150600.4.38.1 * libgobject-2_0-0-2.78.6-150600.4.38.1 * libgio-2_0-0-2.78.6-150600.4.38.1 * libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1 * glib2-tools-2.78.6-150600.4.38.1 * libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libgio-2_0-0-32bit-2.78.6-150600.4.38.1 * libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1 * libglib-2_0-0-32bit-2.78.6-150600.4.38.1 * libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgobject-2_0-0-32bit-2.78.6-150600.4.38.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * glib2-lang-2.78.6-150600.4.38.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glib2-devel-2.78.6-150600.4.38.1 * libgthread-2_0-0-2.78.6-150600.4.38.1 * libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1 * libgmodule-2_0-0-2.78.6-150600.4.38.1 * libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1 * glib2-devel-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-2.78.6-150600.4.38.1 * glib2-tools-debuginfo-2.78.6-150600.4.38.1 * glib2-tools-2.78.6-150600.4.38.1 * libgobject-2_0-0-2.78.6-150600.4.38.1 * libgio-2_0-0-2.78.6-150600.4.38.1 * libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1 * glib2-debugsource-2.78.6-150600.4.38.1 * libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1 * Basesystem Module 15-SP7 (x86_64) * libgio-2_0-0-32bit-2.78.6-150600.4.38.1 * libglib-2_0-0-32bit-2.78.6-150600.4.38.1 * libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1 * libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgobject-2_0-0-32bit-2.78.6-150600.4.38.1 * Basesystem Module 15-SP7 (noarch) * glib2-lang-2.78.6-150600.4.38.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * glib2-devel-2.78.6-150600.4.38.1 * libgthread-2_0-0-2.78.6-150600.4.38.1 * libgmodule-2_0-0-2.78.6-150600.4.38.1 * libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1 * libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1 * glib2-devel-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-2.78.6-150600.4.38.1 * glib2-tools-debuginfo-2.78.6-150600.4.38.1 * glib2-tools-2.78.6-150600.4.38.1 * libgobject-2_0-0-2.78.6-150600.4.38.1 * libgio-2_0-0-2.78.6-150600.4.38.1 * libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1 * glib2-debugsource-2.78.6-150600.4.38.1 * libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libgio-2_0-0-32bit-2.78.6-150600.4.38.1 * libglib-2_0-0-32bit-2.78.6-150600.4.38.1 * libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1 * libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1 * libgobject-2_0-0-32bit-2.78.6-150600.4.38.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * glib2-lang-2.78.6-150600.4.38.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58010.html * https://www.suse.com/security/cve/CVE-2026-58011.html * https://www.suse.com/security/cve/CVE-2026-58012.html * https://www.suse.com/security/cve/CVE-2026-58013.html * https://www.suse.com/security/cve/CVE-2026-58014.html * https://www.suse.com/security/cve/CVE-2026-58016.html * https://bugzilla.suse.com/show_bug.cgi?id=1270008 * https://bugzilla.suse.com/show_bug.cgi?id=1270009 * https://bugzilla.suse.com/show_bug.cgi?id=1270010 * https://bugzilla.suse.com/show_bug.cgi?id=1270016 * https://bugzilla.suse.com/show_bug.cgi?id=1270018 * https://bugzilla.suse.com/show_bug.cgi?id=1270021 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:37:58 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:37:58 -0000 Subject: SUSE-SU-2026:3339-1: important: Security update for apache-sshd Message-ID: <178525667803.499.9109501418190689470@cdce4c525ac1> # Security update for apache-sshd Announcement ID: SUSE-SU-2026:3339-1 Release Date: 2026-07-28T10:03:20Z Rating: important References: * bsc#1271991 * bsc#1271992 * bsc#1271993 * bsc#1272158 Cross-References: * CVE-2026-56452 * CVE-2026-56623 * CVE-2026-56624 * CVE-2026-58624 CVSS scores: * CVE-2026-56452 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56452 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56623 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-56623 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-56624 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2026-56624 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2026-58624 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-58624 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for apache-sshd fixes the following issues: Update to upstream version 2.19.0. Security issues fixed: * CVE-2026-56452: remote users can use SCP to send filenames that lead to arbitrary file writes due to a path traversal issue in the `sshd-scp` component of Apache MINA SSHD. (bsc#1272158). * CVE-2026-56623: remote users can obtain access to git repositories outside of the configured server-side root directory on Windows systems due to path traversal issue in `org.apache.sshd:sshd-git` (bsc#1271993). * CVE-2026-56624: users can authenticate with certificates containing the `force-command` option but still execute other commands due to improper validation of certificate options in Apache MINA SSHD (bsc#1271992). * CVE-2026-58624: remote execution of JGit commands can lead to arbitrary file writes due to improper input validation in `sshd-git` of Apache MINA SSHD (bsc#1271991). Other updates and bugfixes: * Version 2.19.0: * Bug Fixes * GH-899 Fix ProcessShellFactory on Linux. * GH-902 Fix client-side handling of sk-* public key signatures (also in the agent interfaces). * Limit size of decompressed SSH packets. * Improve checking SSH user certificates in public-key authentication. * Improve handling of repository paths in sshd-git on Windows. * Validate file names in SCP. * Escape newlines in filenames in the SCP protocol. * Restrict JGit commands accessible via GitPgmCommandFactory in sshd-git. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3339=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3339=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3339=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3339=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3339=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3339=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3339=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3339=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3339=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3339=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3339=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * apache-sshd-2.19.0-150200.5.16.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * apache-sshd-2.19.0-150200.5.16.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * apache-sshd-2.19.0-150200.5.16.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * apache-sshd-2.19.0-150200.5.16.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * apache-sshd-2.19.0-150200.5.16.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * apache-sshd-2.19.0-150200.5.16.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * apache-sshd-2.19.0-150200.5.16.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * apache-sshd-2.19.0-150200.5.16.1 * Development Tools Module 15-SP7 (noarch) * apache-sshd-2.19.0-150200.5.16.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * apache-sshd-2.19.0-150200.5.16.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * apache-sshd-2.19.0-150200.5.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56452.html * https://www.suse.com/security/cve/CVE-2026-56623.html * https://www.suse.com/security/cve/CVE-2026-56624.html * https://www.suse.com/security/cve/CVE-2026-58624.html * https://bugzilla.suse.com/show_bug.cgi?id=1271991 * https://bugzilla.suse.com/show_bug.cgi?id=1271992 * https://bugzilla.suse.com/show_bug.cgi?id=1271993 * https://bugzilla.suse.com/show_bug.cgi?id=1272158 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:36:57 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:36:57 -0000 Subject: SUSE-SU-2026:3340-1: moderate: Security update for nmap Message-ID: <178525661714.499.4892309250548960303@cdce4c525ac1> # Security update for nmap Announcement ID: SUSE-SU-2026:3340-1 Release Date: 2026-07-28T10:04:18Z Rating: moderate References: * bsc#1269570 Cross-References: * CVE-2026-58058 CVSS scores: * CVE-2026-58058 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58058 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58058 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for nmap fixes the following issue: * CVE-2026-58058: crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash (bsc#1269570). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3340=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3340=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3340=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * nping-7.92-150600.9.3.1 * nping-debuginfo-7.92-150600.9.3.1 * nmap-debuginfo-7.92-150600.9.3.1 * ncat-debuginfo-7.92-150600.9.3.1 * ncat-7.92-150600.9.3.1 * nmap-debugsource-7.92-150600.9.3.1 * nmap-7.92-150600.9.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * nmap-debugsource-7.92-150600.9.3.1 * nmap-debuginfo-7.92-150600.9.3.1 * nmap-7.92-150600.9.3.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * nping-7.92-150600.9.3.1 * nmap-debugsource-7.92-150600.9.3.1 * nmap-debuginfo-7.92-150600.9.3.1 * nping-debuginfo-7.92-150600.9.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58058.html * https://bugzilla.suse.com/show_bug.cgi?id=1269570 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:39:35 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:39:35 -0000 Subject: SUSE-SU-2026:3337-1: important: Security update for wget Message-ID: <178525677503.499.2773982005209206792@cdce4c525ac1> # Security update for wget Announcement ID: SUSE-SU-2026:3337-1 Release Date: 2026-07-28T09:51:28Z Rating: important References: * bsc#1271033 * bsc#1272219 Cross-References: * CVE-2026-58469 CVSS scores: * CVE-2026-58469 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58469 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for wget fixes the following issue * Fix metalink regression from CVE-2026-58469 fix (bsc#1272219, bsc#1271033). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3337=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * wget-1.24.5-150700.3.6.1 * wget-debugsource-1.24.5-150700.3.6.1 * wget-debuginfo-1.24.5-150700.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58469.html * https://bugzilla.suse.com/show_bug.cgi?id=1271033 * https://bugzilla.suse.com/show_bug.cgi?id=1272219 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:38:37 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:38:37 -0000 Subject: SUSE-SU-2026:3338-1: important: Security update for webkit2gtk3 Message-ID: <178525671738.499.5494439412138312825@cdce4c525ac1> # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2026:3338-1 Release Date: 2026-07-28T09:55:09Z Rating: important References: * bsc#1271638 Cross-References: * CVE-2024-4367 * CVE-2026-39872 * CVE-2026-43663 * CVE-2026-43676 * CVE-2026-43699 * CVE-2026-43701 * CVE-2026-43705 * CVE-2026-43707 * CVE-2026-43712 * CVE-2026-43713 * CVE-2026-43715 * CVE-2026-43716 * CVE-2026-43720 * CVE-2026-43721 * CVE-2026-43725 * CVE-2026-43726 * CVE-2026-43727 * CVE-2026-43731 * CVE-2026-43732 * CVE-2026-43734 * CVE-2026-43740 * CVE-2026-43742 * CVE-2026-43745 CVSS scores: * CVE-2024-4367 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-4367 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-4367 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43676 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43699 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43699 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43701 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L * CVE-2026-43701 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L * CVE-2026-43705 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43705 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43707 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43707 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43712 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43712 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43713 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43713 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43715 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43715 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43716 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43716 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43720 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43720 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43721 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43721 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43725 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L * CVE-2026-43725 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L * CVE-2026-43726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43726 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43727 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43731 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43731 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43732 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43732 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43734 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43742 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43742 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43745 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43745 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: * CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638). * CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638). * CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638). * CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638). * CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638). * CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). * CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638). * CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). * CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638). * CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638). * CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). * CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). * CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638). * CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638). * CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). Changes for webkit2gtk3: * Update to version 2.52.5: * Fire scrollend event for instant programmatic scrolls. * Increase network idle connection timeout to 115 seconds. * Add User-Agent quirk for HBO Max. * Fix the build with system malloc. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3338=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3338=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3338=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3338=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3338=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3338=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1 * webkit2gtk4-debugsource-2.52.5-150600.12.71.1 * typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1 * webkit2gtk4-devel-2.52.5-150600.12.71.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1 * libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1 * libwebkitgtk-6_0-4-2.52.5-150600.12.71.1 * webkit2gtk3-debugsource-2.52.5-150600.12.71.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1 * webkit2gtk4-devel-2.52.5-150600.12.71.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk4-debugsource-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1 * webkit2gtk3-devel-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1 * webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * WebKitGTK-4.0-lang-2.52.5-150600.12.71.1 * WebKitGTK-4.1-lang-2.52.5-150600.12.71.1 * WebKitGTK-6.0-lang-2.52.5-150600.12.71.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1 * libwebkitgtk-6_0-4-2.52.5-150600.12.71.1 * webkit2gtk3-debugsource-2.52.5-150600.12.71.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1 * webkit-jsc-6.0-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk4-devel-2.52.5-150600.12.71.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1 * webkit-jsc-4-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk4-debugsource-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1 * webkit2gtk4-minibrowser-2.52.5-150600.12.71.1 * webkit-jsc-6.0-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1 * webkit2gtk3-devel-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk3-minibrowser-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-minibrowser-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk3-minibrowser-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1 * webkit2gtk4-minibrowser-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1 * webkit-jsc-4.1-2.52.5-150600.12.71.1 * webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1 * webkit-jsc-4.1-debuginfo-2.52.5-150600.12.71.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-minibrowser-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1 * webkit-jsc-4-debuginfo-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1 * openSUSE Leap 15.6 (noarch) * WebKitGTK-4.0-lang-2.52.5-150600.12.71.1 * WebKitGTK-4.1-lang-2.52.5-150600.12.71.1 * WebKitGTK-6.0-lang-2.52.5-150600.12.71.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-64bit-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-64bit-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-64bit-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-64bit-2.52.5-150600.12.71.1 * openSUSE Leap 15.6 (x86_64) * libjavascriptcoregtk-4_0-18-32bit-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-32bit-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-32bit-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-32bit-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.52.5-150600.12.71.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1 * libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1 * webkit2gtk4-debugsource-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1 * libwebkitgtk-6_0-4-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1 * Basesystem Module 15-SP7 (noarch) * WebKitGTK-4.0-lang-2.52.5-150600.12.71.1 * WebKitGTK-6.0-lang-2.52.5-150600.12.71.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk3-debugsource-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1 * webkit2gtk3-devel-2.52.5-150600.12.71.1 * Desktop Applications Module 15-SP7 (noarch) * WebKitGTK-4.1-lang-2.52.5-150600.12.71.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1 * libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1 * libwebkitgtk-6_0-4-2.52.5-150600.12.71.1 * webkit2gtk3-debugsource-2.52.5-150600.12.71.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk4-devel-2.52.5-150600.12.71.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * webkit2gtk4-debugsource-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1 * typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1 * webkit2gtk3-devel-2.52.5-150600.12.71.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1 * webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1 * webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1 * libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1 * libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1 * libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * WebKitGTK-4.0-lang-2.52.5-150600.12.71.1 * WebKitGTK-4.1-lang-2.52.5-150600.12.71.1 * WebKitGTK-6.0-lang-2.52.5-150600.12.71.1 ## References: * https://www.suse.com/security/cve/CVE-2024-4367.html * https://www.suse.com/security/cve/CVE-2026-39872.html * https://www.suse.com/security/cve/CVE-2026-43663.html * https://www.suse.com/security/cve/CVE-2026-43676.html * https://www.suse.com/security/cve/CVE-2026-43699.html * https://www.suse.com/security/cve/CVE-2026-43701.html * https://www.suse.com/security/cve/CVE-2026-43705.html * https://www.suse.com/security/cve/CVE-2026-43707.html * https://www.suse.com/security/cve/CVE-2026-43712.html * https://www.suse.com/security/cve/CVE-2026-43713.html * https://www.suse.com/security/cve/CVE-2026-43715.html * https://www.suse.com/security/cve/CVE-2026-43716.html * https://www.suse.com/security/cve/CVE-2026-43720.html * https://www.suse.com/security/cve/CVE-2026-43721.html * https://www.suse.com/security/cve/CVE-2026-43725.html * https://www.suse.com/security/cve/CVE-2026-43726.html * https://www.suse.com/security/cve/CVE-2026-43727.html * https://www.suse.com/security/cve/CVE-2026-43731.html * https://www.suse.com/security/cve/CVE-2026-43732.html * https://www.suse.com/security/cve/CVE-2026-43734.html * https://www.suse.com/security/cve/CVE-2026-43740.html * https://www.suse.com/security/cve/CVE-2026-43742.html * https://www.suse.com/security/cve/CVE-2026-43745.html * https://bugzilla.suse.com/show_bug.cgi?id=1271638 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:40:13 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:40:13 -0000 Subject: SUSE-SU-2026:3336-1: important: Security update for ImageMagick Message-ID: <178525681383.499.11397562601988318090@cdce4c525ac1> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3336-1 Release Date: 2026-07-28T09:45:03Z Rating: important References: * bsc#1268878 Cross-References: * CVE-2026-56379 CVSS scores: * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for ImageMagick fixes the following issue: * Extend CVE-2026-56379 patch by f63c78b (bsc#1268878). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3336=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3336=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-debugsource-7.1.1.43-150700.3.73.1 * ImageMagick-7.1.1.43-150700.3.73.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.43-150700.3.73.1 * ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.73.1 * ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.73.1 * ImageMagick-devel-7.1.1.43-150700.3.73.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.73.1 * libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.73.1 * libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.73.1 * ImageMagick-debuginfo-7.1.1.43-150700.3.73.1 * libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.73.1 * ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.73.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.73.1 * ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.73.1 * libMagick++-devel-7.1.1.43-150700.3.73.1 * ImageMagick-config-7-SUSE-7.1.1.43-150700.3.73.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-PerlMagick-7.1.1.43-150700.3.73.1 * ImageMagick-debugsource-7.1.1.43-150700.3.73.1 * perl-PerlMagick-debuginfo-7.1.1.43-150700.3.73.1 * ImageMagick-debuginfo-7.1.1.43-150700.3.73.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1268878 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:40:53 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:40:53 -0000 Subject: SUSE-SU-2026:3335-1: important: Security update for ImageMagick Message-ID: <178525685319.499.2195489943423012466@cdce4c525ac1> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3335-1 Release Date: 2026-07-28T09:43:52Z Rating: important References: * bsc#1268878 Cross-References: * CVE-2026-56379 CVSS scores: * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for ImageMagick fixes the following issue * Extend CVE-2026-56379 patch by f63c78b (bsc#1268878). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3335=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3335=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3335=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3335=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3335=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3335=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3335=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3335=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3335=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3335=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3335=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3335=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * ImageMagick-extra-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1 * ImageMagick-devel-7.1.0.9-150400.6.104.1 * libMagick++-devel-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-extra-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1 * perl-PerlMagick-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.104.1 * libMagick++-devel-64bit-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.104.1 * ImageMagick-devel-64bit-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.104.1 * openSUSE Leap 15.4 (x86_64) * ImageMagick-devel-32bit-7.1.0.9-150400.6.104.1 * libMagick++-devel-32bit-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.104.1 * openSUSE Leap 15.4 (noarch) * ImageMagick-doc-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1 * perl-PerlMagick-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1 * ImageMagick-devel-7.1.0.9-150400.6.104.1 * libMagick++-devel-7.1.0.9-150400.6.104.1 * ImageMagick-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1 * perl-PerlMagick-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1 * ImageMagick-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * libMagick++-devel-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-devel-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1 * perl-PerlMagick-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * ImageMagick-7.1.0.9-150400.6.104.1 * ImageMagick-devel-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * libMagick++-devel-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1 * ImageMagick-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * libMagick++-devel-7.1.0.9-150400.6.104.1 * ImageMagick-devel-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1 * perl-PerlMagick-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1 * perl-PerlMagick-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1 * ImageMagick-devel-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * ImageMagick-7.1.0.9-150400.6.104.1 * libMagick++-devel-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1 * perl-PerlMagick-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1 * ImageMagick-devel-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * ImageMagick-7.1.0.9-150400.6.104.1 * libMagick++-devel-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1 * ImageMagick-7.1.0.9-150400.6.104.1 * ImageMagick-devel-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * libMagick++-devel-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1 * perl-PerlMagick-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-7.1.0.9-150400.6.104.1 * ImageMagick-devel-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * libMagick++-devel-7.1.0.9-150400.6.104.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1 * perl-PerlMagick-7.1.0.9-150400.6.104.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.104.1 * ImageMagick-debugsource-7.1.0.9-150400.6.104.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1268878 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:41:49 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:41:49 -0000 Subject: SUSE-SU-2026:3334-1: moderate: Security update for perl-HTTP-Date Message-ID: <178525690977.499.781106895364333246@cdce4c525ac1> # Security update for perl-HTTP-Date Announcement ID: SUSE-SU-2026:3334-1 Release Date: 2026-07-28T09:41:21Z Rating: moderate References: * bsc#1271705 Cross-References: * CVE-2026-14741 CVSS scores: * CVE-2026-14741 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-14741 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-14741 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTTP-Date fixes the following issue: * CVE-2026-14741: CPU exhaustion due to polynomial regex backtracking in `parse_date` when processing specially crafted date strings (bsc#1271705). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3334=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * perl-HTTP-Date-6.02-9.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14741.html * https://bugzilla.suse.com/show_bug.cgi?id=1271705 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:42:29 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:42:29 -0000 Subject: SUSE-SU-2026:3333-1: moderate: Security update for nmap Message-ID: <178525694942.499.9250083358502554717@cdce4c525ac1> # Security update for nmap Announcement ID: SUSE-SU-2026:3333-1 Release Date: 2026-07-28T09:40:38Z Rating: moderate References: * bsc#1269570 Cross-References: * CVE-2026-58058 CVSS scores: * CVE-2026-58058 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58058 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58058 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for nmap fixes the following issue * CVE-2026-58058: crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash (bsc#1269570). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3333=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * nmap-debugsource-6.46-3.9.1 * nmap-6.46-3.9.1 * nmap-debuginfo-6.46-3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58058.html * https://bugzilla.suse.com/show_bug.cgi?id=1269570 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:43:22 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:43:22 -0000 Subject: SUSE-SU-2026:3332-1: important: Security update for java-21-openjdk Message-ID: <178525700274.499.17667247908597854938@cdce4c525ac1> # Security update for java-21-openjdk Announcement ID: SUSE-SU-2026:3332-1 Release Date: 2026-07-28T09:37:59Z Rating: important References: * bsc#1264397 * bsc#1264994 * bsc#1267355 * bsc#1272223 * bsc#1272224 * bsc#1272225 * bsc#1272227 * bsc#1272228 * bsc#1272235 * bsc#1272236 * bsc#1272237 Cross-References: * CVE-2026-41254 * CVE-2026-46917 * CVE-2026-46968 * CVE-2026-47010 * CVE-2026-47021 * CVE-2026-47027 * CVE-2026-47059 * CVE-2026-47063 * CVE-2026-60147 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities and has two security fixes can now be installed. ## Description: This update for java-21-openjdk fixes the following issues: Update to upstream tag jdk-21.0.12+8 (July 2026 CPU). Security issues fixed: * CVE-2026-41254: lcms: information disclosure and denial of service via integer overflow in `CubeSize` (bsc#1264994). * CVE-2026-46917: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1272223). * CVE-2026-46968: unauthenticated attacker with network access via TLS can gain unauthorized creation, deletion or modification access to critical data(bsc#1272224). * CVE-2026-47010: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert or delete access to some data (bsc#1272225). * CVE-2026-47021: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272227). * CVE-2026-47027: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272228). * CVE-2026-47059: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272235). * CVE-2026-47063: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation, deletion or modification access to critical data (bsc#1272236). * CVE-2026-60147: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert, delete and read access to some(bsc#1272237). Other updates and bugfixes: * Errors from update-alternatives when installing java-25-openjdk (bsc#1267355). * Make post scripts less noisy (bsc#1267355). * Use libalternatives instead of update-alternatives for distributions where libalternatives is available. * Update to upstream tag jdk-21.0.12+8 (July 2026 CPU): * JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail * JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails * JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails * JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel * JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F * JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/ /PrintDialogsTest.java instruction need to update * JDK-8129418: JShell: better highlighting of errors in imports on demand * JDK-8144124: [macosx] The tabs can't be aligned when we pressing the key of 'R','B','L','C' or 'T'. * JDK-8183336: Better cleanup for jdk/test/java/lang/module/ /customfs/ModulesInCustomFileSystem.java * JDK-8203004: UnixMultiResolutionSplashTest.java fails on Ubuntu16.04 * JDK-8212084: G1: Implement UseGCOverheadLimit * JDK-8213530: Test java/awt/Modal/ToFront/ /DialogToFrontModeless1Test.java fails on Linux * JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails * JDK-8225787: java/awt/Window/GetScreenLocation/ /GetScreenLocationTest.java fails on Ubuntu * JDK-8255463: java/nio/channels/spi/SelectorProvider/ /inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException * JDK-8274082: Wrong test name in jtreg run tag for java/awt/print/PrinterJob/SwingUIText.java * JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking * JDK-8278102: containers/docker/TestJcmd.java failed with "RuntimeException: Could not find specified process" * JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially * JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/nativeAndMH/ /Test.java fails with Out of space in CodeCache * JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support * JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages * JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed with "RuntimeException: MyObject is not found in test output" * JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!" * JDK-8299304: Test "java/awt/print/PrinterJob/ /PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit * JDK-8310645: CancelledResponse.java does not use HTTP/2 when testing the HttpClient * JDK-8311538: CDS InternSharedString test fails on huge pages host - cannot find shared string * JDK-8315588: JShell does not accept underscore from JEP 443 even with --enable-preview * JDK-8318365: Test runtime/cds/appcds/sharedStrings/ /InternSharedString.java fails after JDK-8311538 * JDK-8318662: Refactor some jdk/java/net/httpclient/http2 tests to JUnit * JDK-8319326: GC: Make TestParallelRefProc use createTestJavaProcessBuilder * JDK-8319540: GC: Make TestSelectDefaultGC use createTestJavaProcessBuilder * JDK-8320677: Printer tests use invalid '@run main/manual=yesno * JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux * JDK-8321687: Test vmTestbase/nsk/jvmti/scenarios/contention/ /TC03/tc03t002/TestDescription.java failed: JVMTI_ERROR_THREAD_NOT_ALIVE * JDK-8322532: JShell : Unnamed variable issue * JDK-8323089: networkaddress.cache.ttl is not a system property * JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java fails with "exit code: 133" * JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX * JDK-8323792: ThreadSnapshot::initialize can cause assert in Thread::check_for_dangling_thread_pointer (possibility of dangling Thread pointer) * JDK-8326458: Menu mnemonics don't toggle in Windows LAF when F10 is pressed * JDK-8328300: Convert PrintDialogsTest.java from Applet to main program * JDK-8329273: C2 SuperWord: Some basic MemorySegment IR tests * JDK-8330704: Clean up non-standard use of /** comments in some langtools tests * JDK-8330806: test/hotspot/jtreg/compiler/c1/ /TestLargeMonitorOffset.java fails on ARM32 * JDK-8332495: java/util/logging/LoggingDeadlock2.java fails with AssertionError: Some tests failed * JDK-8333729: C2 SuperWord: remove some @requires usages in test/hotspot/jtreg/compiler/loopopts/superword * JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ /ReuseAddr.java failed: java.net.BindException: Address already in use * JDK-8338103: Stabilize and open source a Swing OGL ButtonResizeTest * JDK-8338554: Fix inconsistencies in javadoc/doclet/ /testLinkOption/TestRedirectLinks.java * JDK-8338883: Show warning when CreateCoredumpOnCrash set, but core dump will not happen * JDK-8339233: Test javax/swing/JButton/ /SwingButtonResizeTestWithOpenGL.java#id failed: Button renderings are different after window resize * JDK-8339638: Update vmTestbase/nsk/jvmti/_Field_ Watch tests to use virtual thread factory * JDK-8339879: Open some dialog awt tests * JDK-8339975: Open some dialog awt tests 2 * JDK-8340140: Open some dialog awt tests 3 * JDK-8340336: Open some checkbox awt tests * JDK-8340494: Open some dialog awt tests 4 * JDK-8340818: Add a new jtreg test root to test the generated documentation * JDK-8340851: Open some TextArea awt tests * JDK-8340987: Open some TextArea awt tests 1 * JDK-8341055: Open some TextArea awt tests 2 * JDK-8341292: Open some TextArea awt tests 3 * JDK-8341376: Open some TextArea awt tests 4 * JDK-8341427: JFR: Adjust object sampler span handling * JDK-8341436: containers/docker/TestJcmdWithSideCar.java takes needlessly long to run * JDK-8341833: incomplete snippet from loaded files from command line is ignored * JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/ /JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts * JDK-8342836: Automatically determine that a test in the docs test root is requested * JDK-8344128: Regression: make help broken after JDK-8340818 * JDK-8345618: javax/swing/text/Caret/8163124/ /CaretFloatingPointAPITest.java leaves Caret is not complete * JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally * JDK-8346683: Problem list automated tests that fail on macOS15 * JDK-8347836: Disabled PopupMenu shows shortcuts on Mac * JDK-8349084: Update vectors used in several PQC benchmarks * JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000) * JDK-8349533: Refactor validator tests shell files to java * JDK-8349699: XSL transform fails with certain UTF-8 characters on 1024 byte boundaries * JDK-8349959: Test CR6740048.java passes unexpectedly missing CR6740048.xsd * JDK-8350749: Upgrade JLine to 3.29.0 * JDK-8350808: Small typos in JShell method SnippetEvent .toString() * JDK-8352020: [CompileFramework] enable compilation for VectorAPI * JDK-8352147: G1: TestEagerReclaimHumongousRegionsClearMarkBits test takes very long * JDK-8352149: Test java/awt/Frame/MultiScreenTest.java fails: Window list is empty * JDK-8352431: java/net/httpclient/EmptyAuthenticate.java uses "localhost" * JDK-8352685: Opensource JInternalFrame tests - series2 * JDK-8352733: Improve RotFontBoundsTest test * JDK-8352877: Opensource Several Font related tests - Batch 1 * JDK-8353124: java/lang/Thread/virtual/stress/Skynet.java#Z times out on macosx-x64-debug * JDK-8353488: Open some JComboBox bugs 3 * JDK-8353552: Opensource Several Font related tests - Batch 3 * JDK-8354163: Open source Swing tests Batch 1 * JDK-8354695: Open source several swing tests batch7 * JDK-8354900: javax/swing/AbstractButton/bug4133768.java failing on macosx-aarch64 * JDK-8354910: Output by java.io.IO or System.console() corrupted for some non-ASCII characters * JDK-8355048: ProblemList TestGlyphVectorLayout.java on all platforms * JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/ /bug4865918.java headful and macos run * JDK-8355332: Fix failing semi-manual test EDT issue * JDK-8355371: NegativeArraySizeException in print methods in IO or System.console() in JShell * JDK-8355443: [java.io] Use @requires tag instead of exiting based on File.separatorChar value * JDK-8356695: java/lang/StringBuilder/HugeCapacity.java failing with OOME * JDK-8356868: Not all cgroup parameters are made available * JDK-8357062: Update Public Suffix List to 823beb1 * JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java * JDK-8357086: os::xxx functions returning memory size should return size_t * JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/ /LimitDirectMemory[NegativeTest].java * JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ /ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system * JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently * JDK-8359364: java/net/URL/EarlyOrDelayedParsing test fails intermittently * JDK-8359472: JVM crashes when attaching a dynamic agent before JVMTI_PHASE_LIVE * JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine * JDK-8360160: ubuntu-22-04 machine is failing client tests * JDK-8360395: sun/security/tools/keytool/i18n.java user country is current user location instead of the language * JDK-8360562: sun/security/tools/keytool/i18n.java add an ability to add comment for failures * JDK-8360702: runtime/Thread/AsyncExceptionTest.java timed out * JDK-8360882: Tests throw SkippedException when they should fail * JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException * JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a * JDK-8361894: sun/security/krb5/config/native/ /TestDynamicStore.java ensure that the test is run with sudo * JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25 * JDK-8363943: ARM32: Represent Registers as values * JDK-8363949: Incorrect jtreg header in MonitorWithDeadObjectTest.java * JDK-8364190: JFR: RemoteRecordingStream withers don't work * JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/ /jaxp/functional/javax/xml/transform/xmlfiles * JDK-8364756: JFR: Improve slow tests * JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java * JDK-8365379: SU3.applyInsets may produce wrong results * JDK-8365398: TEST_BUG: java/rmi/transport/checkLeaseInfoLeak/ /CheckLeaseLeak.java failing intermittently * JDK-8365423: [macos26] java/awt/MenuBar/8007006/ /bug8007006.java fails on macOS 26 * JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26 * JDK-8365623: test/jdk/sun/security/pkcs11/tls/ tests skipped without skip exception * JDK-8365625: Can't change accelerator colors in Windows L&F * JDK-8365776: Convert JShell tests to use JUnit instead of TestNG * JDK-8365861: test/jdk/sun/security/pkcs11/Provider/ tests skipped without SkippedException * JDK-8365863: /test/jdk/sun/security/pkcs11/Cipher tests skip without SkippedException * JDK-8365893: test/jdk/java/lang/Thread/virtual/JfrEvents.java failing intermittently * JDK-8366031: Mark com/sun/nio/sctp/SctpChannel/ /CloseDescriptors.java as intermittent * JDK-8366182: Some PKCS11Tests are being skipped when they shouldn't * JDK-8366369: Add @requires linux for GTK L&F tests * JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ /ChoiceMouseWheelTest.java test is failing * JDK-8367096: jdk/open/test/jdk/sun/security/pkcs11/ rsa, ec, config, secmod and sslecc tests are skipping but showing as pass * JDK-8367485: os::physical_memory is broken in 32-bit JVMs when running on 64-bit OSes * JDK-8367784: java/awt/Focus/InitialFocusTest/ /InitialFocusTest1.java failed with Wrong focus owner * JDK-8368029: Several tests in httpserver/simpleserver should throw SkipException * JDK-8368041: Enhance TLS certificate handling * JDK-8368181: ProblemList java/awt/Dialog/ModalExcludedTest/ /ModalExcludedTest.java * JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit * JDK-8368498: Use JUnit instead of TestNG for jdk_text tests * JDK-8368524: Tests are skipped and shown as passed in test/jdk/sun/security/pkcs11/Cipher/KeyWrap * JDK-8368551: Core dump warning may be confusing * JDK-8368625: com/sun/net/httpserver/ /ServerStopTerminationTest.java fails intermittently * JDK-8368670: Deadlock in JFR on event register + class load * JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict * JDK-8368866: compiler/codecache/stress/ /UnexpectedDeoptimizationTest.java intermittent timed out * JDK-8368885: NMT CommandLine tests can check for error better * JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless * JDK-8369251: Opensource few tests * JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058 * JDK-8369516: Delete duplicate imaging test * JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual=ff000000) * JDK-8369683: Exclude runtime/Monitor/ /MonitorWithDeadObjectTest.java#DumpThreadsBeforeDetach on Alpine Linux debug * JDK-8369851: Remove darcy author tags from langtools tests * JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException * JDK-8370378: Some compiler tests inadvertently exclude particular platforms * JDK-8370489: Some compiler tests miss the @key randomness * JDK-8370492: [Linux] Update cpu shares to cpu.weight mapping function * JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys * JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests * JDK-8370905: Update vm.defmeth tests to use virtual threads * JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying * JDK-8371262: sun/security/pkcs11/Cipher/KeyWrap tests may silently skip * JDK-8371349: Update NSS library to 3.117 * JDK-8371364: Refactor javax/swing/JFileChooser/ /FileSizeCheck.java to use Util.findComponent() * JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent() * JDK-8371366: java/net/httpclient/whitebox/ /RawChannelTestDriver.java fails intermittently in jtreg timeout * JDK-8371383: Test sun/security/tools/jarsigner/ /DefaultOptions.java failed due to CertificateNotYetValidException * JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests * JDK-8371895: Lower GCTimeLimit in TestUseGCOverheadLimit.java * JDK-8371967: Add Visual Studio 2026 to build toolchain for Windows * JDK-8372120: Add missing sound keyword to MIDI tests * JDK-8372272: Hotspot shared lib loading - add load attempts to Events::log * JDK-8372351: Add 2 WISeKey roots * JDK-8372609: Bug4944439 does not enforce locale correctly * JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext" * JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field * JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages * JDK-8373275: Improve DTLS handshaking * JDK-8373537: Migrate "test/jdk/com/sun/net/httpserver/" to null-safe "SimpleSSLContext" methods * JDK-8373593: Support latest VS2026 MSC_VER in abstract_vm_version.cpp * JDK-8373623: Refactor Serialization tests for Records to JUnit * JDK-8373632: Some sound tests failing in CI due to lack of sound key * JDK-8373650: Test "javax/swing/JMenuItem/6458123/ /ManualBug6458123.java" fails because the check icons are not aligned properly as expected * JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms * JDK-8373704: Improve "SocketException: Protocol family unavailable" message * JDK-8373716: Refactor further java/util tests from TestNG to JUnit * JDK-8373793: TestDynamicStore.java '/manual' disables use of '/timeout' * JDK-8373796: Refactor java/net/httpclient/ /ThrowingPublishers*.java tests to use JUnit5 * JDK-8373807: test/jdk/java/net/httpclient/websocket/ /DummyWebSocketServer.java getURI() uses "localhost" * JDK-8373832: Test java/lang/invoke/TestVHInvokerCaching.java tests nothing * JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/ /bug6197830.java failed because The test case automatically fails when clicking any items in the ?Nothing? menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test * JDK-8373866: Refactor java/net/httpclient/ /ThrowingSubscribers*.java tests to use JUnit5 * JDK-8373869: Refactor java/net/httpclient/ /ThrowingPushPromises*.java tests to use JUnit5 * JDK-8373928: 4 Dangling pointer defect groups in java.c * JDK-8373931: Test javax/sound/sampled/Clip/ /AutoCloseTimeCheck.java timed out * JDK-8374058: Enhance JPEG handling * JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!" * JDK-8374322: TestMemoryWithSubgroups.java fails Permission denied * JDK-8374434: Several JShell tests report JUnit discovery warnings * JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F * JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/ /TestOptionsWithRanges fails without printing the option name * JDK-8374769: PPC: MASM::pop_cont_fastpath() should reset _cont_fastpath if SP == _cont_fastpath * JDK-8374888: Implement internal test cache to help UserIterCount test performance * JDK-8374998: Failing os::write - remove bad file * JDK-8375065: Update LCMS to 2.18 * JDK-8375080: The tools/jpackage/windows/Win8365790Test.java may fail with ClassNotFoundException: jtreg.SkippedException * JDK-8375231: Refactor util/ServiceLoader tests to use JUnit * JDK-8375232: Refactor util/StringJoiner tests to use JUnit * JDK-8375233: Refactor util/Vector tests to use JUnit * JDK-8375742: Test java/lang/invoke/MethodHandleProxies/ /Driver.java does not run Unnamed.java * JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method * JDK-8376151: Test javax/swing/JFileChooser/4966171/ /bug4966171.java is failing with OOME * JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed * JDK-8376233: Clean up code in Desktop native peer * JDK-8376889: Enhance JfrRecorder::on_create_vm_3() assert output * JDK-8377158: Enhance XBM image support * JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable * JDK-8377347: jdk/jfr/event/gc/detailed/ /TestZAllocationStallEvent.java intermittent OOME * JDK-8377498: Improve HttpServer handling * JDK-8377602: Create automated test for PageRange * JDK-8377727: Ghost caret and focus appear in non?editable text fields * JDK-8377833: Enhance Jar file processing * JDK-8377910: Minor cleanup of java/io/FileDescriptor/ /Sharing.java * JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace * JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file * JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable * JDK-8378353: [PPC64] StringCoding.countPositives causes errors when the length is not a proper 32 bit int * JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob * JDK-8378561: Mark gc/shenandoah/compiler/ /TestLinkToNativeRBP.java as /native * JDK-8378687: Improve delegation of HttpURLConnection * JDK-8378775: Bump update version for OpenJDK: jdk-21.0.12 * JDK-8378802: [21u] backport changes to TKit.java by JDK-8352419 * JDK-8378810: Enable missing FFM test via jtreg requires for RISC-V * JDK-8378878: Refactor java/nio/channels/ /AsynchronousSocketChannel test to use JUnit * JDK-8379464: Enable missing stack walking test via jtreg requires for RISC-V * JDK-8380011: Path-to-gcroots search should not trigger stack overflows * JDK-8380222: Refactor test/jdk/java/lang/Character TestNG tests to JUnit * JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument * JDK-8380428: ProblemList containers/docker/ /TestJcmdWithSideCar.java on linux-all * JDK-8380474: Crash SEGV in ThreadIdTable::lazy_initialize after JDK-8323792 * JDK-8380565: PPC64: deoptimization stub should save vector registers * JDK-8380672: Improve certification checking * JDK-8380947: Add pull request template * JDK-8381039: Enhance AWT ImagingLib * JDK-8381049: Enhance Jar handling * JDK-8381205: GHA: Upgrade Node.js 20 to 24 * JDK-8381315: compiler/vectorapi/TestVectorReallocation.java fails with -XX:UseAVX=1 after JDK-8380565 * JDK-8381519: Enhance Der Value Handling * JDK-8381796: Enhance Certificate parsing * JDK-8382018: test/jdk/java/nio/file/spi/ /SetDefaultProvider.java leaves a directory in /tmp * JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String * JDK-8382419: Add missed @key randomness after JDK-8370489 * JDK-8383175: (tz) Update Timezone Data to 2026b * JDK-8383185: [21u] Backport of JDK-8382925 causes test failure in SetDefaultProvider * JDK-8383354: Update LCMS to 2.19.1 * JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change * JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path * JDK-8383630: Fix iteration in tests doing class redefinition * JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily * JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025 * JDK-8384495: Update Libpng to 1.6.58 * JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates * JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate * JDK-8384902: Update GIFlib to 6.1.3 * JDK-8385390: Update FreeType to 2.14.3 * JDK-8385490: Update HarfBuzz to 14.2.0 * JDK-8386551: Windows build broken because of MSys2/Make update ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3332=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3332=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3332=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3332=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * java-21-openjdk-jmods-21.0.12.0-150600.3.29.1 * java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1 * java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-devel-21.0.12.0-150600.3.29.1 * java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-21.0.12.0-150600.3.29.1 * java-21-openjdk-src-21.0.12.0-150600.3.29.1 * java-21-openjdk-headless-21.0.12.0-150600.3.29.1 * java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-demo-21.0.12.0-150600.3.29.1 * openSUSE Leap 15.6 (noarch) * java-21-openjdk-javadoc-21.0.12.0-150600.3.29.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-devel-21.0.12.0-150600.3.29.1 * java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-21.0.12.0-150600.3.29.1 * java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1 * java-21-openjdk-headless-21.0.12.0-150600.3.29.1 * java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-demo-21.0.12.0-150600.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1 * java-21-openjdk-devel-21.0.12.0-150600.3.29.1 * java-21-openjdk-21.0.12.0-150600.3.29.1 * java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-headless-21.0.12.0-150600.3.29.1 * java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-demo-21.0.12.0-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1 * java-21-openjdk-devel-21.0.12.0-150600.3.29.1 * java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-21.0.12.0-150600.3.29.1 * java-21-openjdk-headless-21.0.12.0-150600.3.29.1 * java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1 * java-21-openjdk-demo-21.0.12.0-150600.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-46917.html * https://www.suse.com/security/cve/CVE-2026-46968.html * https://www.suse.com/security/cve/CVE-2026-47010.html * https://www.suse.com/security/cve/CVE-2026-47021.html * https://www.suse.com/security/cve/CVE-2026-47027.html * https://www.suse.com/security/cve/CVE-2026-47059.html * https://www.suse.com/security/cve/CVE-2026-47063.html * https://www.suse.com/security/cve/CVE-2026-60147.html * https://bugzilla.suse.com/show_bug.cgi?id=1264397 * https://bugzilla.suse.com/show_bug.cgi?id=1264994 * https://bugzilla.suse.com/show_bug.cgi?id=1267355 * https://bugzilla.suse.com/show_bug.cgi?id=1272223 * https://bugzilla.suse.com/show_bug.cgi?id=1272224 * https://bugzilla.suse.com/show_bug.cgi?id=1272225 * https://bugzilla.suse.com/show_bug.cgi?id=1272227 * https://bugzilla.suse.com/show_bug.cgi?id=1272228 * https://bugzilla.suse.com/show_bug.cgi?id=1272235 * https://bugzilla.suse.com/show_bug.cgi?id=1272236 * https://bugzilla.suse.com/show_bug.cgi?id=1272237 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:44:35 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:44:35 -0000 Subject: SUSE-SU-2026:3331-1: important: Security update for java-25-openjdk Message-ID: <178525707592.499.513246396729639093@cdce4c525ac1> # Security update for java-25-openjdk Announcement ID: SUSE-SU-2026:3331-1 Release Date: 2026-07-28T09:36:57Z Rating: important References: * bsc#1264398 * bsc#1264994 * bsc#1267355 * bsc#1272223 * bsc#1272224 * bsc#1272225 * bsc#1272227 * bsc#1272228 * bsc#1272235 * bsc#1272236 * bsc#1272237 Cross-References: * CVE-2026-41254 * CVE-2026-46917 * CVE-2026-46968 * CVE-2026-47010 * CVE-2026-47021 * CVE-2026-47027 * CVE-2026-47059 * CVE-2026-47063 * CVE-2026-60147 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities and has two security fixes can now be installed. ## Description: This update for java-25-openjdk fixes the following issues: Update to upstream tag jdk-25.0.4+7 (July 2026 CPU). Security issues fixed: * CVE-2026-41254: lcms: information disclosure and denial of service via integer overflow in `CubeSize` (bsc#1264994). * CVE-2026-46917: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1272223). * CVE-2026-46968: unauthenticated attacker with network access via TLS can gain unauthorized creation, deletion or modification access to critical data(bsc#1272224). * CVE-2026-47010: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert or delete access to some data (bsc#1272225). * CVE-2026-47021: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272227). * CVE-2026-47027: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272228). * CVE-2026-47059: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272235). * CVE-2026-47063: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation, deletion or modification access to critical data (bsc#1272236). * CVE-2026-60147: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert, delete and read access to some(bsc#1272237). Other updates and bugfixes: * Errors from update-alternatives when installing java-25-openjdk (bsc#1267355). * Make post scripts less noisy (bsc#1267355). * Use libalternatives instead of update-alternatives for distributions where libalternatives is available. * Update to upstream tag jdk-25.0.4+7 (July 2026 CPU): * JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail * JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails * JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails * JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel * JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F * JDK-8144124: [macosx] The tabs can't be aligned when we pressing the key of 'R','B','L','C' or 'T'. * JDK-8203004: UnixMultiResolutionSplashTest.java fails on Ubuntu16.04 * JDK-8213530: Test java/awt/Modal/ToFront/ /DialogToFrontModeless1Test.java fails on Linux * JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails * JDK-8225787: java/awt/Window/GetScreenLocation/ /GetScreenLocationTest.java fails on Ubuntu * JDK-8241066: Shenandoah: fix or cleanup SH::do_full_collection * JDK-8261743: Shenandoah: enable String deduplication with compact heuristics * JDK-8264851: Shenandoah: Rework control loop mechanics to use timed waits * JDK-8278102: containers/docker/TestJcmd.java failed with "RuntimeException: Could not find specified process" * JDK-8279196: Test: jdk/jfr/event/gc/stacktrace/ /TestG1OldAllocationPendingStackTrace.java timed out * JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages * JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!" * JDK-8319326: GC: Make TestParallelRefProc use createTestJavaProcessBuilder * JDK-8319540: GC: Make TestSelectDefaultGC use createTestJavaProcessBuilder * JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux * JDK-8321687: Test vmTestbase/nsk/jvmti/scenarios/contention/ /TC03/tc03t002/TestDescription.java failed: JVMTI_ERROR_THREAD_NOT_ALIVE * JDK-8323792: ThreadSnapshot::initialize can cause assert in Thread::check_for_dangling_thread_pointer (possibility of dangling Thread pointer) * JDK-8325482: Test that distinct seeds produce distinct traces for compiler stress flags * JDK-8335355: Shenandoah: Fix race condition in gc/shenandoah/ /mxbeans/TestPauseNotifications.java * JDK-8339526: C2: store incorrectly removed for clone() transformed to series of loads/stores * JDK-8340182: Java HttpClient does not follow default retry limit of 3 retries * JDK-8341735: Rewrite the build/AbsPathsInImage.java test to not load the entire file at once * JDK-8344345: test/hotspot/gtest/x86/x86-asmtest.py has trailing whitespaces * JDK-8345631: TestRegionSamplingLogging.java #generational-rotation intermittent fails * JDK-8347167: Reduce allocation in com.sun.net.httpserver.Headers::normalize * JDK-8347938: Add Support for the Latest ML-KEM and ML-DSA Private Key Encodings * JDK-8351010: Test java/io/File/GetXSpace.java failed: / usable space 56380809216 > free space 14912244940 * JDK-8352914: Shenandoah: Change definition of ShenandoahSharedValue to int32_t to leverage platform atomics * JDK-8353115: GenShen: mixed evacuation candidate regions need accurate live_data * JDK-8354650: [PPC64] Try to reduce register definitions * JDK-8355339: Test java/io/File/GetCanonicalPath.java failed: The specified network name is no longer available * JDK-8357086: os::xxx functions returning memory size should return size_t * JDK-8358600: Template-Framework Library: Template for TestFramework test class * JDK-8358772: Template-Framework Library: Primitive Types * JDK-8359083: Test jdkCheckHtml.java should report SkippedException rather than report fails when miss tidy * JDK-8359223: HttpClient: Remove leftovers from the SecurityManager cleanup * JDK-8359412: Template-Framework Library: Operations and Expressions * JDK-8359433: The final modifier on Windows L&F internal UI classes prevents extending them in apps * JDK-8361339: Test gc/shenandoah/TestLargeObjectAlignment.java #generational fails on macOS aarch64 with OOM: Java heap space * JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a * JDK-8361699: C2: assert(can_reduce_phi(n->as_Phi())) failed: Sanity: previous reducible Phi is no longer reducible before SUT * JDK-8361726: Shenandoah: More detailed evacuation instrumentation * JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25 * JDK-8363943: ARM32: Represent Registers as values * JDK-8363949: Incorrect jtreg header in MonitorWithDeadObjectTest.java * JDK-8363986: Heap region in CDS archive is not at deterministic address * JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/ /jaxp/functional/javax/xml/transform/xmlfiles * JDK-8364657: Crash for SecureRandom.generateSeed(0) on Windows x86-64 * JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java * JDK-8365057: Add support for java.util.concurrent lock information to Thread.dump_to_file * JDK-8365379: SU3.applyInsets may produce wrong results * JDK-8365423: [macos26] java/awt/MenuBar/8007006/ /bug8007006.java fails on macOS 26 * JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26 * JDK-8365623: test/jdk/sun/security/pkcs11/tls/ tests skipped without skip exception * JDK-8365625: Can't change accelerator colors in Windows L&F * JDK-8365792: GenShen: assertion "Generations aren't reconciled" * JDK-8366692: Several gc/shenandoah tests timed out * JDK-8366695: Test sun/jvmstat/monitor/MonitoredVm/ /MonitorVmStartTerminate.java timed out * JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ /ChoiceMouseWheelTest.java test is failing * JDK-8367096: jdk/open/test/jdk/sun/security/pkcs11/ rsa, ec, config, secmod and sslecc tests are skipping but showing as pass * JDK-8367450: Shenandoah: Log the composition of the collection set * JDK-8367451: GenShen: Remove the option to compute age census during evacuation * JDK-8367473: Shenandoah: Make the detailed evacuation metrics a runtime diagnostic option * JDK-8367485: os::physical_memory is broken in 32-bit JVMs when running on 64-bit OSes * JDK-8367531: Template Framework: use scopes and tokens instead of misbehaving immediate-return-queries * JDK-8367646: [GenShen] Control thread may overwrite gc cancellation cause set by mutator * JDK-8367708: GenShen: Reduce total evacuation burden * JDK-8367709: GenShen: Dirty cards for objects that get promoted by safepoint that intervenes between allocation and stores * JDK-8367722: [GenShen] ShenandoahEvacuationStats is always empty * JDK-8367949: JFR: MethodTrace double-counts methods that catch their own exceptions * JDK-8368001: java/text/Format/NumberFormat/ /NumberRoundTrip.java timed out * JDK-8368015: Shenandoah: fix error in computation of average allocation rate * JDK-8368041: Enhance TLS certificate handling * JDK-8368159: Significant performance overhead when started with jdwp agent and unattached debugger * JDK-8368181: ProblemList java/awt/Dialog/ModalExcludedTest/ /ModalExcludedTest.java * JDK-8368307: Shenandoah: get_next_bit_impl should special case weak and strong mark bits * JDK-8368499: GenShen: Do not collect age census during evac when adaptive tenuring is disabled * JDK-8368501: Shenandoah: GC progress evaluation does not use generation * JDK-8368524: Tests are skipped and shown as passed in test/ /jdk/sun/security/pkcs11/Cipher/KeyWrap * JDK-8368681: Shenandoah: Add documentation comments for ShenandoahAllocationRate * JDK-8369128: ProblemList jdk/jfr/event/profiling/ /TestCPUTimeSampleQueueAutoSizes.java in Xcomp configs * JDK-8369132: Disable vmTestbase/gc/vector/CircularListLow and LinearListLow with SerialGC * JDK-8369133: Disable gc/g1/TestShrinkAuxiliaryDataRunner.java with UseLargePages option * JDK-8369251: Opensource few tests * JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual=ff000000) * JDK-8369683: Exclude runtime/Monitor/ /MonitorWithDeadObjectTest.java#DumpThreadsBeforeDetach on Alpine Linux debug * JDK-8369736: Add management interface for AOT cache creation * JDK-8369817: [TESTBUG] EmptyPath::toString is ignored * JDK-8369912: [TESTBUG] testlibrary_tests/template_framework/ /examples/TestExpressions.java fails with ArithmeticException: / by zero - forgot to respect Expression.info * JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException * JDK-8370370: Add still more cases to WorstCaseTests * JDK-8370489: Some compiler tests miss the @key randomness * JDK-8370502: C2: segfault while adding node to IGVN worklist * JDK-8370521: GenShen: Various code cleanup related to promotion * JDK-8370939: C2: SIGSEGV in SafePointNode::verify_input when processing MH call from Compile::process_late_inline_calls_no_inline() * JDK-8371284: GenShen: Avoid unnecessary card marking * JDK-8371381: [Shenandoah] Setting ergo flags should use FLAG_SET_ERGO * JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests * JDK-8371792: Refactor barrier loop tests out of TestIfMinMax * JDK-8371893: [macOS] use dead_strip linker option to reduce binary size * JDK-8372272: Hotspot shared lib loading - add load attempts to Events::log * JDK-8372351: Add 2 WISeKey roots * JDK-8372380: Make hs_err reporting more robust for unattached threads * JDK-8372513: Shenandoah: ShenandoahMaxRegionSize can produce an unaligned heap alignment * JDK-8372851: Modify java/io/File/GetXSpace.java to print path on failure of native call * JDK-8372861: Genshen: Override parallel_region_stride of ShenandoahResetBitmapClosure to a reasonable value for better parallelism * JDK-8373039: Remove Incorrect Asserts in shenandoahScanRemembered * JDK-8373120: Virtual thread stuck in BLOCKED state * JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages * JDK-8373275: Improve DTLS handshaking * JDK-8373515: Migrate "test/jdk/java/net/httpclient/" to null-safe "SimpleSSLContext" methods * JDK-8373579: Problem list compiler/runtime/Test7196199.java * JDK-8373650: Test "javax/swing/JMenuItem/6458123/ /ManualBug6458123.java" fails because the check icons are not aligned properly as expected * JDK-8373676: Test javax/net/ssl/HttpsURLConnection/ /SubjectAltNameIP.java fails on a machine without IPV6 * JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms * JDK-8373714: Shenandoah: Register heuristic penalties following a degenerated GC * JDK-8373718: jdk/internal/misc/VM/RuntimeArguments.java test fails in Virtual threads mode * JDK-8373796: Refactor java/net/httpclient/ /ThrowingPublishers*.java tests to use JUnit5 * JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/ /bug6197830.java failed because The test case automatically fails when clicking any items in the ?Nothing? menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test * JDK-8373866: Refactor java/net/httpclient/ /ThrowingSubscribers*.java tests to use JUnit5 * JDK-8373893: Refactor networking http server tests to use JUnit * JDK-8373913: Refactor serialization tests to use JUnit * JDK-8373928: 4 Dangling pointer defect groups in java.c * JDK-8374001: sun/security/ skip without Exceptions * JDK-8374058: Enhance JPEG handling * JDK-8374168: Resolve disabled warnings in JDWP agent * JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!" * JDK-8374322: TestMemoryWithSubgroups.java fails Permission denied * JDK-8374343: Fix SIGSEGV when lib/modules is unreadable * JDK-8374449: Shenandoah: Leaf locks used by Shenandoah need lower ranks * JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F * JDK-8374712: AOTMappedHeapWriter::relocate_field_in_buffer should use CompressedOops::narrow_oop_cast * JDK-8374727: Audio configuration Platform class - use nio for getting endianness of the underlying platform * JDK-8374744: Enable dumping of APX EGPRs (R16?R31) in JVM fatal error logs * JDK-8374769: PPC: MASM::pop_cont_fastpath() should reset _cont_fastpath if SP == _cont_fastpath * JDK-8374888: Implement internal test cache to help UserIterCount test performance * JDK-8374998: Failing os::write - remove bad file * JDK-8375065: Update LCMS to 2.18 * JDK-8375177: Gtest os_linux.decoder_get_source_info_valid_vm fails with -ffunction-sections * JDK-8375294: (fs) Files.copy can fail with EOPNOTSUPP when copy_file_range not supported * JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method * JDK-8376104: C2 crashes in PhiNode::Ideal(PhaseGVN*, bool) accessing NULL pointer * JDK-8376151: Test javax/swing/JFileChooser/4966171/ /bug4966171.java is failing with OOME * JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed * JDK-8376185: NoSuchFieldError thrown after a record with type annotation retransformed * JDK-8376233: Clean up code in Desktop native peer * JDK-8376287: Crashes when using -XX:ObjArrayMarkingStride=0 * JDK-8376402: Dependencies::print_statistics() and AbstractClassHierarchyWalker::print_statistics() are not called from PRODUCT code * JDK-8376684: Compile OpenJDK in headless mode without required X11 libraries * JDK-8376956: Add JVMTI phase entering/setting to hserr event log * JDK-8376969: Shenandoah: GC state getters should be inlineable * JDK-8376970: Shenandoah: Verifier should do basic verification before touching oops * JDK-8377158: Enhance XBM image support * JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable * JDK-8377498: Improve HttpServer handling * JDK-8377512: AOT cache creation fails with invalid native pointer * JDK-8377602: Create automated test for PageRange * JDK-8377727: Ghost caret and focus appear in non?editable text fields * JDK-8377833: Enhance Jar file processing * JDK-8377907: (process) Race in ProcessBuilder can cause JVM hangs * JDK-8377910: Minor cleanup of java/io/FileDescriptor/ /Sharing.java * JDK-8377932: AOT cache is not rejected when JAR file has changed * JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace * JDK-8377949: TestZRelocationSetEvent.java intermittent fails OOME * JDK-8378083: Mark shenandoah/generational/ /TestOldGrowthTriggers.java as flagless * JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable * JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob * JDK-8378561: Mark gc/shenandoah/compiler/ /TestLinkToNativeRBP.java as /native * JDK-8378687: Improve delegation of HttpURLConnection * JDK-8378727: [macOS] Missing dispatch_release for semaphores in CDesktopPeer * JDK-8378746: ZGC: jdk/jfr/event/gc/detailed/ /TestZRelocationSetGroupEvent.java intermittent OOME * JDK-8378764: fileStream::fileSize() fails for >2GB files on Windows * JDK-8378774: Bump update version for OpenJDK: jdk-25.0.4 * JDK-8378810: Enable missing FFM test via jtreg requires for RISC-V * JDK-8378836: Enable linktime-gc by default on Linux ppc64le * JDK-8378878: Refactor java/nio/channels/ /AsynchronousSocketChannel test to use JUnit * JDK-8378888: jdk/incubator/vector/ /Float16OperationsBenchmark.java uses wrong package name * JDK-8379021: Shenandoah: Speedup ShenandoahSimpleBitMapTest * JDK-8379202: Support linktime-gc on Linux with clang * JDK-8379416: AIX build fails if system (not GNU) date tool is in PATH * JDK-8379425: Windows and macOS should not allow unsupported headless-only build * JDK-8379457: Test EATests.java#id0 ERROR: monitor list errors: error_cnt=1 * JDK-8379464: Enable missing stack walking test via jtreg requires for RISC-V * JDK-8379499: [AIX] headless-only build of libjawt.so fails * JDK-8379515: draft-ietf-lamps-kyber-certificates is now RFC 9935 * JDK-8380011: Path-to-gcroots search should not trigger stack overflows * JDK-8380041: PPC: remove POWER6 remnants * JDK-8380222: Refactor test/jdk/java/lang/Character TestNG tests to JUnit * JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument * JDK-8380409: JVM crashes when -XX:AOTMode=create uses app.aotconf generated with JVMTI agent * JDK-8380428: ProblemList containers/docker/ /TestJcmdWithSideCar.java on linux-all * JDK-8380431: Shenandoah: Concurrent modification of stack-chunk objects during evacuation * JDK-8380474: Crash SEGV in ThreadIdTable::lazy_initialize after JDK-8323792 * JDK-8380565: PPC64: deoptimization stub should save vector registers * JDK-8380663: Update jcmd man page to include AOT.end_recording diagnostic command * JDK-8380672: Improve certification checking * JDK-8380846: GenShen: Remove the experimental option to disable adaptive tenuring * JDK-8380947: Add pull request template * JDK-8381039: Enhance AWT ImagingLib * JDK-8381049: Enhance Jar handling * JDK-8381205: GHA: Upgrade Node.js 20 to 24 * JDK-8381315: compiler/vectorapi/TestVectorReallocation.java fails with -XX:UseAVX=1 after JDK-8380565 * JDK-8381382: Shenandoah: assert(capacity > 0) failed: free regions must have allocation capacity * JDK-8381519: Enhance Der Value Handling * JDK-8381796: Enhance Certificate parsing * JDK-8381871: GenShen: ShenandoahGCHeuristics flag not reset after ignoring non-adaptive value * JDK-8381935: Improve numChunks range in the PPC64 CallAranger * JDK-8381937: Make exceptions in Java_sun_security_mscapi_CKeyPairGenerator generateCKeyPair more specific * JDK-8382018: test/jdk/java/nio/file/spi/ /SetDefaultProvider.java leaves a directory in /tmp * JDK-8382020: Time Zone Abbreviation Not Localized for Non-English Locales * JDK-8382035: [ubsan] Under UBSAN builds, disable tests that rely on simulated JVM crashes * JDK-8382090: Remove .rej and .orig from .gitignore * JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String * JDK-8382295: Shenandoah: wrong denominator in full gc summary * JDK-8382395: Disable stringop-overflow in shenandoahGenerationalHeap.cpp * JDK-8382419: Add missed @key randomness after JDK-8370489 * JDK-8382522: Disable stringop-overflow in safepointMechanism.cpp * JDK-8382740: JFR: Disable jdk.OldObjectSample event for generational ZGC * JDK-8382878: RISC-V: Missing InlineSkippedInstructionsCounter in ZGC barriers stubs * JDK-8382932: [25u] Test java/lang/instrument/ /RetransformRecordTypeAnn/TestRetransformRecord.java? fails with compilation error * JDK-8383161: [PPC64] MachCallDynamicJavaNode::ret_addr_offset() needs adaptation for COH * JDK-8383175: (tz) Update Timezone Data to 2026b * JDK-8383183: Shenandoah: Mangle trashed regions up to top instead of end * JDK-8383354: Update LCMS to 2.19.1 * JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change * JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path * JDK-8383630: Fix iteration in tests doing class redefinition * JDK-8384043: [REDO] Incorrect handling of Hawaii_Aleutian metazone * JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily * JDK-8384163: (so) SocketChannel.connect and finishConnect() exception messages could be improved * JDK-8384223: RISC-V: entry_barrier_offset should consider UseZtso * JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025 * JDK-8384495: Update Libpng to 1.6.58 * JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates * JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate * JDK-8384902: Update GIFlib to 6.1.3 * JDK-8385390: Update FreeType to 2.14.3 * JDK-8385490: Update HarfBuzz to 14.2.0 * JDK-8386551: Windows build broken because of MSys2/Make update ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3331=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-25-openjdk-devel-25.0.4.0-150700.15.13.1 * java-25-openjdk-headless-25.0.4.0-150700.15.13.1 * java-25-openjdk-demo-25.0.4.0-150700.15.13.1 * java-25-openjdk-debuginfo-25.0.4.0-150700.15.13.1 * java-25-openjdk-devel-debuginfo-25.0.4.0-150700.15.13.1 * java-25-openjdk-headless-debuginfo-25.0.4.0-150700.15.13.1 * java-25-openjdk-25.0.4.0-150700.15.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-46917.html * https://www.suse.com/security/cve/CVE-2026-46968.html * https://www.suse.com/security/cve/CVE-2026-47010.html * https://www.suse.com/security/cve/CVE-2026-47021.html * https://www.suse.com/security/cve/CVE-2026-47027.html * https://www.suse.com/security/cve/CVE-2026-47059.html * https://www.suse.com/security/cve/CVE-2026-47063.html * https://www.suse.com/security/cve/CVE-2026-60147.html * https://bugzilla.suse.com/show_bug.cgi?id=1264398 * https://bugzilla.suse.com/show_bug.cgi?id=1264994 * https://bugzilla.suse.com/show_bug.cgi?id=1267355 * https://bugzilla.suse.com/show_bug.cgi?id=1272223 * https://bugzilla.suse.com/show_bug.cgi?id=1272224 * https://bugzilla.suse.com/show_bug.cgi?id=1272225 * https://bugzilla.suse.com/show_bug.cgi?id=1272227 * https://bugzilla.suse.com/show_bug.cgi?id=1272228 * https://bugzilla.suse.com/show_bug.cgi?id=1272235 * https://bugzilla.suse.com/show_bug.cgi?id=1272236 * https://bugzilla.suse.com/show_bug.cgi?id=1272237 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:45:24 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:45:24 -0000 Subject: SUSE-SU-2026:3330-1: moderate: Security update for libssh Message-ID: <178525712423.499.3676230729466774985@cdce4c525ac1> # Security update for libssh Announcement ID: SUSE-SU-2026:3330-1 Release Date: 2026-07-28T09:36:04Z Rating: moderate References: * bsc#1272164 * bsc#1272165 * bsc#1272166 * bsc#1272167 * bsc#1272168 * bsc#1272169 * bsc#1272171 Cross-References: * CVE-2026-59843 * CVE-2026-59844 * CVE-2026-59845 * CVE-2026-59846 * CVE-2026-59847 * CVE-2026-59848 * CVE-2026-59850 CVSS scores: * CVE-2026-59843 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59843 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59845 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-59845 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2026-59846 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59846 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59847 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-59847 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59848 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59848 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for libssh fixes the following issues: * CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). * CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). * CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). * CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). * CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). * CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). * CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3330=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3330=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3330=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3330=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libssh4-debuginfo-0.9.8-150600.11.15.1 * libssh-config-0.9.8-150600.11.15.1 * libssh4-0.9.8-150600.11.15.1 * libssh-devel-0.9.8-150600.11.15.1 * libssh-debugsource-0.9.8-150600.11.15.1 * openSUSE Leap 15.6 (x86_64) * libssh4-32bit-0.9.8-150600.11.15.1 * libssh4-32bit-debuginfo-0.9.8-150600.11.15.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libssh4-64bit-0.9.8-150600.11.15.1 * libssh4-64bit-debuginfo-0.9.8-150600.11.15.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libssh4-debuginfo-0.9.8-150600.11.15.1 * libssh-config-0.9.8-150600.11.15.1 * libssh4-0.9.8-150600.11.15.1 * libssh-devel-0.9.8-150600.11.15.1 * libssh-debugsource-0.9.8-150600.11.15.1 * Basesystem Module 15-SP7 (x86_64) * libssh4-32bit-0.9.8-150600.11.15.1 * libssh4-32bit-debuginfo-0.9.8-150600.11.15.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libssh4-debuginfo-0.9.8-150600.11.15.1 * libssh-config-0.9.8-150600.11.15.1 * libssh4-0.9.8-150600.11.15.1 * libssh-devel-0.9.8-150600.11.15.1 * libssh-debugsource-0.9.8-150600.11.15.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libssh4-32bit-0.9.8-150600.11.15.1 * libssh4-32bit-debuginfo-0.9.8-150600.11.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libssh4-32bit-0.9.8-150600.11.15.1 * libssh4-32bit-debuginfo-0.9.8-150600.11.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libssh4-debuginfo-0.9.8-150600.11.15.1 * libssh-config-0.9.8-150600.11.15.1 * libssh4-0.9.8-150600.11.15.1 * libssh-devel-0.9.8-150600.11.15.1 * libssh-debugsource-0.9.8-150600.11.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59843.html * https://www.suse.com/security/cve/CVE-2026-59844.html * https://www.suse.com/security/cve/CVE-2026-59845.html * https://www.suse.com/security/cve/CVE-2026-59846.html * https://www.suse.com/security/cve/CVE-2026-59847.html * https://www.suse.com/security/cve/CVE-2026-59848.html * https://www.suse.com/security/cve/CVE-2026-59850.html * https://bugzilla.suse.com/show_bug.cgi?id=1272164 * https://bugzilla.suse.com/show_bug.cgi?id=1272165 * https://bugzilla.suse.com/show_bug.cgi?id=1272166 * https://bugzilla.suse.com/show_bug.cgi?id=1272167 * https://bugzilla.suse.com/show_bug.cgi?id=1272168 * https://bugzilla.suse.com/show_bug.cgi?id=1272169 * https://bugzilla.suse.com/show_bug.cgi?id=1272171 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:47:21 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:47:21 -0000 Subject: SUSE-SU-2026:3327-1: important: Security update for yq Message-ID: <178525724166.499.12582225261725118388@cdce4c525ac1> # Security update for yq Announcement ID: SUSE-SU-2026:3327-1 Release Date: 2026-07-28T09:18:18Z Rating: important References: * bsc#1267199 * bsc#1271994 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for yq fixes the following issues: Update to v4.53.3. * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1267199). * CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1271994). Changes for yq: * v4.53.3: * Add --ini-preserve-quotes flag for INI round-trip quote preservation. * Fix: reset INI decoder state on init. * Fix: decode properties array bracket paths. * Fix: preserve floats with trailing zero when encoding YAML to JSON. * Fix: JSON to TOML root scope and null handling. * Fix: reset TOML decoder finished flag on Init for multi-doc evaluation. * Fix: reset TOML decoder between files when evaluating all at once. * Fix: preserve TOML inline table array scope. * Fix: preserve empty TOML arrays in tables * Fix: TOML encoder uses inline tables for YAML FlowStyle mappings. * Fix nested inline YAML merge explode. * Fix repeatString overflow test on 32-bit platforms. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3327=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3327=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * yq-debuginfo-4.53.3-150500.3.12.1 * yq-4.53.3-150500.3.12.1 * openSUSE Leap 15.5 (noarch) * yq-bash-completion-4.53.3-150500.3.12.1 * yq-zsh-completion-4.53.3-150500.3.12.1 * yq-fish-completion-4.53.3-150500.3.12.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * yq-debuginfo-4.53.3-150500.3.12.1 * yq-4.53.3-150500.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1267199 * https://bugzilla.suse.com/show_bug.cgi?id=1271994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 16:46:24 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 16:46:24 -0000 Subject: SUSE-SU-2026:3329-1: important: Security update for nginx Message-ID: <178525718423.499.9131619300107648437@cdce4c525ac1> # Security update for nginx Announcement ID: SUSE-SU-2026:3329-1 Release Date: 2026-07-28T09:34:39Z Rating: important References: * bsc#1267525 * bsc#1268492 * bsc#1268495 Cross-References: * CVE-2026-42055 * CVE-2026-48142 CVSS scores: * CVE-2026-42055 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42055 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48142 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-48142 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48142 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for nginx fixes the following issues * CVE-2026-42055: heap-based buffer overflow in the `ngx_http_proxy_v2_module` and `ngx_http_grpc_module` modules (bsc#1268492). * CVE-2026-48142: heap buffer over-read in the `ngx_http_charset_module` module (bsc#1268495). * Remote denial of service via the HTTP/2 bomb exploit (bsc#1267525). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3329=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3329=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3329=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3329=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * nginx-debugsource-1.21.5-150600.10.24.1 * nginx-debuginfo-1.21.5-150600.10.24.1 * nginx-1.21.5-150600.10.24.1 * openSUSE Leap 15.6 (noarch) * nginx-source-1.21.5-150600.10.24.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * nginx-debugsource-1.21.5-150600.10.24.1 * nginx-debuginfo-1.21.5-150600.10.24.1 * nginx-1.21.5-150600.10.24.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * nginx-source-1.21.5-150600.10.24.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * nginx-debugsource-1.21.5-150600.10.24.1 * nginx-debuginfo-1.21.5-150600.10.24.1 * nginx-1.21.5-150600.10.24.1 * Server Applications Module 15-SP7 (noarch) * nginx-source-1.21.5-150600.10.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * nginx-debugsource-1.21.5-150600.10.24.1 * nginx-debuginfo-1.21.5-150600.10.24.1 * nginx-1.21.5-150600.10.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * nginx-source-1.21.5-150600.10.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42055.html * https://www.suse.com/security/cve/CVE-2026-48142.html * https://bugzilla.suse.com/show_bug.cgi?id=1267525 * https://bugzilla.suse.com/show_bug.cgi?id=1268492 * https://bugzilla.suse.com/show_bug.cgi?id=1268495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:31:40 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:31:40 -0000 Subject: SUSE-SU-2026:22956-1: moderate: Security update for libssh Message-ID: <178527070098.544.899320505744886138@f1bb1996abf5> # Security update for libssh Announcement ID: SUSE-SU-2026:22956-1 Release Date: 2026-07-25T17:18:11Z Rating: moderate References: * bsc#1272162 * bsc#1272164 * bsc#1272165 * bsc#1272166 * bsc#1272167 * bsc#1272168 * bsc#1272169 * bsc#1272170 * bsc#1272171 * jsc#PED-15815 Cross-References: * CVE-2026-15370 * CVE-2026-59843 * CVE-2026-59844 * CVE-2026-59845 * CVE-2026-59846 * CVE-2026-59847 * CVE-2026-59848 * CVE-2026-59849 * CVE-2026-59850 CVSS scores: * CVE-2026-15370 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-15370 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15370 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59843 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59843 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59845 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-59845 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2026-59846 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59846 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59847 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-59847 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59848 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59848 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59849 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59849 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59849 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities and contains one feature can now be installed. ## Description: This update for libssh fixes the following issues: * CVE-2026-15370: stack buffer overflow in SFTP server longname construction (bsc#1272162). * CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). * CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). * CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). * CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). * CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). * CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). * CVE-2026-59849: denial of service via automatic certificate authentication loop (bsc#1272170). * CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). Changes for libssh: * Update to 0.11.5: * Zero-initialize every ssh_string * Fix compatibility with C23 / gcc16 * Fix multiple memory leaks, null checks, and error checks * Validate peer public key in DH key exchange * Avoid remote window overflow * Avoid off-by-one overflow during kbdint authentication * Avoid logging uninitialized sequence numbers * Avoid double conversion of SFTP version number * Send correct SFTP server version number * Avoid handling repeated SFTP INIT messages * Harmonize return values from SFTP server callbacks * Update %suse_version checks for SLES 16.x (jsc#PED-15815) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1349=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1349=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libssh4-debuginfo-0.11.5-160000.1.1 * libssh4-0.11.5-160000.1.1 * libssh-devel-0.11.5-160000.1.1 * libssh-debugsource-0.11.5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * libssh-config-0.11.5-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libssh-debugsource-0.11.5-160000.1.1 * libssh4-debuginfo-0.11.5-160000.1.1 * libssh4-0.11.5-160000.1.1 * libssh-devel-0.11.5-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * libssh-config-0.11.5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15370.html * https://www.suse.com/security/cve/CVE-2026-59843.html * https://www.suse.com/security/cve/CVE-2026-59844.html * https://www.suse.com/security/cve/CVE-2026-59845.html * https://www.suse.com/security/cve/CVE-2026-59846.html * https://www.suse.com/security/cve/CVE-2026-59847.html * https://www.suse.com/security/cve/CVE-2026-59848.html * https://www.suse.com/security/cve/CVE-2026-59849.html * https://www.suse.com/security/cve/CVE-2026-59850.html * https://bugzilla.suse.com/show_bug.cgi?id=1272162 * https://bugzilla.suse.com/show_bug.cgi?id=1272164 * https://bugzilla.suse.com/show_bug.cgi?id=1272165 * https://bugzilla.suse.com/show_bug.cgi?id=1272166 * https://bugzilla.suse.com/show_bug.cgi?id=1272167 * https://bugzilla.suse.com/show_bug.cgi?id=1272168 * https://bugzilla.suse.com/show_bug.cgi?id=1272169 * https://bugzilla.suse.com/show_bug.cgi?id=1272170 * https://bugzilla.suse.com/show_bug.cgi?id=1272171 * https://jira.suse.com/browse/PED-15815 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:31:08 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:31:08 -0000 Subject: SUSE-RU-2026:22957-1: moderate: Recommended update for policycoreutils Message-ID: <178527066813.544.11527047959426946884@f1bb1996abf5> # Recommended update for policycoreutils Announcement ID: SUSE-RU-2026:22957-1 Release Date: 2026-07-27T09:30:50Z Rating: moderate References: * bsc#1271645 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for policycoreutils fixes the following issues: Changes in policycoreutils: * Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645) * can be dropped once "policycoreutils/scripts/fixfiles: drop /tmp cleanup" is in the upstream release ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1350=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1350=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * policycoreutils-3.8.1-160000.5.1 * policycoreutils-debugsource-3.8.1-160000.5.1 * policycoreutils-devel-debuginfo-3.8.1-160000.5.1 * policycoreutils-debuginfo-3.8.1-160000.5.1 * policycoreutils-devel-3.8.1-160000.5.1 * policycoreutils-newrole-3.8.1-160000.5.1 * policycoreutils-newrole-debuginfo-3.8.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * policycoreutils-python-utils-3.8.1-160000.5.1 * policycoreutils-lang-3.8.1-160000.5.1 * python313-policycoreutils-3.8.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * policycoreutils-python-utils-3.8.1-160000.5.1 * policycoreutils-lang-3.8.1-160000.5.1 * python313-policycoreutils-3.8.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * policycoreutils-3.8.1-160000.5.1 * policycoreutils-debugsource-3.8.1-160000.5.1 * policycoreutils-devel-debuginfo-3.8.1-160000.5.1 * policycoreutils-debuginfo-3.8.1-160000.5.1 * policycoreutils-devel-3.8.1-160000.5.1 * policycoreutils-newrole-3.8.1-160000.5.1 * policycoreutils-newrole-debuginfo-3.8.1-160000.5.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271645 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:30:28 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:30:28 -0000 Subject: SUSE-SU-2026:22958-1: moderate: Security update for go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21 Message-ID: <178527062894.544.14605787340960600079@f1bb1996abf5> # Security update for go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21 Announcement ID: SUSE-SU-2026:22958-1 Release Date: 2026-07-27T10:21:06Z Rating: moderate References: * bsc#1245878 * bsc#1264390 * bsc#1264391 * bsc#1264392 * bsc#1264393 * bsc#1264394 * bsc#1264395 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2025-22871 CVSS scores: * CVE-2025-22871 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2025-22871 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-22871 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves one vulnerability, contains two features and has six fixes can now be installed. ## Description: This update for go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21 fixes the following issues: Changes in go compilers: * Switch from update-alternatives to new method. * Packaging improvements: * Revert %ghost /usr/bin/go /usr/bin/gofmt which prevents install of a working go command. Refs boo#1245878 bsc#1264395 * Based on feedback from Factory maintainers restore the original lifecycle for these files: Each go1.x toolchain shares ownership of a go and gofmt symlink managed by the alternatives system (update-alternatives and libalternatives). When the last go1.x package is uninstalled the symlinks will be removed. * Context: %ghost was introduced to prevent file conflicts among go1.x toolchain packages reported by installcheck dev tool. %ghost prevents the files from being installed, which results in no installed go command. The shared ownership of the go and gofmt symlinks is intentional. * Define go_bootstrap_version with digits without go1.x prefix. Correct path spelling to align with current toolchain layout GOROOT_BOOTSTRAP=%{_libdir}/go/%{go_bootstrap_version}, Noting interstitial /go/ in path. Fixes bootstrap ERROR: Cannot find /usr/lib64/go1.x/bin/go. Set $GOROOT_BOOTSTRAP to a working Go tree >= Go 1.x.y. Bootstrap error first observed when using %ghost /usr/bin/go. Fixed by Eugenio Paolantonio. Refs boo#1245878 bsc#1264395 * Mark %ghost /usr/bin/go /usr/bin/gofmt to avoid file conflicts among go1.x toolchain packages. These files are managed by the alternatives system. Refs boo#1245878 bsc#1264395 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1352=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.25-openssl-debuginfo-1.25.12-160000.2.1 * go1.24-doc-1.24.13-160000.3.1 * go1.26-openssl-race-1.26.5-160000.2.1 * go1.24-1.24.13-160000.3.1 * go1.25-doc-1.25.12-160000.2.1 * go1.24-openssl-1.24.13-160000.3.1 * go1.26-race-1.26.5-160000.2.1 * go1.26-doc-1.26.5-160000.2.1 * go1.24-openssl-debuginfo-1.24.13-160000.3.1 * go1.24-openssl-race-1.24.13-160000.3.1 * go1.26-1.26.5-160000.2.1 * go1.24-openssl-doc-1.24.13-160000.3.1 * go1.26-openssl-doc-1.26.5-160000.2.1 * go1.25-1.25.12-160000.2.1 * go1.25-openssl-1.25.12-160000.2.1 * go1.26-openssl-1.26.5-160000.2.1 * go1.25-race-1.25.12-160000.2.1 * go1.25-openssl-race-1.25.12-160000.2.1 * go1.25-openssl-doc-1.25.12-160000.2.1 * go1.24-race-1.24.13-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22871.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1264390 * https://bugzilla.suse.com/show_bug.cgi?id=1264391 * https://bugzilla.suse.com/show_bug.cgi?id=1264392 * https://bugzilla.suse.com/show_bug.cgi?id=1264393 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:32:20 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:32:20 -0000 Subject: SUSE-SU-2026:22955-1: important: Security update for openssl-3 Message-ID: <178527074097.544.10932105510376311852@f1bb1996abf5> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22955-1 Release Date: 2026-07-25T16:36:55Z Rating: important References: * bsc#1271712 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for openssl-3 fixes the following issue: * "HollowByte" DoS via attacker-controlled memory allocation (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1348=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1348=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libopenssl3-debuginfo-3.5.0-160000.9.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.9.1 * openssl-3-3.5.0-160000.9.1 * libopenssl-3-fips-provider-3.5.0-160000.9.1 * libopenssl-3-devel-3.5.0-160000.9.1 * openssl-3-debugsource-3.5.0-160000.9.1 * openssl-3-debuginfo-3.5.0-160000.9.1 * libopenssl3-3.5.0-160000.9.1 * SUSE Linux Enterprise Server 16.0 (noarch) * openssl-3-doc-3.5.0-160000.9.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.9.1 * libopenssl3-x86-64-v3-debuginfo-3.5.0-160000.9.1 * libopenssl-3-fips-provider-x86-64-v3-debuginfo-3.5.0-160000.9.1 * libopenssl3-x86-64-v3-3.5.0-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libopenssl3-debuginfo-3.5.0-160000.9.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.9.1 * openssl-3-3.5.0-160000.9.1 * libopenssl-3-devel-3.5.0-160000.9.1 * libopenssl-3-fips-provider-3.5.0-160000.9.1 * openssl-3-debugsource-3.5.0-160000.9.1 * openssl-3-debuginfo-3.5.0-160000.9.1 * libopenssl3-3.5.0-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * openssl-3-doc-3.5.0-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.9.1 * libopenssl3-x86-64-v3-3.5.0-160000.9.1 * libopenssl3-x86-64-v3-debuginfo-3.5.0-160000.9.1 * libopenssl-3-fips-provider-x86-64-v3-debuginfo-3.5.0-160000.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:32:59 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:32:59 -0000 Subject: SUSE-SU-2026:22954-1: important: Security update for alloy Message-ID: <178527077981.544.4981662259229516274@f1bb1996abf5> # Security update for alloy Announcement ID: SUSE-SU-2026:22954-1 Release Date: 2026-07-24T15:44:11Z Rating: important References: * bsc#1267811 Cross-References: * CVE-2026-10722 CVSS scores: * CVE-2026-10722 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10722 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10722 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10722 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-10722 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for alloy fixes the following issue: Update to version 1.17.1. Security issue fixed: * CVE-2026-10722: github.com/cilium/ebpf: interger overflow when performing BTF string offset boundary check can lead to crash when malformed ELF/BTF input is parsed (bsc#1267811). Other updates and bugfixes: \- Version 1.17.1: * Back off usage reporting on persistent failure instead of retrying every minute. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1347=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1347=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * alloy-debuginfo-1.17.1-160000.1.1 * alloy-1.17.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * alloy-debuginfo-1.17.1-160000.1.1 * alloy-1.17.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10722.html * https://bugzilla.suse.com/show_bug.cgi?id=1267811 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:33:49 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:33:49 -0000 Subject: SUSE-SU-2026:22953-1: important: Security update for java-17-openjdk Message-ID: <178527082985.544.9829717501955192311@f1bb1996abf5> # Security update for java-17-openjdk Announcement ID: SUSE-SU-2026:22953-1 Release Date: 2026-07-24T08:43:19Z Rating: important References: * bsc#1264994 * bsc#1272223 * bsc#1272224 * bsc#1272225 * bsc#1272227 * bsc#1272228 * bsc#1272235 * bsc#1272236 * bsc#1272237 Cross-References: * CVE-2026-41254 * CVE-2026-46917 * CVE-2026-46968 * CVE-2026-47010 * CVE-2026-47021 * CVE-2026-47027 * CVE-2026-47059 * CVE-2026-47063 * CVE-2026-60147 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for java-17-openjdk fixes the following issues * Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU) * CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). * CVE-2026-46917: partial denial of service via TLS (bsc#1272223). * CVE-2026-46968: unauthorized creation, deletion or modification access to critical data (bsc#1272224). * CVE-2026-47010: unauthorized update, insert or delete access (bsc#1272225). * CVE-2026-47021: partial denial of service via multiple network protocols (bsc#1272227). * CVE-2026-47027: partial denial of service via multiple network protocols (bsc#1272228). * CVE-2026-47059: partial denial of service via multiple network protocols (bsc#1272235). * CVE-2026-47063: unauthorized creation, deletion or modification access to critical data (bsc#1272236). * CVE-2026-60147: unauthorized update, insert or delete access (bsc#1272237). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1344=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1344=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-devel-17.0.20.0-160000.1.1 * java-17-openjdk-jmods-17.0.20.0-160000.1.1 * java-17-openjdk-src-17.0.20.0-160000.1.1 * java-17-openjdk-debuginfo-17.0.20.0-160000.1.1 * java-17-openjdk-headless-17.0.20.0-160000.1.1 * java-17-openjdk-17.0.20.0-160000.1.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-160000.1.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-160000.1.1 * java-17-openjdk-demo-17.0.20.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * java-17-openjdk-javadoc-17.0.20.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * java-17-openjdk-devel-17.0.20.0-160000.1.1 * java-17-openjdk-jmods-17.0.20.0-160000.1.1 * java-17-openjdk-debuginfo-17.0.20.0-160000.1.1 * java-17-openjdk-src-17.0.20.0-160000.1.1 * java-17-openjdk-headless-17.0.20.0-160000.1.1 * java-17-openjdk-17.0.20.0-160000.1.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-160000.1.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-160000.1.1 * java-17-openjdk-demo-17.0.20.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * java-17-openjdk-javadoc-17.0.20.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-46917.html * https://www.suse.com/security/cve/CVE-2026-46968.html * https://www.suse.com/security/cve/CVE-2026-47010.html * https://www.suse.com/security/cve/CVE-2026-47021.html * https://www.suse.com/security/cve/CVE-2026-47027.html * https://www.suse.com/security/cve/CVE-2026-47059.html * https://www.suse.com/security/cve/CVE-2026-47063.html * https://www.suse.com/security/cve/CVE-2026-60147.html * https://bugzilla.suse.com/show_bug.cgi?id=1264994 * https://bugzilla.suse.com/show_bug.cgi?id=1272223 * https://bugzilla.suse.com/show_bug.cgi?id=1272224 * https://bugzilla.suse.com/show_bug.cgi?id=1272225 * https://bugzilla.suse.com/show_bug.cgi?id=1272227 * https://bugzilla.suse.com/show_bug.cgi?id=1272228 * https://bugzilla.suse.com/show_bug.cgi?id=1272235 * https://bugzilla.suse.com/show_bug.cgi?id=1272236 * https://bugzilla.suse.com/show_bug.cgi?id=1272237 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:35:12 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:35:12 -0000 Subject: SUSE-SU-2026:22951-1: important: Security update for nginx Message-ID: <178527091251.544.17464250205835436158@f1bb1996abf5> # Security update for nginx Announcement ID: SUSE-SU-2026:22951-1 Release Date: 2026-07-24T07:39:50Z Rating: important References: * bsc#1265228 * bsc#1267525 * bsc#1268492 * bsc#1268495 Cross-References: * CVE-2026-40460 * CVE-2026-42055 * CVE-2026-48142 CVSS scores: * CVE-2026-40460 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40460 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40460 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40460 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-42055 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42055 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48142 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-48142 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48142 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for nginx fixes the following issues * CVE-2026-40460: bypass of authorization and bypass of rate limiting when NGINX is configured to use the HTTP/3 QUIC module (bsc#1265228). * CVE-2026-42055: heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules (bsc#1268492). * CVE-2026-48142: heap buffer over-read in the ngx_http_charset_module module (bsc#1268495). * HTTP2-BOMB denial of service (bsc#1267525). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1343=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1343=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * nginx-debugsource-1.27.2-160000.6.1 * nginx-1.27.2-160000.6.1 * nginx-debuginfo-1.27.2-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * nginx-source-1.27.2-160000.6.1 * SUSE Linux Enterprise Server 16.0 (noarch) * nginx-source-1.27.2-160000.6.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * nginx-debugsource-1.27.2-160000.6.1 * nginx-1.27.2-160000.6.1 * nginx-debuginfo-1.27.2-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40460.html * https://www.suse.com/security/cve/CVE-2026-42055.html * https://www.suse.com/security/cve/CVE-2026-48142.html * https://bugzilla.suse.com/show_bug.cgi?id=1265228 * https://bugzilla.suse.com/show_bug.cgi?id=1267525 * https://bugzilla.suse.com/show_bug.cgi?id=1268492 * https://bugzilla.suse.com/show_bug.cgi?id=1268495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:34:29 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:34:29 -0000 Subject: SUSE-SU-2026:22952-1: important: Security update for distribution Message-ID: <178527086982.544.2663570365928807031@f1bb1996abf5> # Security update for distribution Announcement ID: SUSE-SU-2026:22952-1 Release Date: 2026-07-24T08:41:05Z Rating: important References: * bsc#1266629 * bsc#1272132 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for distribution fixes the following issues * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266629). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272132). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1345=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1345=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * distribution-registry-3.1.1-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * distribution-registry-3.1.1-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266629 * https://bugzilla.suse.com/show_bug.cgi?id=1272132 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:37:09 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:37:09 -0000 Subject: SUSE-SU-2026:22948-1: moderate: Security update for libssh Message-ID: <178527102999.544.6870407749897355298@f1bb1996abf5> # Security update for libssh Announcement ID: SUSE-SU-2026:22948-1 Release Date: 2026-07-25T17:13:20Z Rating: moderate References: * bsc#1272162 * bsc#1272164 * bsc#1272165 * bsc#1272166 * bsc#1272167 * bsc#1272168 * bsc#1272169 * bsc#1272170 * bsc#1272171 * jsc#PED-15815 Cross-References: * CVE-2026-15370 * CVE-2026-59843 * CVE-2026-59844 * CVE-2026-59845 * CVE-2026-59846 * CVE-2026-59847 * CVE-2026-59848 * CVE-2026-59849 * CVE-2026-59850 CVSS scores: * CVE-2026-15370 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-15370 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15370 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59843 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59843 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59845 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-59845 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2026-59846 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59846 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59847 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-59847 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59848 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59848 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59849 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59849 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59849 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities and contains one feature can now be installed. ## Description: This update for libssh fixes the following issues: * CVE-2026-15370: stack buffer overflow in SFTP server longname construction (bsc#1272162). * CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). * CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). * CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). * CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). * CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). * CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). * CVE-2026-59849: denial of service via automatic certificate authentication loop (bsc#1272170). * CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). Changes for libssh: * Update to 0.11.5: * Zero-initialize every ssh_string * Fix compatibility with C23 / gcc16 * Fix multiple memory leaks, null checks, and error checks * Validate peer public key in DH key exchange * Avoid remote window overflow * Avoid off-by-one overflow during kbdint authentication * Avoid logging uninitialized sequence numbers * Avoid double conversion of SFTP version number * Send correct SFTP server version number * Avoid handling repeated SFTP INIT messages * Harmonize return values from SFTP server callbacks * Update %suse_version checks for SLES 16.x (jsc#PED-15815) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1349=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libssh-debugsource-0.11.5-160000.1.1 * libssh4-debuginfo-0.11.5-160000.1.1 * libssh4-0.11.5-160000.1.1 * libssh-devel-0.11.5-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * libssh-config-0.11.5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15370.html * https://www.suse.com/security/cve/CVE-2026-59843.html * https://www.suse.com/security/cve/CVE-2026-59844.html * https://www.suse.com/security/cve/CVE-2026-59845.html * https://www.suse.com/security/cve/CVE-2026-59846.html * https://www.suse.com/security/cve/CVE-2026-59847.html * https://www.suse.com/security/cve/CVE-2026-59848.html * https://www.suse.com/security/cve/CVE-2026-59849.html * https://www.suse.com/security/cve/CVE-2026-59850.html * https://bugzilla.suse.com/show_bug.cgi?id=1272162 * https://bugzilla.suse.com/show_bug.cgi?id=1272164 * https://bugzilla.suse.com/show_bug.cgi?id=1272165 * https://bugzilla.suse.com/show_bug.cgi?id=1272166 * https://bugzilla.suse.com/show_bug.cgi?id=1272167 * https://bugzilla.suse.com/show_bug.cgi?id=1272168 * https://bugzilla.suse.com/show_bug.cgi?id=1272169 * https://bugzilla.suse.com/show_bug.cgi?id=1272170 * https://bugzilla.suse.com/show_bug.cgi?id=1272171 * https://jira.suse.com/browse/PED-15815 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:38:27 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:38:27 -0000 Subject: SUSE-SU-2026:22946-1: important: Security update for alloy Message-ID: <178527110727.544.12236127138310942479@f1bb1996abf5> # Security update for alloy Announcement ID: SUSE-SU-2026:22946-1 Release Date: 2026-07-24T15:45:31Z Rating: important References: * bsc#1267811 Cross-References: * CVE-2026-10722 CVSS scores: * CVE-2026-10722 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10722 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10722 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10722 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-10722 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for alloy fixes the following issue: Update to version 1.17.1. Security issue fixed: * CVE-2026-10722: github.com/cilium/ebpf: interger overflow when performing BTF string offset boundary check can lead to crash when malformed ELF/BTF input is parsed (bsc#1267811). Other updates and bugfixes: \- Version 1.17.1: * Back off usage reporting on persistent failure instead of retrying every minute. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1347=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * alloy-debuginfo-1.17.1-160000.1.1 * alloy-1.17.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10722.html * https://bugzilla.suse.com/show_bug.cgi?id=1267811 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:37:48 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:37:48 -0000 Subject: SUSE-SU-2026:22947-1: important: Security update for openssl-3 Message-ID: <178527106881.544.1429266484802633171@f1bb1996abf5> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22947-1 Release Date: 2026-07-25T16:46:55Z Rating: important References: * bsc#1271712 Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for openssl-3 fixes the following issue: * "HollowByte" DoS via attacker-controlled memory allocation (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1348=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libopenssl3-debuginfo-3.5.0-160000.9.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.9.1 * openssl-3-3.5.0-160000.9.1 * libopenssl-3-devel-3.5.0-160000.9.1 * libopenssl-3-fips-provider-3.5.0-160000.9.1 * openssl-3-debugsource-3.5.0-160000.9.1 * openssl-3-debuginfo-3.5.0-160000.9.1 * libopenssl3-3.5.0-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * openssl-3-doc-3.5.0-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.9.1 * libopenssl3-x86-64-v3-3.5.0-160000.9.1 * libopenssl3-x86-64-v3-debuginfo-3.5.0-160000.9.1 * libopenssl-3-fips-provider-x86-64-v3-debuginfo-3.5.0-160000.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:36:37 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:36:37 -0000 Subject: SUSE-RU-2026:22949-1: moderate: Recommended update for policycoreutils Message-ID: <178527099797.544.2681827675921815786@f1bb1996abf5> # Recommended update for policycoreutils Announcement ID: SUSE-RU-2026:22949-1 Release Date: 2026-07-27T09:31:01Z Rating: moderate References: * bsc#1271645 Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for policycoreutils fixes the following issues: Changes in policycoreutils: * Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645) * can be dropped once "policycoreutils/scripts/fixfiles: drop /tmp cleanup" is in the upstream release ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1350=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * policycoreutils-python-utils-3.8.1-160000.5.1 * policycoreutils-lang-3.8.1-160000.5.1 * python313-policycoreutils-3.8.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * policycoreutils-3.8.1-160000.5.1 * policycoreutils-debugsource-3.8.1-160000.5.1 * policycoreutils-devel-debuginfo-3.8.1-160000.5.1 * policycoreutils-debuginfo-3.8.1-160000.5.1 * policycoreutils-devel-3.8.1-160000.5.1 * policycoreutils-newrole-3.8.1-160000.5.1 * policycoreutils-newrole-debuginfo-3.8.1-160000.5.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271645 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:35:59 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:35:59 -0000 Subject: SUSE-SU-2026:22950-1: moderate: Security update for go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21 Message-ID: <178527095907.544.642551380829180925@f1bb1996abf5> # Security update for go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21 Announcement ID: SUSE-SU-2026:22950-1 Release Date: 2026-07-27T09:55:12Z Rating: moderate References: * bsc#1245878 * bsc#1264390 * bsc#1264391 * bsc#1264392 * bsc#1264393 * bsc#1264394 * bsc#1264395 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2025-22871 CVSS scores: * CVE-2025-22871 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2025-22871 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-22871 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability, contains two features and has six fixes can now be installed. ## Description: This update for go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21 fixes the following issues: Changes in go compilers: * Switch from update-alternatives to new method. * Packaging improvements: * Revert %ghost /usr/bin/go /usr/bin/gofmt which prevents install of a working go command. Refs boo#1245878 bsc#1264395 * Based on feedback from Factory maintainers restore the original lifecycle for these files: Each go1.x toolchain shares ownership of a go and gofmt symlink managed by the alternatives system (update-alternatives and libalternatives). When the last go1.x package is uninstalled the symlinks will be removed. * Context: %ghost was introduced to prevent file conflicts among go1.x toolchain packages reported by installcheck dev tool. %ghost prevents the files from being installed, which results in no installed go command. The shared ownership of the go and gofmt symlinks is intentional. * Define go_bootstrap_version with digits without go1.x prefix. Correct path spelling to align with current toolchain layout GOROOT_BOOTSTRAP=%{_libdir}/go/%{go_bootstrap_version}, Noting interstitial /go/ in path. Fixes bootstrap ERROR: Cannot find /usr/lib64/go1.x/bin/go. Set $GOROOT_BOOTSTRAP to a working Go tree >= Go 1.x.y. Bootstrap error first observed when using %ghost /usr/bin/go. Fixed by Eugenio Paolantonio. Refs boo#1245878 bsc#1264395 * Mark %ghost /usr/bin/go /usr/bin/gofmt to avoid file conflicts among go1.x toolchain packages. These files are managed by the alternatives system. Refs boo#1245878 bsc#1264395 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1352=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.25-openssl-debuginfo-1.25.12-160000.2.1 * go1.24-doc-1.24.13-160000.3.1 * go1.26-openssl-race-1.26.5-160000.2.1 * go1.24-1.24.13-160000.3.1 * go1.25-doc-1.25.12-160000.2.1 * go1.24-openssl-1.24.13-160000.3.1 * go1.26-race-1.26.5-160000.2.1 * go1.26-doc-1.26.5-160000.2.1 * go1.24-openssl-debuginfo-1.24.13-160000.3.1 * go1.24-openssl-race-1.24.13-160000.3.1 * go1.26-1.26.5-160000.2.1 * go1.24-openssl-doc-1.24.13-160000.3.1 * go1.26-openssl-doc-1.26.5-160000.2.1 * go1.25-1.25.12-160000.2.1 * go1.25-openssl-1.25.12-160000.2.1 * go1.26-openssl-1.26.5-160000.2.1 * go1.25-race-1.25.12-160000.2.1 * go1.25-openssl-race-1.25.12-160000.2.1 * go1.25-openssl-doc-1.25.12-160000.2.1 * go1.24-race-1.24.13-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22871.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1264390 * https://bugzilla.suse.com/show_bug.cgi?id=1264391 * https://bugzilla.suse.com/show_bug.cgi?id=1264392 * https://bugzilla.suse.com/show_bug.cgi?id=1264393 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:42:00 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:42:00 -0000 Subject: SUSE-SU-2026:3383-1: important: Security update for the Linux Kernel (Live Patch 83 for SUSE Linux Enterprise 12 SP5) Message-ID: <178527132003.544.18380190961837110356@f1bb1996abf5> # Security update for the Linux Kernel (Live Patch 83 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3383-1 Release Date: 2026-07-28T15:36:03Z Rating: important References: * bsc#1266970 * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 CVSS scores: * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.310 fixes various security issues: The following security issues were fixed: * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3383=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_310-default-4-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:39:07 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:39:07 -0000 Subject: SUSE-SU-2026:22945-1: important: Security update for distribution Message-ID: <178527114713.544.15894514538437829179@f1bb1996abf5> # Security update for distribution Announcement ID: SUSE-SU-2026:22945-1 Release Date: 2026-07-24T08:41:15Z Rating: important References: * bsc#1266629 * bsc#1272132 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for distribution fixes the following issues * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266629). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272132). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1345=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * distribution-registry-3.1.1-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266629 * https://bugzilla.suse.com/show_bug.cgi?id=1272132 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:39:56 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:39:56 -0000 Subject: SUSE-SU-2026:22944-1: important: Security update for java-17-openjdk Message-ID: <178527119609.544.17418877574247773047@f1bb1996abf5> # Security update for java-17-openjdk Announcement ID: SUSE-SU-2026:22944-1 Release Date: 2026-07-24T08:22:41Z Rating: important References: * bsc#1264994 * bsc#1272223 * bsc#1272224 * bsc#1272225 * bsc#1272227 * bsc#1272228 * bsc#1272235 * bsc#1272236 * bsc#1272237 Cross-References: * CVE-2026-41254 * CVE-2026-46917 * CVE-2026-46968 * CVE-2026-47010 * CVE-2026-47021 * CVE-2026-47027 * CVE-2026-47059 * CVE-2026-47063 * CVE-2026-60147 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for java-17-openjdk fixes the following issues * Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU) * CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). * CVE-2026-46917: partial denial of service via TLS (bsc#1272223). * CVE-2026-46968: unauthorized creation, deletion or modification access to critical data (bsc#1272224). * CVE-2026-47010: unauthorized update, insert or delete access (bsc#1272225). * CVE-2026-47021: partial denial of service via multiple network protocols (bsc#1272227). * CVE-2026-47027: partial denial of service via multiple network protocols (bsc#1272228). * CVE-2026-47059: partial denial of service via multiple network protocols (bsc#1272235). * CVE-2026-47063: unauthorized creation, deletion or modification access to critical data (bsc#1272236). * CVE-2026-60147: unauthorized update, insert or delete access (bsc#1272237). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1344=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * java-17-openjdk-devel-17.0.20.0-160000.1.1 * java-17-openjdk-jmods-17.0.20.0-160000.1.1 * java-17-openjdk-debuginfo-17.0.20.0-160000.1.1 * java-17-openjdk-src-17.0.20.0-160000.1.1 * java-17-openjdk-headless-17.0.20.0-160000.1.1 * java-17-openjdk-17.0.20.0-160000.1.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-160000.1.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-160000.1.1 * java-17-openjdk-demo-17.0.20.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * java-17-openjdk-javadoc-17.0.20.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-46917.html * https://www.suse.com/security/cve/CVE-2026-46968.html * https://www.suse.com/security/cve/CVE-2026-47010.html * https://www.suse.com/security/cve/CVE-2026-47021.html * https://www.suse.com/security/cve/CVE-2026-47027.html * https://www.suse.com/security/cve/CVE-2026-47059.html * https://www.suse.com/security/cve/CVE-2026-47063.html * https://www.suse.com/security/cve/CVE-2026-60147.html * https://bugzilla.suse.com/show_bug.cgi?id=1264994 * https://bugzilla.suse.com/show_bug.cgi?id=1272223 * https://bugzilla.suse.com/show_bug.cgi?id=1272224 * https://bugzilla.suse.com/show_bug.cgi?id=1272225 * https://bugzilla.suse.com/show_bug.cgi?id=1272227 * https://bugzilla.suse.com/show_bug.cgi?id=1272228 * https://bugzilla.suse.com/show_bug.cgi?id=1272235 * https://bugzilla.suse.com/show_bug.cgi?id=1272236 * https://bugzilla.suse.com/show_bug.cgi?id=1272237 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:41:18 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:41:18 -0000 Subject: SUSE-SU-2026:22942-1: low: Security update for runc Message-ID: <178527127838.544.14125854621871041784@f1bb1996abf5> # Security update for runc Announcement ID: SUSE-SU-2026:22942-1 Release Date: 2026-07-23T13:29:15Z Rating: low References: * bsc#1268275 Cross-References: * CVE-2025-31133 * CVE-2025-52565 * CVE-2026-41579 CVSS scores: * CVE-2025-31133 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-31133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-31133 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-52565 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-52565 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-52565 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-52565 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2026-41579 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-41579 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Security update for runc ### Description: This update for runc fixes the following issues: Update to 1.3.6. * CVE-2026-41579: malicious image with a `/dev` symlink can trigger limited host filesystem integrity violations (bsc#1268275). Other updates and bugfixes: * Version 1.3.6: * Various integration test improvements. * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). * Version 1.3.5: * Recursive atime-related mount flags (rrelatime et al.) are now applied properly. * PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted. * Updated builds to Go 1.25, libseccomp v2.6.0. * Minor signing keyring updates. ## Security update for runc ### Description: This update for runc fixes the following issues: Update to 1.3.6. * CVE-2026-41579: malicious image with a `/dev` symlink can trigger limited host filesystem integrity violations (bsc#1268275). Other updates and bugfixes: * Version 1.3.6: * Various integration test improvements. * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). * Version 1.3.5: * Recursive atime-related mount flags (rrelatime et al.) are now applied properly. * PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted. * Updated builds to Go 1.25, libseccomp v2.6.0. * Minor signing keyring updates. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1342=1 SUSE-SLES-16.0-1342=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1342=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * runc-debuginfo-1.3.6-160000.1.1 * runc-1.3.6-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.3.6-160000.1.1 * runc-1.3.6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31133.html * https://www.suse.com/security/cve/CVE-2025-52565.html * https://www.suse.com/security/cve/CVE-2026-41579.html * https://bugzilla.suse.com/show_bug.cgi?id=1268275 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:42:38 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:42:38 -0000 Subject: SUSE-SU-2026:3376-1: important: Security update for the Linux Kernel (Live Patch 84 for SUSE Linux Enterprise 12 SP5) Message-ID: <178527135886.544.17708544317159450301@f1bb1996abf5> # Security update for the Linux Kernel (Live Patch 84 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3376-1 Release Date: 2026-07-28T15:33:54Z Rating: important References: * bsc#1270060 Cross-References: * CVE-2026-53359 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.317 fixes one security issue: The following security issue was fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3376=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_317-default-2-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:40:39 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:40:39 -0000 Subject: SUSE-SU-2026:22943-1: important: Security update for nginx Message-ID: <178527123923.544.15070711031463736775@f1bb1996abf5> # Security update for nginx Announcement ID: SUSE-SU-2026:22943-1 Release Date: 2026-07-24T07:40:23Z Rating: important References: * bsc#1265228 * bsc#1267525 * bsc#1268492 * bsc#1268495 Cross-References: * CVE-2026-40460 * CVE-2026-42055 * CVE-2026-48142 CVSS scores: * CVE-2026-40460 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40460 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40460 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40460 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-42055 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42055 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48142 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-48142 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48142 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for nginx fixes the following issues * CVE-2026-40460: bypass of authorization and bypass of rate limiting when NGINX is configured to use the HTTP/3 QUIC module (bsc#1265228). * CVE-2026-42055: heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules (bsc#1268492). * CVE-2026-48142: heap buffer over-read in the ngx_http_charset_module module (bsc#1268495). * HTTP2-BOMB denial of service (bsc#1267525). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1343=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * nginx-debugsource-1.27.2-160000.6.1 * nginx-1.27.2-160000.6.1 * nginx-debuginfo-1.27.2-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * nginx-source-1.27.2-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40460.html * https://www.suse.com/security/cve/CVE-2026-42055.html * https://www.suse.com/security/cve/CVE-2026-48142.html * https://bugzilla.suse.com/show_bug.cgi?id=1265228 * https://bugzilla.suse.com/show_bug.cgi?id=1267525 * https://bugzilla.suse.com/show_bug.cgi?id=1268492 * https://bugzilla.suse.com/show_bug.cgi?id=1268495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:47:54 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:47:54 -0000 Subject: SUSE-RU-2026:3381-1: important: Recommended update for log4j Message-ID: <178527167460.544.14646639242625954449@f1bb1996abf5> # Recommended update for log4j Announcement ID: SUSE-RU-2026:3381-1 Release Date: 2026-07-28T15:35:47Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for log4j fixes the following issues: Upgrade to 2.26.1: * Changed * Improve logging for LinkageError scenarios involving the LMAX Disruptor library * Fixed * Fix the createOnDemand behavior of RollingFileAppender to correctly defer file and directory creation until the first log event, while preserving eager creation when disabled * Improve documentation for locale handling in the Pattern Layout date pattern converter * Fix handling of non-finite numbers while encoding MapMessage to JSON * Fix encoding of MSGID and SD-ID fields of StructuredDataMessage to XML * Fix stack trace rendering for exceptions with identity malfunction (e.g., colliding equals() and/or hashCode() implementations) * Fix resource leaks in ConfigurationSource when loading configuration via URL fails * Fix KafkaAppender reporting error to error handler even after a successful retry * Generate META-INF/services files using bnd-maven-plugin ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3381=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3381=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3381=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3381=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3381=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3381=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3381=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3381=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3381=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3381=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3381=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * log4j-jcl-2.26.1-150200.4.39.1 * log4j-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * log4j-2.26.1-150200.4.39.1 * log4j-jcl-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * log4j-jcl-2.26.1-150200.4.39.1 * log4j-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * log4j-jcl-2.26.1-150200.4.39.1 * log4j-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * log4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-jcl-2.26.1-150200.4.39.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * log4j-jcl-2.26.1-150200.4.39.1 * log4j-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * Basesystem Module 15-SP7 (noarch) * log4j-jcl-2.26.1-150200.4.39.1 * log4j-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * log4j-jcl-2.26.1-150200.4.39.1 * log4j-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * log4j-jcl-2.26.1-150200.4.39.1 * log4j-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * log4j-2.26.1-150200.4.39.1 * log4j-jcl-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * log4j-2.26.1-150200.4.39.1 * log4j-jcl-2.26.1-150200.4.39.1 * log4j-slf4j-2.26.1-150200.4.39.1 * log4j-javadoc-2.26.1-150200.4.39.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:48:16 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:48:16 -0000 Subject: SUSE-SU-2026:3368-1: moderate: Security update for sssd Message-ID: <178527169652.544.14219647730026890312@f1bb1996abf5> # Security update for sssd Announcement ID: SUSE-SU-2026:3368-1 Release Date: 2026-07-28T12:23:46Z Rating: moderate References: * bsc#1269807 Cross-References: * CVE-2026-12610 CVSS scores: * CVE-2026-12610 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-12610 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12610 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for sssd fixes the following issue: * CVE-2026-12610: cancelled or completed PAM request while the asynchronous child process is still running can lead to a use-after-free (bsc#1269807). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3368=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3368=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3368=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3368=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3368=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libsss_certmap0-2.5.2-150400.4.48.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap0-2.5.2-150400.4.48.1 * libsss_idmap0-2.5.2-150400.4.48.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1 * sssd-debugsource-2.5.2-150400.4.48.1 * sssd-ldap-debuginfo-2.5.2-150400.4.48.1 * sssd-ldap-2.5.2-150400.4.48.1 * sssd-common-2.5.2-150400.4.48.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.48.1 * sssd-common-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1 * sssd-2.5.2-150400.4.48.1 * sssd-krb5-common-2.5.2-150400.4.48.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libsss_certmap0-2.5.2-150400.4.48.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap0-2.5.2-150400.4.48.1 * libsss_idmap0-2.5.2-150400.4.48.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1 * sssd-debugsource-2.5.2-150400.4.48.1 * sssd-ldap-debuginfo-2.5.2-150400.4.48.1 * sssd-ldap-2.5.2-150400.4.48.1 * sssd-common-2.5.2-150400.4.48.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.48.1 * sssd-common-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1 * sssd-2.5.2-150400.4.48.1 * sssd-krb5-common-2.5.2-150400.4.48.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python3-sssd-config-debuginfo-2.5.2-150400.4.48.1 * python3-ipa_hbac-2.5.2-150400.4.48.1 * libsss_nss_idmap0-2.5.2-150400.4.48.1 * sssd-winbind-idmap-debuginfo-2.5.2-150400.4.48.1 * libsss_simpleifp-devel-2.5.2-150400.4.48.1 * sssd-krb5-2.5.2-150400.4.48.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1 * libsss_idmap-devel-2.5.2-150400.4.48.1 * sssd-ldap-2.5.2-150400.4.48.1 * libsss_certmap-devel-2.5.2-150400.4.48.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.48.1 * libsss_simpleifp0-2.5.2-150400.4.48.1 * libipa_hbac-devel-2.5.2-150400.4.48.1 * python3-sssd-config-2.5.2-150400.4.48.1 * sssd-proxy-debuginfo-2.5.2-150400.4.48.1 * sssd-ipa-debuginfo-2.5.2-150400.4.48.1 * libipa_hbac0-debuginfo-2.5.2-150400.4.48.1 * python3-ipa_hbac-debuginfo-2.5.2-150400.4.48.1 * sssd-ldap-debuginfo-2.5.2-150400.4.48.1 * sssd-krb5-debuginfo-2.5.2-150400.4.48.1 * sssd-common-2.5.2-150400.4.48.1 * sssd-2.5.2-150400.4.48.1 * sssd-ad-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1 * python3-sss-murmur-debuginfo-2.5.2-150400.4.48.1 * python3-sss-murmur-2.5.2-150400.4.48.1 * libsss_idmap0-2.5.2-150400.4.48.1 * libipa_hbac0-2.5.2-150400.4.48.1 * sssd-dbus-2.5.2-150400.4.48.1 * sssd-debugsource-2.5.2-150400.4.48.1 * python3-sss_nss_idmap-debuginfo-2.5.2-150400.4.48.1 * sssd-kcm-debuginfo-2.5.2-150400.4.48.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.48.1 * sssd-tools-debuginfo-2.5.2-150400.4.48.1 * sssd-krb5-common-2.5.2-150400.4.48.1 * libsss_certmap0-2.5.2-150400.4.48.1 * sssd-tools-2.5.2-150400.4.48.1 * libnfsidmap-sss-debuginfo-2.5.2-150400.4.48.1 * libsss_simpleifp0-debuginfo-2.5.2-150400.4.48.1 * sssd-proxy-2.5.2-150400.4.48.1 * sssd-dbus-debuginfo-2.5.2-150400.4.48.1 * python3-sss_nss_idmap-2.5.2-150400.4.48.1 * sssd-ad-2.5.2-150400.4.48.1 * sssd-kcm-2.5.2-150400.4.48.1 * sssd-winbind-idmap-2.5.2-150400.4.48.1 * sssd-common-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap-devel-2.5.2-150400.4.48.1 * sssd-ipa-2.5.2-150400.4.48.1 * libnfsidmap-sss-2.5.2-150400.4.48.1 * openSUSE Leap 15.4 (aarch64_ilp32) * sssd-common-64bit-debuginfo-2.5.2-150400.4.48.1 * sssd-common-64bit-2.5.2-150400.4.48.1 * openSUSE Leap 15.4 (x86_64) * sssd-common-32bit-2.5.2-150400.4.48.1 * sssd-common-32bit-debuginfo-2.5.2-150400.4.48.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libsss_certmap0-2.5.2-150400.4.48.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap0-2.5.2-150400.4.48.1 * libsss_idmap0-2.5.2-150400.4.48.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1 * sssd-debugsource-2.5.2-150400.4.48.1 * sssd-ldap-debuginfo-2.5.2-150400.4.48.1 * sssd-common-2.5.2-150400.4.48.1 * sssd-ldap-2.5.2-150400.4.48.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.48.1 * sssd-common-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1 * sssd-2.5.2-150400.4.48.1 * sssd-krb5-common-2.5.2-150400.4.48.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libsss_certmap0-2.5.2-150400.4.48.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap0-2.5.2-150400.4.48.1 * libsss_idmap0-2.5.2-150400.4.48.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1 * sssd-debugsource-2.5.2-150400.4.48.1 * sssd-ldap-debuginfo-2.5.2-150400.4.48.1 * sssd-common-2.5.2-150400.4.48.1 * sssd-ldap-2.5.2-150400.4.48.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.48.1 * sssd-common-debuginfo-2.5.2-150400.4.48.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1 * sssd-2.5.2-150400.4.48.1 * sssd-krb5-common-2.5.2-150400.4.48.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12610.html * https://bugzilla.suse.com/show_bug.cgi?id=1269807 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:46:48 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:46:48 -0000 Subject: SUSE-SU-2026:3390-1: important: Security update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn Message-ID: <178527160859.544.5127280995548659308@f1bb1996abf5> # Security update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn Announcement ID: SUSE-SU-2026:3390-1 Release Date: 2026-07-28T15:40:06Z Rating: important References: Cross-References: * CVE-2025-48924 CVSS scores: * CVE-2025-48924 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-48924 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-48924 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn fixes the following issues: apache-commons-lang3 was updated to 3.20.0: * New features: * Add SystemProperties.getPath(String, Supplier) * Add JavaVersion.JAVA_25 * Add JavaVersion.JAVA_26 * Add SystemUtils.IS_JAVA_25 * Add SystemUtils.IS_JAVA_26 * Add MutablePair.ofNonNull(Map.Entry) * Add TimedSemaphore.builder(), Builder, and deprecate constructors * LANG-1504: Adding labels and history to split StopWatch * Fixed Bugs: * Optimize ObjectToStringComparator.compare() method * [javadoc] Improve StringUtils Javadoc * Fix internal inverted logic in private isEnum() method and correct its usage in getFirstEnum() * Use accessors in ToStringStyle so subclasses can effectively override them * 'LocaleUtils.toLocale(String)' for a 2 letter country code now returns a value instead of throwing an 'IllegalArgumentException' * Fix typo in StringUtils.trunctate() IllegalArgumentException message and test assertion messages * Fix test fixture in ReflectionDiffBuilderTest.testTransientFieldDifference() * LANG-1789: NullPointerException when generating NoSuchMethodException in MethodUtils * LANG-1786: Map deprecated TimeZone short IDs and avoid JRE WARNINGs to the console * LANG-1792: TypeUtils.toString() skips angle brackets for Class type * Mention JDK 25 LTS as a tested version in the release notes * Changes: * Bump org.apache.commons:commons-parent from 88 to 92 Update to 3.19.0: * New features: * Add ArrayUtils.SOFT_MAX_ARRAY_LENGTH * Add SystemUtils.IS_OS_NETWARE * Add MethodUtils.getAccessibleMethod(Class, Method) * Add documentation to site for CVE-2025-48924 ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs * Add StringUtils.indexOfAny(CharSequence, int, char...) * Add ConcurrentException.ConcurrentException(String) * Add DateUtils.toLocalDateTime(Date[, TimeZone]) * Add DateUtils.toOffsetDateTime(Date[, TimeZone]) * Add DateUtils.toZonedDateTime(Date[, TimeZone]) * Add ByteConsumer * Add ByteSupplier * Add FailableByteConsumer * Add FailableByteSupplier * LANG-1784: Add Functions methods for null-safe mapping and chaining * LANG-1784: Add Failable methods for null-safe mapping and chaining * Add DoubleRange.fit(double) * Add IntegerRange.fit(int) * Add LongRange.fit(long) * Add DurationUtils.get(String, TemporalUnit, long) * Add DurationUtils.getMillis(String, long) * Add DurationUtils.getSeconds(String, long) * Add SystemProperties.getBoolean(Class, String, boolean) * Add SystemProperties.getInt(Class, String, int) * Add SystemProperties.getLong(Class, String, long) * Fixed Bugs: * LANG-1778: MethodUtils.getMatchingMethod() doesn't respect the hierarchy of methods * MethodUtils.getMethodObject(Class, String, Class...) now returns null instead of throwing a NullPointerException, as it does for other exception types * Reduce spurious failures in ArrayUtilsTest methods that test ArrayUtils.shuffle() methods * MethodUtils cannot find or invoke a public method on a public class implemented in its package-private superclass * AtomicSafeInitializer.get() can spin internally if the FailableSupplier given to AbstractConcurrentInitializer .AbstractBuilder.setInitializer(FailableSupplier) throws a RuntimeException * LANG-1783: WordUtils.containsAllWords?() may throw PatternSyntaxException * LANG-1782: MethodUtils cannot find or invoke vararg methods without providing vararg types or values * MethodUtils cannot find or invoke vararg methods of interface types * MethodUtils cannot find or invoke vararg methods when widening primitive types following the JLS 5.1.2. Widening Primitive Conversion * LANG-1597: Invocation fails because matching varargs method found but then discarded * Don't check accessibility twice in MemberUtils .setAccessibleWorkaround(T) * LANG-1774: Improve handling of ClassUtils .getShortCanonicalName() for invalid input * LANG-1720: Improve Javadocs for Conversion * Fix CalendarUtils.toLocalDate() Javadoc return type description * Fix the method name in Javadoc examples for CharUtils.isHex() * Deprecate NumberUtils.compare(byte, byte) in favor of Byte.compare(byte, byte) * Deprecate NumberUtils.compare(int, int) in favor of Integer.compare(int, int) * Deprecate NumberUtils.compare(long, long) in favor of Long.compare(long, long) * Deprecate NumberUtils.compare(short, short) in favor of Short.compare(short, short) * Deprecate obsolete system property constant SystemProperties.AWT_TOOLKIT * Deprecate obsolete system property constant SystemProperties.JAVA_AWT_FONTS * Deprecate obsolete system property constant SystemProperties.JAVA_AWT_GRAPHICSENV * Deprecate obsolete system property constant SystemProperties.JAVA_AWT_HEADLESS * Deprecate obsolete system property constant SystemProperties.JAVA_AWT_PRINTERJOB * Deprecate obsolete system property constant SystemProperties.JAVA_COMPILER * Deprecate obsolete system property constant SystemProperties.JAVA_ENDORSED_DIRS * Deprecate obsolete system property constant SystemProperties.JAVA_EXT_DIRS * Deprecate method for obsolete system property constant SystemProperties.getAwtToolkit() * Deprecate method for obsolete system property constant SystemProperties.getJavaAwtFonts() * Deprecate method for obsolete system property constant SystemProperties.getJavaAwtGraphicsenv() * Deprecate method for obsolete system property constant SystemProperties.getJavaAwtHeadless() * Deprecate method for obsolete system property constant SystemProperties.getJavaAwtPrinterjob() * Deprecate method for obsolete system property constant SystemProperties.getJavaCompiler() * Deprecate method for obsolete system property constant SystemProperties.getJavaEndorsedDirs() * Deprecate method for obsolete system property constant SystemProperties.getJavaExtDirs() * Deprecate method for obsolete system property constant SystemUtils.isJavaAwtHeadless() * Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_FONTS * Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_GRAPHICSENV * Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_HEADLESS * Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_PRINTERJOB * Deprecate constants for obsolete system property SystemUtils.JAVA_COMPILER * Deprecate constants for obsolete system property SystemUtils.JAVA_ENDORSED_DIRS * Deprecate constants for obsolete system property SystemUtils.JAVA_EXT_DIRS * [javadoc] General improvements * [javadoc] Fix thrown exception documentation for MethodUtils.getMethodObject(Class, String, Class...) * [javadoc] Strings::equalsAny: CI doc string should show it's insensitive * [javadoc] General Javadoc improvements * LANG-1780: [javadoc] Fix Strings Javadoc * [javadoc] Fix typo in Javadoc of Strings instances * [javadoc] Fix Javadocs in ClassUtils * [javadoc] Fix @deprecated link for StringUtils#startsWithAny * Replace old feather logotype with new oak logotype * Changes: * [test] Bump org.apache.commons:commons-text from 1.13.1 to 1.14.0 * Bump org.apache.commons:commons-parent from 85 to 88 Update to 3.18.0: * Fix component version in default.properties to 3.12 * Add and use LocaleUtils.toLocale(Locale) to avoid NPEs. * Add FailableShortSupplier, handy for JDBC APIs. * Add JavaVersion.JAVA_17. * Add StringUtils.substringBefore(String, int). * Add Range.INTEGER. * Add DurationUtils. * Correct implementation of RandomUtils.nextLong(long, long). * Update maven-surefire-plugin 2.22.2 -> 3.0.0-M5. * Bump junit-bom from 5.7.0 to 5.7.1. * Ignored exception 'ignored', should not be called so. * Change array style from 'int a[]' to 'int[] a'. google-guice was updated to fix: * Fix build with Java 25 * Add alias to com.google.inject:guice::classes artifact, needed by maven 4.x maven-resolver-supplier was updated to upstream version 1.9.27: * Bug Fixes * Sync TrackingFileManager with 2.x Update to upstream version 1.9.26: * New features and improvements * GH-1773: Treat 410 Gone as 404 Not Found * GH-1737: Revert partially parallel upload change * Bug Fixes * GH-1768; Drastically simplify auth caching * [1.9.x] Bug: GH-1703 Locally cached artifacts defy RRF * Documentation updates * Clarify that HTTP Transport uses Apache HTTP Client * Dependency updates * Bump org.redisson:redisson from 3.52.0 to 4.2.0 * Bump commons-codec:commons-codec from 1.20.0 to 1.21.0 * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27 * Bump org.apache.maven:maven-parent from 46 to 47 * Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.0 to 0.25.4 * Bump mavenVersion from 3.9.11 to 3.9.12 * Update to upstream version 1.9.25 * New features and improvements * Add scope support for trusted checksums * Name mappers cleanup and new GAECV mapper * Proper metadata locking support * Ability to augment metadata nature for version range request * Bug Fixes * TrackingFileManager changes * Maven filters daemon friendly * Remove hack from Basic connector * Fix locking issues * Documentation updates * Updated the documentation to reflect the current list of name mappers * Maintenance * Mild backport: support same properties as Resolver 2.x * Maven resolver lockrepro * Bugfix: Java 25 broke test * Dependency updates * Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.23.1 to 0.25.0 * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26 * Bump commons-codec:commons-codec from 1.18.0 to 1.20.0 * Bump org.redisson:redisson from 3.50.0 to 3.52.0 * Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre * Bump com.google.code.gson:gson from 2.13.1 to 2.13.2 * Bump jettyVersion from 9.4.57.v20241219 to 9.4.58.v20250814 * Bump mavenVersion from 3.9.10 to 3.9.11 * Update to upstream version 1.9.24 * New features and improvements * Metadata type out of coordinates * RFC9457 implementation * Intern context strings * Maintenance * Align plexus-util version with Maven * Align guice version with Maven * Enable Github Issues (1.9.x branch) * Build also maven-resolver-supplier package in separate spec file * Add dependency on objectweb-asm to build with sisu 0.9.0.M4 * Update to upstream version 1.9.23 * Bug * MRESOLVER-659: NPE in trusted checksum post processor if * Improvement * MRESOLVER-680: Disable checksum by default for .sigstore.json as well * MRESOLVER-703: HTTP transport should expose config for max redirects * Upgrade to upstream version 1.9.22 * Bug * MRESOLVER-572: Resolver-Supplier unusable in OSGi runtimes * MRESOLVER-574: Invalid Cookie set under proxy conditions * MRESOLVER-586: In typical setups, DefaultArtifact copies the same maps over and over again * MRESOLVER-587: Memory consumption improvements * New Feature * MRESOLVER-571: Import o.e.aether packages with the exact same version in OSGi metadata * Improvement * MRESOLVER-570: Remove excessive strictness of OSGi dependency metadata * Task * MRESOLVER-576: Allow co-release of Resolver 1.x and 2.x * Upgrade to upstream version 1.9.20 * Bug * MRESOLVER-483: PreorderNodeListGenerator bug: may print trailing ":" * MRESOLVER-522: File locking threads not entering critical region were "oversleeping" * MRESOLVER-547: BF collector always copies artifacts, even when it should not * Improvement * MRESOLVER-536: Skip setting last modified time when FS does not support it * Add dependency on plexus-xml where relevant * this will be needed for smooth upgrade to plexus-utils 4.0.0 * Upgrade to upstream version 1.9.18 * Bug * MRESOLVER-372: Sporadic AccessDeniedEx on Windows * MRESOLVER-441: Undo FileUtils changes that altered non-Windows execution path * Improvement * MRESOLVER-396: Native transport should retry on HTTP 429 (Retry-After) * Task * MRESOLVER-397: Deprecate Guice modules * MRESOLVER-405: Get rid of component name string literals, make them constants and reusable * MRESOLVER-433: Expose configuration for inhibiting Expect-Continue handshake in 1.x * MRESOLVER-435: Refresh download page * MRESOLVER-437: Resolver should not override given HTTP transport default use of expect-continue handshake * Upgrade to upstream version 1.9.15 * Bug * MRESOLVER-373: Remove lock upgrading code * MRESOLVER-375: Several key aspects are broken in provided and trusted checksum feature * MRESOLVER-376: StackOverflowError at BfDependencyCollector.processDependency * MRESOLVER-380: Lock diagnostic: attempted lock step is recorded, but on failed attempt is not removed * MRESOLVER-393: Transport HTTP does not retain last modified as sent by remote end * Improvement * MRESOLVER-220: Modify signaling for unsupported operations * MRESOLVER-382: Define local outgoing (bind) address * MRESOLVER-385: Reduce default value for aether.connector.http.connectionMaxTtl * Task * MRESOLVER-378: Update parent POM to 40 * MRESOLVER-381: Undo MRESOLVER-373 as it was fixed by other means * MRESOLVER-386: Make all injected ctors public, deprecate all def ctors * MRESOLVER-388: Transport HTTP old codec proper override * Upgrade to upstream version 1.9.12 * Bug * [MRESOLVER-371] Unjustified WARNING log added by MRESOLVER-364 * [MRESOLVER-361] Unreliable TCP and retries on upload * [MRESOLVER-357] ConflictResolver STANDARD verbosity misbehaves * [MRESOLVER-352] Duplicate METADATA_DOWNLOADING event is being sent * Improvement * [MRESOLVER-360] disable checksum by default for .sigstore in addition to .asc * New Feature * [MRESOLVER-370] Lock factory should dump lock states on failure * [MRESOLVER-353] Make aether.checksums.algorithms settable per remote repository * Task * [MRESOLVER-366] Upgrade build plugins * [MRESOLVER-364] Revert MRESOLVER-132 * [MRESOLVER-359] Make build be explicit about build time requirements * [MRESOLVER-356] Remove Guava (is unused) * [MRESOLVER-354] Document expected checksums * Upgrade to upstream version 1.9.8 * Bug * [MRESOLVER-345] Conflict resolution in verbose mode is sensitive to version ordering * [MRESOLVER-348] SslConfig httpSecurityMode change is not detected * [MRESOLVER-339] Preemptive Auth broken when default ports used * [MRESOLVER-325] [REGRESSION] Suddenly seeing I/O errors under windows aborting the build * [MRESOLVER-330] Static name mapper is unusable with file-lock factory * [MRESOLVER-314] Getting "IllegalArgumentException: Comparison method violates its general contract!" * [MRESOLVER-316] DF collector enters endless loop when collecting org.webjars.npm:musquette:1.1.1 * [MRESOLVER-298] javax.inject should be provided or optional * [MRESOLVER-305] Evaluate blocked repositories also when retrieving metadata * [MRESOLVER-309] PrefixesRemoteRepositoryFilterSource aborts the build while it should not * [MRESOLVER-313] Artifact file permissions are 0600 and not implicitly set by umask * [MRESOLVER-296] FileProcessor.write( File, InputStream ) is defunct * [MRESOLVER-292] Documented and used param names mismatch * [MRESOLVER-294] Fix JapiCmp configuration and document it * [MRESOLVER-285] File locking on Windows knows to misbehave * [MRESOLVER-246] m-deploy-p will create hashes for hashes * [MRESOLVER-265] Discrepancy between produced and recognized checksums * [MRESOLVER-241] Resolver checksum calculation should be driven by layout * [MRESOLVER-242] When no remote checksums provided by layout, transfer inevitably fails/warns * [MRESOLVER-250] Usage of descriptors map in DataPool prevents gargabe collection * New Feature * [MRESOLVER-32] Support parallel artifact/metadata uploads * [MRESOLVER-319] Support parallel deploy * [MRESOLVER-297] Chained LRM * [MRESOLVER-167] Support forcing specific repositories for artifacts * [MRESOLVER-268] Apply artifact checksum verification for any resolved artifact * [MRESOLVER-274] Introduce Remote Repository Filter feature * [MRESOLVER-275] Introduce trusted checksums source * [MRESOLVER-276] Resolver post-processor * [MRESOLVER-278] BREAKING: Introduce RepositorySystem shutdown hooks * [MRESOLVER-236] Make it possible to resolve .asc on a 'fail' respository. * Improvement * [MRESOLVER-346] Too eager locking * [MRESOLVER-347] Better connection pool configuration (reuse, max TTL, maxPerRoute) * [MRESOLVER-349] Adapter when locking should "give up and retry" * [MRESOLVER-350] Get rid of commons-lang dependency * [MRESOLVER-327] Make tranport-http obey system properties regarding proxy settings * [MRESOLVER-340] Make WebDAV "dance" disabled by default * [MRESOLVER-341] Add option for preemptive PUT Auth * [MRESOLVER-315] Implement preemptive authentication feature for transport-http * [MRESOLVER-328] The transport-http should be able to ignore cert errors * [MRESOLVER-337] Real cause when artifact not found with repository filtering * [MRESOLVER-287] Get rid of deprecated finalize methods * [MRESOLVER-317] Improvements for BF collector * [MRESOLVER-318] Cleanup redundant code and centralize executor handling * [MRESOLVER-303] Make checksum detection reusable * [MRESOLVER-290] Improve file handling resolver wide * [MRESOLVER-7] Download dependency POMs in parallel in BF collector * [MRESOLVER-266] Simplify adapter creation and align configuration for it * [MRESOLVER-269] Allow more compact storage of provided checksums * [MRESOLVER-273] Create more compact File locking layout/mapper * [MRESOLVER-284] BREAKING: Some Sisu parameters needs to be bound * [MRESOLVER-286] Improve basic connector closed state handling * [MRESOLVER-240] Using breadth-first approach to resolve Maven dependencies * [MRESOLVER-247] Avoid unnecessary dependency resolution by a Skip solution based on BFS * [MRESOLVER-248] Make DF and BF collector implementations coexist * Task * [MRESOLVER-326] Resolver transport-http should retry on failures * [MRESOLVER-331] Make DefaultTrackingFileManager write directly to tracking files * [MRESOLVER-333] Distinguish better resolver errors for artifact availability * [MRESOLVER-320] Investigate slower resolving speeds as reported by users * [MRESOLVER-291] Undo MRESOLVER-284 * [MRESOLVER-279] Simplify and improve trusted checksum sources * [MRESOLVER-281] Update configurations page with new elements * [MRESOLVER-282] Drop PartialFile * [MRESOLVER-230] Make supported checksum algorithms extensible * [MRESOLVER-231] Extend ?smart checksum? feature * [MRESOLVER-234] Introduce ?provided? checksums feature * [MRESOLVER-237] Make all checksum mismatches handled same * [MRESOLVER-239] Update and sanitize dependencies * [MRESOLVER-244] Deprecate FileTransformer API * [MRESOLVER-245] Isolate Hazelcast tests * Dependency upgrade * [MRESOLVER-311] Upgrade Parent to 39 * [MRESOLVER-293] Update dependencies, align with Maven * [MRESOLVER-272] Update parent POM to 37, remove plugin version overrides, update bnd * [MRESOLVER-280] Upgrade invoker, install, deploy, require maven 3.8.4+ * [MRESOLVER-251] Upgrade Redisson to 3.17.5 * [MRESOLVER-249] Update Hazelcast to 5.1.1 in named-locks-hazelcast module * Add an alias for the wagon connector * Build against the standalone JavaEE modules unconditionally * Remove the javax.annotation:javax.annotation-api dependency on distribution versions that do not incorporate the JavaEE modules * Add the glassfish-annotation-api jar to the build classpath * Upgrade to upstream version 1.7.3 * Bug * [MRESOLVER-96] - Dependency Injection fails after upgrading to Maven 3.6.2 * [MRESOLVER-153] - resolver-status.properties file is corrupted due to concurrent writes * [MRESOLVER-171] - Resolver fails when compiled on Java 9+ an run on Java 8 due to JDK API breakage * [MRESOLVER-189] - Using semaphore-redisson followed by rwlock-redisson on many parallel build of the same project triggers redisson error * New Feature * [MRESOLVER-90] - HTML content in POM: Maven should validate content before storing in local repo * [MRESOLVER-145] - Introduce more SyncContext implementations * Improvement * [MRESOLVER-103] - Replace deprecated HttpClient classes * [MRESOLVER-104] - maven-resolver-demo-maven-plugin uses reserved artifactId * [MRESOLVER-147] - Upgrade to Java 8 * [MRESOLVER-148] - Use vanilla Guice 4 instead of forked Guice 3 * [MRESOLVER-156] - Active dependency management for Google Guice/Guava * [MRESOLVER-168] - add DEBUG message when downloading an artifact from repositories * [MRESOLVER-193] - Properly type lock key names in Redis * [MRESOLVER-197] - Minors improvements (umbrella) * [MRESOLVER-204] - Add a SessionData#computeIfAbsent method * [MRESOLVER-214] - Remove clirr configuration * Task * [MRESOLVER-141] - Review index-based access to collections * [MRESOLVER-151] - Enforce a checksum policy to be provided explicitly * [MRESOLVER-152] - Perform null checks when interface contracts require it * [MRESOLVER-154] - Move SyncContextFactory interface to SPI module * [MRESOLVER-155] - Make TrackingFileManager member of DefaultUpdateCheckManager * [MRESOLVER-158] - Simplify SimpleDigest class * [MRESOLVER-159] - Mark singleton components as Sisu Singletons * [MRESOLVER-160] - Deprecate ServiceLocator * [MRESOLVER-162] - Restore binary compatibility broken by MRESOLVER-154 * [MRESOLVER-170] - Deprecate org.eclipse.aether.spi.log * [MRESOLVER-172] - Make TrackingFileManager shared singleton component * [MRESOLVER-173] - Drop deprecated AetherModule * [MRESOLVER-174] - Use all bindings in UTs and tests * [MRESOLVER-175] - Drop SyncContextFactory delegates in favor of a selector approach * [MRESOLVER-177] - Move pre-/post-processing of metadata from ResolveTask to DefaultMetadataResolver * [MRESOLVER-183] - Don't require optional dependencies for Redisson * [MRESOLVER-184] - Destroy Redisson semaphores if not used anymore * [MRESOLVER-186] - Update Maven version in Resolver Demo Snippets * [MRESOLVER-188] - Improve documentation on using the named locks with redis/hazelcast (umbrella) * [MRESOLVER-190] - [Regression] Revert MRESOLVER-184 * [MRESOLVER-191] - Document how to analyze lock issues * [MRESOLVER-196] - Document named locks configuration options * [MRESOLVER-219] - Implement NamedLock with advisory file locking * [MRESOLVER-227] - Refactor NamedLockFactorySelector to a managed component * [MRESOLVER-232] - Make SimpleNamedLockFactorySelector logic reusable * Sub-task * [MRESOLVER-198] - Replace assert by simpler but equivalent calls * [MRESOLVER-199] - Java 8 improvements * [MRESOLVER-200] - Simplify conditions with the same result and avoid extra validations * [MRESOLVER-201] - Make variables final whenever possible * [MRESOLVER-202] - Use isEmpty() instead length() <= 0 * Dependency upgrade * [MRESOLVER-185] - Upgrade Redisson to 3.15.6 * Change of API and incompatible with maven-resolver < 1.7 * Upgrade to upstream version 1.6.3 * Bug * [MRESOLVER-153] - resolver-status.properties file is corrupted due to concurrent writes * [MRESOLVER-171] - Resolver fails when compiled on Java 9+ and run on Java 8 due to JDK API breakage * Improvement * [MRESOLVER-168] - add DEBUG message when downloading an artifact from repositories * Task * [MRESOLVER-177] - Move pre-/post-processing of metadata from ResolveTask to DefaultMetadataResolver * Needed for maven 3.8.4 * Do not build/run the tests against the legacy guava20 package * Upgrade to upstream version 1.6.2 * Sub-task * [MRESOLVER-139] - Make SimpleDigest use SHA-1 or MD5 only * [MRESOLVER-140] - Default to SHA-1 and MD5 hashing algorithms * Bug * [MRESOLVER-25] - Resume support is broken under high concurrency * [MRESOLVER-114] - ArtifactNotFoundExceptions when building in parallel * [MRESOLVER-129] - Exclusion has no setters * [MRESOLVER-137] - Make OSGi bundles reproducible * [MRESOLVER-138] - MRESOLVER-56 introduces severe performance regression * New Feature * [MRESOLVER-109] - AndDependencySelector should override toString * [MRESOLVER-115] - Make checksum algorithms configurable * [MRESOLVER-123] - Provide a global locking sync context by default * [MRESOLVER-131] - Introduce a Redisson-based SyncContextFactory * [MRESOLVER-165] - Add support for mirror selector on external:http:* * [MRESOLVER-166] - Add support for blocked repositories/mirrors * Improvement * [MRESOLVER-56] - Support SHA-256 and SHA-512 as checksums * [MRESOLVER-116] - Add page with all supported configuration options * [MRESOLVER-125] - Use type conversions returning primitives * [MRESOLVER-127] - Don't use boolean for property 'aether.updateCheckManager.sessionState' * [MRESOLVER-136] - Migrate from maven-bundle-plugin to bnd-maven-plugin * Task * [MRESOLVER-119] - Turn log messages to SLF4J placeholders * [MRESOLVER-130] - Move GlobalSyncContextFactory to a separate module * [MRESOLVER-132] - Remove synchronization in TrackingFileManager * Dependency upgrade * [MRESOLVER-105] - Update Plexus Components * [MRESOLVER-106] - Update HttpComponents * [MRESOLVER-107] - Update Wagon Provider API to 3.4.0 * [MRESOLVER-108] - Update mockito-core to 2.28.2 * [MRESOLVER-117] - Upgrade SLF4J to 1.7.30 * [MRESOLVER-118] - Upgrade Sisu Components to 0.3.4 * Needed for maven 3.8.x * Set buildshell to bash for "<<<". * Upgrade to upstream version 1.4.2 * Bug: * MRESOLVER-38 ? SOE/OOME in DefaultDependencyNode.accept * Improvements: * MRESOLVER-93 ? PathRecordingDependencyVisitor to handle 3 cycles * MRESOLVER-102 ? make build Reproducible * Upgrade to upstream version 1.4.1 * Task * [MRESOLVER-92] - Revert MRESOLVER-7 * Bug * [MRESOLVER-86] - ResolveArtifactMojo from resolver example uses plugin repositories to resolve dependencies * New Feature * [MRESOLVER-10] - New 'TransitiveDependencyManager' supporting transitive dependency management * [MRESOLVER-33] - New 'DefaultDependencyManager' managing dependencies on all levels supporting transitive dependency management * Improvement * [MRESOLVER-7] - Download dependency POMs in parallel * [MRESOLVER-84] - Add support for "release" qualifier * [MRESOLVER-87] - Refresh examples to use maven-resolver artifacts for demo * [MRESOLVER-88] - Code style cleanup to use Java 7 features * Initial packaging of maven-resolver 1.3.1 * Generate and customize the ant build files maven-resolver was update to upstream version 1.9.27: * Bug Fixes * Sync TrackingFileManager with 2.x * Update to upstream version 1.9.26 * New features and improvements * GH-1773: Treat 410 Gone as 404 Not Found * GH-1737: Revert partially parallel upload change * Bug Fixes * GH-1768; Drastically simplify auth caching * [1.9.x] Bug: GH-1703 Locally cached artifacts defy RRF * Documentation updates * Clarify that HTTP Transport uses Apache HTTP Client * Dependency updates * Bump org.redisson:redisson from 3.52.0 to 4.2.0 * Bump commons-codec:commons-codec from 1.20.0 to 1.21.0 * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27 * Bump org.apache.maven:maven-parent from 46 to 47 * Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.0 to 0.25.4 * Bump mavenVersion from 3.9.11 to 3.9.12 * Update to upstream version 1.9.25 * New features and improvements * Add scope support for trusted checksums * Name mappers cleanup and new GAECV mapper * Proper metadata locking support * Ability to augment metadata nature for version range request * Bug Fixes * TrackingFileManager changes * Maven filters daemon friendly * Remove hack from Basic connector * Fix locking issues * Documentation updates * Updated the documentation to reflect the current list of name mappers * Maintenance * Mild backport: support same properties as Resolver 2.x * Maven resolver lockrepro * Bugfix: Java 25 broke test * Dependency updates * Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.23.1 to 0.25.0 * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26 * Bump commons-codec:commons-codec from 1.18.0 to 1.20.0 * Bump org.redisson:redisson from 3.50.0 to 3.52.0 * Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre * Bump com.google.code.gson:gson from 2.13.1 to 2.13.2 * Bump jettyVersion from 9.4.57.v20241219 to 9.4.58.v20250814 * Bump mavenVersion from 3.9.10 to 3.9.11 * Update to upstream version 1.9.24 * New features and improvements * Metadata type out of coordinates * RFC9457 implementation * Intern context strings * Maintenance * Align plexus-util version with Maven * Align guice version with Maven * Enable Github Issues (1.9.x branch) * Build also maven-resolver-supplier package in separate spec file * Add dependency on objectweb-asm to build with sisu 0.9.0.M4 * Update to upstream version 1.9.23 * Bug * MRESOLVER-659: NPE in trusted checksum post processor if * Improvement * MRESOLVER-680: Disable checksum by default for .sigstore.json as well * MRESOLVER-703: HTTP transport should expose config for max redirects * Upgrade to upstream version 3.9.16 * Bug Fixes * Trim threadConfiguration to accept input surrounded with spaces * Backport: Maven 3.10.x fixed plugin resolution * Dependency updates * Bump org.codehaus.plexus:plexus-classworlds from 2.9.0 to 2.11.0 * [3.9.x] Bump to parent POM 48 * Bump commons-io:commons-io from 2.21.0 to 2.22.0 * Bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre * Bump actions/cache from 5.0.4 to 5.0.5 * There is no need to link the jansi-native library into the tree, since our jansi java library will load it from the system anyway * Upgrade to upstream version 3.9.15 * Documentation updates * Use new Maven logos in documentation * document modelVersion only supported value: 4.0.0 * Dependency updates * Bump actions/upload-artifact from 7.0.0 to 7.0.1 * Bump org.codehaus.plexus:plexus-utils from 3.6.0 to 3.6.1 * Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 * Bump actions/cache from 5.0.3 to 5.0.4 * Bump actions/download-artifact from 8.0.0 to 8.0.1 * Upgrade to upstream version 3.9.14 * Bug Fixes * plexus-testing dependencies should be used in test scope * Dependency updates * Bump actions/upload-artifact from 6.0.0 to 7.0.0 * Bump actions/download-artifact from 7.0.0 to 8.0.0 * Upgrade to upstream version 3.9.13 * Bug Fixes * Bug: SecDispatcher is managed by legacy Plexus DI * [3.9.x] MavenPluginJavaPrerequisiteChecker: Handle 8/1.8 Java version in ranges as well * Maintenance * Update Maven plugin versions in default-bindings.xml * Migrate to JUnit 5 - avoid using TestCase * Dependency updates * Maven Resolver 1.9.27 * Bump resolverVersion from 1.9.25 to 1.9.26 * Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0 * Bump actions/cache from 5.0.0 to 5.0.3 * Bump org.apache.maven:maven-parent from 45 to 47 * Bump actions/checkout from 6.0.1 to 6.0.2 * Bump actions/setup-java from 5.1.0 to 5.2.0 * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27 * Bump org.codehaus.mojo:buildnumber-maven-plugin from 3.2.1 to 3.3.0 * Bump org.codehaus.plexus:plexus-testing from 2.0.2 to 2.1.0 * Bump org.ow2.asm:asm from 9.9 to 9.9.1 * Bump actions/upload-artifact from 5.0.0 to 6.0.0 * Bump actions/download-artifact from 6.0.0 to 7.0.0 * Specify required maven-resolver version since the maven-resolver-provider requires methods added in 1.9.25 * Upgrade to upstream version 3.9.12 * New features and improvements * Apply resolver changes and improvements * Update formatting of prerequisites-requirements error to improve readability * Allow a Maven plugin to require a Java version * Use MavenRepositorySystem in ProjectBuildingHelper instead of deprecated RepositorySystem * Make maven.config use UTF8 * Simplify prefix resolution * Bug Fixes * Add default implementation for new method in MavenPluginManager * Repository layout should be used in MavenRepositorySystem * Fix plugin prefix resolution when metadata is not available from repository * Improve source root modification warning message * Bug: bad cache isolation between two sessions * Set Guice class loading to CHILD - avoid using terminally deprecated methods * Avoid parsing MAVEN_OPTS (3.9.x) * Documentation updates * clarify repository vs deployment repository * add maintained branches * Maintenance * Add IntelliJ icon * Build by JDK 25 * Deprecate org.apache.maven.repository.RepositorySystem in 3.9.x * Build * Bump actions/download-artifact from 5.0.0 to 6.0.0 * Bump actions/upload-artifact from 4.6.2 to 5.0.0 * Dependency updates * Bump actions/cache from 4.2.3 to 5.0.0 * Bump resolverVersion from 1.9.24 to 1.9.25 * Bump actions/checkout from 5.0.0 to 6.0.1 * Bump actions/setup-java from 5.0.0 to 5.1.0 * Bump commons-cli:commons-cli from 1.9.0 to 1.11.0 * Bump org.codehaus.plexus:plexus-interpolation from 1.28 to 1.29 * Bump commons-io:commons-io from 2.19.0 to 2.21.0 * Bump xmlunitVersion from 2.10.3 to 2.11.0 * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26 * Bump org.ow2.asm:asm from 9.8 to 9.9 * Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre * Upgrade to upstream version 3.9.11 * New features and improvements * Augment version range resolution used repositories * Bug Fixes * Deduplicate filtered dependency graph * Move ensure in boundaries of project lock * Maintenance * [MNGSITE-393] - remove references to Maven 2 * Update CONTRIBUTING after GitHub issues enabled * Enable Github Issues * [MNG-8763] - Remove name from site bannerLeft * Build * Pin GitHub action versions by hash * Build the project by JDK 21 as default * Use Maven 3.9.10 for build on GitHub * Upgrade to upstream version 3.9.10 * Bug * MNG-8096: Inconsistent dependency resolution behaviour for concurrent multi-module build can cause failures * MNG-8169: MINGW support requires \--add-opens java.base/java.lang=ALL-UNNAMED * MNG-8170: Maven 3.9.8 contains weird native library for Jansi on Windows/arm64 * MNG-8211: Maven should fail builds that use CI Friendly versions but have no values set * MNG-8248: WARNING: A restricted method in java.lang.System has been called * MNG-8256: ProjectDependencyGraph bug: in case of filtering, non-direct module links are lost * MNG-8315: Failure of mvn.cmd if a .mvn directory is located at drive root * MNG-8396: Maven takes forever to resume * MNG-8711: "Duplicate artifact" in LifecycleDependencyResolver * Improvement * MNG-8370: Introduce maven.repo.local.head * MNG-8399: JDK 24+ issues warning about usage of sun.misc.Unsafe * MNG-8707: Add methods to remove compile and test source roots * MNG-8712: improve dependency version explanation: it's a requirement, not always effective version * MNG-8717: Remove maven-plugin-plugin:addPluginArtifactMetadata from default binding * MNG-8722: Use a single standalone version of asm * MNG-8731: Use https for xsi:schemaLocation in generated descriptors * MNG-8734: Simplify scripting like "get project version" cases * Task * MNG-8728: Bump Eclipse Sisu from 0.9.0.M3 to 0.9.0.M4 and use Java 24 on CI * Link also the objectweb-asm/asm to the lib directory * MNG-8177: Warning xmvn-connector was updated to fix: * Add dependency on objectweb-asm to build with sisu 0.9.0.M4 * Upgrade to version 4.3.0 * Changes: * Fix typo in JavadocMojo * Reproducible javadoc * Reproducible manifest injection * Deprecate UUIDs * Implement MetadataResult.getPackageMetadataMap() xmvn-mojo was updated to fix: Upgrade to version 4.3.0 * Changes: * Fix typo in JavadocMojo * Reproducible javadoc * Reproducible manifest injection * Deprecate UUIDs * Implement MetadataResult.getPackageMetadataMap() xmvn-parent was updated to fix: * Upgrade to version 4.3.0 * Changes: * Fix typo in JavadocMojo * Reproducible javadoc * Reproducible manifest injection * Deprecate UUIDs * Implement MetadataResult.getPackageMetadataMap() xmvn-tools was updated to: * The new commons-compress needs commons-lang3 * Upgrade to version 4.3.0 * Changes: * Fix typo in JavadocMojo * Reproducible javadoc * Reproducible manifest injection * Deprecate UUIDs * Implement MetadataResult.getPackageMetadataMap() xmvn was updated to fix: * Adapt to no libjansi.so linked into the arch independent path * Fix build after removal of the default %%{java_home} define * Upgrade to version 4.3.0 * Changes: * Fix typo in JavadocMojo * Reproducible javadoc * Reproducible manifest injection * Deprecate UUIDs * Implement MetadataResult.getPackageMetadataMap() ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3390=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3390=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3390=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3390=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3390=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3390=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3390=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3390=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3390=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3390=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3390=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3390=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * jansi-debuginfo-2.4.0-150200.3.9.1 * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * jansi-debuginfo-2.4.0-150200.3.9.1 * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * jansi-debuginfo-2.4.0-150200.3.9.1 * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * jansi-debuginfo-2.4.0-150200.3.9.1 * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * jansi-debuginfo-2.4.0-150200.3.9.1 * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * jansi-debuginfo-2.4.0-150200.3.9.1 * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * jansi-debuginfo-2.4.0-150200.3.9.1 * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * Development Tools Module 15-SP7 (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * xmvn-install-4.3.0-150200.3.30.1 * beust-jcommander-1.83-150200.3.15.1 * apache-commons-lang3-3.20.0-150200.3.15.2 * maven-resolver-api-1.9.27-150200.3.29.1 * maven-resolver-named-locks-1.9.27-150200.3.29.1 * xmvn-resolve-4.3.0-150200.3.30.1 * apache-commons-compress-1.28.0-150200.3.21.1 * xmvn-core-4.3.0-150200.3.30.1 * maven-resolver-connector-basic-1.9.27-150200.3.29.1 * maven-resolver-transport-file-1.9.27-150200.3.29.1 * plexus-interpolation-1.27.0-150200.3.9.1 * maven-resolver-transport-http-1.9.27-150200.3.29.1 * maven-resolver-transport-wagon-1.9.27-150200.3.29.1 * xmvn-connector-4.3.0-150200.3.30.1 * xmvn-mojo-4.3.0-150200.3.30.1 * maven-resolver-impl-1.9.27-150200.3.29.1 * maven-resolver-spi-1.9.27-150200.3.29.1 * xmvn-api-4.3.0-150200.3.30.1 * maven-resolver-util-1.9.27-150200.3.29.1 * google-guice-6.0.0-150200.3.13.2 * plexus-xml-3.0.1-150200.5.10.1 * guava-33.2.1-150200.3.15.1 * xmvn-subst-4.3.0-150200.3.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * xmvn-minimal-4.3.0-150200.3.30.1 * jansi-2.4.0-150200.3.9.1 * xmvn-4.3.0-150200.3.30.1 * maven-lib-3.9.16-150200.4.33.1 * maven-3.9.16-150200.4.33.1 * Basesystem Module 15-SP7 (noarch) * apache-commons-lang3-3.20.0-150200.3.15.2 * apache-commons-compress-1.28.0-150200.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48924.html -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:47:25 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:47:25 -0000 Subject: SUSE-RU-2026:3389-1: moderate: Recommended update for amavisd-new Message-ID: <178527164576.544.7193502191333965706@f1bb1996abf5> # Recommended update for amavisd-new Announcement ID: SUSE-RU-2026:3389-1 Release Date: 2026-07-28T15:37:05Z Rating: moderate References: Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for amavisd-new fixes the following issue: * ships system-user-vscan to SLE Micro 5.5. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3389=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3389=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3389=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * system-user-vscan-2.12.1-150400.3.2.1 * amavisd-new-2.12.1-150400.3.2.1 * amavisd-new-docs-2.12.1-150400.3.2.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * system-user-vscan-2.12.1-150400.3.2.1 * openSUSE Leap 15.4 (noarch) * amavisd-new-2.12.1-150400.3.2.1 * system-user-vscan-2.12.1-150400.3.2.1 * amavisd-new-docs-2.12.1-150400.3.2.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:45:53 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:45:53 -0000 Subject: SUSE-SU-2026:3354-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4) Message-ID: <178527155397.544.9331839559971786861@f1bb1996abf5> # Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:3354-1 Release Date: 2026-07-28T12:16:30Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.167 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3354=1 SUSE-2026-3358=1 SUSE-2026-3359=1 SUSE-2026-3357=1 SUSE-2026-3360=1 SUSE-2026-3361=1 SUSE-2026-3355=1 SUSE-2026-3356=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3354=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-3358=1 SUSE-SLE-Module-Live- Patching-15-SP4-2026-3359=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3357=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3360=1 SUSE-SLE-Module-Live- Patching-15-SP4-2026-3361=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3355=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3356=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_47-debugsource-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-18-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_42-debugsource-21-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_48-debugsource-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-15-150400.2.1 * kernel-livepatch-5_14_21-150400_24_170-default-21-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-15-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-18-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-18-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-15-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_44-debugsource-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-22-150400.2.1 * kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-21-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_41-debugsource-22-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-22-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-6-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_47-debugsource-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-18-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_42-debugsource-21-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_48-debugsource-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-15-150400.2.1 * kernel-livepatch-5_14_21-150400_24_170-default-21-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-15-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-18-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-18-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-15-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_44-debugsource-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-22-150400.2.1 * kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-21-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-22-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_41-debugsource-22-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-6-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:44:02 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:44:02 -0000 Subject: SUSE-SU-2026:3372-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Message-ID: <178527144279.544.10300544336389195060@f1bb1996abf5> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3372-1 Release Date: 2026-07-28T14:33:43Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.60 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3371=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-3372=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3373=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3372=1 SUSE-2026-3371=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_115-default-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_118-default-3-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_27-debugsource-3-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_28-debugsource-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-3-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_60-default-debuginfo-3-150700.2.1 * kernel-livepatch-6_4_0-150700_53_60-default-3-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_16-debugsource-3-150700.2.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_115-default-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_118-default-3-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_27-debugsource-3-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_28-debugsource-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-3-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:45:09 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:45:09 -0000 Subject: SUSE-SU-2026:3369-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise 15 SP7) Message-ID: <178527150934.544.12752267724590104184@f1bb1996abf5> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3369-1 Release Date: 2026-07-28T13:06:21Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53359 * CVE-2026-53362 * CVE-2026-53366 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.63 fixes various security issues: The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3369=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_63-default-2-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_17-debugsource-2-150700.2.1 * kernel-livepatch-6_4_0-150700_53_63-default-debuginfo-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:43:22 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:43:22 -0000 Subject: SUSE-SU-2026:3388-1: important: Security update for the Linux Kernel (Live Patch 71 for SUSE Linux Enterprise 12 SP5) Message-ID: <178527140216.544.17302521464963700031@f1bb1996abf5> # Security update for the Linux Kernel (Live Patch 71 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3388-1 Release Date: 2026-07-28T15:36:43Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.269 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3380=1 SUSE-SLE-Live- Patching-12-SP5-2026-3382=1 SUSE-SLE-Live-Patching-12-SP5-2026-3384=1 SUSE-SLE- Live-Patching-12-SP5-2026-3385=1 SUSE-SLE-Live-Patching-12-SP5-2026-3386=1 SUSE- SLE-Live-Patching-12-SP5-2026-3387=1 SUSE-SLE-Live-Patching-12-SP5-2026-3388=1 SUSE-SLE-Live-Patching-12-SP5-2026-3375=1 SUSE-SLE-Live- Patching-12-SP5-2026-3374=1 SUSE-SLE-Live-Patching-12-SP5-2026-3377=1 SUSE-SLE- Live-Patching-12-SP5-2026-3378=1 SUSE-SLE-Live-Patching-12-SP5-2026-3379=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_302-default-6-2.1 * kgraft-patch-4_12_14-122_272-default-15-2.1 * kgraft-patch-4_12_14-122_283-default-11-2.1 * kgraft-patch-4_12_14-122_299-default-7-2.1 * kgraft-patch-4_12_14-122_280-default-11-2.1 * kgraft-patch-4_12_14-122_290-default-11-2.1 * kgraft-patch-4_12_14-122_266-default-19-2.1 * kgraft-patch-4_12_14-122_275-default-13-2.1 * kgraft-patch-4_12_14-122_296-default-7-2.1 * kgraft-patch-4_12_14-122_307-default-4-2.1 * kgraft-patch-4_12_14-122_293-default-10-2.1 * kgraft-patch-4_12_14-122_269-default-16-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:52:16 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:52:16 -0000 Subject: SUSE-SU-2026:3364-1: important: Security update for samba Message-ID: <178527193686.544.9342237737268214241@f1bb1996abf5> # Security update for samba Announcement ID: SUSE-SU-2026:3364-1 Release Date: 2026-07-28T12:19:49Z Rating: important References: * bsc#1271469 * bsc#1271672 * bsc#1271673 * bsc#1271674 * bsc#1271675 * bsc#1271676 * bsc#1271677 Cross-References: * CVE-2026-15779 * CVE-2026-58216 * CVE-2026-58218 * CVE-2026-58221 * CVE-2026-58222 * CVE-2026-58224 * CVE-2026-6949 CVSS scores: * CVE-2026-15779 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58216 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58218 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58222 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58224 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-6949 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves seven vulnerabilities can now be installed. ## Description: This update for samba fixes the following issues * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). * CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). * CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). * CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3364=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3364=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3364=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3364=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * samba-ldb-ldap-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-devel-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-dcerpc-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-4.19.8+git.501.67274891bc-150600.3.29.1 * ctdb-pcp-pmda-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-tool-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-gpupdate-4.19.8+git.501.67274891bc-150600.3.29.1 * ctdb-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-test-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-test-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy-devel-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy-python3-devel-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-ldb-ldap-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * ctdb-pcp-pmda-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * ctdb-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-dcerpc-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-python3-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-4.19.8+git.501.67274891bc-150600.3.29.1 * openSUSE Leap 15.6 (aarch64_ilp32) * samba-client-libs-64bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-devel-64bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-64bit-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-64bit-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-64bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-64bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-64bit-4.19.8+git.501.67274891bc-150600.3.29.1 * openSUSE Leap 15.6 (x86_64) * samba-winbind-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-devel-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * openSUSE Leap 15.6 (noarch) * samba-doc-4.19.8+git.501.67274891bc-150600.3.29.1 * openSUSE Leap 15.6 (aarch64 x86_64) * samba-ceph-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-ceph-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * samba-ldb-ldap-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-devel-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-dcerpc-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-tool-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-gpupdate-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy-devel-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy-python3-devel-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-ldb-ldap-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-dcerpc-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-python3-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-4.19.8+git.501.67274891bc-150600.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * samba-winbind-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * samba-ceph-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-ceph-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1 * ctdb-4.19.8+git.501.67274891bc-150600.3.29.1 * ctdb-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * samba-ldb-ldap-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-devel-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-dcerpc-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-tool-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-gpupdate-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy-devel-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy-python3-devel-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-ldb-ldap-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-dcerpc-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-python3-4.19.8+git.501.67274891bc-150600.3.29.1 * libsamba-policy0-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-python3-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-4.19.8+git.501.67274891bc-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * samba-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-ceph-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-winbind-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-ceph-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 * samba-client-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15779.html * https://www.suse.com/security/cve/CVE-2026-58216.html * https://www.suse.com/security/cve/CVE-2026-58218.html * https://www.suse.com/security/cve/CVE-2026-58221.html * https://www.suse.com/security/cve/CVE-2026-58222.html * https://www.suse.com/security/cve/CVE-2026-58224.html * https://www.suse.com/security/cve/CVE-2026-6949.html * https://bugzilla.suse.com/show_bug.cgi?id=1271469 * https://bugzilla.suse.com/show_bug.cgi?id=1271672 * https://bugzilla.suse.com/show_bug.cgi?id=1271673 * https://bugzilla.suse.com/show_bug.cgi?id=1271674 * https://bugzilla.suse.com/show_bug.cgi?id=1271675 * https://bugzilla.suse.com/show_bug.cgi?id=1271676 * https://bugzilla.suse.com/show_bug.cgi?id=1271677 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:49:20 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:49:20 -0000 Subject: SUSE-SU-2026:3367-1: important: Security update for samba Message-ID: <178527176028.544.4445682299206820482@f1bb1996abf5> # Security update for samba Announcement ID: SUSE-SU-2026:3367-1 Release Date: 2026-07-28T12:22:54Z Rating: important References: * bsc#1271469 * bsc#1271672 * bsc#1271673 * bsc#1271674 * bsc#1271675 * bsc#1271676 * bsc#1271677 Cross-References: * CVE-2026-15779 * CVE-2026-58216 * CVE-2026-58218 * CVE-2026-58221 * CVE-2026-58222 * CVE-2026-58224 * CVE-2026-6949 CVSS scores: * CVE-2026-15779 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58216 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58218 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58222 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58224 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-6949 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Availability Extension 12 SP5 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for samba fixes the following issues * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). * CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). * CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). * CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3367=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3367=1 * SUSE Linux Enterprise High Availability Extension 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2026-3367=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2026-3367=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * samba-client-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-debugsource-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-devel-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-devel-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy0-python3-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-libs-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy0-python3-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy0-python3-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-ldb-ldap-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-libs-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-ldb-ldap-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-python3-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy-devel-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-libs-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-libs-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy0-python3-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-libs-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-python3-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-python3-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-libs-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-tool-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-libs-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy-python3-devel-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-libs-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-python3-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-python3-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-python3-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-4.15.13+git.729.a8ce057e8d-3.109.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * samba-doc-4.15.13+git.729.a8ce057e8d-3.109.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * samba-debugsource-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-devel-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-libs-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy0-python3-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-ldb-ldap-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy0-python3-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-libs-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-ldb-ldap-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy-devel-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-python3-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-libs-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-python3-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-libs-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-tool-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy-python3-devel-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-python3-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-python3-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-4.15.13+git.729.a8ce057e8d-3.109.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * samba-winbind-libs-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-libs-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-winbind-libs-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-devel-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-python3-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-libs-python3-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-libs-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy0-python3-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-client-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * libsamba-policy0-python3-debuginfo-32bit-4.15.13+git.729.a8ce057e8d-3.109.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * samba-doc-4.15.13+git.729.a8ce057e8d-3.109.1 * SUSE Linux Enterprise High Availability Extension 12 SP5 (ppc64le s390x x86_64) * ctdb-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * ctdb-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-debugsource-4.15.13+git.729.a8ce057e8d-3.109.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * ctdb-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * ctdb-debuginfo-4.15.13+git.729.a8ce057e8d-3.109.1 * samba-debugsource-4.15.13+git.729.a8ce057e8d-3.109.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15779.html * https://www.suse.com/security/cve/CVE-2026-58216.html * https://www.suse.com/security/cve/CVE-2026-58218.html * https://www.suse.com/security/cve/CVE-2026-58221.html * https://www.suse.com/security/cve/CVE-2026-58222.html * https://www.suse.com/security/cve/CVE-2026-58224.html * https://www.suse.com/security/cve/CVE-2026-6949.html * https://bugzilla.suse.com/show_bug.cgi?id=1271469 * https://bugzilla.suse.com/show_bug.cgi?id=1271672 * https://bugzilla.suse.com/show_bug.cgi?id=1271673 * https://bugzilla.suse.com/show_bug.cgi?id=1271674 * https://bugzilla.suse.com/show_bug.cgi?id=1271675 * https://bugzilla.suse.com/show_bug.cgi?id=1271676 * https://bugzilla.suse.com/show_bug.cgi?id=1271677 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:51:12 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:51:12 -0000 Subject: SUSE-SU-2026:3365-1: important: Security update for samba Message-ID: <178527187228.544.18248292988037320066@f1bb1996abf5> # Security update for samba Announcement ID: SUSE-SU-2026:3365-1 Release Date: 2026-07-28T12:20:57Z Rating: important References: * bsc#1271469 * bsc#1271672 * bsc#1271673 * bsc#1271674 * bsc#1271675 * bsc#1271676 * bsc#1271677 Cross-References: * CVE-2026-15779 * CVE-2026-58216 * CVE-2026-58218 * CVE-2026-58221 * CVE-2026-58222 * CVE-2026-58224 * CVE-2026-6949 CVSS scores: * CVE-2026-15779 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58216 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58218 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58222 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58224 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-6949 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Availability Extension 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for samba fixes the following issues * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). * CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). * CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). * CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2026-3365=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3365=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3365=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3365=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3365=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3365=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3365=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * ctdb-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-test-4.17.12+git.581.f49579c6cd-150500.3.42.1 * ctdb-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-test-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1 * ctdb-pcp-pmda-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * ctdb-pcp-pmda-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * openSUSE Leap 15.5 (x86_64) * samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-devel-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * openSUSE Leap 15.5 (aarch64 x86_64) * samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libsamba-policy0-python3-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-devel-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * openSUSE Leap 15.5 (noarch) * samba-doc-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64) * samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise High Availability Extension 15 SP5 (aarch64 ppc64le s390x x86_64) * samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1 * ctdb-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * ctdb-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 * samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15779.html * https://www.suse.com/security/cve/CVE-2026-58216.html * https://www.suse.com/security/cve/CVE-2026-58218.html * https://www.suse.com/security/cve/CVE-2026-58221.html * https://www.suse.com/security/cve/CVE-2026-58222.html * https://www.suse.com/security/cve/CVE-2026-58224.html * https://www.suse.com/security/cve/CVE-2026-6949.html * https://bugzilla.suse.com/show_bug.cgi?id=1271469 * https://bugzilla.suse.com/show_bug.cgi?id=1271672 * https://bugzilla.suse.com/show_bug.cgi?id=1271673 * https://bugzilla.suse.com/show_bug.cgi?id=1271674 * https://bugzilla.suse.com/show_bug.cgi?id=1271675 * https://bugzilla.suse.com/show_bug.cgi?id=1271676 * https://bugzilla.suse.com/show_bug.cgi?id=1271677 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:54:09 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:54:09 -0000 Subject: SUSE-SU-2026:3362-1: important: Security update for samba Message-ID: <178527204955.544.10668321584738080877@f1bb1996abf5> # Security update for samba Announcement ID: SUSE-SU-2026:3362-1 Release Date: 2026-07-28T12:18:51Z Rating: important References: * bsc#1271469 * bsc#1271672 * bsc#1271673 * bsc#1271674 * bsc#1271675 * bsc#1271676 * bsc#1271677 Cross-References: * CVE-2026-15779 * CVE-2026-58216 * CVE-2026-58218 * CVE-2026-58221 * CVE-2026-58222 * CVE-2026-58224 * CVE-2026-6949 CVSS scores: * CVE-2026-15779 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58216 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58218 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58222 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58224 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-6949 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves seven vulnerabilities can now be installed. ## Description: This update for samba fixes the following issues * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). * CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). * CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). * CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-3362=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3362=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3362=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3362=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3362=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3362=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3362=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3362=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3362=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3362=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * ctdb-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-test-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-test-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * ctdb-pcp-pmda-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * ctdb-pcp-pmda-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * openSUSE Leap 15.4 (x86_64) * samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * openSUSE Leap 15.4 (aarch64_ilp32) * samba-client-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * openSUSE Leap 15.4 (aarch64 x86_64) * samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * openSUSE Leap 15.4 (noarch) * samba-doc-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * ctdb-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15779.html * https://www.suse.com/security/cve/CVE-2026-58216.html * https://www.suse.com/security/cve/CVE-2026-58218.html * https://www.suse.com/security/cve/CVE-2026-58221.html * https://www.suse.com/security/cve/CVE-2026-58222.html * https://www.suse.com/security/cve/CVE-2026-58224.html * https://www.suse.com/security/cve/CVE-2026-6949.html * https://bugzilla.suse.com/show_bug.cgi?id=1271469 * https://bugzilla.suse.com/show_bug.cgi?id=1271672 * https://bugzilla.suse.com/show_bug.cgi?id=1271673 * https://bugzilla.suse.com/show_bug.cgi?id=1271674 * https://bugzilla.suse.com/show_bug.cgi?id=1271675 * https://bugzilla.suse.com/show_bug.cgi?id=1271676 * https://bugzilla.suse.com/show_bug.cgi?id=1271677 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:53:21 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:53:21 -0000 Subject: SUSE-SU-2026:3363-1: important: Security update for samba Message-ID: <178527200148.544.12121977414236517483@f1bb1996abf5> # Security update for samba Announcement ID: SUSE-SU-2026:3363-1 Release Date: 2026-07-28T12:19:16Z Rating: important References: * bsc#1271469 * bsc#1271672 * bsc#1271673 * bsc#1271674 * bsc#1271675 * bsc#1271676 * bsc#1271677 Cross-References: * CVE-2026-15779 * CVE-2026-58216 * CVE-2026-58218 * CVE-2026-58221 * CVE-2026-58222 * CVE-2026-58224 * CVE-2026-6949 CVSS scores: * CVE-2026-15779 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58216 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58218 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58222 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58224 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-6949 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for samba fixes the following issues * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). * CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). * CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). * CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-3363=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3363=1 ## Package List: * Basesystem Module 15-SP7 (x86_64) * samba-client-libs-32bit-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-winbind-libs-32bit-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-libs-32bit-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * libldb2-32bit-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-winbind-libs-32bit-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-client-libs-32bit-4.21.10+git.533.31d7e5508d-150700.3.29.1 * libldb2-32bit-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-libs-32bit-4.21.10+git.533.31d7e5508d-150700.3.29.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libldb-devel-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-python3-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-libs-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-winbind-libs-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-ldb-ldap-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-winbind-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-dcerpc-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-debugsource-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-winbind-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * libldb2-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-client-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-tool-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-client-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-4.21.10+git.533.31d7e5508d-150700.3.29.1 * ldb-tools-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-libs-python3-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-winbind-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 * python3-ldb-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-ldb-ldap-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-client-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 * ldb-tools-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-python3-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-client-libs-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-gpupdate-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-dcerpc-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-libs-python3-4.21.10+git.533.31d7e5508d-150700.3.29.1 * libldb2-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * python3-ldb-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-devel-4.21.10+git.533.31d7e5508d-150700.3.29.1 * Basesystem Module 15-SP7 (aarch64 x86_64) * samba-ceph-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-ceph-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * ctdb-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 * samba-debugsource-4.21.10+git.533.31d7e5508d-150700.3.29.1 * ctdb-debuginfo-4.21.10+git.533.31d7e5508d-150700.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15779.html * https://www.suse.com/security/cve/CVE-2026-58216.html * https://www.suse.com/security/cve/CVE-2026-58218.html * https://www.suse.com/security/cve/CVE-2026-58221.html * https://www.suse.com/security/cve/CVE-2026-58222.html * https://www.suse.com/security/cve/CVE-2026-58224.html * https://www.suse.com/security/cve/CVE-2026-6949.html * https://bugzilla.suse.com/show_bug.cgi?id=1271469 * https://bugzilla.suse.com/show_bug.cgi?id=1271672 * https://bugzilla.suse.com/show_bug.cgi?id=1271673 * https://bugzilla.suse.com/show_bug.cgi?id=1271674 * https://bugzilla.suse.com/show_bug.cgi?id=1271675 * https://bugzilla.suse.com/show_bug.cgi?id=1271676 * https://bugzilla.suse.com/show_bug.cgi?id=1271677 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 28 20:50:07 2026 From: null at suse.de (SLE-UPDATES) Date: Tue, 28 Jul 2026 20:50:07 -0000 Subject: SUSE-SU-2026:3366-1: important: Security update for samba Message-ID: <178527180743.544.17579574011467035860@f1bb1996abf5> # Security update for samba Announcement ID: SUSE-SU-2026:3366-1 Release Date: 2026-07-28T12:21:29Z Rating: important References: * bsc#1271469 * bsc#1271672 * bsc#1271673 * bsc#1271674 * bsc#1271675 * bsc#1271676 * bsc#1271677 Cross-References: * CVE-2026-15779 * CVE-2026-58216 * CVE-2026-58218 * CVE-2026-58221 * CVE-2026-58222 * CVE-2026-58224 * CVE-2026-6949 CVSS scores: * CVE-2026-15779 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58216 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58218 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58222 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58224 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-6949 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Server 15 SP3 An update that solves seven vulnerabilities can now be installed. ## Description: This update for samba fixes the following issues * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). * CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). * CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). * CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3366=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2026-3366=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * ctdb-pcp-pmda-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-tool-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ad-dc-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ad-dc-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-devel-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-test-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-gpupdate-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * ctdb-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-test-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * ctdb-pcp-pmda-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * openSUSE Leap 15.3 (x86_64) * samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-python3-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * libsamba-policy0-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * libsamba-policy0-python3-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libsamba-policy0-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * libsamba-policy0-python3-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ad-dc-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-devel-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-python3-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ad-dc-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * openSUSE Leap 15.3 (noarch) * samba-doc-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * openSUSE Leap 15.3 (aarch64 x86_64) * samba-ceph-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * samba-client-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-debugsource-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ceph-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * ctdb-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1 * samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15779.html * https://www.suse.com/security/cve/CVE-2026-58216.html * https://www.suse.com/security/cve/CVE-2026-58218.html * https://www.suse.com/security/cve/CVE-2026-58221.html * https://www.suse.com/security/cve/CVE-2026-58222.html * https://www.suse.com/security/cve/CVE-2026-58224.html * https://www.suse.com/security/cve/CVE-2026-6949.html * https://bugzilla.suse.com/show_bug.cgi?id=1271469 * https://bugzilla.suse.com/show_bug.cgi?id=1271672 * https://bugzilla.suse.com/show_bug.cgi?id=1271673 * https://bugzilla.suse.com/show_bug.cgi?id=1271674 * https://bugzilla.suse.com/show_bug.cgi?id=1271675 * https://bugzilla.suse.com/show_bug.cgi?id=1271676 * https://bugzilla.suse.com/show_bug.cgi?id=1271677 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 08:30:22 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 08:30:22 -0000 Subject: SUSE-SU-2026:3393-1: important: Security update for the Linux Kernel (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Message-ID: <178531382222.753.18389004570072005583@cdce4c525ac1> # Security update for the Linux Kernel (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3393-1 Release Date: 2026-07-28T17:04:06Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.55 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3393=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_15-debugsource-3-150700.2.1 * kernel-livepatch-6_4_0-150700_53_55-default-3-150700.2.1 * kernel-livepatch-6_4_0-150700_53_55-default-debuginfo-3-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 08:31:01 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 08:31:01 -0000 Subject: SUSE-SU-2026:3392-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP7) Message-ID: <178531386129.753.16347999895898262492@cdce4c525ac1> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3392-1 Release Date: 2026-07-28T17:03:59Z Rating: important References: * bsc#1271370 Cross-References: * CVE-2026-53366 CVSS scores: * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.66 fixes various security issues: The following security issues were fixed: * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3392=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_66-default-debuginfo-2-150700.2.1 * kernel-livepatch-6_4_0-150700_53_66-default-2-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_18-debugsource-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 08:31:42 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 08:31:42 -0000 Subject: SUSE-SU-2026:3397-1: moderate: Security update for python-urllib3 Message-ID: <178531390202.753.7543707456605855824@cdce4c525ac1> # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:3397-1 Release Date: 2026-07-28T18:31:35Z Rating: moderate References: * bsc#1268683 Cross-References: * CVE-2026-9375 CVSS scores: * CVE-2026-9375 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-9375 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-9375 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-urllib3 fixes the following issue * CVE-2026-9375: decompression bomb bypass in the streaming API when using Brotli support can lead to a denial of service (bsc#1268683). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3397=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3397=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3397=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-urllib3-2.0.7-150400.7.33.1 * Public Cloud Module 15-SP4 (noarch) * python311-urllib3-2.0.7-150400.7.33.1 * openSUSE Leap 15.4 (noarch) * python311-urllib3-2.0.7-150400.7.33.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9375.html * https://bugzilla.suse.com/show_bug.cgi?id=1268683 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 08:32:38 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 08:32:38 -0000 Subject: SUSE-SU-2026:3396-1: important: Security update for webkit2gtk3 Message-ID: <178531395819.753.10671337517871562299@cdce4c525ac1> # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2026:3396-1 Release Date: 2026-07-28T18:31:07Z Rating: important References: * bsc#1271638 Cross-References: * CVE-2024-4367 * CVE-2026-39872 * CVE-2026-43663 * CVE-2026-43676 * CVE-2026-43699 * CVE-2026-43701 * CVE-2026-43705 * CVE-2026-43707 * CVE-2026-43712 * CVE-2026-43713 * CVE-2026-43715 * CVE-2026-43716 * CVE-2026-43720 * CVE-2026-43721 * CVE-2026-43725 * CVE-2026-43726 * CVE-2026-43727 * CVE-2026-43731 * CVE-2026-43732 * CVE-2026-43734 * CVE-2026-43740 * CVE-2026-43742 * CVE-2026-43745 CVSS scores: * CVE-2024-4367 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-4367 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-4367 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43676 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43699 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43699 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43701 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L * CVE-2026-43701 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L * CVE-2026-43705 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43705 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43707 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43707 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43712 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43712 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43713 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43713 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43715 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43715 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43716 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43716 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43720 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43720 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43721 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43721 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43725 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L * CVE-2026-43725 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L * CVE-2026-43726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43726 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43727 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43731 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43731 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43732 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43732 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43734 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43742 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43742 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43745 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43745 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: * CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638). * CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638). * CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638). * CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638). * CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638). * CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). * CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638). * CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). * CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638). * CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638). * CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). * CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). * CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638). * CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638). * CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). * CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). Changes for webkit2gtk3: * Update to version 2.52.5: * Fire scrollend event for instant programmatic scrolls. * Increase network idle connection timeout to 115 seconds. * Add User-Agent quirk for HBO Max. * Fix the build with system malloc. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3396=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3396=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3396=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3396=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3396=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3396=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3396=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3396=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3396=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * webkit2gtk4-debugsource-2.52.5-150400.4.146.1 * webkit-jsc-4.1-debuginfo-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1 * webkit2gtk4-devel-2.52.5-150400.4.146.1 * webkit2gtk4-minibrowser-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1 * webkit-jsc-4-debuginfo-2.52.5-150400.4.146.1 * webkit-jsc-6.0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-6_0-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1 * typelib-1_0-WebKit-6_0-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1 * webkit2gtk4-minibrowser-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-minibrowser-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1 * webkit-jsc-4-2.52.5-150400.4.146.1 * webkit-jsc-6.0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-minibrowser-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-devel-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1 * webkit2gtk3-minibrowser-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-debugsource-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1 * webkit-jsc-4.1-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-minibrowser-2.52.5-150400.4.146.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libwebkit2gtk-4_1-0-64bit-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-64bit-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-64bit-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-64bit-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.52.5-150400.4.146.1 * openSUSE Leap 15.4 (noarch) * WebKitGTK-4.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-6.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-4.1-lang-2.52.5-150400.4.146.1 * openSUSE Leap 15.4 (x86_64) * libwebkit2gtk-4_1-0-32bit-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-32bit-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-32bit-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-32bit-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-32bit-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.52.5-150400.4.146.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * webkit2gtk4-debugsource-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-devel-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1 * webkit2gtk3-debugsource-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * WebKitGTK-4.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-6.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-4.1-lang-2.52.5-150400.4.146.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * webkit2gtk4-debugsource-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-devel-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1 * webkit2gtk3-debugsource-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * WebKitGTK-4.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-6.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-4.1-lang-2.52.5-150400.4.146.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * webkit2gtk4-debugsource-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-devel-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1 * webkit2gtk3-debugsource-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * WebKitGTK-4.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-6.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-4.1-lang-2.52.5-150400.4.146.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * webkit2gtk4-debugsource-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-devel-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1 * webkit2gtk3-debugsource-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * WebKitGTK-4.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-6.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-4.1-lang-2.52.5-150400.4.146.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * webkit2gtk4-debugsource-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-devel-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1 * webkit2gtk3-debugsource-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * WebKitGTK-4.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-6.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-4.1-lang-2.52.5-150400.4.146.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * webkit2gtk4-debugsource-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-devel-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1 * webkit2gtk3-debugsource-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * WebKitGTK-4.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-6.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-4.1-lang-2.52.5-150400.4.146.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * webkit2gtk4-debugsource-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-devel-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1 * webkit2gtk3-debugsource-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * WebKitGTK-4.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-6.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-4.1-lang-2.52.5-150400.4.146.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * webkit2gtk4-debugsource-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-2.52.5-150400.4.146.1 * typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1 * webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1 * webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1 * webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1 * webkit2gtk3-devel-2.52.5-150400.4.146.1 * typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1 * webkit2gtk3-debugsource-2.52.5-150400.4.146.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * WebKitGTK-4.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-6.0-lang-2.52.5-150400.4.146.1 * WebKitGTK-4.1-lang-2.52.5-150400.4.146.1 ## References: * https://www.suse.com/security/cve/CVE-2024-4367.html * https://www.suse.com/security/cve/CVE-2026-39872.html * https://www.suse.com/security/cve/CVE-2026-43663.html * https://www.suse.com/security/cve/CVE-2026-43676.html * https://www.suse.com/security/cve/CVE-2026-43699.html * https://www.suse.com/security/cve/CVE-2026-43701.html * https://www.suse.com/security/cve/CVE-2026-43705.html * https://www.suse.com/security/cve/CVE-2026-43707.html * https://www.suse.com/security/cve/CVE-2026-43712.html * https://www.suse.com/security/cve/CVE-2026-43713.html * https://www.suse.com/security/cve/CVE-2026-43715.html * https://www.suse.com/security/cve/CVE-2026-43716.html * https://www.suse.com/security/cve/CVE-2026-43720.html * https://www.suse.com/security/cve/CVE-2026-43721.html * https://www.suse.com/security/cve/CVE-2026-43725.html * https://www.suse.com/security/cve/CVE-2026-43726.html * https://www.suse.com/security/cve/CVE-2026-43727.html * https://www.suse.com/security/cve/CVE-2026-43731.html * https://www.suse.com/security/cve/CVE-2026-43732.html * https://www.suse.com/security/cve/CVE-2026-43734.html * https://www.suse.com/security/cve/CVE-2026-43740.html * https://www.suse.com/security/cve/CVE-2026-43742.html * https://www.suse.com/security/cve/CVE-2026-43745.html * https://bugzilla.suse.com/show_bug.cgi?id=1271638 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 08:33:34 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 08:33:34 -0000 Subject: SUSE-SU-2026:3395-1: low: Security update for GraphicsMagick Message-ID: <178531401418.753.12724433570392035160@cdce4c525ac1> # Security update for GraphicsMagick Announcement ID: SUSE-SU-2026:3395-1 Release Date: 2026-07-28T18:28:19Z Rating: low References: * bsc#1271496 Cross-References: * CVE-2026-61464 CVSS scores: * CVE-2026-61464 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61464 ( NVD ): 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-61464 ( NVD ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for GraphicsMagick fixes the following issue: * CVE-2026-61464: heap buffer overwrite when running an X11 import with a crafted window title (bsc#1271496). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3395=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3395=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libGraphicsMagick++-devel-1.3.42-150600.3.39.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.39.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.39.1 * perl-GraphicsMagick-1.3.42-150600.3.39.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.39.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.39.1 * GraphicsMagick-devel-1.3.42-150600.3.39.1 * GraphicsMagick-debugsource-1.3.42-150600.3.39.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.39.1 * libGraphicsMagick3-config-1.3.42-150600.3.39.1 * GraphicsMagick-1.3.42-150600.3.39.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.39.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.39.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.39.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libGraphicsMagick++-devel-1.3.42-150600.3.39.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.39.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.39.1 * perl-GraphicsMagick-1.3.42-150600.3.39.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.39.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.39.1 * GraphicsMagick-devel-1.3.42-150600.3.39.1 * GraphicsMagick-debugsource-1.3.42-150600.3.39.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.39.1 * libGraphicsMagick3-config-1.3.42-150600.3.39.1 * GraphicsMagick-1.3.42-150600.3.39.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.39.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.39.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.39.1 ## References: * https://www.suse.com/security/cve/CVE-2026-61464.html * https://bugzilla.suse.com/show_bug.cgi?id=1271496 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 08:34:30 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 08:34:30 -0000 Subject: SUSE-SU-2026:3394-1: moderate: Security update for sssd Message-ID: <178531407003.753.12545917131847992158@cdce4c525ac1> # Security update for sssd Announcement ID: SUSE-SU-2026:3394-1 Release Date: 2026-07-28T18:27:52Z Rating: moderate References: * bsc#1269807 Cross-References: * CVE-2026-12610 CVSS scores: * CVE-2026-12610 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-12610 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12610 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for sssd fixes the following issue: * CVE-2026-12610: cancelled or completed PAM request while the asynchronous child process is still running can lead to a use-after-free (bsc#1269807). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3394=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python-sssd-config-1.16.1-7.76.1 * sssd-krb5-debuginfo-1.16.1-7.76.1 * sssd-common-1.16.1-7.76.1 * python-sssd-config-debuginfo-1.16.1-7.76.1 * libsss_simpleifp0-debuginfo-1.16.1-7.76.1 * libsss_idmap-devel-1.16.1-7.76.1 * sssd-ipa-debuginfo-1.16.1-7.76.1 * sssd-ad-1.16.1-7.76.1 * libsss_idmap0-debuginfo-1.16.1-7.76.1 * sssd-krb5-common-1.16.1-7.76.1 * sssd-krb5-1.16.1-7.76.1 * sssd-common-debuginfo-1.16.1-7.76.1 * sssd-tools-debuginfo-1.16.1-7.76.1 * sssd-ipa-1.16.1-7.76.1 * sssd-dbus-debuginfo-1.16.1-7.76.1 * sssd-proxy-debuginfo-1.16.1-7.76.1 * libipa_hbac-devel-1.16.1-7.76.1 * sssd-krb5-common-debuginfo-1.16.1-7.76.1 * libsss_certmap0-debuginfo-1.16.1-7.76.1 * libsss_certmap0-1.16.1-7.76.1 * libsss_idmap0-1.16.1-7.76.1 * libsss_nss_idmap0-debuginfo-1.16.1-7.76.1 * libsss_nss_idmap0-1.16.1-7.76.1 * libipa_hbac0-1.16.1-7.76.1 * sssd-common-debuginfo-32bit-1.16.1-7.76.1 * libipa_hbac0-debuginfo-1.16.1-7.76.1 * sssd-debugsource-1.16.1-7.76.1 * sssd-ldap-debuginfo-1.16.1-7.76.1 * sssd-ldap-1.16.1-7.76.1 * libsss_nss_idmap-devel-1.16.1-7.76.1 * sssd-dbus-1.16.1-7.76.1 * sssd-ad-debuginfo-1.16.1-7.76.1 * sssd-1.16.1-7.76.1 * sssd-common-32bit-1.16.1-7.76.1 * sssd-proxy-1.16.1-7.76.1 * sssd-tools-1.16.1-7.76.1 * libsss_simpleifp0-1.16.1-7.76.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12610.html * https://bugzilla.suse.com/show_bug.cgi?id=1269807 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 08:35:07 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 08:35:07 -0000 Subject: SUSE-RU-2026:3391-1: moderate: Recommended update for tiertune Message-ID: <178531410721.753.5246554009131677037@cdce4c525ac1> # Recommended update for tiertune Announcement ID: SUSE-RU-2026:3391-1 Release Date: 2026-07-28T16:49:49Z Rating: moderate References: Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for tiertune fixes the following issues: * Add KernelWorkQueue class: * Introduces KernelWorkQueue, a new settings class parallel to CPUPower, for managing kernel workqueue parameters. (jsc#PCT-1941) * Add X4 watchdog settings: * Add watchdog_thresh=60 and workqueue.watchdog_thresh=120 to be set by the sysctl component. (jsc#PCT-1941) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3391=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3391=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3391=1 ## Package List: * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * tiertune-azure-0.1.2-150600.13.6.1 * python311-tiertune-0.1.2-150600.13.6.1 * tiertune-aws-0.1.2-150600.13.6.1 * tiertune-gce-0.1.2-150600.13.6.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * tiertune-azure-0.1.2-150600.13.6.1 * tiertune-aws-0.1.2-150600.13.6.1 * python311-tiertune-0.1.2-150600.13.6.1 * tiertune-gce-0.1.2-150600.13.6.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * tiertune-azure-0.1.2-150600.13.6.1 * tiertune-aws-0.1.2-150600.13.6.1 * python311-tiertune-0.1.2-150600.13.6.1 * tiertune-gce-0.1.2-150600.13.6.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 12:30:24 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 12:30:24 -0000 Subject: SUSE-SU-2026:3399-1: important: Security update for gimp Message-ID: <178532822433.841.2398072676792460692@cdce4c525ac1> # Security update for gimp Announcement ID: SUSE-SU-2026:3399-1 Release Date: 2026-07-29T07:44:50Z Rating: important References: * bsc#1270239 * bsc#1270299 * bsc#1270444 Cross-References: * CVE-2026-58379 * CVE-2026-58380 * CVE-2026-58381 CVSS scores: * CVE-2026-58379 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58379 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-58379 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-58380 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58380 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-58380 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-58380 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-58381 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-58381 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-58381 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for gimp fixes the following issues * CVE-2026-58379: Heap buffer overflow in read_channel_data() (bsc#1270299). * CVE-2026-58380: Stack buffer overflow in pnmscanner_gettoken() (bsc#1270444). * CVE-2026-58381: double-free in read_layer_block() (bsc#1270239). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3399=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3399=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3399=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gimp-devel-2.10.30-150400.3.58.1 * gimp-devel-debuginfo-2.10.30-150400.3.58.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.58.1 * gimp-debugsource-2.10.30-150400.3.58.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.58.1 * gimp-2.10.30-150400.3.58.1 * gimp-plugin-aa-2.10.30-150400.3.58.1 * gimp-debuginfo-2.10.30-150400.3.58.1 * gimp-plugin-aa-debuginfo-2.10.30-150400.3.58.1 * libgimpui-2_0-0-2.10.30-150400.3.58.1 * libgimp-2_0-0-2.10.30-150400.3.58.1 * openSUSE Leap 15.4 (x86_64) * libgimp-2_0-0-32bit-2.10.30-150400.3.58.1 * libgimp-2_0-0-32bit-debuginfo-2.10.30-150400.3.58.1 * libgimpui-2_0-0-32bit-debuginfo-2.10.30-150400.3.58.1 * libgimpui-2_0-0-32bit-2.10.30-150400.3.58.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgimp-2_0-0-64bit-debuginfo-2.10.30-150400.3.58.1 * libgimpui-2_0-0-64bit-2.10.30-150400.3.58.1 * libgimp-2_0-0-64bit-2.10.30-150400.3.58.1 * libgimpui-2_0-0-64bit-debuginfo-2.10.30-150400.3.58.1 * openSUSE Leap 15.4 (noarch) * gimp-lang-2.10.30-150400.3.58.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * gimp-devel-2.10.30-150400.3.58.1 * gimp-devel-debuginfo-2.10.30-150400.3.58.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.58.1 * gimp-debugsource-2.10.30-150400.3.58.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.58.1 * gimp-2.10.30-150400.3.58.1 * gimp-debuginfo-2.10.30-150400.3.58.1 * libgimpui-2_0-0-2.10.30-150400.3.58.1 * libgimp-2_0-0-2.10.30-150400.3.58.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (noarch) * gimp-lang-2.10.30-150400.3.58.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * libgimp-2_0-0-debuginfo-2.10.30-150400.3.58.1 * gimp-debugsource-2.10.30-150400.3.58.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.58.1 * gimp-debuginfo-2.10.30-150400.3.58.1 * libgimpui-2_0-0-2.10.30-150400.3.58.1 * libgimp-2_0-0-2.10.30-150400.3.58.1 * SUSE Package Hub 15 15-SP7 (aarch64) * gimp-devel-debuginfo-2.10.30-150400.3.58.1 * gimp-devel-2.10.30-150400.3.58.1 * gimp-2.10.30-150400.3.58.1 * gimp-plugin-aa-2.10.30-150400.3.58.1 * gimp-plugin-aa-debuginfo-2.10.30-150400.3.58.1 * SUSE Package Hub 15 15-SP7 (noarch) * gimp-lang-2.10.30-150400.3.58.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58379.html * https://www.suse.com/security/cve/CVE-2026-58380.html * https://www.suse.com/security/cve/CVE-2026-58381.html * https://bugzilla.suse.com/show_bug.cgi?id=1270239 * https://bugzilla.suse.com/show_bug.cgi?id=1270299 * https://bugzilla.suse.com/show_bug.cgi?id=1270444 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 12:31:20 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 12:31:20 -0000 Subject: SUSE-SU-2026:3398-1: important: Security update for rsyslog Message-ID: <178532828095.841.14898983571471557519@cdce4c525ac1> # Security update for rsyslog Announcement ID: SUSE-SU-2026:3398-1 Release Date: 2026-07-29T07:44:27Z Rating: important References: * bsc#1271910 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one security fix can now be installed. ## Description: This update for rsyslog fixes the following issue * input sequence during oversize-frame recovery in imptcp can cause denial of service (bsc#1271910). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3398=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3398=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3398=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rsyslog-module-ossl-8.2406.0-150600.12.13.1 * rsyslog-module-mysql-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-relp-8.2406.0-150600.12.13.1 * rsyslog-module-relp-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-ossl-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-debugsource-8.2406.0-150600.12.13.1 * rsyslog-module-mmnormalize-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-mmnormalize-8.2406.0-150600.12.13.1 * rsyslog-module-gtls-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-mysql-8.2406.0-150600.12.13.1 * rsyslog-module-pgsql-8.2406.0-150600.12.13.1 * rsyslog-module-udpspoof-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-8.2406.0-150600.12.13.1 * rsyslog-module-snmp-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-gssapi-8.2406.0-150600.12.13.1 * rsyslog-module-gssapi-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-gtls-8.2406.0-150600.12.13.1 * rsyslog-module-udpspoof-8.2406.0-150600.12.13.1 * rsyslog-module-pgsql-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-snmp-8.2406.0-150600.12.13.1 * rsyslog-debuginfo-8.2406.0-150600.12.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rsyslog-module-ossl-8.2406.0-150600.12.13.1 * rsyslog-module-mysql-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-relp-8.2406.0-150600.12.13.1 * rsyslog-module-relp-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-ossl-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-debugsource-8.2406.0-150600.12.13.1 * rsyslog-module-mmnormalize-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-mmnormalize-8.2406.0-150600.12.13.1 * rsyslog-module-gtls-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-mysql-8.2406.0-150600.12.13.1 * rsyslog-module-pgsql-8.2406.0-150600.12.13.1 * rsyslog-module-udpspoof-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-8.2406.0-150600.12.13.1 * rsyslog-module-snmp-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-gssapi-8.2406.0-150600.12.13.1 * rsyslog-module-gssapi-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-pgsql-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-udpspoof-8.2406.0-150600.12.13.1 * rsyslog-module-gtls-8.2406.0-150600.12.13.1 * rsyslog-module-snmp-8.2406.0-150600.12.13.1 * rsyslog-debuginfo-8.2406.0-150600.12.13.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * rsyslog-module-ossl-8.2406.0-150600.12.13.1 * rsyslog-module-elasticsearch-8.2406.0-150600.12.13.1 * rsyslog-module-mysql-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-diag-tools-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-elasticsearch-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-diag-tools-8.2406.0-150600.12.13.1 * rsyslog-module-relp-8.2406.0-150600.12.13.1 * rsyslog-module-relp-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-ossl-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-doc-8.2406.0-150600.12.13.1 * rsyslog-debugsource-8.2406.0-150600.12.13.1 * rsyslog-module-mmnormalize-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-mmnormalize-8.2406.0-150600.12.13.1 * rsyslog-module-gtls-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-mysql-8.2406.0-150600.12.13.1 * rsyslog-module-gcrypt-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-omhttpfs-8.2406.0-150600.12.13.1 * rsyslog-module-kafka-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-kafka-8.2406.0-150600.12.13.1 * rsyslog-module-gcrypt-8.2406.0-150600.12.13.1 * rsyslog-module-omhttpfs-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-udpspoof-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-dbi-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-omamqp1-8.2406.0-150600.12.13.1 * rsyslog-module-pgsql-8.2406.0-150600.12.13.1 * rsyslog-8.2406.0-150600.12.13.1 * rsyslog-module-snmp-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-omtcl-8.2406.0-150600.12.13.1 * rsyslog-module-gssapi-8.2406.0-150600.12.13.1 * rsyslog-module-omtcl-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-gssapi-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-gtls-8.2406.0-150600.12.13.1 * rsyslog-module-udpspoof-8.2406.0-150600.12.13.1 * rsyslog-module-pgsql-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-module-dbi-8.2406.0-150600.12.13.1 * rsyslog-module-snmp-8.2406.0-150600.12.13.1 * rsyslog-module-omamqp1-debuginfo-8.2406.0-150600.12.13.1 * rsyslog-debuginfo-8.2406.0-150600.12.13.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:30:40 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:30:40 -0000 Subject: SUSE-SU-2026:3409-1: important: Security update for xen Message-ID: <178534264066.15698.903391691505766588@ca426f5eb28c> # Security update for xen Announcement ID: SUSE-SU-2026:3409-1 Release Date: 2026-07-29T11:18:18Z Rating: important References: * bsc#1271528 * bsc#1271530 * bsc#1271531 * bsc#1271532 * bsc#1271533 * bsc#1271534 * bsc#1271535 * bsc#1271536 * bsc#1271537 * bsc#1271538 * bsc#1271539 * bsc#1271947 Cross-References: * CVE-2026-42493 * CVE-2026-42494 * CVE-2026-42495 * CVE-2026-62423 * CVE-2026-62424 * CVE-2026-62425 * CVE-2026-62426 * CVE-2026-62427 * CVE-2026-62428 * CVE-2026-62429 * CVE-2026-62430 * CVE-2026-62431 * CVE-2026-62432 * CVE-2026-62433 * CVE-2026-62434 CVSS scores: * CVE-2026-42493 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-42493 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-42493 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42494 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42494 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42494 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-42495 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42495 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62423 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62423 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62423 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62424 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62424 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62424 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62425 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62425 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62426 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62426 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62426 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62427 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62427 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62427 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62428 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62428 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62428 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62429 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62429 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62429 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62430 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-62430 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-62430 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62431 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62431 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62431 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-62432 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62432 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62432 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62433 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-62433 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-62433 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62434 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62434 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62434 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528). * CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530). * CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531). * CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532). * CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534). * CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535). * CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536). * CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537). * CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538). * CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539). * pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3409=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3409=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3409=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * xen-tools-domU-4.18.5_20-150600.3.53.3 * xen-tools-debuginfo-4.18.5_20-150600.3.53.3 * xen-tools-domU-debuginfo-4.18.5_20-150600.3.53.3 * xen-debugsource-4.18.5_20-150600.3.53.3 * xen-4.18.5_20-150600.3.53.3 * xen-libs-4.18.5_20-150600.3.53.3 * xen-tools-4.18.5_20-150600.3.53.3 * xen-libs-debuginfo-4.18.5_20-150600.3.53.3 * xen-devel-4.18.5_20-150600.3.53.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * xen-tools-xendomains-wait-disk-4.18.5_20-150600.3.53.3 * openSUSE Leap 15.6 (x86_64) * xen-libs-32bit-debuginfo-4.18.5_20-150600.3.53.3 * xen-doc-html-4.18.5_20-150600.3.53.3 * xen-libs-32bit-4.18.5_20-150600.3.53.3 * xen-tools-debuginfo-4.18.5_20-150600.3.53.3 * xen-4.18.5_20-150600.3.53.3 * xen-tools-4.18.5_20-150600.3.53.3 * openSUSE Leap 15.6 (i586 x86_64) * xen-tools-domU-debuginfo-4.18.5_20-150600.3.53.3 * xen-debugsource-4.18.5_20-150600.3.53.3 * xen-libs-debuginfo-4.18.5_20-150600.3.53.3 * xen-libs-4.18.5_20-150600.3.53.3 * xen-devel-4.18.5_20-150600.3.53.3 * xen-tools-domU-4.18.5_20-150600.3.53.3 * openSUSE Leap 15.6 (noarch) * xen-tools-xendomains-wait-disk-4.18.5_20-150600.3.53.3 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * xen-tools-domU-4.18.5_20-150600.3.53.3 * xen-tools-debuginfo-4.18.5_20-150600.3.53.3 * xen-tools-domU-debuginfo-4.18.5_20-150600.3.53.3 * xen-debugsource-4.18.5_20-150600.3.53.3 * xen-4.18.5_20-150600.3.53.3 * xen-libs-debuginfo-4.18.5_20-150600.3.53.3 * xen-tools-4.18.5_20-150600.3.53.3 * xen-libs-4.18.5_20-150600.3.53.3 * xen-devel-4.18.5_20-150600.3.53.3 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * xen-tools-xendomains-wait-disk-4.18.5_20-150600.3.53.3 ## References: * https://www.suse.com/security/cve/CVE-2026-42493.html * https://www.suse.com/security/cve/CVE-2026-42494.html * https://www.suse.com/security/cve/CVE-2026-42495.html * https://www.suse.com/security/cve/CVE-2026-62423.html * https://www.suse.com/security/cve/CVE-2026-62424.html * https://www.suse.com/security/cve/CVE-2026-62425.html * https://www.suse.com/security/cve/CVE-2026-62426.html * https://www.suse.com/security/cve/CVE-2026-62427.html * https://www.suse.com/security/cve/CVE-2026-62428.html * https://www.suse.com/security/cve/CVE-2026-62429.html * https://www.suse.com/security/cve/CVE-2026-62430.html * https://www.suse.com/security/cve/CVE-2026-62431.html * https://www.suse.com/security/cve/CVE-2026-62432.html * https://www.suse.com/security/cve/CVE-2026-62433.html * https://www.suse.com/security/cve/CVE-2026-62434.html * https://bugzilla.suse.com/show_bug.cgi?id=1271528 * https://bugzilla.suse.com/show_bug.cgi?id=1271530 * https://bugzilla.suse.com/show_bug.cgi?id=1271531 * https://bugzilla.suse.com/show_bug.cgi?id=1271532 * https://bugzilla.suse.com/show_bug.cgi?id=1271533 * https://bugzilla.suse.com/show_bug.cgi?id=1271534 * https://bugzilla.suse.com/show_bug.cgi?id=1271535 * https://bugzilla.suse.com/show_bug.cgi?id=1271536 * https://bugzilla.suse.com/show_bug.cgi?id=1271537 * https://bugzilla.suse.com/show_bug.cgi?id=1271538 * https://bugzilla.suse.com/show_bug.cgi?id=1271539 * https://bugzilla.suse.com/show_bug.cgi?id=1271947 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:31:38 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:31:38 -0000 Subject: SUSE-SU-2026:3408-1: important: Security update for python-dulwich Message-ID: <178534269884.15698.9393598200188894726@ca426f5eb28c> # Security update for python-dulwich Announcement ID: SUSE-SU-2026:3408-1 Release Date: 2026-07-29T11:13:04Z Rating: important References: * bsc#1271525 Cross-References: * CVE-2026-38974 CVSS scores: * CVE-2026-38974 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-38974 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-dulwich fixes the following issue * CVE-2026-38974: Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py (bsc#1271525). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3408=1 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * python-dulwich-0.18.5-4.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-38974.html * https://bugzilla.suse.com/show_bug.cgi?id=1271525 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:32:19 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:32:19 -0000 Subject: SUSE-SU-2026:3407-1: important: Security update for openvpn Message-ID: <178534273925.15698.15011051202004012111@ca426f5eb28c> # Security update for openvpn Announcement ID: SUSE-SU-2026:3407-1 Release Date: 2026-07-29T11:10:53Z Rating: important References: * bsc#1270413 * bsc#1270414 Cross-References: * CVE-2026-13122 * CVE-2026-13698 CVSS scores: * CVE-2026-13122 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13122 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13122 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13122 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13698 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13698 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13698 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for openvpn fixes the following issues: * CVE-2026-13122: denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled (bsc#1270413). * CVE-2026-13698: denial of service via memory leak triggered by remote attackers with a valid tls-crypt-v2 client key (bsc#1270414). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3407=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3407=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3407=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3407=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openvpn-dco-debuginfo-2.6.10-150600.3.23.1 * openvpn-debugsource-2.6.10-150600.3.23.1 * openvpn-dco-2.6.10-150600.3.23.1 * openvpn-dco-devel-2.6.10-150600.3.23.1 * openvpn-dco-debugsource-2.6.10-150600.3.23.1 * openvpn-debuginfo-2.6.10-150600.3.23.1 * openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.23.1 * openvpn-devel-2.6.10-150600.3.23.1 * openvpn-auth-pam-plugin-2.6.10-150600.3.23.1 * openvpn-2.6.10-150600.3.23.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * openvpn-dco-debuginfo-2.6.10-150600.3.23.1 * openvpn-debugsource-2.6.10-150600.3.23.1 * openvpn-dco-2.6.10-150600.3.23.1 * openvpn-auth-pam-plugin-2.6.10-150600.3.23.1 * openvpn-dco-devel-2.6.10-150600.3.23.1 * openvpn-dco-debugsource-2.6.10-150600.3.23.1 * openvpn-debuginfo-2.6.10-150600.3.23.1 * openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.23.1 * openvpn-devel-2.6.10-150600.3.23.1 * openvpn-down-root-plugin-2.6.10-150600.3.23.1 * openvpn-down-root-plugin-debuginfo-2.6.10-150600.3.23.1 * openvpn-2.6.10-150600.3.23.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * openvpn-dco-debuginfo-2.6.10-150600.3.23.1 * openvpn-debugsource-2.6.10-150600.3.23.1 * openvpn-dco-2.6.10-150600.3.23.1 * openvpn-dco-devel-2.6.10-150600.3.23.1 * openvpn-dco-debugsource-2.6.10-150600.3.23.1 * openvpn-debuginfo-2.6.10-150600.3.23.1 * openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.23.1 * openvpn-devel-2.6.10-150600.3.23.1 * openvpn-auth-pam-plugin-2.6.10-150600.3.23.1 * openvpn-2.6.10-150600.3.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * openvpn-dco-debuginfo-2.6.10-150600.3.23.1 * openvpn-debugsource-2.6.10-150600.3.23.1 * openvpn-dco-2.6.10-150600.3.23.1 * openvpn-dco-devel-2.6.10-150600.3.23.1 * openvpn-dco-debugsource-2.6.10-150600.3.23.1 * openvpn-debuginfo-2.6.10-150600.3.23.1 * openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.23.1 * openvpn-devel-2.6.10-150600.3.23.1 * openvpn-auth-pam-plugin-2.6.10-150600.3.23.1 * openvpn-2.6.10-150600.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13122.html * https://www.suse.com/security/cve/CVE-2026-13698.html * https://bugzilla.suse.com/show_bug.cgi?id=1270413 * https://bugzilla.suse.com/show_bug.cgi?id=1270414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:33:31 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:33:31 -0000 Subject: SUSE-SU-2026:3406-1: important: Security update for java-17-openjdk Message-ID: <178534281196.15698.14416256954669158283@ca426f5eb28c> # Security update for java-17-openjdk Announcement ID: SUSE-SU-2026:3406-1 Release Date: 2026-07-29T11:10:17Z Rating: important References: * bsc#1264396 * bsc#1264994 * bsc#1267355 * bsc#1272223 * bsc#1272224 * bsc#1272225 * bsc#1272227 * bsc#1272228 * bsc#1272235 * bsc#1272236 * bsc#1272237 Cross-References: * CVE-2026-41254 * CVE-2026-46917 * CVE-2026-46968 * CVE-2026-47010 * CVE-2026-47021 * CVE-2026-47027 * CVE-2026-47059 * CVE-2026-47063 * CVE-2026-60147 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities and has two security fixes can now be installed. ## Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU). Security issues fixed: * CVE-2026-41254: lcms: information disclosure and denial of service via integer overflow in `CubeSize` (bsc#1264994). * CVE-2026-46917: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1272223). * CVE-2026-46968: unauthenticated attacker with network access via TLS can gain unauthorized creation, deletion or modification access to critical data (bsc#1272224). * CVE-2026-47010: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert or delete access to some data (bsc#1272225). * CVE-2026-47021: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272227). * CVE-2026-47027: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272228). * CVE-2026-47059: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272235). * CVE-2026-47063: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation, deletion or modification access to critical data (bsc#1272236). * CVE-2026-60147: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert, delete and read access to some data (bsc#1272237). Other updates and bugfixes: * Make post scripts less noisy (bsc#1267355). * Use `libalternatives` instead of `update-alternatives` for distributions where `libalternatives` is available. * Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU): * JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail * JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails * JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails * JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel * JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F * JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/ /PrintDialogsTest.java instruction need to update * JDK-8183336: Better cleanup for jdk/test/java/lang/module/ /customfs/ModulesInCustomFileSystem.java * JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails * JDK-8240908: RetransformClass does not know about MethodParameters attribute * JDK-8255463: java/nio/channels/spi/SelectorProvider/ /inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException * JDK-8272477: Additional cleanup of test/jdk/java/nio/file/spi/ /SetDefaultProvider.java * JDK-8274082: Wrong test name in jtreg run tag for java/awt/ /print/PrinterJob/SwingUIText.java * JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking * JDK-8281243: Test java/lang/instrument/ /RetransformWithMethodParametersTest.java is failing * JDK-8282044: [JVMCI] Export _sha3_implCompress, _md5_implCompress and aarch64::_has_negatives stubs to JVMCI compiler. * JDK-8284993: Replace System.exit call in swing tests with RuntimeException * JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially * JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/ /nativeAndMH/Test.java fails with Out of space in CodeCache * JDK-8287062: com/sun/jndi/ldap/LdapPoolTimeoutTest.java failed due to different timeout message * JDK-8290504: Close streams returned by ModuleReader::list * JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support * JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages * JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed with "RuntimeException: MyObject is not found in test output" * JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!" * JDK-8299304: Test "java/awt/print/PrinterJob/ /PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit * JDK-8304065: HttpServer.stop should terminate immediately if no exchanges are in progress * JDK-8309142: Refactor test/langtools/tools/javac/versions/ /Versions.java * JDK-8316274: javax/swing/ButtonGroup/ /TestButtonGroupFocusTraversal.java fails in Ubuntu 23.10 with Motif LAF * JDK-8317801: java/net/Socket/asyncClose/Race.java fails intermittently (aix) * JDK-8320677: Printer tests use invalid '@run main/manual=yesno * JDK-8321182: SourceExample.SOURCE_14 comment should refer to 'switch expressions' instead of 'text blocks' * JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux * JDK-8323089: networkaddress.cache.ttl is not a system property * JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java fails with "exit code: 133" * JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX * JDK-8324345: Stack overflow during C2 compilation when splitting memory phi * JDK-8324641: [IR Framework] Add Setup method to provide custom arguments and set fields * JDK-8328300: Convert PrintDialogsTest.java from Applet to main program * JDK-8332495: java/util/logging/LoggingDeadlock2.java fails with AssertionError: Some tests failed * JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ /ReuseAddr.java failed: java.net.BindException: Address already in use * JDK-8337876: [IR Framework] Add support for IR tests with @Stable * JDK-8338103: Stabilize and open source a Swing OGL ButtonResizeTest * JDK-8338112: Test testlibrary_tests/ir_framework/tests/ /TestPrivilegedMode.java fails with release build * JDK-8338344: Test TestPrivilegedMode.java intermittent fails java.lang.NoClassDefFoundError: jdk/test/lib/Platform * JDK-8338554: Fix inconsistencies in javadoc/doclet/ /testLinkOption/TestRedirectLinks.java * JDK-8338883: Show warning when CreateCoredumpOnCrash set, but core dump will not happen * JDK-8339233: Test javax/swing/JButton/ /SwingButtonResizeTestWithOpenGL.java#id failed: Button renderings are different after window resize * JDK-8339238: Update to use jtreg 7.5.1 * JDK-8339879: Open some dialog awt tests * JDK-8339975: Open some dialog awt tests 2 * JDK-8340140: Open some dialog awt tests 3 * JDK-8340336: Open some checkbox awt tests * JDK-8340494: Open some dialog awt tests 4 * JDK-8340851: Open some TextArea awt tests * JDK-8340987: Open some TextArea awt tests 1 * JDK-8341055: Open some TextArea awt tests 2 * JDK-8341292: Open some TextArea awt tests 3 * JDK-8341376: Open some TextArea awt tests 4 * JDK-8341427: JFR: Adjust object sampler span handling * JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/ /JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts * JDK-8345618: javax/swing/text/Caret/8163124/ /CaretFloatingPointAPITest.java leaves Caret is not complete * JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally * JDK-8347811: Container detection code for cgroups v2 should use cgroup.controllers * JDK-8347836: Disabled PopupMenu shows shortcuts on Mac * JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000) * JDK-8349533: Refactor validator tests shell files to java * JDK-8349988: Change cgroup version detection logic to not depend on /proc/cgroups * JDK-8350749: Upgrade JLine to 3.29.0 * JDK-8352685: Opensource JInternalFrame tests - series2 * JDK-8352733: Improve RotFontBoundsTest test * JDK-8352877: Opensource Several Font related tests - Batch 1 * JDK-8353488: Open some JComboBox bugs 3 * JDK-8353552: Opensource Several Font related tests - Batch 3 * JDK-8354163: Open source Swing tests Batch 1 * JDK-8354469: Keytool exposes the password in plain text when command is piped using | grep * JDK-8354695: Open source several swing tests batch7 * JDK-8354878: File Leak in CgroupSubsystemFactory::determine_type of cgroupSubsystem_linux.cpp:300 * JDK-8354900: javax/swing/AbstractButton/bug4133768.java failing on macosx-aarch64 * JDK-8355048: ProblemList TestGlyphVectorLayout.java on all platforms * JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/ /bug4865918.java headful and macos run * JDK-8355332: Fix failing semi-manual test EDT issue * JDK-8355443: [java.io] Use @requires tag instead of exiting based on File.separatorChar value * JDK-8355445: [java.nio] Use @requires tag instead of exiting based on "os.name" property value * JDK-8356107: [java.lang] Use @requires tag instead of exiting based on os.name or separatorChar property * JDK-8357062: Update Public Suffix List to 823beb1 * JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java * JDK-8357141: Update to use jtreg 7.5.2 * JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/ /LimitDirectMemory[NegativeTest].java * JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ /ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system * JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently * JDK-8358751: C2: Recursive inlining check for compiled lambda forms is broken * JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine * JDK-8360160: ubuntu-22-04 machine is failing client tests * JDK-8360882: Tests throw SkippedException when they should fail * JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException * JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a * JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25 * JDK-8364190: JFR: RemoteRecordingStream withers don't work * JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/ /jaxp/functional/javax/xml/transform/xmlfiles * JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java * JDK-8365379: SU3.applyInsets may produce wrong results * JDK-8365423: [macos26] java/awt/MenuBar/8007006/ /bug8007006.java fails on macOS 26 * JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26 * JDK-8365526: Crash with null Symbol passed to SystemDictionary::resolve_or_null * JDK-8365625: Can't change accelerator colors in Windows L&F * JDK-8366128: jdk/jdk/nio/zipfs/TestPosix.java::testJarFile uses wrong file * JDK-8366261: Provide utility methods for sun.security.util.Password * JDK-8366369: Add @requires linux for GTK L&F tests * JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ /ChoiceMouseWheelTest.java test is failing * JDK-8367583: sun/security/util/AlgorithmConstraints/ /InvalidCryptoDisabledAlgos.java fails after JDK-8244336 * JDK-8367772: Refactor createUI in PassFailJFrame * JDK-8367784: java/awt/Focus/InitialFocusTest/ /InitialFocusTest1.java failed with Wrong focus owner * JDK-8368041: Enhance TLS certificate handling * JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit * JDK-8368498: Use JUnit instead of TestNG for jdk_text tests * JDK-8368551: Core dump warning may be confusing * JDK-8368670: Deadlock in JFR on event register + class load * JDK-8368683: [process] Increase jtreg debug output maxOutputSize for TreeTest * JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict * JDK-8368885: NMT CommandLine tests can check for error better * JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless * JDK-8369251: Opensource few tests * JDK-8369319: java/net/httpclient/CancelRequestTest.java fails intermittently * JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058 * JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual=ff000000) * JDK-8369851: Remove darcy author tags from langtools tests * JDK-8369858: Remove darcy author tags from jdk tests * JDK-8369911: Test sun/java2d/marlin/ClipShapeTest.java #CubicDoDash, #Cubic and #Poly fail intermittent * JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException * JDK-8370325: G1: Disallow GC for TLAB allocation * JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys * JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests * JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying * JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent() * JDK-8371366: java/net/httpclient/whitebox/ /RawChannelTestDriver.java fails intermittently in jtreg timeout * JDK-8371383: Test sun/security/tools/jarsigner/ /DefaultOptions.java failed due to CertificateNotYetValidException * JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests * JDK-8372120: Add missing sound keyword to MIDI tests * JDK-8372351: Add 2 WISeKey roots * JDK-8372609: Bug4944439 does not enforce locale correctly * JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext" * JDK-8372988: Test runtime/Nestmates/membership/ /TestNestHostErrorWithMultiThread.java failed: Unexpected interrupt * JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field * JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages * JDK-8373275: Improve DTLS handshaking * JDK-8373623: Refactor Serialization tests for Records to JUnit * JDK-8373650: Test "javax/swing/JMenuItem/6458123/ /ManualBug6458123.java" fails because the check icons are not aligned properly as expected * JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms * JDK-8373716: Refactor further java/util tests from TestNG to JUnit * JDK-8373807: test/jdk/java/net/httpclient/websocket/ /DummyWebSocketServer.java getURI() uses "localhost" * JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/ /bug6197830.java failed because The test case automatically fails when clicking any items in the ?Nothing? menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test * JDK-8373869: Refactor java/net/httpclient/ /ThrowingPushPromises*.java tests to use JUnit5 * JDK-8373928: 4 Dangling pointer defect groups in java.c * JDK-8373931: Test javax/sound/sampled/Clip/ /AutoCloseTimeCheck.java timed out * JDK-8374058: Enhance JPEG handling * JDK-8374178: Missing include in systemDictionary.cpp after JDK-8365526 * JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!" * JDK-8374433: java/util/Locale/PreserveTagCase.java does not run any tests * JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F * JDK-8374548: Process httpserver cancelled keys more quickly * JDK-8374555: No need for visible input warning in s.s.u.Password when not reading from System.in * JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/ /TestOptionsWithRanges fails without printing the option name * JDK-8374888: Implement internal test cache to help UserIterCount test performance * JDK-8374998: Failing os::write - remove bad file * JDK-8375065: Update LCMS to 2.18 * JDK-8375080: The tools/jpackage/windows/Win8365790Test.java may fail with ClassNotFoundException: jtreg.SkippedException * JDK-8375231: Refactor util/ServiceLoader tests to use JUnit * JDK-8375232: Refactor util/StringJoiner tests to use JUnit * JDK-8375233: Refactor util/Vector tests to use JUnit * JDK-8375999: com/sun/jndi/ldap/LdapPoolTimeoutTest.java fails sporadically on Windows * JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method * JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed * JDK-8376233: Clean up code in Desktop native peer * JDK-8377158: Enhance XBM image support * JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable * JDK-8377498: Improve HttpServer handling * JDK-8377602: Create automated test for PageRange * JDK-8377678: G1: Heap Dumping crashes with -UseClassUnloading * JDK-8377727: Ghost caret and focus appear in non?editable text fields * JDK-8377833: Enhance Jar file processing * JDK-8377910: Minor cleanup of java/io/FileDescriptor/ /Sharing.java * JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace * JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file * JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable * JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob * JDK-8378687: Improve delegation of HttpURLConnection * JDK-8378777: Bump update version for OpenJDK: jdk-17.0.20 * JDK-8378802: [21u] backport changes to TKit.java by JDK-8352419 * JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument * JDK-8380565: PPC64: deoptimization stub should save vector registers * JDK-8380672: Improve certification checking * JDK-8380947: Add pull request template * JDK-8381039: Enhance AWT ImagingLib * JDK-8381049: Enhance Jar handling * JDK-8381205: GHA: Upgrade Node.js 20 to 24 * JDK-8381519: Enhance Der Value Handling * JDK-8381796: Enhance Certificate parsing * JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String * JDK-8383175: (tz) Update Timezone Data to 2026b * JDK-8383354: Update LCMS to 2.19.1 * JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change * JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path * JDK-8383630: Fix iteration in tests doing class redefinition * JDK-8383659: [17u] JVM crashes during stub routines generation on Windows and rare combination of CPU features * JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily * JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025 * JDK-8384495: Update Libpng to 1.6.58 * JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates * JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate * JDK-8384902: Update GIFlib to 6.1.3 * JDK-8385390: Update FreeType to 2.14.3 * JDK-8385490: Update HarfBuzz to 14.2.0 * JDK-8386343: [17u] Fix NTLMHeadTest after backport of 8384486 * JDK-8386551: Windows build broken because of MSys2/Make update ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3406=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3406=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3406=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3406=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3406=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3406=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3406=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3406=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3406=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3406=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3406=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3406=1 ## Package List: * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-jmods-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-src-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * openSUSE Leap 15.4 (noarch) * java-17-openjdk-javadoc-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-17-openjdk-demo-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-17.0.20.0-150400.3.69.1 * java-17-openjdk-headless-17.0.20.0-150400.3.69.1 * java-17-openjdk-devel-17.0.20.0-150400.3.69.1 * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1 * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-46917.html * https://www.suse.com/security/cve/CVE-2026-46968.html * https://www.suse.com/security/cve/CVE-2026-47010.html * https://www.suse.com/security/cve/CVE-2026-47021.html * https://www.suse.com/security/cve/CVE-2026-47027.html * https://www.suse.com/security/cve/CVE-2026-47059.html * https://www.suse.com/security/cve/CVE-2026-47063.html * https://www.suse.com/security/cve/CVE-2026-60147.html * https://bugzilla.suse.com/show_bug.cgi?id=1264396 * https://bugzilla.suse.com/show_bug.cgi?id=1264994 * https://bugzilla.suse.com/show_bug.cgi?id=1267355 * https://bugzilla.suse.com/show_bug.cgi?id=1272223 * https://bugzilla.suse.com/show_bug.cgi?id=1272224 * https://bugzilla.suse.com/show_bug.cgi?id=1272225 * https://bugzilla.suse.com/show_bug.cgi?id=1272227 * https://bugzilla.suse.com/show_bug.cgi?id=1272228 * https://bugzilla.suse.com/show_bug.cgi?id=1272235 * https://bugzilla.suse.com/show_bug.cgi?id=1272236 * https://bugzilla.suse.com/show_bug.cgi?id=1272237 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:34:28 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:34:28 -0000 Subject: SUSE-SU-2026:3405-1: moderate: Security update for PackageKit Message-ID: <178534286843.15698.17497658601445940075@ca426f5eb28c> # Security update for PackageKit Announcement ID: SUSE-SU-2026:3405-1 Release Date: 2026-07-29T10:59:53Z Rating: moderate References: * bsc#1267250 Cross-References: * CVE-2026-10294 CVSS scores: * CVE-2026-10294 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10294 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-10294 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10294 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for PackageKit fixes the following issue: * CVE-2026-10294: manipulation of the argument frontend-socket can lead to improper authorization (bsc#1267250). ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3405=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * PackageKit-debugsource-1.1.3-24.26.1 * libpackagekit-glib2-18-1.1.3-24.26.1 * libpackagekit-glib2-18-debuginfo-1.1.3-24.26.1 * PackageKit-1.1.3-24.26.1 * PackageKit-debuginfo-1.1.3-24.26.1 * PackageKit-devel-1.1.3-24.26.1 * PackageKit-devel-debuginfo-1.1.3-24.26.1 * PackageKit-backend-zypp-1.1.3-24.26.1 * PackageKit-backend-zypp-debuginfo-1.1.3-24.26.1 * libpackagekit-glib2-devel-1.1.3-24.26.1 * typelib-1_0-PackageKitGlib-1_0-1.1.3-24.26.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * PackageKit-lang-1.1.3-24.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10294.html * https://bugzilla.suse.com/show_bug.cgi?id=1267250 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:35:07 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:35:07 -0000 Subject: SUSE-SU-2026:3404-1: moderate: Security update for PackageKit Message-ID: <178534290738.15698.5325438641955419481@ca426f5eb28c> # Security update for PackageKit Announcement ID: SUSE-SU-2026:3404-1 Release Date: 2026-07-29T10:59:45Z Rating: moderate References: * bsc#1267250 Cross-References: * CVE-2026-10294 CVSS scores: * CVE-2026-10294 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10294 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-10294 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10294 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for PackageKit fixes the following issues: * CVE-2026-10294: manipulation of the argument frontend-socket can lead to improper authorization (bsc#1267250). ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3404=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3404=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3404=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libpackagekit-glib2-devel-1.2.8-150600.4.17.1 * PackageKit-backend-zypp-1.2.8-150600.4.17.1 * PackageKit-1.2.8-150600.4.17.1 * PackageKit-debuginfo-1.2.8-150600.4.17.1 * PackageKit-devel-1.2.8-150600.4.17.1 * libpackagekit-glib2-18-1.2.8-150600.4.17.1 * PackageKit-backend-zypp-debuginfo-1.2.8-150600.4.17.1 * typelib-1_0-PackageKitGlib-1_0-1.2.8-150600.4.17.1 * libpackagekit-glib2-18-debuginfo-1.2.8-150600.4.17.1 * PackageKit-debugsource-1.2.8-150600.4.17.1 * PackageKit-devel-debuginfo-1.2.8-150600.4.17.1 * Desktop Applications Module 15-SP7 (noarch) * PackageKit-lang-1.2.8-150600.4.17.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libpackagekit-glib2-devel-1.2.8-150600.4.17.1 * PackageKit-backend-dnf-debuginfo-1.2.8-150600.4.17.1 * PackageKit-1.2.8-150600.4.17.1 * PackageKit-debuginfo-1.2.8-150600.4.17.1 * PackageKit-backend-zypp-1.2.8-150600.4.17.1 * PackageKit-devel-1.2.8-150600.4.17.1 * PackageKit-debugsource-1.2.8-150600.4.17.1 * libpackagekit-glib2-18-1.2.8-150600.4.17.1 * PackageKit-backend-zypp-debuginfo-1.2.8-150600.4.17.1 * PackageKit-gtk3-module-1.2.8-150600.4.17.1 * typelib-1_0-PackageKitGlib-1_0-1.2.8-150600.4.17.1 * PackageKit-gstreamer-plugin-1.2.8-150600.4.17.1 * PackageKit-backend-dnf-1.2.8-150600.4.17.1 * libpackagekit-glib2-18-debuginfo-1.2.8-150600.4.17.1 * PackageKit-gtk3-module-debuginfo-1.2.8-150600.4.17.1 * PackageKit-gstreamer-plugin-debuginfo-1.2.8-150600.4.17.1 * PackageKit-devel-debuginfo-1.2.8-150600.4.17.1 * openSUSE Leap 15.6 (x86_64) * libpackagekit-glib2-devel-32bit-1.2.8-150600.4.17.1 * libpackagekit-glib2-18-32bit-debuginfo-1.2.8-150600.4.17.1 * libpackagekit-glib2-18-32bit-1.2.8-150600.4.17.1 * openSUSE Leap 15.6 (noarch) * PackageKit-branding-upstream-1.2.8-150600.4.17.1 * PackageKit-lang-1.2.8-150600.4.17.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libpackagekit-glib2-devel-64bit-1.2.8-150600.4.17.1 * libpackagekit-glib2-18-64bit-1.2.8-150600.4.17.1 * libpackagekit-glib2-18-64bit-debuginfo-1.2.8-150600.4.17.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * PackageKit-debuginfo-1.2.8-150600.4.17.1 * PackageKit-gtk3-module-1.2.8-150600.4.17.1 * PackageKit-gstreamer-plugin-1.2.8-150600.4.17.1 * PackageKit-gstreamer-plugin-debuginfo-1.2.8-150600.4.17.1 * PackageKit-debugsource-1.2.8-150600.4.17.1 * PackageKit-gtk3-module-debuginfo-1.2.8-150600.4.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10294.html * https://bugzilla.suse.com/show_bug.cgi?id=1267250 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:36:04 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:36:04 -0000 Subject: SUSE-SU-2026:3403-1: moderate: Security update for perl-XML-Bare Message-ID: <178534296484.15698.4856395389090544019@ca426f5eb28c> # Security update for perl-XML-Bare Announcement ID: SUSE-SU-2026:3403-1 Release Date: 2026-07-29T10:53:49Z Rating: moderate References: * bsc#1271637 * bsc#1271640 Cross-References: * CVE-2026-13401 * CVE-2026-57074 CVSS scores: * CVE-2026-13401 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13401 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57074 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-57074 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-XML-Bare fixes the following issues * CVE-2026-13401: infinite loop when parsing malformed attributes in `parserc_parse` function (bsc#1271640). * CVE-2026-57074: out-of-bounds read due to unbounded character lookahead in the `parserc_parse` function (bsc#1271637). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3403=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-XML-Bare-0.53-150000.3.3.1 * perl-XML-Bare-debuginfo-0.53-150000.3.3.1 * perl-XML-Bare-debugsource-0.53-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13401.html * https://www.suse.com/security/cve/CVE-2026-57074.html * https://bugzilla.suse.com/show_bug.cgi?id=1271637 * https://bugzilla.suse.com/show_bug.cgi?id=1271640 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:36:43 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:36:43 -0000 Subject: SUSE-SU-2026:3402-1: important: Security update for python-ujson Message-ID: <178534300349.15698.17661156897549803259@ca426f5eb28c> # Security update for python-ujson Announcement ID: SUSE-SU-2026:3402-1 Release Date: 2026-07-29T10:46:13Z Rating: important References: * bsc#1270301 Cross-References: * CVE-2026-44660 CVSS scores: * CVE-2026-44660 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44660 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44660 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44660 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 An update that solves one vulnerability can now be installed. ## Description: This update for python-ujson fixes the following issue: * CVE-2026-44660: failing to decrement a serialized JSON object during a write exception in ujson.dump() can lead to memory leaks (bsc#1270301). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3402=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * python311-ujson-5.9.0-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44660.html * https://bugzilla.suse.com/show_bug.cgi?id=1270301 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:37:38 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:37:38 -0000 Subject: SUSE-SU-2026:3401-1: moderate: Security update for sssd Message-ID: <178534305899.15698.1075067794146212655@ca426f5eb28c> # Security update for sssd Announcement ID: SUSE-SU-2026:3401-1 Release Date: 2026-07-29T10:39:11Z Rating: moderate References: * bsc#1269807 Cross-References: * CVE-2026-12610 CVSS scores: * CVE-2026-12610 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-12610 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12610 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for sssd fixes the following issue: * CVE-2026-12610: cancelled or completed PAM request while the asynchronous child process is still running can lead to a use-after-free (bsc#1269807). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3401=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * sssd-ad-2.10.2-150700.9.37.1 * libsss_nss_idmap-devel-2.10.2-150700.9.37.1 * sssd-krb5-common-2.10.2-150700.9.37.1 * libsss_idmap0-2.10.2-150700.9.37.1 * sssd-debugsource-2.10.2-150700.9.37.1 * sssd-dbus-debuginfo-2.10.2-150700.9.37.1 * python3-sssd-config-debuginfo-2.10.2-150700.9.37.1 * libipa_hbac-devel-2.10.2-150700.9.37.1 * sssd-kcm-debuginfo-2.10.2-150700.9.37.1 * libsss_simpleifp0-2.10.2-150700.9.37.1 * libsss_nss_idmap0-2.10.2-150700.9.37.1 * python3-sssd-config-2.10.2-150700.9.37.1 * sssd-tools-2.10.2-150700.9.37.1 * libsss_certmap-devel-2.10.2-150700.9.37.1 * sssd-proxy-debuginfo-2.10.2-150700.9.37.1 * sssd-krb5-debuginfo-2.10.2-150700.9.37.1 * sssd-ldap-2.10.2-150700.9.37.1 * libsss_certmap0-2.10.2-150700.9.37.1 * sssd-ldap-debuginfo-2.10.2-150700.9.37.1 * sssd-kcm-2.10.2-150700.9.37.1 * sssd-debuginfo-2.10.2-150700.9.37.1 * sssd-proxy-2.10.2-150700.9.37.1 * libsss_simpleifp-devel-2.10.2-150700.9.37.1 * sssd-dbus-2.10.2-150700.9.37.1 * sssd-winbind-idmap-2.10.2-150700.9.37.1 * libipa_hbac0-debuginfo-2.10.2-150700.9.37.1 * libsss_simpleifp0-debuginfo-2.10.2-150700.9.37.1 * sssd-tools-debuginfo-2.10.2-150700.9.37.1 * sssd-ipa-debuginfo-2.10.2-150700.9.37.1 * sssd-2.10.2-150700.9.37.1 * sssd-krb5-common-debuginfo-2.10.2-150700.9.37.1 * libipa_hbac0-2.10.2-150700.9.37.1 * sssd-krb5-2.10.2-150700.9.37.1 * libsss_nss_idmap0-debuginfo-2.10.2-150700.9.37.1 * libsss_idmap0-debuginfo-2.10.2-150700.9.37.1 * sssd-winbind-idmap-debuginfo-2.10.2-150700.9.37.1 * libsss_idmap-devel-2.10.2-150700.9.37.1 * libsss_certmap0-debuginfo-2.10.2-150700.9.37.1 * sssd-ad-debuginfo-2.10.2-150700.9.37.1 * sssd-ipa-2.10.2-150700.9.37.1 * Basesystem Module 15-SP7 (x86_64) * sssd-32bit-2.10.2-150700.9.37.1 * sssd-32bit-debuginfo-2.10.2-150700.9.37.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12610.html * https://bugzilla.suse.com/show_bug.cgi?id=1269807 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 16:38:15 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 16:38:15 -0000 Subject: SUSE-OU-2026:3400-1: low: Optional update for salt Message-ID: <178534309599.15698.15462953159242051266@ca426f5eb28c> # Optional update for salt Announcement ID: SUSE-OU-2026:3400-1 Release Date: 2026-07-29T10:01:36Z Rating: low References: * jsc#PED-16466 Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Systems Management Module 15-SP7 An update that contains one feature can now be installed. ## Description: This update for salt fixes the following issue: * Add salt-cloud to SLE-Module-Systems-Management ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Systems Management Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Systems-Management-15-SP7-2026-3400=1 ## Package List: * Systems Management Module 15-SP7 (aarch64 ppc64le s390x x86_64) * salt-doc-3006.0-150700.14.25.2 * salt-cloud-3006.0-150700.14.25.2 * salt-3006.0-150700.14.25.2 * salt-standalone-formulas-configuration-3006.0-150700.14.25.2 * salt-master-3006.0-150700.14.25.2 * salt-minion-3006.0-150700.14.25.2 * python311-salt-3006.0-150700.14.25.2 * salt-transactional-update-3006.0-150700.14.25.2 * salt-syndic-3006.0-150700.14.25.2 * salt-api-3006.0-150700.14.25.2 * salt-ssh-3006.0-150700.14.25.2 * salt-proxy-3006.0-150700.14.25.2 * Systems Management Module 15-SP7 (noarch) * salt-zsh-completion-3006.0-150700.14.25.2 * salt-bash-completion-3006.0-150700.14.25.2 * salt-fish-completion-3006.0-150700.14.25.2 ## References: * https://jira.suse.com/browse/PED-16466 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 20:30:12 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 20:30:12 -0000 Subject: SUSE-RU-2026:3411-1: moderate: Recommended update for suse-migration-rpm Message-ID: <178535701231.961.7518915411609732806@7908fdd063b2> # Recommended update for suse-migration-rpm Announcement ID: SUSE-RU-2026:3411-1 Release Date: 2026-07-29T14:54:59Z Rating: moderate References: Affected Products: * Basesystem Module 15-SP7 * SAP Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for suse migration stack fixes the following issues: suse-migration-rpm: \- Add handling for Staging builds \- Make sure the profile name does not interfere with the \- built package name suse-migration-services: \- Make sure optional profile name does not interfere with the package name \- Add production/staging profiles for SLE16 \- Handle multipath root \- Explicitly request python3-base suse-migration-sle16-activation: \- Handle multipath root (#493) \- Fix md device detection SLES16-Migration, SLES16-SAP_Migration: \- Bump version: 2.1.35 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SAP Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP7-2026-3411=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3411=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * python3-migration-2.1.35-150700.15.27.6 * suse-migration-pre-checks-2.1.35-150700.15.27.6 * suse-migration-scripts-2.1.35-150700.15.27.6 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * suse-migration-sle16-activation-2.1.35-150700.15.19.6 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * SLES16-Migration-2.1.35-Production * SAP Applications Module 15-SP7 (ppc64le x86_64) * SLES16-SAP_Migration-2.1.35-Production -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 29 20:30:36 2026 From: null at suse.de (SLE-UPDATES) Date: Wed, 29 Jul 2026 20:30:36 -0000 Subject: SUSE-RU-2026:3410-1: moderate: Recommended update for sap-installation-wizard Message-ID: <178535703674.961.14976075988233928868@7908fdd063b2> # Recommended update for sap-installation-wizard Announcement ID: SUSE-RU-2026:3410-1 Release Date: 2026-07-29T12:54:06Z Rating: moderate References: * bsc#1261407 Affected Products: * openSUSE Leap 15.6 * SAP Applications Module 15-SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one fix can now be installed. ## Description: This update for sap-installation-wizard fixes the following issues: * Update to version 4.6.20: * wizard_hana_install failed on "hdblcm --lss_trust_unsigned_components", it reports "Unknown option: lss_trust_unsigned_components" (bsc#1261407) * Distinguish between a B1 installation and a standard HANA installation. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3410=1 * SAP Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP6-2026-3410=1 ## Package List: * openSUSE Leap 15.6 (ppc64le x86_64) * sap-installation-wizard-4.6.20-150600.3.21.2 * bone-installation-wizard-4.6.20-150600.3.21.2 * SAP Applications Module 15-SP6 (ppc64le x86_64) * sap-installation-wizard-4.6.20-150600.3.21.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1261407 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:30:12 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:30:12 -0000 Subject: SUSE-RU-2026:2384-2: moderate: Recommended update for python-typing_extensions Message-ID: <178541461266.1210.14965158017307779954@cdce4c525ac1> # Recommended update for python-typing_extensions Announcement ID: SUSE-RU-2026:2384-2 Release Date: 2026-07-30T07:51:14Z Rating: moderate References: Affected Products: * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for python-typing_extensions fixes the following issues: Update to 4.12.2: * Fix regression in v4.12.0 where specialization of certain * generics with an overridden `__eq__` method would raise errors. * Fix tests so they pass on 3.13.0b2 * Preliminary changes for compatibility with the draft implementation of PEP 649 in Python 3.14. * Fix regression in v4.12.0 where nested `Annotated` types would cause `TypeError` to be raised if the nested `Annotated` type had unhashable metadata. * Fix incorrect behaviour of `typing_extensions.ParamSpec` on Python 3.8 and 3.9 that meant that `isinstance(typing_extensions.ParamSpec("P"), typing.TypeVar)` would have a different result in some situations depending on whether or not a profiling function had been set using `sys.setprofile`. * This release focuses on compatibility with the upcoming release of Python 3.13. Most changes are related to the implementation of type parameter defaults (PEP 696). Update to 4.11.0: * Fix tests on Python 3.13.0a5. Patch by Jelle Zijlstra. * Fix the runtime behavior of type parameters with defaults * Fix minor discrepancy between error messages produced by `typing` and `typing_extensions` on Python 3.10. * When `include_extra=False`, `get_type_hints()` now strips `ReadOnly` from the annotation. Update to 4.10.0: This feature release adds support for PEP 728 (TypedDict with extra items) and PEP 742 (`TypeIs`). * Add support for PEP 728, supporting the `closed` keyword argument and the special `__extra_items__` key for TypedDict. Patch by Zixuan James Li. * Add support for PEP 742, adding `typing_extensions.TypeIs`. Patch by Jelle Zijlstra. * Drop runtime error when a read-only `TypedDict` item overrides a mutable one. Type checkers should still flag this as an error. Patch by Jelle Zijlstra. * Speedup `issubclass()` checks against simple runtime-checkable protocols by around 6% (backporting https://github.com/python/cpython/pull/112717, by Alex Waygood). * Fix a regression in the implementation of protocols where `typing.Protocol` classes that were not marked as `@runtime_checkable` would be unnecessarily introspected, potentially causing exceptions to be raised if the protocol had problematic members. Patch by Alex Waygood, backporting https://github.com/python/cpython/pull/113401. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2384=1 ## Package List: * Public Cloud Module 15-SP7 (noarch) * python311-typing_extensions-4.12.2-150600.3.3.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:31:03 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:31:03 -0000 Subject: SUSE-SU-2026:3423-1: important: Security update for xen Message-ID: <178541466365.1210.290261087141166215@cdce4c525ac1> # Security update for xen Announcement ID: SUSE-SU-2026:3423-1 Release Date: 2026-07-30T07:50:01Z Rating: important References: * bsc#1271528 * bsc#1271530 * bsc#1271531 * bsc#1271532 * bsc#1271533 * bsc#1271534 * bsc#1271535 * bsc#1271536 * bsc#1271537 * bsc#1271538 * bsc#1271539 * bsc#1271947 Cross-References: * CVE-2026-42493 * CVE-2026-42494 * CVE-2026-42495 * CVE-2026-62423 * CVE-2026-62424 * CVE-2026-62425 * CVE-2026-62426 * CVE-2026-62427 * CVE-2026-62428 * CVE-2026-62429 * CVE-2026-62430 * CVE-2026-62431 * CVE-2026-62432 * CVE-2026-62433 * CVE-2026-62434 CVSS scores: * CVE-2026-42493 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-42493 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-42493 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42494 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42494 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42494 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-42495 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42495 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62423 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62423 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62423 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62424 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62424 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62424 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62425 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62425 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62426 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62426 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62426 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62427 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62427 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62427 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62428 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62428 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62428 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62429 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62429 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62429 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62430 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-62430 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-62430 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62431 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62431 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62431 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-62432 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62432 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62432 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62433 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-62433 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-62433 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62434 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62434 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62434 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues * CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528). * CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530). * CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531). * CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532). * CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534). * CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535). * CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536). * CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537). * CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538). * CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539). * pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3423=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3423=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3423=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3423=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3423=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3423=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * xen-tools-4.17.6_14-150500.3.76.3 * xen-4.17.6_14-150500.3.76.3 * xen-libs-32bit-debuginfo-4.17.6_14-150500.3.76.3 * xen-tools-debuginfo-4.17.6_14-150500.3.76.3 * xen-doc-html-4.17.6_14-150500.3.76.3 * xen-libs-32bit-4.17.6_14-150500.3.76.3 * openSUSE Leap 15.5 (noarch) * xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3 * openSUSE Leap 15.5 (i586 x86_64) * xen-tools-domU-4.17.6_14-150500.3.76.3 * xen-debugsource-4.17.6_14-150500.3.76.3 * xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3 * xen-libs-4.17.6_14-150500.3.76.3 * xen-devel-4.17.6_14-150500.3.76.3 * xen-libs-debuginfo-4.17.6_14-150500.3.76.3 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * xen-tools-domU-4.17.6_14-150500.3.76.3 * xen-debugsource-4.17.6_14-150500.3.76.3 * xen-tools-4.17.6_14-150500.3.76.3 * xen-4.17.6_14-150500.3.76.3 * xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3 * xen-tools-debuginfo-4.17.6_14-150500.3.76.3 * xen-libs-4.17.6_14-150500.3.76.3 * xen-devel-4.17.6_14-150500.3.76.3 * xen-libs-debuginfo-4.17.6_14-150500.3.76.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * xen-tools-domU-4.17.6_14-150500.3.76.3 * xen-debugsource-4.17.6_14-150500.3.76.3 * xen-tools-4.17.6_14-150500.3.76.3 * xen-4.17.6_14-150500.3.76.3 * xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3 * xen-tools-debuginfo-4.17.6_14-150500.3.76.3 * xen-libs-4.17.6_14-150500.3.76.3 * xen-devel-4.17.6_14-150500.3.76.3 * xen-libs-debuginfo-4.17.6_14-150500.3.76.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * xen-tools-domU-4.17.6_14-150500.3.76.3 * xen-debugsource-4.17.6_14-150500.3.76.3 * xen-tools-4.17.6_14-150500.3.76.3 * xen-4.17.6_14-150500.3.76.3 * xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3 * xen-tools-debuginfo-4.17.6_14-150500.3.76.3 * xen-libs-4.17.6_14-150500.3.76.3 * xen-devel-4.17.6_14-150500.3.76.3 * xen-libs-debuginfo-4.17.6_14-150500.3.76.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * xen-tools-domU-4.17.6_14-150500.3.76.3 * xen-debugsource-4.17.6_14-150500.3.76.3 * xen-tools-4.17.6_14-150500.3.76.3 * xen-4.17.6_14-150500.3.76.3 * xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3 * xen-tools-debuginfo-4.17.6_14-150500.3.76.3 * xen-libs-4.17.6_14-150500.3.76.3 * xen-devel-4.17.6_14-150500.3.76.3 * xen-libs-debuginfo-4.17.6_14-150500.3.76.3 * SUSE Linux Enterprise Micro 5.5 (x86_64) * xen-libs-4.17.6_14-150500.3.76.3 * xen-debugsource-4.17.6_14-150500.3.76.3 * xen-libs-debuginfo-4.17.6_14-150500.3.76.3 ## References: * https://www.suse.com/security/cve/CVE-2026-42493.html * https://www.suse.com/security/cve/CVE-2026-42494.html * https://www.suse.com/security/cve/CVE-2026-42495.html * https://www.suse.com/security/cve/CVE-2026-62423.html * https://www.suse.com/security/cve/CVE-2026-62424.html * https://www.suse.com/security/cve/CVE-2026-62425.html * https://www.suse.com/security/cve/CVE-2026-62426.html * https://www.suse.com/security/cve/CVE-2026-62427.html * https://www.suse.com/security/cve/CVE-2026-62428.html * https://www.suse.com/security/cve/CVE-2026-62429.html * https://www.suse.com/security/cve/CVE-2026-62430.html * https://www.suse.com/security/cve/CVE-2026-62431.html * https://www.suse.com/security/cve/CVE-2026-62432.html * https://www.suse.com/security/cve/CVE-2026-62433.html * https://www.suse.com/security/cve/CVE-2026-62434.html * https://bugzilla.suse.com/show_bug.cgi?id=1271528 * https://bugzilla.suse.com/show_bug.cgi?id=1271530 * https://bugzilla.suse.com/show_bug.cgi?id=1271531 * https://bugzilla.suse.com/show_bug.cgi?id=1271532 * https://bugzilla.suse.com/show_bug.cgi?id=1271533 * https://bugzilla.suse.com/show_bug.cgi?id=1271534 * https://bugzilla.suse.com/show_bug.cgi?id=1271535 * https://bugzilla.suse.com/show_bug.cgi?id=1271536 * https://bugzilla.suse.com/show_bug.cgi?id=1271537 * https://bugzilla.suse.com/show_bug.cgi?id=1271538 * https://bugzilla.suse.com/show_bug.cgi?id=1271539 * https://bugzilla.suse.com/show_bug.cgi?id=1271947 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:31:59 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:31:59 -0000 Subject: SUSE-SU-2026:3422-1: important: Security update for python-sh Message-ID: <178541471994.1210.15861834075896066485@cdce4c525ac1> # Security update for python-sh Announcement ID: SUSE-SU-2026:3422-1 Release Date: 2026-07-30T07:42:14Z Rating: important References: * bsc#1272424 Cross-References: * CVE-2026-54552 CVSS scores: * CVE-2026-54552 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-sh fixes the following issues: * CVE-2026-54552: incomplete privilege drop in the _uid option can allow a subprocess to retain parent supplementary groups (bsc#1272424). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3422=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3422=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3422=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3422=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3422=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3422=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3422=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3422=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3422=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3422=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3422=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3422=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-sh-2.0.4-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-sh-2.0.4-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-sh-2.0.4-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-sh-2.0.4-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-sh-2.0.4-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-sh-2.0.4-150400.9.6.1 * openSUSE Leap 15.4 (noarch) * python311-sh-2.0.4-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python311-sh-2.0.4-150400.9.6.1 * Python 3 Module 15-SP7 (noarch) * python311-sh-2.0.4-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-sh-2.0.4-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-sh-2.0.4-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-sh-2.0.4-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54552.html * https://bugzilla.suse.com/show_bug.cgi?id=1272424 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:32:55 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:32:55 -0000 Subject: SUSE-SU-2026:3421-1: important: Security update for prometheus-ha_cluster_exporter Message-ID: <178541477545.1210.13119290005814447786@cdce4c525ac1> # Security update for prometheus-ha_cluster_exporter Announcement ID: SUSE-SU-2026:3421-1 Release Date: 2026-07-30T07:37:12Z Rating: important References: * bsc#1266552 * jsc#PED-2560 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for prometheus-ha_cluster_exporter fixes the following issue: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266552). Other updates and bugfixes: * Release 1.4.2 * Use proper obs time format on changes generation. * Upgrade x/net to 0.57. * Full changelog *: https://github.com/ClusterLabs/ha_cluster_exporter/compare/1.4.1...1.4.2 * Release 1.4.1 * Upgrade to use go 1.25. * Bump github.com/prometheus/common from 0.59.1 to 0.61.0. * Bump golang.org/x/net from 0.33.0 to 0.55.0. * Full changelog: https://github.com/ClusterLabs/ha_cluster_exporter/compare/1.4.0...1.4.1 * Release 1.4.0 * add support to show overall cluster maintenance mode. * add supportconfig plugin (jsc#PED-2560). * update the CI workflow. * change default OBS development project. * bump required Go version to 1.23. * fix corosync collector parser when using IPv6 hostnames (#245). * Bump github.com/prometheus/client_model from 0.3.0 to 0.4.0 . * Bump github.com/prometheus/client_golang from 1.15.0 to 1.15.1 . * Bump github.com/prometheus/common from 0.42.0 to 0.44.0. * Bump github.com/spf13/viper from 1.15.0 to 1.16.0. * Bump github.com/stretchr/testify from 1.8.2 to 1.8.4. * Bump github.com/prometheus/client_golang from 1.15.1 to 1.16.0. * Bump github.com/prometheus/client_golang from 1.16.0 to 1.17.0. * Bump golang.org/x/net from 0.10.0 to 0.17.0. * Bump github.com/prometheus/common from 0.44.0 to 0.55.0. * Bump github.com/spf13/viper from 1.16.0 to 1.19.0. * Bump actions/download-artifact from 3 to 4.1.7. * Bump github.com/prometheus/client_golang from 1.19.1 to 1.20.2. * Bump github.com/prometheus/common from 0.55.0 to 0.59.1. * Bump github.com/prometheus/client_golang from 1.20.2 to 1.20.4. * Bump github.com/prometheus/client_golang from 1.20.4 to 1.20.5. * Bump github.com/stretchr/testify from 1.9.0 to 1.10.0. * Bump golang.org/x/crypto from 0.26.0 to 0.31.0. * Full changelog: https://github.com/ClusterLabs/ha_cluster_exporter/compare/1.3.3...1.4.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SAP-12-SP5-2026-3421=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * prometheus-ha_cluster_exporter-1.4.2-4.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266552 * https://jira.suse.com/browse/PED-2560 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:33:45 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:33:45 -0000 Subject: SUSE-SU-2026:3420-1: important: Security update for liboqs, oqs-provider Message-ID: <178541482512.1210.2257788308147136223@cdce4c525ac1> # Security update for liboqs, oqs-provider Announcement ID: SUSE-SU-2026:3420-1 Release Date: 2026-07-30T07:28:37Z Rating: important References: * bsc#1101107 * bsc#1242701 * bsc#1244617 * bsc#1245315 * bsc#1246301 * bsc#1249081 * bsc#1267001 * bsc#1267007 Cross-References: * CVE-2025-52473 * CVE-2026-44518 * CVE-2026-46344 CVSS scores: * CVE-2025-52473 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-52473 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-52473 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-52473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44518 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-44518 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46344 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46344 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities and has five security fixes can now be installed. ## Description: This update for liboqs, oqs-provider fixes the following issues: * disable KEM_HQC and SIG_MQOM and KEM_NTRUPRIME on s390x for now, testsuite shows them not working. Updated to 0.16.0: Deprecation notice: * SPHINCS+ was removed in 0.16.0. Security issues: * Fixed uninitialized `encaps_derand` pointer dereference * CVE-2026-46344, CVE-2026-44518: Fixed out-of-bounds read in XMSS/XMSS^MT signature verification (bsc#1267007 bsc#1267001) * Fixed Integer underflow in CROSS `crypto_sign_open()` * Fixed incorrect array size when calling `secure_clean` * Implemented optimization barrier `OQS_MEM_BLACK_BOX` and applied to `ct_select` in FrodoKEM Significant change: FrodoKEM algorithm change: * Existing FrodoKEM in 0.15.0 was renamed to ephemeral FrodoKEM (`KEM_efrodokem_<640|976|1344>_<aes|shake>`), and the salted variant of FrodoKEM was added under the prior names (`KEM_frodokem_<640|976|1344>_<aes|shake>`). Ephemeral FrodoKEM is recommended for applications where each keypair will encapsulate only a small number of shared secrets and ciphertexts. Standard (salted) FrodoKEM is recommended for applications where each keypair is expected to encapsulate large number of ciphertexts. Please consult upstream for more details. * mldsa-native integration: mldsa-native is a secure, fast, and portable C90 implementation of the ML-DSA post-quantum signature standard. It also includes optimized builds for x86_64 and aarch64. It is now the default implementation behind `SIG_ml_dsa_<44|65|87>`. * Updated HQC implementation: The HQC implementations in liboqs were updated to 20250822 spec. Its upstream switched from PQClean to the official repo. `KEM_hqc_<1|3|5>` is now enabled by default. * MQOM integration and memory-optimized build flag: MQOM is a third-round candidate in NIST's Additional Digital Signatures for the PQC Standardization Process. Portable, x86_64-optimized, and memory-optimized implementations were integrate into liboqs under `OQS_ENABLE_SIG_MQOM`. * OpenSSH implementation of NTRU Prime: A public-domain OpenSSH implementation of NTRUPrime761 replaced the PQClean implementation as the default backend for `KEM_ntruprime_sntrup761`. Bug fixes: * Fixed incremental absorption bug in AVX512VL SHA3-512 #2442 * Implemented fallback for when `EVP_DigestSqueeze` is unavailable #2433 * Added API for detecting stateful signature support at runtime #2434 * Fixed missing initialization and indexing bug in LMS #2416 * Fixed erroneous MAYO_OK despite failed sample_solution() attempts in MAYO #2403 * Limited pytest parallelism to prevent memory exhaustion in constrained environment #2397 * Fixed cuPQC ML-KEM derand symbol names and `#if/#elif` chains #2396 * Tightened Windows compiler detection #2394 * Fixed mismatched macros in LMS #2379 * Made fuzzers tolerant to disabled algorithms #2359 * Removed inlined exponentiation in CROSS-RSDPG-1 #2357 * Fixed incorrect arg register update in AVX512 Keccak #2330 Update to 0.15.0: * Significant changes: * Integrated SLH-DSA implementation from pq-code-package/slhdsa-c * SLH-DSA ACVP tests (#2237) * Integrate SLH-DSA-C Library (#2175) * Added NTRU back (#2176) * Removed all Dilithium implementations (#2275) * Replaced SPHINCS+ with SLH-DSA for CMake build option OQS_ALGS_ENABLED=STD (#2290) * Updated CROSS to version 2.2 (#2247) * Included DeriveEncapsulation functionality (#2221) * Integrated ML-KEM implementation from ICICLE-PQC (#2216) * Bug fixes: * Fixed erroneously disabled LMS variants with build flag OQS_ENABLE_SIG_STFL_LMS (#2310) * Fixed incorrect import in OV-III-pkc_skc (#2299) * Fixed incorrect actual signature length in signature full-cycle speed test (#2293) * Fixed ICICLE ML-KEM integration (#2288) * Disabled strict aliasing on SPHINCS+-SHAKE (#2264) * Fixed uninitialized length_encaps_seed for NTRU implementations (#2266) * Changed 64 bit add to 32 bit add to wrap on 32 bit counter for AES-CTR AES-NI implementation (#2252) * Improved random number generator security (#2225) * Added Classic McEliece sanitization patch (#2218) * Miscellaneous: * Deprecated noregress scripts (#2295) * Updated no-pass explanation for constant-time testing (#2294) * Re-enabled all ACVP tests (#2283) * Updated license info for ML-KEM (#2250) * Added Poutine SASL (#2213) * Updated ACVP to 1.1.0.40 (#2172) * Switched to dev mode for 0.14.1 (#2199) * Deprecation notice: liboqs 0.15.0 is the last version to officially support SPHINCS+. SPHINCS+ will be removed in the 0.16.0 release and replaced by SLH-DSA. liboqs 0.15.0 also removes support for Dilithium. Updated to 0.14.0: * Key encapsulation mechanisms: * HQC: Disabled compiler optimizations to avoid secret-dependent branching in certain configurations. HQC remains disabled by default. * ML-KEM: Updated the default ML-KEM implementation to PQCP's mlkem-native v1.0.0. * Digital signature schemes: * New API: added an API function to check if a signature scheme supports signing with a context string. * SNOVA: added SNOVA from NIST Additional Signature Schemes Round 2. * Other changes: * Added an AVX512VL-optimized backend for SHA3. * Improved memory management throughout the codebase. * CVE-2025-52473: Disabled compiler optimizations for HQC to avoid secret- dependent branches. Thank you to Zhenzhi Lai and Zhiyuan Zhang from from the University of Melbourne and the Max Planck Institute for Security and Privacy for identifying the issue. (bsc#1246301) * new major library version liboqs.so.8 * add -DOQS_ENABLE_KEM_HQC=ON even due to security issues, as otherwise we dropped binary compatibility with postquantumcryptoengine (bsc#1242701) * Do not embed the buildhost's kernel version to help reproducibility (bsc#1101107) Updated to 0.13.0: * Key encapsulation mechanisms * New API: Added a deterministic key generation and API for KEMs (only ML-KEM supported at the moment). * ML-KEM: Changed the default ML-KEM implementation to PQCP's mlkem-native. There are three variants: Portable C, AVX2, and AArch64. Large +parts of these implementations are formally verified: all of the C code is verified for memory and type safety using CBMC and the functional correctness +of the core AArch64 assembly routines is verified using HOL-Light. * ML-KEM: Added support for the ML-KEM implementation from Nvidia cuPQC, a GPU accelerated cryptography library. * ML-KEM: Implementation from mlkem-native upstream updated to add Pair-wise Consistency Test (PCT) and Intel CET support. * ML-KEM: Improved testing of ML-KEM keys. * HQC: Disabled HQC by default until a new security flaw is fixed. * Digital signature schemes * ML-DSA: Improved testing for ML-DSA. * CROSS: Updated to NIST Additional Signatures Round 2 version. * MAYO: Updated to NIST Additional Signatures Round 2 version. * UOV: Added support for UOV algorithm from NIST Additional Signatures Round 2. Update to 0.11.0: * Hide all symbols except for OSSL_provider_init entrypoint * corrects fixed test cert validity * Update CROSS to version 2.2 * update contributing guide to point to more resilient script * follow upstream and fixup Composites removal * Add Brainpool hybrid KEM support * Fix 'enable_tls' SIG algorithm mismatch Updated to 0.10.0: * Add SNOVA signatures * Remove Composite Signature logic, templating, and documentation * disable openssl.cnf which blocks some of our tests (bsc#1249081) updated to 0.9.0: * Adds support for UOV (NIST Additional Signatures Round 2) * Adds support for Mayo (NIST Additional Signatures Round 2) * Adds support for CROSS (NIST Additional Signatures Round 2) * Disables HQC KEM by default, following liboqs v0.13.0, until a security flaw is fixed. * Disables default support for Kyber (Round 3 version). * Disables default support for Dilithium (Round 3 version). * Restricts non-standard TLS group code points to IANA private use range. * Updates TLS group code point and name for ML-KEM 1024 hybrid SecP384r1MLKEM1024. * Disables ML-KEM (along with certain hybrid variants) and ML-DSA (along with all composite/hybrid variants) when oqs-provider is loaded with OpenSSL (version >= 3.5.0) which offers native support for some of these algorithms. Please see README.md for detailed information. * fixes build with openssl 3.5 (bsc#1244617) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3420=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3420=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3420=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3420=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * oqs-provider-debuginfo-0.11.0.32-150600.3.9.1 * liboqs9-debuginfo-0.16.0-150600.3.6.1 * oqs-provider-0.11.0.32-150600.3.9.1 * liboqs-devel-0.16.0-150600.3.6.1 * liboqs9-0.16.0-150600.3.6.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * oqs-provider-debuginfo-0.11.0.32-150600.3.9.1 * liboqs9-debuginfo-0.16.0-150600.3.6.1 * oqs-provider-0.11.0.32-150600.3.9.1 * liboqs-devel-0.16.0-150600.3.6.1 * liboqs9-0.16.0-150600.3.6.1 * openSUSE Leap 15.6 (x86_64) * liboqs-devel-32bit-0.16.0-150600.3.6.1 * liboqs9-32bit-0.16.0-150600.3.6.1 * liboqs9-32bit-debuginfo-0.16.0-150600.3.6.1 * openSUSE Leap 15.6 (aarch64_ilp32) * liboqs9-64bit-debuginfo-0.16.0-150600.3.6.1 * liboqs-devel-64bit-0.16.0-150600.3.6.1 * liboqs9-64bit-0.16.0-150600.3.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * oqs-provider-debuginfo-0.11.0.32-150600.3.9.1 * liboqs9-debuginfo-0.16.0-150600.3.6.1 * oqs-provider-0.11.0.32-150600.3.9.1 * liboqs-devel-0.16.0-150600.3.6.1 * liboqs9-0.16.0-150600.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * oqs-provider-debuginfo-0.11.0.32-150600.3.9.1 * liboqs9-debuginfo-0.16.0-150600.3.6.1 * oqs-provider-0.11.0.32-150600.3.9.1 * liboqs-devel-0.16.0-150600.3.6.1 * liboqs9-0.16.0-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-52473.html * https://www.suse.com/security/cve/CVE-2026-44518.html * https://www.suse.com/security/cve/CVE-2026-46344.html * https://bugzilla.suse.com/show_bug.cgi?id=1101107 * https://bugzilla.suse.com/show_bug.cgi?id=1242701 * https://bugzilla.suse.com/show_bug.cgi?id=1244617 * https://bugzilla.suse.com/show_bug.cgi?id=1245315 * https://bugzilla.suse.com/show_bug.cgi?id=1246301 * https://bugzilla.suse.com/show_bug.cgi?id=1249081 * https://bugzilla.suse.com/show_bug.cgi?id=1267001 * https://bugzilla.suse.com/show_bug.cgi?id=1267007 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:34:42 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:34:42 -0000 Subject: SUSE-SU-2026:3419-1: important: Security update for tomcat Message-ID: <178541488280.1210.274420445150383626@cdce4c525ac1> # Security update for tomcat Announcement ID: SUSE-SU-2026:3419-1 Release Date: 2026-07-30T07:09:05Z Rating: important References: * bsc#1271397 * bsc#1271398 Cross-References: * CVE-2026-59083 * CVE-2026-59084 CVSS scores: * CVE-2026-59083 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-59083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-59084 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-59084 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues: Update to Tomcat 9.0.120. Security issues fixed: * CVE-2026-59083: incorrect URL decoding in `RewriteValve` may allow security control bypass (bsc#1271397). * CVE-2026-59084: `EncryptInterceptor` requirements are not clearly documented (bsc#1271398). Other updates and bugfixes: * Tomcat 9.0.120: * Catalina * Fix: Avoid a race condition with concurrent lookups for a singleton JNDI resource. (markt) * Fix: Improve the performance of range validation for the default servlet. (markt) * Fix: Avoid NPE in RewriteValve. (markt) * Fix: 70127: Fix use of Bootstrap through reflection by restoring the public constructor. Use through scripts was not affected. (remm) * Fix: Restore ability to extend many element classes from AbstractAccessLogValve. (remm) * Fix: Align DIGEST authentication with RFC 7616 and require clients to provide a valid qop parameter. (markt) * Fix: Use Files API to create temporary docBase when antiLockingDocBase is enabled. (markt) * Fix: Improve validation of configuration when DataSourceRealm starts. (remm) * Fix: JAASRealm should do a logout if login does not fail outright but does not produce a Principal. (remm) * Fix: Various edge cases for SSI substitutions, quoting and escaping. * Fix: unintentional conversion of literal + to a space during rule processing in the RewriteValve. (markt) * Coyote * Fix: Avoid a potential JVM crash if a suitable version of Tomcat Native is not available when the connector is explicitly configured to use Tomcat Native with OpenSSL for TLS. (markt) * Fix: Correct a regression introduced in 9.0.119 that broke reading of some request bodies via a Reader. (markt) * Jasper * Fix: 70120: The fix for 69399 (itself a fix for a regression in the fix for 69333) was incomplete and tags that threw exceptions in doStartTag() and doEndTag() were incorrectly re-used. This fix prevents tags from being re-used if such an exception occurs. (markt) * Fix: 70135: Fix security classload regression. (remm) * Add: support for specifying Java 28 (with the value 28) as the compiler source and/or compiler target for JSP compilation. If used with an Eclipse JDT compiler version that does not support these values, a warning will be logged and the default will be used. (markt) * WebSocket * Fix: 70126: Fix WebSocket extension permessage-deflate so that it does not drop bytes if a compressed message inflates to more than the available buffer. Fix written by GPT-5.5. Test case written by Hironori Ichimiya. (markt) * Fix: Optimise WebSocket client processing of server responses during WebSocket HTTP upgrade process. (markt) * Other * Update: Byte Buddy to 1.18.9. (markt) * Update: UnboundID to 7.0.5. (markt) * Update: JaCoCo to 0.8.15. (markt) * Update: BND to 7.3.0. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3419=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3419=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3419=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3419=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3419=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3419=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3419=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3419=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3419=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3419=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3419=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * Web and Scripting Module 15-SP7 (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * tomcat-webapps-9.0.120-150200.114.1 * tomcat-admin-webapps-9.0.120-150200.114.1 * tomcat-el-3_0-api-9.0.120-150200.114.1 * tomcat-9.0.120-150200.114.1 * tomcat-jsp-2_3-api-9.0.120-150200.114.1 * tomcat-lib-9.0.120-150200.114.1 * tomcat-servlet-4_0-api-9.0.120-150200.114.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59083.html * https://www.suse.com/security/cve/CVE-2026-59084.html * https://bugzilla.suse.com/show_bug.cgi?id=1271397 * https://bugzilla.suse.com/show_bug.cgi?id=1271398 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:35:23 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:35:23 -0000 Subject: SUSE-SU-2026:3418-1: important: Security update for tomcat10 Message-ID: <178541492325.1210.13493405594824529657@cdce4c525ac1> # Security update for tomcat10 Announcement ID: SUSE-SU-2026:3418-1 Release Date: 2026-07-30T07:07:43Z Rating: important References: * bsc#1271397 * bsc#1271398 Cross-References: * CVE-2026-59083 * CVE-2026-59084 CVSS scores: * CVE-2026-59083 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-59083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-59084 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-59084 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for tomcat10 fixes the following issues: Update to Tomcat 10.1.57. Security issues fixed: * CVE-2026-59083: incorrect URL decoding in `RewriteValve` may allow security control bypass (bsc#1271397). * CVE-2026-59084: `EncryptInterceptor` requirements are not clearly documented (bsc#1271398). Other updates and bugfixes: * Tomcat 10.1.57: * Catalina * Fix: Avoid a race condition with concurrent lookups for a singleton JNDI resource. (markt) * Fix: Improve the performance of range validation for the default servlet. (markt) * Fix: Avoid NPE in RewriteValve. (markt) * Fix: 70127: Fix use of Bootstrap through reflection by restoring the public constructor. Use through scripts was not affected. (remm) * Fix: Restore ability to extend many element classes from AbstractAccessLogValve. (remm) * Fix: Align DIGEST authentication with RFC 7616 and require clients to provide a valid qop parameter. (markt) * Fix: Use Files API to create temporary docBase when antiLockingDocBase is enabled. (markt) * Fix: Improve validation of configuration when DataSourceRealm starts. (remm) * Fix: JAASRealm should do a logout if login does not fail outright but does not produce a Principal. (remm) * Fix: Various edge cases for SSI substitutions, quoting and escaping. (remm) * Fix: unintentional conversion of literal + to a space during rule processing in the RewriteValve. (markt) * Coyote * Fix: Avoid a potential JVM crash if a suitable version of Tomcat Native is not available when the connector is explicitly configured to use Tomcat Native with OpenSSL for TLS. (markt) * Jasper * Fix: 70120: The fix for 69399 (itself a fix for a regression in the fix for 69333) was incomplete and tags that threw exceptions in doStartTag() and doEndTag() were incorrectly re-used. This fix prevents tags from being re-used if such an exception occurs. (markt) * Fix: 70135: Fix security classload regression. (remm) * Add: support for specifying Java 28 (with the value 28) as the compiler source and/or compiler target for JSP compilation. If used with an Eclipse JDT compiler version that does not support these values, a warning will be logged and the default will be used. (markt) * WebSocket * Fix: 70126: Fix WebSocket extension permessage-deflate so that it does not drop bytes if a compressed message inflates to more than the available buffer. Fix written by GPT-5.5. Test case written by Hironori Ichimiya. (markt) * Fix: Optimise WebSocket client processing of server responses during WebSocket HTTP upgrade process. (markt) * Other * Update: Byte Buddy to 1.18.9. (markt) * Update: UnboundID to 7.0.5. (markt) * Update: JaCoCo to 0.8.15. (markt) * Update: BND to 7.3.0. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3418=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3418=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3418=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3418=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3418=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3418=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3418=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * tomcat10-jsp-3_1-api-10.1.57-150200.5.73.1 * tomcat10-admin-webapps-10.1.57-150200.5.73.1 * tomcat10-webapps-10.1.57-150200.5.73.1 * tomcat10-el-5_0-api-10.1.57-150200.5.73.1 * tomcat10-lib-10.1.57-150200.5.73.1 * tomcat10-10.1.57-150200.5.73.1 * tomcat10-servlet-6_0-api-10.1.57-150200.5.73.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * tomcat10-jsp-3_1-api-10.1.57-150200.5.73.1 * tomcat10-admin-webapps-10.1.57-150200.5.73.1 * tomcat10-webapps-10.1.57-150200.5.73.1 * tomcat10-el-5_0-api-10.1.57-150200.5.73.1 * tomcat10-lib-10.1.57-150200.5.73.1 * tomcat10-10.1.57-150200.5.73.1 * tomcat10-servlet-6_0-api-10.1.57-150200.5.73.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * tomcat10-jsp-3_1-api-10.1.57-150200.5.73.1 * tomcat10-admin-webapps-10.1.57-150200.5.73.1 * tomcat10-webapps-10.1.57-150200.5.73.1 * tomcat10-el-5_0-api-10.1.57-150200.5.73.1 * tomcat10-lib-10.1.57-150200.5.73.1 * tomcat10-10.1.57-150200.5.73.1 * tomcat10-servlet-6_0-api-10.1.57-150200.5.73.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * tomcat10-jsp-3_1-api-10.1.57-150200.5.73.1 * tomcat10-admin-webapps-10.1.57-150200.5.73.1 * tomcat10-webapps-10.1.57-150200.5.73.1 * tomcat10-el-5_0-api-10.1.57-150200.5.73.1 * tomcat10-lib-10.1.57-150200.5.73.1 * tomcat10-10.1.57-150200.5.73.1 * tomcat10-servlet-6_0-api-10.1.57-150200.5.73.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * tomcat10-jsp-3_1-api-10.1.57-150200.5.73.1 * tomcat10-admin-webapps-10.1.57-150200.5.73.1 * tomcat10-webapps-10.1.57-150200.5.73.1 * tomcat10-el-5_0-api-10.1.57-150200.5.73.1 * tomcat10-lib-10.1.57-150200.5.73.1 * tomcat10-10.1.57-150200.5.73.1 * tomcat10-servlet-6_0-api-10.1.57-150200.5.73.1 * Web and Scripting Module 15-SP7 (noarch) * tomcat10-jsp-3_1-api-10.1.57-150200.5.73.1 * tomcat10-admin-webapps-10.1.57-150200.5.73.1 * tomcat10-webapps-10.1.57-150200.5.73.1 * tomcat10-el-5_0-api-10.1.57-150200.5.73.1 * tomcat10-lib-10.1.57-150200.5.73.1 * tomcat10-10.1.57-150200.5.73.1 * tomcat10-servlet-6_0-api-10.1.57-150200.5.73.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * tomcat10-jsp-3_1-api-10.1.57-150200.5.73.1 * tomcat10-admin-webapps-10.1.57-150200.5.73.1 * tomcat10-webapps-10.1.57-150200.5.73.1 * tomcat10-el-5_0-api-10.1.57-150200.5.73.1 * tomcat10-lib-10.1.57-150200.5.73.1 * tomcat10-10.1.57-150200.5.73.1 * tomcat10-servlet-6_0-api-10.1.57-150200.5.73.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59083.html * https://www.suse.com/security/cve/CVE-2026-59084.html * https://bugzilla.suse.com/show_bug.cgi?id=1271397 * https://bugzilla.suse.com/show_bug.cgi?id=1271398 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:36:03 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:36:03 -0000 Subject: SUSE-SU-2026:3417-1: important: Security update for apptainer Message-ID: <178541496381.1210.9018398771003365832@cdce4c525ac1> # Security update for apptainer Announcement ID: SUSE-SU-2026:3417-1 Release Date: 2026-07-30T07:06:34Z Rating: important References: * bsc#1266656 * bsc#1272115 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for apptainer fixes the following issues: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266656). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272115). Changes for apptainer: * Update apptainer to version 1.5.3: * If the ptrace() system call does not work while building an image as an unprivileged user, skip using PRoot to preserve file ownership and print an INFO message. * Bind getopt from the host when using fakeroot command mode, to make the fakeroot command work with base containers which no longer contain getopt by default. * Extended the mksquashfs segmentation fault workaround for cases where mksquashfs uses many processor cores. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3417=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-3417=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3417=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3417=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * apptainer-sle15_6-1.5.3-150600.4.34.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * apptainer-1.5.3-150600.4.34.2 * apptainer-debuginfo-1.5.3-150600.4.34.2 * openSUSE Leap 15.6 (noarch) * apptainer-sle16-1.5.3-150600.4.34.2 * apptainer-leap-1.5.3-150600.4.34.2 * apptainer-sle15_7-1.5.3-150600.4.34.2 * apptainer-sle15_6-1.5.3-150600.4.34.2 * openSUSE Leap 15.6 (aarch64 x86_64) * apptainer-1.5.3-150600.4.34.2 * apptainer-suid-1.5.3-150600.4.34.2 * apptainer-debuginfo-1.5.3-150600.4.34.2 * apptainer-suid-debuginfo-1.5.3-150600.4.34.2 * SUSE Package Hub 15 15-SP7 (aarch64 x86_64) * apptainer-1.5.3-150600.4.34.2 * apptainer-suid-1.5.3-150600.4.34.2 * HPC Module 15-SP7 (noarch) * apptainer-sle15_7-1.5.3-150600.4.34.2 * HPC Module 15-SP7 (aarch64 x86_64) * apptainer-1.5.3-150600.4.34.2 * apptainer-debuginfo-1.5.3-150600.4.34.2 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266656 * https://bugzilla.suse.com/show_bug.cgi?id=1272115 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:36:59 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:36:59 -0000 Subject: SUSE-SU-2026:3416-1: important: Security update for prometheus-ha_cluster_exporter Message-ID: <178541501972.1210.11173626750624069882@cdce4c525ac1> # Security update for prometheus-ha_cluster_exporter Announcement ID: SUSE-SU-2026:3416-1 Release Date: 2026-07-30T07:04:47Z Rating: important References: * bsc#1266552 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SAP Applications Module 15-SP4 * SUSE Linux Enterprise High Availability Extension 15 SP5 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for prometheus-ha_cluster_exporter fixes the following issue: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266552). Other updates and bugfixes: * Release 1.4.2: * Use proper obs time format on changes generation. * Upgrade x/net to 0.57. * Full changelog: https://github.com/ClusterLabs/ha_cluster_exporter/compare/1.4.1...1.4.2 * Release 1.4.1: * Upgrade to use go 1.25 * Bump github.com/prometheus/common from 0.59.1 to 0.61.0. * Bump golang.org/x/net from 0.33.0 to 0.55.0. * Full changelog: https://github.com/ClusterLabs/ha_cluster_exporter/compare/1.4.0...1.4.1 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SAP Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-SAP-Applications-15-SP4-2026-3416=1 * SUSE Linux Enterprise High Availability Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2026-3416=1 * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3416=1 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-3416=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP5 (aarch64 ppc64le s390x x86_64) * prometheus-ha_cluster_exporter-1.4.2-150200.3.32.1 * SAP Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * prometheus-ha_cluster_exporter-1.4.2-150200.3.32.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * prometheus-ha_cluster_exporter-1.4.2-150200.3.32.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * prometheus-ha_cluster_exporter-1.4.2-150200.3.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266552 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:37:45 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:37:45 -0000 Subject: SUSE-SU-2026:3415-1: important: Security update for perl-DBI Message-ID: <178541506599.1210.3671098988426136365@cdce4c525ac1> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:3415-1 Release Date: 2026-07-30T06:54:43Z Rating: important References: * bsc#1271017 * bsc#1271018 * bsc#1271399 * bsc#1271458 * bsc#1271459 * bsc#1271629 Cross-References: * CVE-2026-14380 * CVE-2026-14740 * CVE-2026-15043 * CVE-2026-15392 * CVE-2026-60081 * CVE-2026-60082 CVSS scores: * CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-15043 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-15392 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60081 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60082 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-60082 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). * CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). * CVE-2026-15043: incorrect predicate evaluation in `DBI:SQL:Nano` can lead to bypass of file-backed filters (bsc#1271399). * CVE-2026-15392: missing checks to ensure the table file is not a symlink to an untrusted location in `DBD::File` allows for arbitrary file reads and writes (bsc#1271629). * CVE-2026-60081: no limiting of the path index in profile parser of `DBI:ProfileData` can enable small-file memory-amplification DoS (bsc#1271458). * CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row can lead to a process crash (bsc#1271459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3415=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3415=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3415=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3415=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-DBI-1.647.0-150600.12.18.1 * perl-DBI-debugsource-1.647.0-150600.12.18.1 * perl-DBI-debuginfo-1.647.0-150600.12.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-1.647.0-150600.12.18.1 * perl-DBI-debugsource-1.647.0-150600.12.18.1 * perl-DBI-debuginfo-1.647.0-150600.12.18.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * perl-DBI-1.647.0-150600.12.18.1 * perl-DBI-debugsource-1.647.0-150600.12.18.1 * perl-DBI-debuginfo-1.647.0-150600.12.18.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-DBI-1.647.0-150600.12.18.1 * perl-DBI-debugsource-1.647.0-150600.12.18.1 * perl-DBI-debuginfo-1.647.0-150600.12.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14380.html * https://www.suse.com/security/cve/CVE-2026-14740.html * https://www.suse.com/security/cve/CVE-2026-15043.html * https://www.suse.com/security/cve/CVE-2026-15392.html * https://www.suse.com/security/cve/CVE-2026-60081.html * https://www.suse.com/security/cve/CVE-2026-60082.html * https://bugzilla.suse.com/show_bug.cgi?id=1271017 * https://bugzilla.suse.com/show_bug.cgi?id=1271018 * https://bugzilla.suse.com/show_bug.cgi?id=1271399 * https://bugzilla.suse.com/show_bug.cgi?id=1271458 * https://bugzilla.suse.com/show_bug.cgi?id=1271459 * https://bugzilla.suse.com/show_bug.cgi?id=1271629 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:38:47 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:38:47 -0000 Subject: SUSE-SU-2026:3414-1: moderate: Security update for ImageMagick Message-ID: <178541512737.1210.12427719126476005864@cdce4c525ac1> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3414-1 Release Date: 2026-07-30T06:53:12Z Rating: moderate References: * bsc#1272575 * bsc#1272577 * bsc#1272579 * bsc#1272580 * bsc#1272582 Cross-References: * CVE-2026-25797 * CVE-2026-62343 * CVE-2026-62363 * CVE-2026-62946 * CVE-2026-66011 CVSS scores: * CVE-2026-25797 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2026-25797 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2026-25797 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62343 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-62343 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62343 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62363 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-62363 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62363 ( NVD ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62946 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-62946 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-62946 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66011 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-66011 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-66011 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66011 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575). * CVE-2026-62363: heap buffer overwrite in fx operation when processing a crafted argument (bsc#1272582). * CVE-2026-62946: integer overflow in JNX decoder can lead to heap buffer overwrite when processing extremely large files on 32-bit builds (bsc#1272580). * CVE-2026-66011: memory leak in the magick command-line interface when invalid options are provided (bsc#1272577). * code injection in HTML encoder due to incomplete fix of CVE-2026-25797 (bsc#1272579). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3414=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3414=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-7.1.1.43-150700.3.76.1 * libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.76.1 * libMagick++-devel-7.1.1.43-150700.3.76.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.76.1 * ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.76.1 * ImageMagick-config-7-SUSE-7.1.1.43-150700.3.76.1 * libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.76.1 * libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.76.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.76.1 * ImageMagick-devel-7.1.1.43-150700.3.76.1 * ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.76.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.43-150700.3.76.1 * ImageMagick-debuginfo-7.1.1.43-150700.3.76.1 * ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.76.1 * ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.76.1 * ImageMagick-debugsource-7.1.1.43-150700.3.76.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-PerlMagick-7.1.1.43-150700.3.76.1 * ImageMagick-debuginfo-7.1.1.43-150700.3.76.1 * ImageMagick-debugsource-7.1.1.43-150700.3.76.1 * perl-PerlMagick-debuginfo-7.1.1.43-150700.3.76.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25797.html * https://www.suse.com/security/cve/CVE-2026-62343.html * https://www.suse.com/security/cve/CVE-2026-62363.html * https://www.suse.com/security/cve/CVE-2026-62946.html * https://www.suse.com/security/cve/CVE-2026-66011.html * https://bugzilla.suse.com/show_bug.cgi?id=1272575 * https://bugzilla.suse.com/show_bug.cgi?id=1272577 * https://bugzilla.suse.com/show_bug.cgi?id=1272579 * https://bugzilla.suse.com/show_bug.cgi?id=1272580 * https://bugzilla.suse.com/show_bug.cgi?id=1272582 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:39:29 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:39:29 -0000 Subject: SUSE-SU-2026:3413-1: moderate: Security update for ImageMagick Message-ID: <178541516914.1210.15856850692231610328@cdce4c525ac1> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3413-1 Release Date: 2026-07-30T06:50:50Z Rating: moderate References: * bsc#1272575 * bsc#1272579 * bsc#1272580 Cross-References: * CVE-2026-25797 * CVE-2026-62343 * CVE-2026-62946 CVSS scores: * CVE-2026-25797 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2026-25797 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2026-25797 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62343 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-62343 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62343 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62946 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-62946 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-62946 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575). * CVE-2026-62946: integer overflow in JNX decoder can lead to heap buffer overwrite when processing extremely large files on 32-bit builds (bsc#1272580). * code injection in HTML encoder due to incomplete fix of CVE-2026-25797 (bsc#1272579). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3413=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3413=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-debugsource-7.1.0.9-150400.6.107.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.107.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.107.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.107.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.107.1 * perl-PerlMagick-7.1.0.9-150400.6.107.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.107.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.107.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.107.1 * libMagick++-devel-7.1.0.9-150400.6.107.1 * ImageMagick-7.1.0.9-150400.6.107.1 * ImageMagick-extra-7.1.0.9-150400.6.107.1 * ImageMagick-debugsource-7.1.0.9-150400.6.107.1 * ImageMagick-extra-debuginfo-7.1.0.9-150400.6.107.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.107.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.107.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.107.1 * ImageMagick-devel-7.1.0.9-150400.6.107.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.107.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.107.1 * openSUSE Leap 15.4 (noarch) * ImageMagick-doc-7.1.0.9-150400.6.107.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libMagick++-devel-64bit-7.1.0.9-150400.6.107.1 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.107.1 * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.107.1 * libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.107.1 * libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.107.1 * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.107.1 * libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.107.1 * ImageMagick-devel-64bit-7.1.0.9-150400.6.107.1 * openSUSE Leap 15.4 (x86_64) * libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.107.1 * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.107.1 * ImageMagick-devel-32bit-7.1.0.9-150400.6.107.1 * libMagick++-devel-32bit-7.1.0.9-150400.6.107.1 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.107.1 * libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.107.1 * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.107.1 * libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.107.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25797.html * https://www.suse.com/security/cve/CVE-2026-62343.html * https://www.suse.com/security/cve/CVE-2026-62946.html * https://bugzilla.suse.com/show_bug.cgi?id=1272575 * https://bugzilla.suse.com/show_bug.cgi?id=1272579 * https://bugzilla.suse.com/show_bug.cgi?id=1272580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 12:40:27 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 12:40:27 -0000 Subject: SUSE-SU-2026:3412-1: moderate: Security update for ImageMagick Message-ID: <178541522720.1210.5997912728904011553@cdce4c525ac1> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3412-1 Release Date: 2026-07-30T06:49:53Z Rating: moderate References: * bsc#1272575 * bsc#1272579 * bsc#1272580 Cross-References: * CVE-2026-25797 * CVE-2026-62343 * CVE-2026-62946 CVSS scores: * CVE-2026-25797 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2026-25797 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2026-25797 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62343 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-62343 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62343 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62946 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-62946 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-62946 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575). * CVE-2026-62946: integer overflow in JNX decoder can lead to heap buffer overwrite when processing extremely large files on 32-bit builds (bsc#1272580). * code injection in HTML encoder due to incomplete fix of CVE-2026-25797 (bsc#1272579). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3412=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * ImageMagick-debugsource-6.8.8.1-71.270.1 * libMagickCore-6_Q16-1-6.8.8.1-71.270.1 * ImageMagick-config-6-SUSE-6.8.8.1-71.270.1 * libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.270.1 * ImageMagick-debuginfo-6.8.8.1-71.270.1 * libMagick++-devel-6.8.8.1-71.270.1 * ImageMagick-config-6-upstream-6.8.8.1-71.270.1 * libMagickWand-6_Q16-1-6.8.8.1-71.270.1 * libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.270.1 * ImageMagick-devel-6.8.8.1-71.270.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25797.html * https://www.suse.com/security/cve/CVE-2026-62343.html * https://www.suse.com/security/cve/CVE-2026-62946.html * https://bugzilla.suse.com/show_bug.cgi?id=1272575 * https://bugzilla.suse.com/show_bug.cgi?id=1272579 * https://bugzilla.suse.com/show_bug.cgi?id=1272580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 16:30:20 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 16:30:20 -0000 Subject: SUSE-SU-2026:3430-1: important: Security update for tomcat11 Message-ID: <178542902026.1270.11725600482783104702@cdce4c525ac1> # Security update for tomcat11 Announcement ID: SUSE-SU-2026:3430-1 Release Date: 2026-07-30T11:20:51Z Rating: important References: * bsc#1271397 * bsc#1271398 Cross-References: * CVE-2026-59083 * CVE-2026-59084 CVSS scores: * CVE-2026-59083 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-59083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-59084 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-59084 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for tomcat11 fixes the following issues: Update to Tomcat 11.0.24. Security issues fixed: * CVE-2026-59083: incorrect URL decoding in `RewriteValve` may allow security control bypass (bsc#1271397). * CVE-2026-59084: `EncryptInterceptor` requirements are not clearly documented (bsc#1271398). Other updates and bugfixes: * Tomcat 11.0.24: * Catalina * Fix: Avoid a race condition with concurrent lookups for a singleton JNDI resource. (markt) * Fix: Improve the performance of range validation for the default servlet. (markt) * Fix: Avoid NPE in RewriteValve. (markt) * Fix: 70127: Fix use of Bootstrap through reflection by restoring the public constructor. Use through scripts was not affected. (remm) * Fix: Restore ability to extend many element classes from AbstractAccessLogValve. (remm) * Fix: Align DIGEST authentication with RFC 7616 and require clients to provide a valid qop parameter. (markt) * Fix: Use Files API to create temporary docBase when antiLockingDocBase is enabled. (markt) * Fix: Improve validation of configuration when DataSourceRealm starts. (remm) * Fix: JAASRealm should do a logout if login does not fail outright but does not produce a Principal. (remm) * Fix: Various edge cases for SSI substitutions, quoting and escaping. * Fix: unintentional conversion of literal + to a space during rule processing in the RewriteValve. (markt) * Coyote * Fix: Avoid a potential JVM crash if a suitable version of Tomcat Native is not available when the connector is explicitly configured to use Tomcat Native with OpenSSL for TLS. (markt) * Jasper * Fix: 70120: The fix for 69399 (itself a fix for a regression in the fix for 69333) was incomplete and tags that threw exceptions in doStartTag() and doEndTag() were incorrectly re-used. This fix prevents tags from being re-used if such an exception occurs. (markt) * Add: support for specifying Java 28 (with the value 28) as the compiler source and/or compiler target for JSP compilation. If used with an Eclipse JDT compiler version that does not support these values, a warning will be logged and the default will be used. (markt) * WebSocket * Fix: 70126: Fix WebSocket extension permessage-deflate so that it does not drop bytes if a compressed message inflates to more than the available buffer. Fix written by GPT-5.5. Test case written by Hironori Ichimiya. (markt) * Fix: Optimise WebSocket client processing of server responses during WebSocket HTTP upgrade process. (markt) * Other * Update: to the Eclipse JDT compiler 4.40. (markt) * Update: Byte Buddy to 1.18.9. (markt) * Update: UnboundID to 7.0.5. (markt) * Update: JaCoCo to 0.8.15. (markt) * Update: BND to 7.3.0. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3430=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3430=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3430=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3430=1 ## Package List: * Web and Scripting Module 15-SP7 (noarch) * tomcat11-11.0.24-150600.13.27.1 * tomcat11-el-6_0-api-11.0.24-150600.13.27.1 * tomcat11-webapps-11.0.24-150600.13.27.1 * tomcat11-jsp-4_0-api-11.0.24-150600.13.27.1 * tomcat11-servlet-6_1-api-11.0.24-150600.13.27.1 * tomcat11-admin-webapps-11.0.24-150600.13.27.1 * tomcat11-lib-11.0.24-150600.13.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * tomcat11-11.0.24-150600.13.27.1 * tomcat11-el-6_0-api-11.0.24-150600.13.27.1 * tomcat11-webapps-11.0.24-150600.13.27.1 * tomcat11-jsp-4_0-api-11.0.24-150600.13.27.1 * tomcat11-servlet-6_1-api-11.0.24-150600.13.27.1 * tomcat11-admin-webapps-11.0.24-150600.13.27.1 * tomcat11-lib-11.0.24-150600.13.27.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * tomcat11-11.0.24-150600.13.27.1 * tomcat11-el-6_0-api-11.0.24-150600.13.27.1 * tomcat11-webapps-11.0.24-150600.13.27.1 * tomcat11-jsp-4_0-api-11.0.24-150600.13.27.1 * tomcat11-servlet-6_1-api-11.0.24-150600.13.27.1 * tomcat11-admin-webapps-11.0.24-150600.13.27.1 * tomcat11-lib-11.0.24-150600.13.27.1 * openSUSE Leap 15.6 (noarch) * tomcat11-11.0.24-150600.13.27.1 * tomcat11-embed-11.0.24-150600.13.27.1 * tomcat11-jsvc-11.0.24-150600.13.27.1 * tomcat11-el-6_0-api-11.0.24-150600.13.27.1 * tomcat11-docs-webapp-11.0.24-150600.13.27.1 * tomcat11-doc-11.0.24-150600.13.27.1 * tomcat11-webapps-11.0.24-150600.13.27.1 * tomcat11-jsp-4_0-api-11.0.24-150600.13.27.1 * tomcat11-servlet-6_1-api-11.0.24-150600.13.27.1 * tomcat11-admin-webapps-11.0.24-150600.13.27.1 * tomcat11-lib-11.0.24-150600.13.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59083.html * https://www.suse.com/security/cve/CVE-2026-59084.html * https://bugzilla.suse.com/show_bug.cgi?id=1271397 * https://bugzilla.suse.com/show_bug.cgi?id=1271398 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 16:31:24 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 16:31:24 -0000 Subject: SUSE-SU-2026:3429-1: moderate: Security update for libarchive Message-ID: <178542908499.1270.16695039692339458018@cdce4c525ac1> # Security update for libarchive Announcement ID: SUSE-SU-2026:3429-1 Release Date: 2026-07-30T11:18:19Z Rating: moderate References: * bsc#1254340 * bsc#1254341 * bsc#1260998 * bsc#1261002 * bsc#1261003 Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has five security fixes can now be installed. ## Description: This update for libarchive fixes the following issues: * Creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340). * File descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003). * NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998). * Reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341). * Incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3429=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3429=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3429=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * bsdtar-debuginfo-3.7.2-150600.3.23.1 * libarchive-devel-3.7.2-150600.3.23.1 * libarchive13-debuginfo-3.7.2-150600.3.23.1 * libarchive-debugsource-3.7.2-150600.3.23.1 * bsdtar-3.7.2-150600.3.23.1 * libarchive13-3.7.2-150600.3.23.1 * openSUSE Leap 15.6 (x86_64) * libarchive13-32bit-3.7.2-150600.3.23.1 * libarchive13-32bit-debuginfo-3.7.2-150600.3.23.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libarchive13-64bit-3.7.2-150600.3.23.1 * libarchive13-64bit-debuginfo-3.7.2-150600.3.23.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libarchive13-debuginfo-3.7.2-150600.3.23.1 * libarchive-debugsource-3.7.2-150600.3.23.1 * libarchive-devel-3.7.2-150600.3.23.1 * libarchive13-3.7.2-150600.3.23.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libarchive-debugsource-3.7.2-150600.3.23.1 * bsdtar-debuginfo-3.7.2-150600.3.23.1 * bsdtar-3.7.2-150600.3.23.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1254340 * https://bugzilla.suse.com/show_bug.cgi?id=1254341 * https://bugzilla.suse.com/show_bug.cgi?id=1260998 * https://bugzilla.suse.com/show_bug.cgi?id=1261002 * https://bugzilla.suse.com/show_bug.cgi?id=1261003 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 16:32:20 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 16:32:20 -0000 Subject: SUSE-SU-2026:3428-1: low: Security update for runc Message-ID: <178542914035.1270.4113438425722139829@cdce4c525ac1> # Security update for runc Announcement ID: SUSE-SU-2026:3428-1 Release Date: 2026-07-30T11:16:04Z Rating: low References: * bsc#1268275 Cross-References: * CVE-2026-41579 CVSS scores: * CVE-2026-41579 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-41579 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for runc fixes the following issues: Update to 1.3.6. * CVE-2026-41579: malicious image with a `/dev` symlink can trigger limited host filesystem integrity violations (bsc#1268275). Other updates and bugfixes: * Version 1.3.6: * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). * Version 1.3.5: * Recursive atime-related mount flags (rrelatime et al.) are now applied properly. * PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted. * Updated builds to Go 1.25, libseccomp v2.6.0. * Minor signing keyring updates. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3428=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * runc-debuginfo-1.3.6-16.76.1 * runc-1.3.6-16.76.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41579.html * https://bugzilla.suse.com/show_bug.cgi?id=1268275 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 16:33:00 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 16:33:00 -0000 Subject: SUSE-SU-2026:3427-1: important: Security update for valkey Message-ID: <178542918052.1270.16976310100003441300@cdce4c525ac1> # Security update for valkey Announcement ID: SUSE-SU-2026:3427-1 Release Date: 2026-07-30T11:13:55Z Rating: important References: * bsc#1272442 * bsc#1272443 Cross-References: * CVE-2026-56684 * CVE-2026-63639 CVSS scores: * CVE-2026-56684 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63639 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for valkey fixes the following issues: * CVE-2026-56684: use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (bsc#1272443). * CVE-2026-63639: corrupt stream RDB files containing a shared NACK across consumers can lead to remote code execution (bsc#1272442). Changes for valkey: * Update to 8.0.10. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3427=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * valkey-debugsource-8.0.10-150700.3.20.1 * valkey-8.0.10-150700.3.20.1 * valkey-debuginfo-8.0.10-150700.3.20.1 * valkey-devel-8.0.10-150700.3.20.1 * Server Applications Module 15-SP7 (noarch) * valkey-compat-redis-8.0.10-150700.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56684.html * https://www.suse.com/security/cve/CVE-2026-63639.html * https://bugzilla.suse.com/show_bug.cgi?id=1272442 * https://bugzilla.suse.com/show_bug.cgi?id=1272443 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 16:33:50 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 16:33:50 -0000 Subject: SUSE-SU-2026:3426-1: important: Security update for bind Message-ID: <178542923006.1270.6943108902205252483@cdce4c525ac1> # Security update for bind Announcement ID: SUSE-SU-2026:3426-1 Release Date: 2026-07-30T11:12:13Z Rating: important References: * bsc#1271982 * bsc#1271983 * bsc#1271984 * bsc#1271985 * bsc#1271986 * bsc#1271987 * bsc#1271988 * bsc#1271989 * bsc#1271990 Cross-References: * CVE-2026-10723 * CVE-2026-10822 * CVE-2026-11331 * CVE-2026-11605 * CVE-2026-11622 * CVE-2026-11721 * CVE-2026-12617 * CVE-2026-13204 * CVE-2026-13321 CVSS scores: * CVE-2026-10723 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10822 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10822 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-10822 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-11331 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11605 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11605 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11605 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11721 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-12617 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12617 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12617 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13321 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: Upgrade to release 9.20.26. Security issues fixed: * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-10822: key record using PRIVATEDNS algorithm may lead to unexpected exit (bsc#1271983). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11605: unnecessary validation of DNSSEC signed records (bsc#1271985). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987). * CVE-2026-12617: record ordering based unexpected exit with CNAME or DNAME (bsc#1271988). * CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989). * CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990). Other updates and bugfixes: * Release 9.20.26: * Reclaim memory promptly when DNSSEC validations are canceled. * Removed Features: * Remove the secondary validator in query.c. * Remove ineffective TCP fallback after repeated UDP timeouts. * Feature Changes: * Fall back to TCP on receipt of a UDP response with a mismatched query ID. * Limit the number of glue records cached from a referral. * Fix a resolver stall on a CNAME response to a DS query. * Bug Fixes: * Fix a bug in DNS UPDATE processing with inline-signing enabled. * Properly detect private records before copying. * Tighten referral DS acceptance. * Don't synthesize negative responses with pending NSEC. * Check that an NSEC signer is at or above the name to be validated. * Don't evict DNSSEC-validated cache data on a CD=1 NXDOMAIN. * Fix a deny-answer-aliases configuration bypass issue. * Reject external referrals from forwarders. * Fix a zone transfer over TLS (XoT) issue when using the opportunistic TLS mode. * Unvalidated opt-out NSEC3 could be accepted in insecurity proof. * Check wildcard signer and NOQNAME signer match. * Fix CNAME resolution failure caused by a cached SERVFAIL response. * Reject unsupported RSA DNSKEY shapes during DNSSEC validation. * Fix a bug in GeoIP2 string matching. * Fix DNS-over-HTTPS (DoH) quota configuration issue. * Truncated reply to a TSIG query no longer stalls the resolver. * Ignore updates removing DNSKEY RRset with class ANY. * Ignore 0-byte reads in the TCP read callback. * Only print per-zone glue stats when zone-statistics is set to full. * CDS/CDNSKEY records were not removed when re-configuring the server. * Fix a crash when querying an empty non-terminal in a wildcard zone in RBTDB. * Stop reusing outgoing TCP connections the peer has already closed. * Fix DNSSEC validation failures for names under an apex DNAME. * The resolver now removes other RRsets at the same name when caching a CNAME. * Fix nxdomain-redirect combined with dns64. * Fix DNS64 owner case after DNAME restart. * Clear REDIRECT flag when it isn't needed. * Disable output escaping in bind9.xsl. * Fix crash on badly configured secondary signer. * Fix a possible crash on concurrent TKEY DELETE for the same key. * Reject RRSIG records covering meta-types. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3426=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3426=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * bind-utils-9.20.26-150700.3.29.1 * bind-debugsource-9.20.26-150700.3.29.1 * bind-utils-debuginfo-9.20.26-150700.3.29.1 * bind-debuginfo-9.20.26-150700.3.29.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * bind-debuginfo-9.20.26-150700.3.29.1 * bind-debugsource-9.20.26-150700.3.29.1 * bind-9.20.26-150700.3.29.1 * Server Applications Module 15-SP7 (noarch) * bind-doc-9.20.26-150700.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10723.html * https://www.suse.com/security/cve/CVE-2026-10822.html * https://www.suse.com/security/cve/CVE-2026-11331.html * https://www.suse.com/security/cve/CVE-2026-11605.html * https://www.suse.com/security/cve/CVE-2026-11622.html * https://www.suse.com/security/cve/CVE-2026-11721.html * https://www.suse.com/security/cve/CVE-2026-12617.html * https://www.suse.com/security/cve/CVE-2026-13204.html * https://www.suse.com/security/cve/CVE-2026-13321.html * https://bugzilla.suse.com/show_bug.cgi?id=1271982 * https://bugzilla.suse.com/show_bug.cgi?id=1271983 * https://bugzilla.suse.com/show_bug.cgi?id=1271984 * https://bugzilla.suse.com/show_bug.cgi?id=1271985 * https://bugzilla.suse.com/show_bug.cgi?id=1271986 * https://bugzilla.suse.com/show_bug.cgi?id=1271987 * https://bugzilla.suse.com/show_bug.cgi?id=1271988 * https://bugzilla.suse.com/show_bug.cgi?id=1271989 * https://bugzilla.suse.com/show_bug.cgi?id=1271990 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 16:34:28 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 16:34:28 -0000 Subject: SUSE-SU-2026:3425-1: important: Security update for python-urwid Message-ID: <178542926892.1270.6592633246822677162@cdce4c525ac1> # Security update for python-urwid Announcement ID: SUSE-SU-2026:3425-1 Release Date: 2026-07-30T11:11:36Z Rating: important References: * bsc#1271868 Cross-References: * CVE-2026-9323 CVSS scores: * CVE-2026-9323 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9323 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9323 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-urwid fixes the following issue CVE-2026-9323: web session IDs generated by `Screen.start()` are not cryptographically secure (bsc#1271868). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3425=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3425=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3425=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3425=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3425=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3425=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3425=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3425=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3425=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3425=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3425=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3425=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-urwid-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-urwid-debuginfo-2.1.2-150400.11.6.1 * python311-urwid-2.1.2-150400.11.6.1 * python-urwid-debugsource-2.1.2-150400.11.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9323.html * https://bugzilla.suse.com/show_bug.cgi?id=1271868 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 30 16:35:24 2026 From: null at suse.de (SLE-UPDATES) Date: Thu, 30 Jul 2026 16:35:24 -0000 Subject: SUSE-SU-2026:3424-1: low: Security update for python3-pyOpenSSL Message-ID: <178542932478.1270.16749788318507010507@cdce4c525ac1> # Security update for python3-pyOpenSSL Announcement ID: SUSE-SU-2026:3424-1 Release Date: 2026-07-30T11:07:53Z Rating: low References: * bsc#1259804 Cross-References: * CVE-2026-27448 CVSS scores: * CVE-2026-27448 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27448 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-27448 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27448 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python3-pyOpenSSL fixes the following issue: * CVE-2026-27448: unhandled exception in `set_tlsext_servername_callback` callback can result in connection not being cancelled and allows for possible security measure bypassing (bsc#1259804). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3424=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3424=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3424=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3424=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3424=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3424=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3424=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-pyOpenSSL-21.0.0-150400.22.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-pyOpenSSL-21.0.0-150400.22.1 * openSUSE Leap 15.4 (noarch) * python3-pyOpenSSL-21.0.0-150400.22.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-pyOpenSSL-21.0.0-150400.22.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-pyOpenSSL-21.0.0-150400.22.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-pyOpenSSL-21.0.0-150400.22.1 * Basesystem Module 15-SP7 (noarch) * python3-pyOpenSSL-21.0.0-150400.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27448.html * https://bugzilla.suse.com/show_bug.cgi?id=1259804 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 31 08:30:22 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 31 Jul 2026 08:30:22 -0000 Subject: SUSE-SU-2026:3435-1: moderate: Security update for python-sqlparse Message-ID: <178548662293.1494.2018874229475641079@cdce4c525ac1> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:3435-1 Release Date: 2026-07-30T19:04:44Z Rating: moderate References: * bsc#1268597 Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for python-sqlparse fixes the following issue * Fixed an issue where formatting list of tuples leads to denial of service (bsc#1268597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3435=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3435=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3435=1 ## Package List: * Public Cloud Module 15-SP6 (noarch) * python311-sqlparse-0.4.4-150600.3.6.1 * Python 3 Module 15-SP7 (noarch) * python311-sqlparse-0.4.4-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * python311-sqlparse-0.4.4-150600.3.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 31 08:31:20 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 31 Jul 2026 08:31:20 -0000 Subject: SUSE-SU-2026:3434-1: moderate: Security update for python-sqlparse Message-ID: <178548668016.1494.14792663490526192364@cdce4c525ac1> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:3434-1 Release Date: 2026-07-30T19:04:11Z Rating: moderate References: * bsc#1268597 Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has one security fix can now be installed. ## Description: This update for python-sqlparse fixes the following issue * Fixed an issue where formatting list of tuples leads to denial of service (bsc#1268597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3434=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3434=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3434=1 ## Package List: * Public Cloud Module 15-SP5 (noarch) * python311-sqlparse-0.4.4-150400.6.13.1 * Public Cloud Module 15-SP4 (noarch) * python311-sqlparse-0.4.4-150400.6.13.1 * openSUSE Leap 15.4 (noarch) * python311-sqlparse-0.4.4-150400.6.13.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 31 08:32:19 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 31 Jul 2026 08:32:19 -0000 Subject: SUSE-SU-2026:3433-1: low: Security update for runc Message-ID: <178548673994.1494.12177960698739910378@cdce4c525ac1> # Security update for runc Announcement ID: SUSE-SU-2026:3433-1 Release Date: 2026-07-30T18:54:54Z Rating: low References: * bsc#1268275 Cross-References: * CVE-2026-41579 CVSS scores: * CVE-2026-41579 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-41579 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for runc fixes the following issues: Update to 1.3.6. * CVE-2026-41579: malicious image with a `/dev` symlink can trigger limited host filesystem integrity violations (bsc#1268275). Other updates and bugfixes: * Version 1.3.6: * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). * Version 1.3.5: * Recursive atime-related mount flags (rrelatime et al.) are now applied properly. * PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted. * Updated builds to Go 1.25, libseccomp v2.6.0. * Minor signing keyring updates. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3433=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3433=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3433=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3433=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3433=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3433=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2026-3433=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * runc-1.3.6-150000.101.1 * runc-debuginfo-1.3.6-150000.101.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * runc-1.3.6-150000.101.1 * runc-debuginfo-1.3.6-150000.101.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * runc-1.3.6-150000.101.1 * runc-debuginfo-1.3.6-150000.101.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * runc-1.3.6-150000.101.1 * runc-debuginfo-1.3.6-150000.101.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * runc-1.3.6-150000.101.1 * runc-debuginfo-1.3.6-150000.101.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * runc-1.3.6-150000.101.1 * runc-debuginfo-1.3.6-150000.101.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * runc-1.3.6-150000.101.1 * runc-debuginfo-1.3.6-150000.101.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41579.html * https://bugzilla.suse.com/show_bug.cgi?id=1268275 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 31 08:33:05 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 31 Jul 2026 08:33:05 -0000 Subject: SUSE-SU-2026:3432-1: important: Security update for google-osconfig-agent Message-ID: <178548678530.1494.11753900484495630405@cdce4c525ac1> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:3432-1 Release Date: 2026-07-30T18:51:13Z Rating: important References: * bsc#1266603 * bsc#1272118 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for google-osconfig-agent fixes the following issues * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1272118). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3432=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3432=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3432=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3432=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3432=1 ## Package List: * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260615.01-150000.1.60.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260615.01-150000.1.60.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260615.01-150000.1.60.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260615.01-150000.1.60.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260615.01-150000.1.60.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266603 * https://bugzilla.suse.com/show_bug.cgi?id=1272118 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 31 08:33:44 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 31 Jul 2026 08:33:44 -0000 Subject: SUSE-SU-2026:3431-1: important: Security update for perl-Net-DNS Message-ID: <178548682406.1494.6221761404838201299@cdce4c525ac1> # Security update for perl-Net-DNS Announcement ID: SUSE-SU-2026:3431-1 Release Date: 2026-07-30T18:50:16Z Rating: important References: * bsc#1272214 Cross-References: * CVE-2026-64194 CVSS scores: * CVE-2026-64194 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Net-DNS fixes the following issue * CVE-2026-64194: RFC 1035 compression pointers are followed via recursion with no depth limit established, which can lead to DoS when specially crafted DNS packets are parsed (bsc#1272214). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3431=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3431=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-Net-DNS-debugsource-0.73-5.3.1 * perl-Net-DNS-debuginfo-0.73-5.3.1 * perl-Net-DNS-0.73-5.3.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * perl-Net-DNS-debugsource-0.73-5.3.1 * perl-Net-DNS-debuginfo-0.73-5.3.1 * perl-Net-DNS-0.73-5.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64194.html * https://bugzilla.suse.com/show_bug.cgi?id=1272214 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 31 20:30:21 2026 From: null at suse.de (SLE-UPDATES) Date: Fri, 31 Jul 2026 20:30:21 -0000 Subject: SUSE-RU-2026:3436-1: important: Recommended update for resource-agents Message-ID: <178552982100.19188.16835037229137767551@378bb9517b82> # Recommended update for resource-agents Announcement ID: SUSE-RU-2026:3436-1 Release Date: 2026-07-31T14:59:43Z Rating: important References: * bsc#1251836 * bsc#1269009 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has two fixes can now be installed. ## Description: This update for resource-agents fixes the following issues: * Fix: L3: Backport upstream commit resource-agents (bsc#1269009) * Fix: ec2 and awsvip resource agent's retry mechanism for AWS monitoring (bsc#1251836) * Add auth_type parameter and AWS Policy based authentication type ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-3436=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3436=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * ldirectord-4.10.0+git40.0f4de473-150400.3.42.1 * resource-agents-debuginfo-4.10.0+git40.0f4de473-150400.3.42.1 * resource-agents-4.10.0+git40.0f4de473-150400.3.42.1 * resource-agents-debugsource-4.10.0+git40.0f4de473-150400.3.42.1 * openSUSE Leap 15.4 (noarch) * monitoring-plugins-metadata-4.10.0+git40.0f4de473-150400.3.42.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * ldirectord-4.10.0+git40.0f4de473-150400.3.42.1 * resource-agents-debuginfo-4.10.0+git40.0f4de473-150400.3.42.1 * resource-agents-4.10.0+git40.0f4de473-150400.3.42.1 * resource-agents-debugsource-4.10.0+git40.0f4de473-150400.3.42.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (noarch) * monitoring-plugins-metadata-4.10.0+git40.0f4de473-150400.3.42.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1251836 * https://bugzilla.suse.com/show_bug.cgi?id=1269009 -------------- next part -------------- An HTML attachment was scrubbed... URL: